Back to The LibraryWhat's inside Related artifacts
Artifact 05Coming later· Document
Threat Model
Prompt injection, exfiltration, model abuse — and the controls for each.
A STRIDE-style threat model written specifically for LLM-backed applications. Lists residual risks and the control evidence your CISO can reference in their risk register.
01
LLM-specific threats
- Prompt injection (direct and indirect)
- Training data poisoning
- Model exfiltration
- Output handling and downstream injection
02
STRIDE per component
- Application layer
- Inference gateway
- Foundation model
- Logging and audit pipeline
03
Residual risk register
- Per-threat control evidence and owner
- Severity, likelihood, residual rating
Phase 4 — qualified release
Threat Model is released after a qualified conversation.
This artifact carries enough operational detail that we walk it through with you personally before release. Book a deep dive with our team — sixty minutes, your regulatory context, your stack, your data class.