Back to The Library
Artifact 05Coming later· Document

Threat Model

Prompt injection, exfiltration, model abuse — and the controls for each.

A STRIDE-style threat model written specifically for LLM-backed applications. Lists residual risks and the control evidence your CISO can reference in their risk register.

What's inside
01

LLM-specific threats

  • Prompt injection (direct and indirect)
  • Training data poisoning
  • Model exfiltration
  • Output handling and downstream injection
02

STRIDE per component

  • Application layer
  • Inference gateway
  • Foundation model
  • Logging and audit pipeline
03

Residual risk register

  • Per-threat control evidence and owner
  • Severity, likelihood, residual rating
Phase 4 — qualified release

Threat Model is released after a qualified conversation.

This artifact carries enough operational detail that we walk it through with you personally before release. Book a deep dive with our team — sixty minutes, your regulatory context, your stack, your data class.

Related artifacts