# Threat model

## Scope and assets

- System/version and deployment boundary:
- Protected data, authority, money, availability, models, and reputation:
- Explicitly excluded systems:

## Actors and trust boundaries

- Users, operators, tenants, providers, tools, content sources, and suppliers:
- Authentication and delegated authorization paths:
- Diagram/reference:

## Data and effect flows

- Untrusted inputs and instruction-bearing content:
- Secrets and sensitive outputs:
- Externally visible or irreversible actions:

## Abuse cases

| Threat | Preconditions | Path | Impact | Existing control | Residual risk |
|---|---|---|---|---|---|

## Validation

- Attack suite and environment:
- Containment/effect metrics:
- Open findings, owner, severity, and due date:

