graphs.sgit.aithe evidence estate › Scaling Threat Modeling with Semantic Knowledge Graphs

Scaling Threat Modeling with Semantic Knowledge Graphs

Eleven linked threat models stacked from the customer to the compute instance, so a flaw in one method can be traced to the revenue it threatens.

Vault 0ict6flm · on the sgit.ai ladder this is the system, all the way down to the compute instance. The read key is printed on the vault’s own page and is the whole credential; it is not repeated here, because a credential copied is a credential that goes stale somewhere.

Read from a page, not from the vault. This estate cannot open an encrypted vault: the read key is the whole credential and nothing in this build can decrypt one. Every number below is quoted from the page sgit.ai publishes about this vault, carried here whole at sources/threatmodcon-2025.md (7,521 bytes, SHA-256 3535cbcdf11f70f9…, fetched 2026-09-20T00:25:51Z), and the build fails if a quotation is not in that file byte for byte. The first edition’s five vault analyses were written by opening the vaults; these four were not, and that difference is worth more than the convenience of hiding it.

Why this one is here

This is the answer to how far down, and it is the rung the first edition's worked examples never reached. They stop at the estate; this reaches the method and the runtime.

The reading

The hub states the argument and then counts it: eleven readable layers, and a hundred and seventy-nine threats across them.

11 readable layers, 51 nodes, 179 threats, 3 critical

The ladder runs from the customer to the compute instance, each layer carrying its own counts.

The zoom ladder runs Customer → Business → Application → Component → Package → Class → Method → Source Code → Environment → Runtime → Compute

And it is precise about why stacking them is the point, which is the same argument this site makes about altitude.

One model answers what could go wrong here. Eleven linked models answer what does this line of code put at risk, which is a different question and the one an executive is actually asking.

One critical finding is written four ways for four readers, all derived from one model rather than written four times.

the finding does not change, the framing does, and both are derived from one underlying model rather than written four times by hand

What it says about itself

The vault’s own caveat. The bottom rungs are modelled rather than imported. The sgit.ai ladder says so plainly about this vault, and it is the honest limit of the demonstration.