> threat-model
Where it breaks
Describe what you have built. You will get back the same first pass I run before I touch anyone's system: the entry points, the risks that actually apply to your stack, and what a paragraph of text cannot tell either of us.
- 01
You describe it
Stack, users, what data it touches. Two lines is enough; more is better.
- 02
It reads it as an attacker
Entry points first, then the risks that follow from what you actually run.
- 03
You get the honest limit
It will tell you what a description cannot reveal. Nothing is scanned, nothing is stored.