TrustStencil
Build inspectable trust-boundary maps, derive architecture prompts, prioritize STRIDE threats, trace attack paths, and export a private review packet.
Focused field tools
Name the system boundary, crown-jewel assets, excluded components, review owner, and decision being supported.
Record where identity, administration, tenancy, network, or operational authority changes.
Keep source, destination, payload, protocol, direction, authentication, encryption, and boundary crossing explicit.
Use spoofing, tampering, repudiation, disclosure, denial, and elevation as prompts rather than a substitute for architecture knowledge.
Distinguish human, workload, device, and partner identity plus issuance, rotation, revocation, and replay controls.
Map each privileged operation to a policy decision, enforcement point, resource, and audit record.
TrustStencil structures threat-model evidence; it does not prove a system secure. Validate architecture, assets, assumptions, controls, test evidence, and residual risk with the accountable security team.