NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

SecEng Threat CanvasAI Threat Modeling
by SecEng › DFD canvas · STRIDE · Jira + Confluence
2 high risksCanvas demo
SecEng Threat Canvas — AI Work Item Copilot
THREAT CANVAS
Active Model
AI Work Item Copilot
tm-2026-0527-copilot
Atlassian ForgeConfluence RAGOpenAI GPT-4o
Trust Zones

Security Data Flow Canvas

AI Work Item Copilot

15 nodes·16 flows·5 trust boundaries

Public Internet

Unauthenticated external principals

Atlassian App Zone

Forge-hosted application services

AI Processing Zone

AI orchestration, retrieval, and model calls

Knowledge Platform

Persistent data stores and evidence sinks

External Providers

Third-party AI model and integration endpoints

Trust Boundary Crossings · 8 flows

ReporterApp GatewayHTTPS / auth'd request
Malicious ReporterApp GatewayCrafted issue payload
Issue ServiceAI OrchestratorAI trigger
Confluence RetrieverVector StoreEmbedding similarity
Prompt BuilderLLM GatewayAssembled prompt
LLM GatewayOpenAI GPT-4oModel API call
Tool ExecutorIssue StoreWrite issue / comment
AI OrchestratorAudit LogAction event
tm-2026-0527-copilot2 high · 4 open·15 nodes · 5 zones·Evidence: 22%SecEng Threat Canvas v0.1.0

Grounded Attack Paths (APC) — from this threat model

1 attack paths1 tools in this fixture15 evidence-graph nodes16 evidence-graph edges

Evidence from this surface, normalized and joined into the shared SecEng evidence graph. Every step traces to a specific tool’s output; grounded steps were observed or deterministically derived.

Adding a mandatory approval/control at tc:n-gateway blocks 1 of 1 analyzed paths.

  • Groundedattack· conf 38%33threat-canvas
    Malicious ReporterApp GatewayIssue ServiceAI OrchestratorTool Policy GateTool ExecutorIssue Store
    owasp_llm:LLM01owasp_llm:LLM06
LegendGroundedInferredSpeculativeOpen Evidence Graph

SecEng Threat Canvas · model metadata

Atlassian ForgeConfluence RAGOpenAI GPT-4oJira ActionsAudit Log
Target: AI Work Item CopilotRun: tm-2026-0527-copilotModelled: 5/27/2026Reviewer: Product SecuritySecEng Threat Canvas · v0.1.0