Publication DSL
Compiler repair proof gallery
Six canonical figures rendered through six different, contract-validated geometries.
SP-01
layered cutaway
Keep the scanner. Add the finding and evidence plane.
The scanner remains the product surface while SecEng adds AI-native finding depth, evidence discipline, attack-path context, and lifecycle support.
The scanner remains the product surface while SecEng adds AI-native finding depth, evidence discipline, attack-path context, and lifecycle support.
AC-03
swimlane
One course. One platform. One distribution pilot.
A bounded pilot packages one representative course, validates it in the target LMS or marketplace workflow, and returns the operational assets needed for launch.
A bounded pilot packages one representative course, validates it in the target LMS or marketplace workflow, and returns the operational assets needed for launch.
APC-04
directed topology
Throughline Value Proposition
Throughline qualifies and explains multi-step risk rather than merely correlating alerts or drawing speculative paths.
Comparison between alert correlation and evidence-qualified attack-path analysis with explicit validation and residual state.
TECH-04
radial orbit
Integration Family Map
Technology partnerships span data sources, scanners, offensive platforms, identity systems, workflow tools, and evidence consumers.
Ecosystem map of technology partner families surrounding shared SecEng contracts and evidence.
- Findings, evidence, traces, and lifecycle contracts
- Identity, provenance, and versioning
- Read, enrich, and return workflows
- Scoped API access and approval boundaries
SCN-01
matrix heatmap
AI-Native Scanner Coverage
The scanner evaluates AI-specific code and workflow surfaces that conventional AppSec categories do not fully describe.
Matrix showing scanner coverage across prompts, retrieval, agents, tools, MCP, authority, evidence, and lifecycle stages.
| Discovery | Analysis | Evidence | Retest | |
|---|---|---|---|---|
| Prompts and instructionsSystem prompts, templates, policy text, and instruction boundaries. | Covered | Covered | Covered | Covered |
| Retrieval and contextCorpus access, provenance, tenant boundaries, and prompt assembly. | Covered | Covered | Covered | Partial |
| Agents and orchestrationPlanning, delegation, memory, and workflow transitions. | Covered | Partial | Partial | Planned |
| Tools and MCPTool schemas, invocation boundaries, and consequence-bearing actions. | Covered | Covered | Covered | Partial |
| Identity and authorityUser, agent, service, and delegated permissions. | Covered | Partial | Partial | Planned |
| Evidence and lifecycleFinding state, provenance, remediation, and rescan behavior. | Not applicable | Covered | Covered | Covered |
EVD-03
evidence dossier
Claim State Boundary
Observed, reproduced, grounded, inferred, rejected, and analyst-reviewed claims must remain visibly distinct.
Diagram showing observations and reproductions, grounded claims, review boundary, explicit inference, rejected claims, and analyst-reviewed publication state.