Skip to content
SecHelixSecurity / Attack Surface
Canonical demonstration dataFixture

Security digital twin

See the boundaries before testing them.

Identity, entrypoints, stores, privileged actors, and external providers in one explainable graph.
attack-surface-v1 / demo-store
Entrypoints38routes · jobs · webhooks
Trust boundaries6explicitly mapped
Identities4guest · user · staff · admin
Unknowns3require evidence — never absence
Trust graph

demo-store / digital twin

mapped fixture
Data flow Trust boundary Needs evidence Selected
Priority

Boundaries needing evidence

  1. 01
    seller → repositoryownership predicate is security-critical
  2. 02
    app → provideroutcome-unknown state must fail closed
  3. 03
    agent → toolwrite authority needs an explicit policy
Why it matters

Applicability comes from architecture, not a generic checklist.

The graph is the input to SecHelix check selection. Missing evidence stays unknown; it is never treated as absence.

Open Authorization Matrix