Security digital twin
See the boundaries before testing them.
Identity, entrypoints, stores, privileged actors, and external providers in one explainable graph.attack-surface-v1 / demo-storeTrust graph
mapped fixturedemo-store / digital twin
Priority
Boundaries needing evidence
- 01seller → repositoryownership predicate is security-critical
- 02app → provideroutcome-unknown state must fail closed
- 03agent → toolwrite authority needs an explicit policy
Applicability comes from architecture, not a generic checklist.
The graph is the input to SecHelix check selection. Missing evidence stays unknown; it is never treated as absence.
Open Authorization Matrix