Jump go di content

Di Threat Model

Formal threat model dey document risk like prompt injection, SSRF, and data exfiltration, with control dem and owner accountability.

Prompt injection attack

Strict system prompt, RAG grounding, and refusal logic dey limit answer wey comot from scope.

SSRF through knowledge-ingestion service

Domain allowlist dem and outbound egress control dey block internal abi metadata target.

XSS and how dem dey clean content

Input wey dem sanitize, CSP header, and safe HTML-to-text normalization dey reduce exposure.

To thief data comot

Tenant isolation, encryption, and audit log dey protect customer data and trace access.

Risk wey dey come from supply chain

SBOM dem, dependency scanning, and signed build dey reduce third-party risk.

How often we dey review am

We dey review di threat model every quarter and after major release. Dem dey track control dem with owner, test case, and follow-up action.