SHEET 08AI · ENGINEER-GOVERNED

AI that drafts the TARA.
Engineers sign it.

ThreatZ AI proposes threats, attack paths, vulnerabilities and controls — and answers grounded questions about your project. It never writes to your data. Only an engineer's action commits anything.

See the assist loop RECOMMENDER · ASSISTANT · KAG+RAG · BYO LLM
ASSIST SESSION // read-only
model.endpoint local-llm://byo · air-gap OK
project BMS-ECU / rev C
recommender 42 suggestions generated
grounded-in Neo4j graph + KB (RAG)
engineer 28 accepted · 11 rejected · 3 review
db.writes.by_ai 0 (read-only guarantee)
STATION 1 · RECOMMEND

Suggests,
never decides.

The recommender proposes threats, attack-path chatter, candidate vulnerabilities and controls for your project. Each lands in a review queue as a suggestion an engineer accepts or rejects — high-impact accepts route to a second approver.

EMITS → threats · paths · PVE · controls
QUEUES → accept / reject per item
GATES → high-impact → 2nd approver
plain-language project questions ← INPUT
answers only from your data ← SCOPED
every claim cites an entity ← CITED
STATION 2 · ASSISTANT

Grounded
project Q&A.

Ask the assistant about your project in plain language. It answers only from your project's own data and cites the real entities behind every answer — no free-floating generation, no invented facts.

RECOMMENDATION REVIEW · BMS-ECU AI SUGGESTED · NOT YET IN YOUR MODEL
Spoof CAN diagnostic session grounded on · Asset: OBD-II gateway
HIGH grounded AcceptReject
Extract firmware via JTAG grounded on · Component: MCU flash
MEDIUM grounded AcceptReject
DoS on charging handshake inferred · Threat: charge-ctrl
MEDIUM inferred AcceptReject
PVE: CVE in TLS library grounded on · SBOM: mbedtls
HIGH grounded AcceptReject
Control: mutual-auth on CAN bus grounded on · DamageScenario: unauth
grounded AcceptReject

High-impact accepts require a second approver — separation of duties.

STATION 3 · GROUND

Cites real
entities.

Answers combine RAG over your knowledge base with KAG — knowledge-augmented generation over your project's Neo4j graph. Responses point back to actual threats, assets and damage scenarios, and a guardrail flags any evidence it can't ground.

RAG → knowledge base (Qdrant)
KAG → project Neo4j graph
GUARD → ungrounded evidence flagged
bring your own LLM endpoint ← INPUT
private cloud · on-prem · air-gap ← RUNS
0 database writes by AI ← GUARANTEE
STATION 4 · READ-ONLY

Your model,
your walls.

AI services are strictly read-only — every mutation is a ThreatZ action an engineer authorized. Bring your own LLM endpoint and run entirely in private cloud, on-premise or air-gapped, with no third-party data egress. A misconfigured endpoint fails visibly; it never fabricates.

TITLEAI — ENGINEER-GOVERNED ASSIST
MODEHUMAN-IN-THE-LOOP
OUTPUTSUGGESTIONS · CITATIONS
WRITESREAD-ONLY AI