Foldspan

AI Security & Threat Modeling

Scope and the delivery plan are confirmed after fit, access, authorization, and evidence sources are established.The work begins with a defined AI system, named technical and decision owners, and an agreed evidence window.

Find the attack, misuse, and failure paths that matter.

Foldspan examines models, agents, tools, data, identities, providers, infrastructure, and human control as one system, then prioritizes the controls and decisions that reduce material exposure.

When it fits

For an AI product, agentic workflow, model integration, or AI-enabled service approaching launch, material change, scrutiny, or high-consequence use.

What leadership can act on

Decide what must be redesigned, constrained, tested, monitored, or explicitly accepted before launch or material change.

How Foldspan engages

The work follows the architecture and the threat, separating observed facts, test results, assertions, inferences, and unknowns before recommending action.

What happens next

Findings can move into Secure Design Review, Targeted Security Validation, Ongoing Security Change Review, or Security Strategy & Decision Support.

Engagement detailSee the focus, approach, result, and working model.

What you receive

Clear findings, technical guidance, and an actionable path.

AI System & Trust Map

A versioned view of the agreed system, authority, dependencies, owners, unknowns, and material paths.

Makes the system and the evidence behind its security decisions visible.

AI Threat Model

Credible attack, misuse, and failure scenarios tied to actor capability, evidence maturity, consequence, controls, and owners.

Prioritizes the paths that require design, mitigation, validation, or monitoring.

Security Decision & Action Plan

Immediate action, longer-term changes, owners, dependencies, proof criteria, exceptions, and residual-risk decisions.

Turns the assessment into an owned technical and leadership path.

Scope

What we review.

  • Models, agents, tools, prompts, retrieval, training or reference data, APIs, identities, permissions, human approval, external providers, and supporting infrastructure.

  • Prompt injection, tool misuse, excessive agency, data exposure, tenant crossing, model and supply-chain compromise, insecure fallbacks, and recovery.

  • The controls and operating assumptions intended to prevent, detect, contain, and recover from material attack, misuse, and failure paths.

Approach

How Foldspan addresses the problem.

  • Reconstruct the agreed AI system, its data flows, trust boundaries, identities, permissions, tools, providers, and required human control.

  • Threat-model credible adversary, misuse, failure, and unsafe-automation paths against the actual architecture.

  • Assess the controls and assumptions intended to prevent, detect, contain, and recover from those paths.

  • Define focused validation where direct technical evidence could change the decision.

  • Convert the findings into priorities, design requirements, owners, evidence criteria, and operating conditions.

Working model

How Foldspan works with your team.

  • Conclusions apply to the agreed system, version, configuration, scope, evidence sources, and evidence window.
  • The work does not claim every threat, dependency, or failure path is known.
  • Adversarial or implementation testing requires separate written authorization, method, and rules of engagement.
  • Named organizational owners retain production, release, resource-allocation, and risk authority.