Threat model
The threat model is the signed question behind a scan. It makes assumptions visible and gives your team a shared basis for prioritization.
Authentication, webhooks, integrations, uploads
Browser, API, worker, repository, third-party services
Tenant records, credentials, billing, source code
Create a scan to turn these workspace concerns into a target-specific threat model.