SECURITY

Security is part of the product boundary.

The current project is intentionally designed around defensive use, human approval and evidence-linked analysis.

Data handling

The public website is a static site. It does not include a marketing analytics SDK, advertising tracker or account registration form. Contact is handled through email.

Authorization

Any future connector is intended to operate only on environments the customer is authorized to assess. Read-only access is the default design target.

Human approval

Risk conclusions are intended to be reviewed by a security practitioner. The product does not treat an inferred attack path as proof of a compromise.

Responsible use

The project is for defensive security work, architecture review, vulnerability prioritization and authorized testing. It is not intended to facilitate unauthorized access.

RELEASE DISCIPLINE

Build the evidence trail before adding automation.

For the prototype, a useful result is one a security engineer can reproduce from the source records and relationships that generated it. The roadmap therefore favors normalization, provenance, scoring transparency and review workflows before response automation.

SourceWhere the input came from
ContextWhat asset or relationship changes the risk
ReasoningWhich rule or signal increased priority
ActionWhat remediation would reduce the path
VerificationHow the analyst can confirm the fix

SECURITY CONTACT

Report a concern about the site or project.

Email shubhams@attackpathai.website with the affected page, issue summary and enough detail to reproduce it without including secrets.