Skip to content
PhiloCyber logo

Threat Modeling for AI Systems

A structured security review of how your agents, LLM features and MCP integrations could be misused, delivered one week after a single session with the people who built it.

Scope
One week from the session with your team · Design documents up front, no production access
Built for
Teams designing an agentic feature, adding tool calling, or connecting an LLM to internal data and systems.
Start with your architecture
Animated threat modeling process from architecture mapping to prioritized controlsTrust boundaryArchitectureTrust boundaryThreat pathsAttack pathControls01Architecture02Trust boundary03Threat paths04Mitigations

What this service does

I map the complete system, not just the model: users, prompts, agents, tools, memory, retrieval, data stores, external content and the permissions between them. From that architecture I identify assets, trust boundaries, attacker entry points and realistic abuse paths.

The value

You get a shared picture of where risk actually concentrates and which design changes matter most. A trust boundary is a whiteboard edit before launch and a migration after it, so this is the cheap moment to move one. It also gives later penetration testing a focused, defensible scope.

How it runs

I work from your design documents, sent ahead so I arrive prepared, and one session with the people who built it. The model comes back a week after that session. Production access is not required.

Questions this work answers

  • Where can untrusted instructions, data or tool output enter the system?

  • What can an attacker reach if an agent, identity or permission boundary fails?

  • Which mitigations reduce the most credible risks before production?

What you get

04
  1. D/01Architecture and data-flow diagram covering models, agents, tools, memory, retrieval and external dependencies
  2. D/02Trust boundaries, assets, entry points and abuse paths documented against the real design
  3. D/03Prioritized threat register mapped to OWASP guidance for LLM and agentic systems, plus MITRE ATLAS
  4. D/04Mitigation plan and working session to turn findings into concrete architecture decisions

Something already in production you are not sure about?

Tell me what you are building and what worries you about it. If it is not something I can help with, I will tell you that too.

Start with your architecture
Threat Modeling for AI Systems | Ricardo N. Prieto | PhiloCyber