Pythia

Threat assessment tool Evidence before conclusion

Evidence-led threat assessment for consultants.

Checking API
Checking session
Select an evidence folder or paste documentation to begin.
Ready
Current Case No assessment loaded
STRIDERisk assessment
Industry StandardRisk lens
0Source files
PendingDecision
Overview

Start a focused assessment

Add evidence, run Pythia, then review evidence-supported risks to reach a defensible decision.

Quick start

Choose evidence, select a surface, and run Pythia.

Pythia will prioritize evidence-supported risks, control gaps, and the actions required for treatment.

More start options
Assessment progress View the full risk assessment workflow
Security Utilities History, run comparison, prompt preview, and framework mappings
Supporting analysis Risks, evidence health, actions, and timeline

Top Residual Risks

Highest priority threat findings for reviewer action.

Evidence Health

Readiness of the evidence pack for a defensible risk assessment.

Security Next Actions

Recommended reviewer actions before acceptance.

Mitigation Timeline

Presentation-ready treatment roadmap.

Assessor workbench

Evidence-gated assessment

Create the engagement, prove readiness, complete the generated workpaper, and preserve every material decision.

Assessment gate Not checked No risk score or conclusion yet
Workspace navigation

Jump to an assessment section

Reach any governed workpaper without tabbing through the entire assessment.

Section navigation

Choose a section, then go directly to its heading. Press Alt+Shift+J to return here.

CSA-informed workflows support assessor judgement and do not constitute CSA certification or legal advice.

Engagement-scoping copilot

Define the assessment before requesting evidence

Answer the material scope questions once. Pythia deterministically proposes the method, evidence request, SOW, RACI, schedule, and review depth; nothing becomes binding until lead approval.

No governed scope
Accountable stakeholders

Save an engagement, complete the scope interview, then prepare a deterministic draft for lead approval.

Governed assessment contract

Assign accountability for every assessment output

Bind each required deliverable to a named engagement role while Pythia keeps its minimum-evidence rules, workflow state, and acceptance criteria server-owned.

No output contract

Save or load an engagement to assign accountable output owners.

Governed evidence workflow

Turn evidence gaps into accountable requests

Assign each approved-scope or readiness gap, record a due date, and close it only with exact current evidence or an authorized waiver.

No request register

Approve a scope or run an assessment to create the governed request register.

No evidence requests are available.

Governed evidence quality

Set and enforce evidence-recency policy

Apply topic-, evidence-class-, or source-specific age limits. Stale, undated, future-dated, draft-policy, and chain-invalid evidence stays visible and can block assessment or approval.

No recency policy
1 · Propose exact policy thresholds A separate reviewer must approve the immutable policy fingerprint.
One rule per line: id | maximum days | topics | evidence classes | source origins | label. Separate multiple match values with commas. Blank rules use the governed defaults.
2 · Independent policy approval Approval binds the reviewer to the exact displayed fingerprint.

Save an engagement to configure its governed recency policy.

No evidence recency evaluation is available.

Immutable policy history

No policy versions recorded.

Governed evidence safety

Scan and quarantine evidence before use

Preserve original bytes without parsing them, require policy-bound clean scanner receipts, and exclude pending, detected, failed, expired, or tampered evidence from AI analysis and approval.

No malware-scan policy
1 · Propose exact scanning controls A separate reviewer must approve the immutable policy fingerprint before scan results can release evidence.
2 · Independent policy approval Approval binds the reviewer to the exact displayed policy fingerprint.
3 · Record an authorized scanner receipt Production scanner services should submit this endpoint directly. The administrator form preserves the same immutable receipt and audit trail.

Save an engagement to configure malware scanning and quarantine.

No malware-scan evaluation is available.

Immutable malware-policy history

No policy versions recorded.

Governed evidence connectors

Freeze source-system evidence before assessment use

Define least-privilege read access, obtain lead approval, and convert each collection into an immutable snapshot. A later source change never rewrites evidence already bound to an assessment.

No governed connectors
1 · Define read-only access Store a credential reference only. Secret values are rejected.
2 · Approve the exact fingerprint Only an engagement lead or organization administrator can approve.

Save an engagement and prepare a connector draft.

3 · Freeze a collection The submitted JSON is normalized by the approved adapter, stripped of secret fields, hashed, and frozen as a distinct observation.
Approved read-only permissions are copied into every frozen snapshot.
4 · Bind exact evidence Assessment runs resolve stored snapshot IDs and hashes—not the live source.

No frozen snapshots for the selected connector.

Temporal evidence knowledge graph

Trace what changed and every decision it affects

Freeze a versioned evidence-to-decision graph, keep current and historical truth separate, and test reuse against scope, period, owner, version, and continuing validity.

No graph snapshot
Each version is immutable, hash-chained, and bound to one engagement and assessment run.

Generate or load an assessment before materializing its temporal graph.

Impact query Ask which claims, scores, workpapers, reports, and approvals depend on an exact entity.

Select an entity to trace its governed downstream dependencies.

Governed fact reuse Reuse is blocked unless every source and continuing-validity check passes.

No fact-reuse decision recorded for this engagement.

Immutable graph history

No graph versions recorded.

AI-assisted workflow

Generate complete assessment

Index evidence, test sufficiency, derive architecture, identify STRIDE risk scenarios, prepare workpapers, and create a reviewable draft.

  1. 01EvidenceAwaiting run
  2. 02ArchitectureAwaiting run
  3. 03Risk identificationAwaiting run
  4. 04Risk assessmentAwaiting run
  5. 05WorkpapersAwaiting run
  6. 06ReportAwaiting run
Add evidence, select an assessment model, then generate a complete draft.
Client report and supporting records Client PDF and DOCX exports are limited to 20 rendered pages. Material findings remain traceable to the complete supporting records.
The package includes the editable report, its PDF, and complete supporting records from one snapshot. Edited DOCX files require a new page check.
Supporting workpapers and data

Generate a complete assessment before exporting.

Review narrative and structured tables from the same immutable snapshot before export.
Governed report workspace
One-source reporting

Preview, trace, and govern the report

Every narrative block and table links back to its claims, workpapers, risks, or exact evidence passages. Narrative edits create a new immutable version and cannot change structured facts.

Load a completed assessment

Organization report style

Choose an approved versioned profile for formatting, confidentiality, distribution, and signatories.

Create a new organization style version

Open the source-linked preview after a complete assessment is available.

Independent review

Change-first reviewer workspace

Start with new, changed, high-risk, uncertain, and exception items. Inspect-all mode remains available for independent judgement.

Saved reviewer views

Reuse a personal, engagement-scoped queue view without changing assessment decisions or hiding the inspect-all option.

No saved view selected.

Generate or load an assessment to build the reviewer queue.

Reviewer-efficiency evidence

Changes-first benchmark

Modeled work units compare queue scope; seeded material errors verify that prioritization does not reduce detection.

Load an assessment to calculate the modeled benchmark.

Governed system model

Architecture exception review

Confirm cited candidates, approve explicit assumptions, or edit, merge, split, and reject material inferences. Structural changes invalidate dependent analysis.

Load an assessment to inspect its architecture revision.

No governed architecture model loaded.

Apply architecture decision 0 architecture elements selected
Pure STRIDE completeness

Element/category coverage matrix

Resolve every in-scope element and STRIDE category as a cited threat, a cited not-applicable judgement, or an explicit evidence gap.

Load an assessment to inspect STRIDE coverage.
0 coverage pairs

No STRIDE coverage matrix loaded.

Record supported disposition 0 coverage pairs selected
Review by exception

Lossless threat families

Review related scenarios together while retaining every affected asset, risk, citation, control, and material difference.

Load an assessment to inspect threat families.
Organization wording templates

Use only immutable, organization-approved bilingual wording. Templates change presentation, never threat membership, evidence, mappings, scores, or decisions.

No approved organization templates loaded.

Pythia default wording remains available.

Unsafe bulk acceptance is disabled when evidence conflicts, support is missing, or consequences differ.

No threat families loaded.

Family disposition0 family groups selected
Downstream context only

ATT&CK, CAPEC, and CWE applicability

Confirm relevant enrichment after threat-family review. These mappings never establish threat discovery, attribution, reachability, likelihood, or business risk.

Load an assessment to inspect mapping candidates.
0 mappings

No intelligence mappings loaded.

Applicability decision0 mappings selected
Decision acceleration

ATT&CK assurance coverage

Compare relevant threats, evidenced controls, detection coverage, validation status, and residual gaps without treating ATT&CK as a completion checklist.

Load an assessment to build its assurance layer.
Coverage filters
SolidReviewGap / excluded

No coverage layer loaded.

Every cell keeps its Pythia IDs, exact citations, controls, tests, and risks. A colored ATT&CK cell is never proof of complete defense.

Reusable mitigation

Governed control bundles

Apply approved guidance across relevant risk scenarios while retaining every underlying record and evidence link.

Load an assessment to recommend reusable controls.

No control bundles loaded.

Apply bundle lifecycle0 bundles selected

Suggested, designed, implemented, tested, and effective are separate states. Pythia never reduces residual risk until operating effectiveness is evidenced.

Controlled residual risk

Evidence-bound residual-risk reassessment

Reassess a linked risk only after a complete Effective control test. Pythia calculates the selected factors and preserves the exact test fingerprint; it never reduces risk automatically.

Load an assessment to review eligible residual risks.

No residual-risk reassessments loaded.

A lower score is published only from a human-recorded deterministic calculation bound to current Effective control-test fingerprints and exact evidence.

Explainable prioritization

Deterministic scoring review

Review evidence-proposed factors beside their exact citations, see the formula, and focus on unsupported, disputed, or decision-sensitive judgements.

Load an assessment to review scoring rationale.

No scoring proposals loaded.

Record factor review0 risks selected

Bulk confirmation is permitted only when criteria version, evidence quality, and consequence type match. Scoring confirmation never reduces residual risk.

Decision-grade uncertainty

Calibrated confidence and quantitative risk

Keep evidence, model, and risk uncertainty separate. Empirical bands require reviewed benchmarks; FAIR-style estimates require explicit selection and exact frequency and loss evidence.

Load an assessment to inspect uncertainty.
Reviewed benchmark calibrationExtraction, mapping, scenario, and conclusion are calibrated independently.

No calibration analysis loaded.

Risk uncertainty registerSee the assumptions and factor changes that can alter treatment.

No risk uncertainty records loaded.

Configure reviewed benchmarks and optional quantitative analysis
Add a reviewed benchmark outcomeEach result is attributed and appended to an immutable configuration version.
Optional FAIR-style scenarioNo value is inferred. Leave incomplete inputs visible and Pythia will return “insufficient evidence” without an estimate.
Annual event frequency
Loss per event

Quantitative analysis is not selected.

Uncalibrated confidence is never presented as probability. Quantitative output is supplementary and never replaces the authoritative Pure STRIDE or CSA-Informed CII rating.

Governed investment planning

Remediation portfolios

Rank shared risk treatments, compare constrained delivery options, approve a fingerprint-bound portfolio, and retain ticketing or GRC receipts.

Load an assessment to plan remediation.
Review constraints, estimates, ownership, and validation
Version the planning basisDefaults are planning estimates. Confirm them or record an action-specific override before approval.
Optional action-specific override
Ranked investment actionsShared controls and highest supported risk scores appear first.

No remediation actions loaded.

Constrained portfoliosCompare budget, delivery, disruption, exclusions, and modeled benefit.

No remediation portfolios loaded.

Record portfolio decisionApproval is bound to the current action and constraint fingerprints.
Synchronize approved actions with ticketing or GRC
Record an external receiptPythia stores the external reference with portfolio, action, risk, evidence, and hash-chain identifiers.

No synchronization receipts recorded.

Modeled benefit is planning support, not validated control effectiveness. Current residual risk is retained until operating effectiveness is evidenced and the affected risks are reassessed.

Independent machine challenge

Adversarial verification

Six separated roles challenge generated conclusions. Deterministic validators—not model agreement—decide whether the draft may become Assessor Reviewed.

Load an assessment to run adversarial verification.
Disagreements and critic findingsBlocking findings appear first with exact evidence and a concise resolution path.

No adversarial review loaded.

Rejected candidates and quality telemetry
Rejected candidates

No rejected candidates.

Method and prompt quality

No telemetry loaded.

Governed evidence contradiction resolutions

Load an assessment to inspect evidence conflicts.

No contradiction workflow loaded.

Resolve selected conflictSelect an unresolved conflict above.

A model cannot approve another model. Unsupported conclusions and contradictory evidence must be detected before Assessor Reviewed, then rejected or resolved through an attributable, evidence-bound workflow.

Bulk human disposition 0 review objects selected
Full independent decision history

Prioritized review queue

No assessment run loaded.

Accountable ownership

Residual-risk acceptance

An assigned risk owner must explicitly accept every assessor-confirmed residual risk. Acceptances are time-bound, evidence-linked, versioned, and invalidated by reassessment.

No assessment loaded
Risk tolerance and treatment policy

No governed policy configured.

0 risks selected
0 risks

Generate and review an assessment before recording risk ownership.

Recurring assessment

Prepare the next assessment

Compare updated evidence with the current assessment. Review what needs fresh work and which prior tests may remain useful before creating the next draft.

Load a completed assessment, then update the evidence intake to preview the impact.
Continuous assurance

Scheduled change monitoring

Bind repository, system, policy, or methodology observations to an approved baseline. Editorial changes stay quiet; material changes open an accountable reassessment route and withdraw stale approval when required.

Load a completed assessment to configure monitoring.
Configure a governed monitor

Approval binds the exact monitor fingerprint. A different authorized lead must approve in enterprise mode.

No continuous-assurance monitors configured.

Record a normalized change observation
Repository and system monitors derive changes from the frozen baseline and current snapshot; manual change claims are disabled.
Third-party assurance

Supplier and software supply chain

Model services, software, build and support dependencies; keep inherited controls separate from customer-operated controls; and expose concentration, expiry, transitive path, and contingency gaps.

Load a completed assessment to review supply-chain assurance.

No governed supplier profile.

Add supplier or service
Link a dependency
Record inherited-control reliance

Add supplier records, dependencies, and inherited controls to the draft.

Save a profile to generate transitive paths, concentration risks, expiry, and contingency analysis.

Enterprise intelligence

Cross-framework and portfolio intelligence

Map exact evidence-backed records to versioned criteria without copying conclusions, then view tenant-safe portfolios whose metrics drill down to assessment versions. Unknown or stale coverage never appears as low risk.

Load a completed assessment to configure framework mappings.

No portfolio intelligence loaded.

Add a versioned criteria mapping
Review enterprise portfolio

Refresh to load governed portfolio metrics.

No draft framework mappings.

Governed improvement

AI assurance evaluation and change control

Turn assessor outcomes into bounded proposals, measure them against golden and adversarial cases, and require regression, security, privacy, approval, version, and rollback evidence before a separate manual deployment record.

Save an engagement to govern an improvement evaluation.

No governed improvement scorecard.

Configure benchmark and candidate evaluation
Required invariants

No assurance-improvement versions.

Efficiency benchmark and release scorecard

Historical measurement definitions are retained here. Handler runtime and the earlier 60% touch-time target do not establish the new 50% total human-effort target. Use Human work time for that comparison.

No template loaded. Measurements remain empty until people perform the study.

No privacy-safe workflow timing has been recorded.

Measured evidence

Manual benchmark baseline

Register at least three privacy-safe representative cases. A reviewer must approve the immutable baseline before it can support a comparison.

Manual average per case
Manual quality baseline (%)

No manual baseline versions recorded.

Governed outcome

Release efficiency scorecard

Publish observed results against an approved baseline. Missing measurements produce an insufficient-evidence scorecard, never an inferred saving.

Observed study average per case

Interactions come only from Pythia telemetry. Touch time adds only eligible, run-bound offline diary observations and labels that combined basis explicitly.

Observed quality study (%)

No release scorecard has been published.

Optional observed work

Offline analyst time diary

Record stakeholder follow-up and other work performed outside Pythia. Entries are immutable, hash-chained, and kept separate from application telemetry and modeled estimates.

No diary entries recorded.

No offline work recorded.

Gate 01

Evidence readiness

Pythia will not score or conclude when required inputs are absent.

0%
Run the readiness check before beginning assessment work.
Gate 02

Evidence request list

Blocking requests generated from the selected model and deployment.

No readiness decision yet.

Workpaper

Generated assessor checklist

Record evidence, test result, assessor conclusion, and reviewer note for each procedure.

Not generated

Generate a checklist after selecting an assessment model.

Finding workbench

Auditor-grade draft findings

Review condition, criteria, cause, consequence, rating, evidence, and recommendation as one governed record.

No findings generated

Complete an assessment to generate draft findings.

CSA risk worksheet

Evidence-gated 5×5 calculator

A complete scenario and linked evidence are required before a rating is produced.

No supported score yet.
Review and approval

Assessor conclusion

Approval remains unavailable until evidence readiness and review requirements are met.

Evidence readiness must pass before approval.
Governed segregation exception

Independent review is the default. Request a narrow, time-bound exception only when the same assessor must complete final approval under independently authorized compensating controls.

Save the engagement before requesting an exception.

No segregation exceptions recorded.

Immutable history

Audit trail

Append-only events are linked by SHA-256 hashes and verified whenever this timeline loads.

No saved engagement

Save the engagement to begin the audit trail.

Risk Assessment Pipeline

Evidence to Security Decision

Track every stage, confidence level, evidence usage, local checkpoint, and rerun action from a single review workflow.

Local Checkpoints Rerunnable Stages Audit Manifest Reviewer Friendly
Pipeline Actions

Stage Evidence Trace

Checkpoint Ledger

Assessment Case

Capture the application context before analysis.

No folder selected
The selected assessment model fixes the rating method to prevent methodology mixing.

Evidence Intake

Drop in one folder of PDF, DOCX, XLSX, CSV, policy, API, source, or diagram evidence. Originals are preserved locally when the engagement is saved.

Evidence metadata, custody, retention, and legal hold

Available after the engagement is saved. Metadata changes are versioned; retention, hold, release, and deletion actions are attributable and recorded in the audit chain.

Save the engagement to manage retained evidence.
Advanced: trusted public web references

Advanced Optional Context

Leave the goal blank to run the selected risk assessment.

Optional
Default action: Run the selected application or network risk assessment, produce evidence-linked findings, and prepare a risk decision pack.
Architecture Generator

Evidence to Architecture Draft

Extract components, trust boundaries, data flows, and confidence levels before running the selected model.

Editable Draft Mermaid/C4 Views Evidence Confidence Threat-Ready
Architecture Actions
100%

Select a source or diagram element to review them together.

Assessment Report

Analysis Results

Executive summary, diagrams, residual risk, mitigations, evidence traceability, and raw model output.

Local Evidence MITRE-Linked Residual Risk Presentation Ready
Export Pack

Security Findings Register

Track threat findings as risk items with treatment, owner, status, and residual risk.

Evidence Traceability & Adversarial Review

Challenge Every Finding

Map each risk to local evidence snippets, flag weak support, identify likely duplicates, and capture reviewer challenge questions.

Source Snippets Confidence Scoring False Positive Challenge Security Ready
Review Actions

Guided Risk Triage

Review each risk, choose a treatment decision, assign ownership, and set a due date.

No risks yet

Security Decision Pack

Summarise whether the system can proceed, under what conditions, and who must approve.

Governed Evidence Search

Search only the active engagement's server-held evidence, inspect exact passages, and ask an evidence-grounded question.

Exact citations

Save or open an engagement and generate an assessment run before searching.

Evidence passages

No search has been run.

Evidence-grounded answer