Evidence readiness
Pythia will not score or conclude when required inputs are absent.
Evidence-led threat assessment for consultants.
Add evidence, run Pythia, then review evidence-supported risks to reach a defensible decision.
Pythia will prioritize evidence-supported risks, control gaps, and the actions required for treatment.
Highest priority threat findings for reviewer action.
Readiness of the evidence pack for a defensible risk assessment.
Recommended reviewer actions before acceptance.
Presentation-ready treatment roadmap.
Create the engagement, prove readiness, complete the generated workpaper, and preserve every material decision.
Answer the material scope questions once. Pythia deterministically proposes the method, evidence request, SOW, RACI, schedule, and review depth; nothing becomes binding until lead approval.
Save an engagement, complete the scope interview, then prepare a deterministic draft for lead approval.
Bind each required deliverable to a named engagement role while Pythia keeps its minimum-evidence rules, workflow state, and acceptance criteria server-owned.
Assign each approved-scope or readiness gap, record a due date, and close it only with exact current evidence or an authorized waiver.
Approve a scope or run an assessment to create the governed request register.
No evidence requests are available.
Apply topic-, evidence-class-, or source-specific age limits. Stale, undated, future-dated, draft-policy, and chain-invalid evidence stays visible and can block assessment or approval.
Save an engagement to configure its governed recency policy.
No evidence recency evaluation is available.
No policy versions recorded.
Preserve original bytes without parsing them, require policy-bound clean scanner receipts, and exclude pending, detected, failed, expired, or tampered evidence from AI analysis and approval.
Save an engagement to configure malware scanning and quarantine.
No malware-scan evaluation is available.
No policy versions recorded.
Define least-privilege read access, obtain lead approval, and convert each collection into an immutable snapshot. A later source change never rewrites evidence already bound to an assessment.
Save an engagement and prepare a connector draft.
No frozen snapshots for the selected connector.
Freeze a versioned evidence-to-decision graph, keep current and historical truth separate, and test reuse against scope, period, owner, version, and continuing validity.
Generate or load an assessment before materializing its temporal graph.
Select an entity to trace its governed downstream dependencies.
No fact-reuse decision recorded for this engagement.
No graph versions recorded.
Apply an approved archetype or clone the current engagement with an explicit evidence period and continuing-validity decisions.
Choose a preset to inspect its archetype, evidence requests, control bundles, risk criteria, workpaper program, and report template.
Index evidence, test sufficiency, derive architecture, identify STRIDE risk scenarios, prepare workpapers, and create a reviewable draft.
Compare normalized facts with exact source wording. Suspicious document instructions are isolated as untrusted evidence and never executed.
Generate a complete assessment before exporting.
Every narrative block and table links back to its claims, workpapers, risks, or exact evidence passages. Narrative edits create a new immutable version and cannot change structured facts.
Choose an approved versioned profile for formatting, confidentiality, distribution, and signatories.
Open the source-linked preview after a complete assessment is available.
Start with new, changed, high-risk, uncertain, and exception items. Inspect-all mode remains available for independent judgement.
Reuse a personal, engagement-scoped queue view without changing assessment decisions or hiding the inspect-all option.
No saved view selected.
Generate or load an assessment to build the reviewer queue.
Modeled work units compare queue scope; seeded material errors verify that prioritization does not reduce detection.
Load an assessment to calculate the modeled benchmark.
Confirm cited candidates, approve explicit assumptions, or edit, merge, split, and reject material inferences. Structural changes invalidate dependent analysis.
No governed architecture model loaded.
Resolve every in-scope element and STRIDE category as a cited threat, a cited not-applicable judgement, or an explicit evidence gap.
No STRIDE coverage matrix loaded.
Review related scenarios together while retaining every affected asset, risk, citation, control, and material difference.
Use only immutable, organization-approved bilingual wording. Templates change presentation, never threat membership, evidence, mappings, scores, or decisions.
Pythia default wording remains available.
No threat families loaded.
Confirm relevant enrichment after threat-family review. These mappings never establish threat discovery, attribution, reachability, likelihood, or business risk.
No intelligence mappings loaded.
Compare relevant threats, evidenced controls, detection coverage, validation status, and residual gaps without treating ATT&CK as a completion checklist.
No coverage layer loaded.
Every cell keeps its Pythia IDs, exact citations, controls, tests, and risks. A colored ATT&CK cell is never proof of complete defense.
Apply approved guidance across relevant risk scenarios while retaining every underlying record and evidence link.
No control bundles loaded.
Suggested, designed, implemented, tested, and effective are separate states. Pythia never reduces residual risk until operating effectiveness is evidenced.
Reassess a linked risk only after a complete Effective control test. Pythia calculates the selected factors and preserves the exact test fingerprint; it never reduces risk automatically.
No residual-risk reassessments loaded.
A lower score is published only from a human-recorded deterministic calculation bound to current Effective control-test fingerprints and exact evidence.
Review evidence-proposed factors beside their exact citations, see the formula, and focus on unsupported, disputed, or decision-sensitive judgements.
No scoring proposals loaded.
Bulk confirmation is permitted only when criteria version, evidence quality, and consequence type match. Scoring confirmation never reduces residual risk.
Keep evidence, model, and risk uncertainty separate. Empirical bands require reviewed benchmarks; FAIR-style estimates require explicit selection and exact frequency and loss evidence.
No calibration analysis loaded.
No risk uncertainty records loaded.
Quantitative analysis is not selected.
Uncalibrated confidence is never presented as probability. Quantitative output is supplementary and never replaces the authoritative Pure STRIDE or CSA-Informed CII rating.
Rank shared risk treatments, compare constrained delivery options, approve a fingerprint-bound portfolio, and retain ticketing or GRC receipts.
No remediation actions loaded.
No remediation portfolios loaded.
No synchronization receipts recorded.
Modeled benefit is planning support, not validated control effectiveness. Current residual risk is retained until operating effectiveness is evidenced and the affected risks are reassessed.
Six separated roles challenge generated conclusions. Deterministic validators—not model agreement—decide whether the draft may become Assessor Reviewed.
No adversarial review loaded.
No rejected candidates.
No telemetry loaded.
Load an assessment to inspect evidence conflicts.
No contradiction workflow loaded.
A model cannot approve another model. Unsupported conclusions and contradictory evidence must be detected before Assessor Reviewed, then rejected or resolved through an attributable, evidence-bound workflow.
The review save outcome is not confirmed. Retry the same request to recover its result; your selection and rationale are retained.
No assessment run loaded.
An assigned risk owner must explicitly accept every assessor-confirmed residual risk. Acceptances are time-bound, evidence-linked, versioned, and invalidated by reassessment.
No governed policy configured.
Generate and review an assessment before recording risk ownership.
Compare updated evidence with the current assessment. Review what needs fresh work and which prior tests may remain useful before creating the next draft.
Bind repository, system, policy, or methodology observations to an approved baseline. Editorial changes stay quiet; material changes open an accountable reassessment route and withdraw stale approval when required.
Approval binds the exact monitor fingerprint. A different authorized lead must approve in enterprise mode.
No continuous-assurance monitors configured.
Model services, software, build and support dependencies; keep inherited controls separate from customer-operated controls; and expose concentration, expiry, transitive path, and contingency gaps.
No governed supplier profile.
Add supplier records, dependencies, and inherited controls to the draft.
Save a profile to generate transitive paths, concentration risks, expiry, and contingency analysis.
Map exact evidence-backed records to versioned criteria without copying conclusions, then view tenant-safe portfolios whose metrics drill down to assessment versions. Unknown or stale coverage never appears as low risk.
No portfolio intelligence loaded.
Refresh to load governed portfolio metrics.
No draft framework mappings.
Turn assessor outcomes into bounded proposals, measure them against golden and adversarial cases, and require regression, security, privacy, approval, version, and rollback evidence before a separate manual deployment record.
No governed improvement scorecard.
No assurance-improvement versions.
Historical measurement definitions are retained here. Handler runtime and the earlier 60% touch-time target do not establish the new 50% total human-effort target. Use Human work time for that comparison.
No privacy-safe workflow timing has been recorded.
Register at least three privacy-safe representative cases. A reviewer must approve the immutable baseline before it can support a comparison.
No manual baseline versions recorded.
Publish observed results against an approved baseline. Missing measurements produce an insufficient-evidence scorecard, never an inferred saving.
No release scorecard has been published.
Record stakeholder follow-up and other work performed outside Pythia. Entries are immutable, hash-chained, and kept separate from application telemetry and modeled estimates.
No diary entries recorded.
No offline work recorded.
Pythia will not score or conclude when required inputs are absent.
Blocking requests generated from the selected model and deployment.
No readiness decision yet.
Record evidence, test result, assessor conclusion, and reviewer note for each procedure.
Generate a checklist after selecting an assessment model.
Review condition, criteria, cause, consequence, rating, evidence, and recommendation as one governed record.
Complete an assessment to generate draft findings.
A complete scenario and linked evidence are required before a rating is produced.
Approval remains unavailable until evidence readiness and review requirements are met.
Independent review is the default. Request a narrow, time-bound exception only when the same assessor must complete final approval under independently authorized compensating controls.
No segregation exceptions recorded.
Append-only events are linked by SHA-256 hashes and verified whenever this timeline loads.
Save the engagement to begin the audit trail.
Track every stage, confidence level, evidence usage, local checkpoint, and rerun action from a single review workflow.
Extract components, trust boundaries, data flows, and confidence levels before running the selected model.
Select a source or diagram element to review them together.
Executive summary, diagrams, residual risk, mitigations, evidence traceability, and raw model output.
Track threat findings as risk items with treatment, owner, status, and residual risk.
Map each risk to local evidence snippets, flag weak support, identify likely duplicates, and capture reviewer challenge questions.
Review each risk, choose a treatment decision, assign ownership, and set a due date.
Summarise whether the system can proceed, under what conditions, and who must approve.
Search only the active engagement's server-held evidence, inspect exact passages, and ask an evidence-grounded question.
Save or open an engagement and generate an assessment run before searching.
No search has been run.
Use ↑ ↓ to move, Enter to open, and Esc to close.