Most serious AI security failures cross a boundary that was treated as trusted by default.
THREAT MODELAI SECURITY ENGINEERING
Map trust boundaries
Trust boundaries mark where identity, privilege, data ownership or control assumptions change.
User → app → retriever → agent → MCP server → cloud API are separate boundaries even if one workflow hides them.
Which security control should be explicit?
REMEMBEREvery change of authority deserves a boundary.
No uploads · No company data · No account required