What problem does it solve? Early-stage companies face security risks that live above any single code change — unrevoked access, unvetted vendors, unhardened cloud accounts, and no plan for the day something goes wrong. This Skill provides the proactive security function: threat modeling, incident response, compliance readiness, and identity/vendor/cloud risk management, grounded in the actual system rather than generic boilerplate. ## Core Features & Use Cases - Threat Modeling: STRIDE-based analysis of a system's real data flows and trust boundaries, producing prioritized findings handed to engineering as concrete requirements. - Incident Response: A practical playbook covering triage, containment, evidence preservation, confirmed-vs-suspected tracking, and blameless post-incident review, aligned with current NIST guidance. - Compliance & Audits: Gap analyses against SOC 2, ISO 27001, and OWASP's current Top 10, with prioritized remediation roadmaps. - Vendor & Access Risk: Pre-integration vendor due diligence, least-privilege onboarding/offboarding checklists, and cloud account hardening (MFA, root protection, billing anomaly alerts). - Use Case: Before integrating a new AI vendor that will touch customer data, run a vendor assessment covering actual data access scope, retention, DPA requirements, and a proceed/conditions/don't-integrate recommendation. ## Quick Start Ask the security team to threat-model your new feature or audit your cloud account security posture, for example: "Threat-model our patient data API before launch."