Purple Firefish shield markPurple Firefish

Threat Model

Use this when you need to understand which AI security risks Firefish is designed to reduce.

Firefish focuses on untrusted instructions and sensitive data crossing boundaries between users, documents, models, tools, applications, and operators.

Primary risks

Controls

Local-first posture

Firefish defaults to local/self-hosted operation. Hosted model providers are not required for normal local operation. Raw logging is disabled by default. Audit records should use hashes, redacted previews, reason codes, and structured metadata.

Assumptions

Out of scope

Firefish does not guarantee full prevention of all prompt injection, data leakage, or unsafe model behavior. It does not replace secure application design, access control, endpoint security, SIEM, or human review.