Skip to main content

Platform capabilities / AI assistance

AI-assisted product security analysis

Start with a product description and the information you already have. AI helps draft architecture and security analysis proposals; your team checks the facts, edits the proposals and applies the agreed content to the product records.

Product analysis / Connected gatewayPrepared example
ARCHITECTURE DRAFTDFD · Update flow
DEVICE / TRUST BOUNDARYFirmware packageUpdate serviceExternal serviceUpdate clientPackage authenticationDBFirmware storageWrite after acceptance
Review the flow and trust assumptions before adopting a threat.
Product profileArchitectureThreatsSecurity recordsReview a requirement
Explore the architecture, threat scenarios and security requirements to see how the analysis develops.What AI can help prepare

Security requirement review example

Read the proposal. Make the requirement precise.

The team can review and revise each draft. Edit the proposed requirement below, save the reviewed wording, then apply it to the example record.

Security requirement reviewPrepared example
  1. AI draft
  2. Human review
  3. Product record
T-01 → SR-01Draft requirement

Authenticate firmware before installation

Related threat

An attacker substitutes the firmware package on the delivery path. Whether the attack succeeds depends on the checks performed by the update client.

Security requirement

The device shall verify the firmware package before installation.

Proposed verification · not performed

Submit a package with an invalid signature. Check that the update is rejected before any firmware is written.

Start by checking the proposed requirement against the product design.

This interactive example uses prepared content. Edits stay on this page; the example does not call an AI service or update a Sytance workspace.

The scope of AI assistance

Build the analysis from the product information you have.

Sytance can help prepare a product profile, architecture diagrams, threat scenarios and the requirements, designs and verification activities that follow. The team reviews the content as the analysis develops.

WORKING NOTESProduct profile

Establish the analysis boundary

Inputs
Product descriptions, operating environments, interfaces and the architecture information already available to the team.
AI assistance
Organise the information into a product profile and a proposed architecture. Work through missing information and clarify which systems belong in the analysis.
Team review
Confirm the intended use, deployment and responsibility boundaries. An assumption about the product needs confirmation from someone who knows its design.

Team collaboration and data use

Confirmed analysis becomes part of the product records.

Your team can review and edit the AI analysis, then apply the confirmed content to product records for design, verification and documentation.

AI workflows may send the relevant product information and instructions to external AI services. Review the processing arrangements before submitting restricted material.

AI and customer data

Maintain product information

Record the product interfaces, permissions and data flows in the workspace. Add missing information and update the analysis when the product changes.

Plan and record security work

Plan design and verification work for the security requirements. Keep the implementation details, test results and supporting evidence with those records.

Prepare compliance documentation

Use the team's confirmed analysis and evidence to prepare documentation for review, based on the CRA or medical-device cybersecurity requirements that apply to the product.

AI assistance, threat modelling and SBOM management are capabilities of the same Sytance platform.