Threat modeling, STRIDE, architecture security review. Use when TADs, APIs, or data flows need structured pre-implementation security analysis.