Provides a structured security audit workflow for DevSecOps, application security, and compliance readiness, used for scoped assessments, threat modeling, testing, remediation planning, trust-boundary siting of controls, and evidence-gated triage that suppresses false positives.