Sources & method

How this content is made

Trust comes from traceability. This page discloses where the content comes from, how it is reviewed, and where an assessment is editorial rather than evidenced.

As of June 2026

Principles

  • Primary sources before secondary literature. We reference standards, specifications and official frameworks, not hearsay.
  • No fabricated facts. No invented customers, metrics or legal claims.
  • Assessments are flagged. Where a statement is editorial and not evidenced, it is marked as an “editorial assessment”.
  • Dated review. Every source carries a “last checked” date; every mission a change history.
  • Terminological consistency. Core terms are used consistently across the whole site (see Glossary).

Terminological consistency & vocabulary

Core terms are written and used deliberately consistently. On first occurrence a technical term is explained or linked to the Glossary. Binding spellings:

  • AI and KI — synonymous; "KI" in German running text, "AI" in fixed technical terms (AI-Readiness, AI-SBOM).
  • Agent vs. agent system — the single acting actor vs. the overall system of agents, tools and control.
  • Copilot — suggests but does not replace; clearly distinguished from the acting agent.
  • Tool Call, Eval, Observability — established technical terms, not translated.
  • Human-in-the-Loop, Delegation, Least Privilege, context architecture — consistent across all pages.
  • Nova-7 — always hyphenated.

Maintenance process

Content is published, dated and revised as needed. Changes to a mission appear in its change history. Sources are checked regularly for reachability and currency; the review date sits with each source. The architecture Radar carries its own as-of date, because classifications change faster than foundations.

Limits

This site is an independent knowledge and architecture project — not legal advice. For regulatory questions (e.g. the EU AI Act) the respective original text is authoritative. Answers from the Nova-7 assistant may contain errors; the cited sources should be verified.

Source directory by topic

These standards and primary sources underpin the missions, ordered here by topic. Each entry names the publisher, type and review date and briefly explains why the source is relevant. On the mission detail pages you will find in which context a source is drawn upon.

AI Risk Management & Governance

Agentic AI & Security

  • MITRE ATLAS MITRE · Primary source · checked 24.06.2026 Tactics and techniques against AI-enabled systems — the basis for detection and incident processes.
  • OWASP Top 10 for Agentic Applications 2026 OWASP · Primary source · checked 24.06.2026 Memory/context risks (including poisoning) and authorisation problems of agentic systems.

Identity & Authorization

Interoperability & Agent Protocols

  • Agent2Agent Protocol A2A Project · Specification · checked 24.06.2026 Interoperability between agents — verify maturity and version at each mention.
  • Model Context Protocol — Spezifikation MCP Project · Specification · checked 24.06.2026 Standardised connection of context sources and tools — but replaces neither authorisation nor data quality.

Observability & Reliability

Software Supply Chain

Economics

  • FinOps for AI FinOps Foundation · Primary source · checked 24.06.2026 Framework for cost and value management of AI workloads.

Source hierarchy Official frameworks, standards and specifications (incl. NIST, ISO/IEC, IETF, W3C, OWASP, MITRE, OpenTelemetry, European Union) and original scientific publications are preferred. Secondary sources are used only where they offer additional, clearly flagged interpretive value. The maturity of young protocols (e.g. MCP, A2A) is stated when they are referenced.