Free plan available — no credit card required

Threat Modeling
for Security Teams

ThreatTree organises threat models into forests of trees — add a Data Flow Diagram to map your system, or an Attack Tree to decompose a threat — so every risk stays grounded in your architecture and gets mitigated before it's exploited. Built for security teams, and just as suited to a solo builder securing a side project.

Free forever plan Optional AES-256 encryption Export anytime, no lock-in
Product tour

See it in the product

Real screens from the app — not mockups.

Map your architecture as a Data Flow Diagram

Trust boundaries, processes, data stores, and external entities — including AWS, Azure, and GCP-specific elements — so every threat is grounded in a real component of your system, not a floating assumption.

A Data Flow Diagram in ThreatTree: an AWS trust boundary containing a nested Private Subnet with Amazon EC2 and Amazon RDS nodes connected by a labeled data flow, linked to 3 Attack Trees, next to an on-premise SQL Server database and a site-to-site VPN link

Decompose every threat into an Attack Tree

Break a threat down with AND/OR logic, from high-level goal to atomic attack step. Tag each step with STRIDE and CAPEC, and link the tree straight back to the DFD node it targets.

A finished Attack Tree in ThreatTree: the goal 'Exfiltrate Customer Data from Amazon RDS' broken down through an OR gate into three attack steps, each tagged with STRIDE, CAPEC, and OWASP Top 10 categories
Features

Structured threat intelligence.
Board-ready evidence.

ThreatTree gives you the precision to decompose threats to the atomic attack step, and the evidence to defend every risk decision — whether that's to a board, an auditor, or just your own future self.

  • Architecture-Anchored Threats

    Model your system with DFDs — processes, data stores, trust boundaries, and external entities. Every threat is grounded in a real architecture element, not a floating assumption in a spreadsheet.

  • Attack Path Decomposition

    Break each threat into an Attack Tree with AND/OR logic — from high-level attacker goal to atomic step. Every tree links back to the exact DFD node it targets, keeping risk grounded in your architecture.

  • Multi-Framework Threat Tagging

    Tag every node with STRIDE, LINDDUN, OWASP Top 10, CAPEC, or MITRE ATT&CK. See which frameworks your model covers and where the gaps are — before an auditor or attacker finds them first.

  • Standards-Based Controls

    Map every mitigation to ISO 27001:2022, NIST SP 800-53 Rev 5, CIS Controls v8, PCI DSS v4.0, NIST CSF 2.0, or SOC 2. Each control is traceable to a named standard — evidence your auditors and regulators recognize.

  • Prioritized Risk Register

    Likelihood × Impact scoring generates a ranked risk register automatically across every tree in a forest. Know what to remediate first — backed by structured, auditable evidence rather than gut feel.

  • Board-Ready PDF Reports

    Generate executive-ready reports with risk summaries, ranked registers, cross-reference tables, and architecture appendices in a single PDF. Designed for board presentations, audit submissions, and compliance reviews.

  • Team Collaboration & RBAC

    Invite architects, developers, and compliance leads with owner, editor, or viewer roles. Everyone contributes to the same threat model — no version conflicts, no stale exports sent over email.

  • Optional AES-256 Forest Encryption

    Choose to lock any forest with a browser-generated AES-256-GCM key. The server stores only ciphertext — your key never leaves your device, and a full database breach exposes nothing readable. Available on every plan, including Free.

    How we protect your data →
Workflow

How it works

From zero to a live risk register in five steps.

  1. Create a Forest

    Define scope, name your stakeholders, and invite your team. A forest is the container for everything that follows.

  2. Add a Data Flow Diagram tree

    Model your system — processes, data stores, trust boundaries, external entities — so every threat has a place to live in your architecture.

  3. Add Attack Trees linked to your DFD

    For each threat, add an Attack Tree. Link it to the DFD and decompose the threat with AND/OR gates down to atomic attack steps.

  4. Map & Prioritise Risks

    Score nodes by likelihood and impact. A ranked risk register is generated automatically across all trees in the forest.

  5. Share & Report

    Export to PDF for board and audit submissions, JSON for programmatic use, or STIX 2.1 to feed your threat intelligence pipeline.

FAQ

Frequently asked questions

Answers to what security teams and solo builders ask most before getting started.

Still have questions?

We usually reply within a day.

Get in touch
Do I need a credit card to sign up?

No. The Free plan requires no payment information — just create an account and start building.

How does forest encryption protect my threat models?

When you lock a forest, your browser generates a unique AES-256-GCM key, encrypts every node label, edge annotation, diagram name, and property locally, then downloads the key as a JSON file and emails it to you. The server stores only ciphertext and never sees the plaintext key. Available on every plan, including Free — see the Security page for the full picture.

Why use ThreatTree instead of a spreadsheet or drawing tool?

Draw.io + Excel gets you started, but it doesn't link diagrams to risk entries, can't rank threats automatically, has no standards mapping, and produces no audit-ready PDF. ThreatTree keeps your DFD, attack trees, risk register, and control mappings in one place — so when someone asks why you prioritised a risk, the answer is traceable rather than anecdotal.

Can I export my data if I cancel or downgrade?

Yes. You can export any forest as JSON at any time — no lock-in. If you downgrade from Pro to Free, your forests are not deleted; you simply cannot create new ones beyond the Free limits until you upgrade again.

Start modeling threats today

Free plan available — no credit card required. Be up and running in minutes.