About ThreatTree

We got tired of doing threat modeling in spreadsheets. So we built the tool we always wanted.

"Security teams deserve purpose-built tooling. Threat modeling shouldn't live in a shared spreadsheet — it should be a living, structured artifact that evolves with the architecture it describes."

Our story

ThreatTree was built by security engineers who spent years doing threat modeling the hard way — drawing DFDs in diagramming tools, tracking attack paths in spreadsheets, and generating risk registers by hand before every compliance audit.

The problem wasn't the methodology. STRIDE, attack trees, and risk registers work. The problem was the tooling: either heavyweight enterprise platforms with six-figure price tags, or nothing at all.

We started ThreatTree to fix that. A focused, fast, browser-based tool that lets any security team — from a two-person startup to a CISO's organisation — build real threat models without the friction.

What we build

ThreatTree gives security teams three interconnected tools in a single workspace:

  • Data Flow Diagrams to map your system architecture and identify trust boundaries.
  • Attack Trees to decompose threats and score them against STRIDE, MITRE ATT&CK, and ISO 27001 controls.
  • Risk Registers that auto-populate from your attack trees and export to board-ready PDF reports.

Everything lives in a forest of trees — organised, versioned, and searchable — so your threat models stay grounded in the architecture they describe.

Who we are

We're a small team of security engineers and software developers based in the European Economic Area. Our backgrounds span application security, penetration testing, cloud architecture, and product engineering at companies across the UK and Europe.

We hold relevant industry certifications and have spent years in the field doing the work that ThreatTree now makes faster. We built this for ourselves first — and we use it every day.

Why trust us with your threat models?

We understand that threat models are sensitive documents. They describe your system's weaknesses. Here's what we do to protect them:

  • All data is stored on servers within the European Economic Area, governed by GDPR.
  • Connections are encrypted in transit (TLS 1.2+).
  • Diagram content is encrypted at rest (AES-256-GCM) for forests where encryption is enabled.
  • We don't sell your data or use it for advertising — ever.
  • You can export and delete your data at any time.

For the full picture, see our Security and Privacy Policy pages.

Get in touch

We're a small team and we read every email. Reach us at hello@threattree.com — for product questions, feedback, or if you'd like to discuss enterprise requirements.

For security concerns, contact security@threattree.com.