About ThreatTree
We got tired of doing threat modeling in spreadsheets. So we built the tool we always wanted.
"Security teams deserve purpose-built tooling. Threat modeling shouldn't live in a shared spreadsheet — it should be a living, structured artifact that evolves with the architecture it describes."
Our story
ThreatTree started with a security architect's own frustration with the tooling available. The pattern was always the same: drawing DFDs in a generic diagramming tool, tracking attack paths in a spreadsheet, and rebuilding a risk register by hand before every review.
The problem was never the methodology. STRIDE, attack trees, and risk registers work — they're not the bottleneck. The problem was the tooling: either a heavyweight enterprise platform with a six-figure price tag and a sales process to match, or nothing at all.
We started ThreatTree to fix that. A focused, fast, browser-based tool that lets any security team — from a solo consultant to a CISO's organisation — build real threat models without the friction.
What we build
ThreatTree gives security teams three interconnected tools in a single workspace:
- Data Flow Diagrams to map your system architecture and identify trust boundaries.
- Attack Trees to decompose threats and score them against STRIDE, MITRE ATT&CK, and ISO 27001 controls.
- Risk Registers that auto-populate from your attack trees and export to board-ready PDF reports.
Everything lives in a forest of trees — organised, versioned, and searchable — so your threat models stay grounded in the architecture they describe.
Who we are
We're the team behind ThreatTree, based in the United Kingdom. ThreatTree grew out of a security architect's own day-to-day threat modeling work — the same work it now exists to make faster for everyone else.
We built ThreatTree for our own work first, and we rely on it ourselves today.
Why trust us with your threat models?
We understand that threat models are sensitive documents. They describe your system's weaknesses. Here's what we do to protect them:
- All data is stored on servers within the United Kingdom, governed by UK GDPR — which provides protections equivalent to the EU GDPR — with EU-based hosting planned for the future.
- Connections are encrypted in transit (TLS 1.2+).
- Diagram content is encrypted at rest (AES-256-GCM) for forests where encryption is enabled.
- We don't sell your data or use it for advertising — ever.
- You can export and delete your data at any time.
For the full picture, see our Security and Privacy Policy pages.
Get in touch
We read every email. Reach us at hello@threattree.com — for product questions, feedback, or if you'd like to discuss enterprise requirements.
For security concerns, contact security@threattree.com.