Security
How we protect the threat models you store with us — and why we take it seriously.
Data storage location
All ThreatTree data — account information, threat models, diagrams, and risk registers — is stored on servers within the European Economic Area (EEA). We do not replicate your data outside the EEA. This means your data is governed by GDPR regardless of where you access ThreatTree from.
Encryption in transit
All connections to ThreatTree are encrypted using TLS 1.2 or higher. Plain HTTP connections are automatically redirected to HTTPS. This applies to the web application, API calls, and email delivery.
Encryption at rest
ThreatTree supports per-forest encryption using AES-256-GCM. When you enable encryption for a forest, the diagram content — nodes, edges, labels, and properties — is encrypted at rest using a key derived from your account. Unencrypted backups of encrypted forests are not stored on disk.
Database-level encryption (full disk encryption) is applied at the infrastructure level for all data regardless of per-forest settings.
Access controls
Access to your data is controlled at multiple levels:
- Authentication: all API requests require a valid Bearer token issued at login. Tokens are invalidated on logout and password change.
- Authorization: forests are owned and scoped to your account. Membership sharing is explicit — no forest is accessible to other users without an invitation.
- Employee access: ThreatTree staff do not have routine access to your diagram content. Access to production data is restricted to a small number of engineers, requires justification, and is logged.
Backups and recovery
Database backups are taken daily and retained for 30 days. Backups are stored encrypted and in a separate location from the primary data store. Recovery procedures are tested regularly.
Dependency and supply-chain practices
We keep our dependency footprint minimal and review third-party packages before inclusion. Dependencies are pinned and updated through a controlled process. We do not include third-party analytics, advertising, or tracking scripts in the application.
Compliance roadmap
ThreatTree is not currently SOC 2 or ISO 27001 certified. Pursuing formal certification is on our roadmap as we grow. In the meantime, the controls described on this page reflect our commitment to sound security practices aligned with those frameworks.
If your organisation has specific compliance requirements, contact us to discuss what evidence we can provide.
Vulnerability disclosure
If you discover a security vulnerability in ThreatTree, please report it responsibly to security@threattree.com.
We ask that you give us reasonable time to investigate and remediate before public disclosure. We will acknowledge receipt within 2 business days and aim to resolve confirmed vulnerabilities within 30 days depending on severity.
We do not currently operate a paid bug bounty programme, but we recognise researchers who report valid findings in our release notes (with their consent).
Contact
For security-related questions or concerns, contact us at security@threattree.com. For general privacy questions, see our Privacy Policy or email privacy@threattree.com.