Built for SOC 2 Trust Services Criteria

Threat Modeling
for SaaS & Startups

SOC 2 auditors want continuous evidence of risk management, not a spreadsheet refreshed once a year before the audit window opens. ThreatTree gives a small security team -- or a solo founder wearing the security hat -- a structured way to identify, score, and re-evaluate risk as the system actually changes.

Free forever plan Works for Type I and Type II Export anytime, no lock-in
SOC 2 Trust Services Criteria

Risk-assessment criteria, mapped to ThreatTree

SOC 2 isn't prescriptive about tooling, but the criteria most relevant to risk assessment are consistent. Here's where each fits in a ThreatTree forest.

TSC criterion In ThreatTree
1 Audit scope definition
The systems that actually handle customer data, not everything that might
A Data Flow Diagram tree shows exactly which systems touch customer data, preventing the over-scoping that inflates audit cost
2 CC3.2 -- specify security objectives and identify risks to achieving them STRIDE tagging across every DFD element gives you a documented, repeatable risk identification process, not an ad hoc list
3 CC3.3 -- assess the significance of identified risks, including likelihood and impact Attack Trees decomposed with Likelihood x Impact scoring produce a scored risk register with rationale, not a gut-feel priority list
4 CC4.1 -- ongoing monitoring evaluates the continuing relevance of controls Update the forest as your system changes and re-export the risk register -- a timestamped series of exports across the audit period is the evidence of continuous process CC4.1 wants
5 CC9.2 -- assess and manage risk associated with vendors and business partners External entities in the DFD are tied to specific integration points and trust boundaries, categorically stronger evidence than a vendor questionnaire

What this is, and isn't: ThreatTree is a threat modeling tool, not an auditor or a substitute for your SOC 2 readiness advisor. It helps you build the living risk-identification evidence auditors look for under CC3.2, CC3.3, CC4.1, and CC9.2 -- whether it satisfies a specific engagement is your auditor's call.

Why teams use ThreatTree

A living risk register, not a yearly spreadsheet

Every threat traces back to a real system, and every risk decision traces back to a rated attack path.

  • Architecture-Anchored Scope

    Model your system with DFDs -- processes, data stores, trust boundaries, and external entities -- so audit scope is drawn from your actual architecture, not a guess.

  • Attack Path Decomposition

    Break each threat into an Attack Tree with AND/OR logic, from attacker goal to atomic step -- evidence an auditor can follow, not just a claim.

  • Prioritized Risk Register

    Likelihood x Impact scoring generates a ranked risk register automatically across every tree in a forest -- re-export it as often as your audit window needs.

  • Auditor-Ready PDF Reports

    Generate a report with architecture, attack trees, and ranked risk register in a single PDF -- built to sit alongside your SOC 2 evidence package.

FAQ

SaaS & startup threat modeling, answered

What founders and small security teams ask before adopting ThreatTree.

Still have questions?

We usually reply within a day.

Get in touch
Does ThreatTree replace our SOC 2 auditor?

No. ThreatTree helps you build the risk identification, scoring, and vendor-risk evidence auditors look for under TSC CC3.2, CC3.3, and CC9.2 -- it doesn't perform the audit or issue a report.

Can a solo founder without a security background use this?

Yes. ThreatTree is built for security teams and just as suited to a solo builder securing a side project or a first SOC 2 audit -- STRIDE and the risk register give you a structured process to follow rather than requiring you to invent one.

Does this work for SOC 2 Type I and Type II?

Yes. Export the risk register at a single point in time for Type I, or export it repeatedly across your audit window for Type II -- the timestamped history is what demonstrates the ongoing process CC3.3 and CC4.1 ask for.

Is there a deeper guide on this?

Yes -- the blog post linked below goes deep on why static, once-a-year documents fail the continuous-assurance test auditors now expect, and walks through CC3.2, CC3.3, CC4.1, CC7.2, and CC9.2 in detail.

Start building SOC 2 evidence in ThreatTree

Free plan available -- no credit card required. Be up and running in minutes.