Data Flow Diagram
Template
A worked example with external entities, processes, a data store, and a trust boundary already laid out and labeled -- open it in draw.io, delete the example content, and drop in your own system.
Every DFD element, already placed and labeled
A small e-commerce example -- a customer, a web app, a database, and a payment provider -- so the notation is obvious before you replace it with your own architecture.
| Element | Shape | Example in the template |
|---|---|---|
| External Entity | Gray rectangle | "Customer" and "Payment Provider" -- anything outside your system's control |
| Process | Blue rounded rectangle | "Web Application" -- anything that transforms or acts on data |
| Data Store | Yellow cylinder | "Customer Database" -- anywhere data is persisted at rest |
| Trust Boundary | Dashed red rectangle | "Production VPC" -- any point where trust level changes |
| Data Flow | Labeled arrow | Four labeled flows, including one crossing the trust boundary |
Get the file
Opens directly in draw.io / diagrams.net, or drag it into the VS Code draw.io extension.
A diagram tells you the shape. It doesn't tell you the risk.
This template gets your architecture on paper correctly. What it can't do is tell you which flow is actually dangerous, or turn that judgment into evidence someone else can review.
-
STRIDE Tagging Per Element
In ThreatTree, every process, data store, and flow can be tagged with STRIDE, LINDDUN, or MITRE ATT&CK directly on the diagram -- not in a separate spreadsheet you have to keep in sync by hand.
-
Attack Trees Linked to the DFD
Decompose a threat into an Attack Tree and link it straight back to the DFD node it targets -- the connection this template can't express on its own.
-
Auto-Generated Risk Register
Every threat rolls up into a ranked risk register automatically -- no copying rows between a diagram tool and a spreadsheet.
-
Board-Ready PDF Reports
Export the diagram, attack trees, and risk register together as one PDF -- not a diagram file and a spreadsheet that drift apart over time.
Questions about the template
What people ask before downloading.
Do I need to sign up to download this?
No. The download link goes straight to the file -- no email, no account, no form.
What software do I need to open a .drawio file?
draw.io (also called diagrams.net) is free and runs at app.diagrams.net -- open it, choose File > Open From > Device, and select the downloaded file. It also has free desktop apps for Windows, macOS, and Linux, and a VS Code extension.
Is this template free to use, including commercially?
Yes. Edit it, rebrand it, use it in client work -- no attribution required.
How is this different from just using ThreatTree directly?
This template gets you a correctly structured diagram. ThreatTree adds STRIDE tagging per element, links each threat to an Attack Tree, and rolls everything into a scored, exportable risk register -- the parts a static diagram can't do on its own.
Outgrow the static diagram when you're ready
Free plan available -- no credit card required. Import your DFD's structure straight into a forest.