Graph-native • Deterministic • Modular • Open-source • AI-accelerated

Threat modeling at the pace of change.

A deterministic, graph-native platform that keeps your model current as your architecture moves — every finding traced to real evidence, not a model's guess. Open-source to self-host; AI accelerates the work, it never decides it.

Built to analyze, not just document

Graph-Native Core

Graph-Native Core

Model security as relationships, not rows. Attack paths, blast radius, and chokepoints are first-class graph operations.

MITRE ATT&CK Integration

MITRE ATT&CK Integration

Automatic exposure-to-ATT&CK and control-to-D3FEND mapping. Coverage gap analysis in seconds.

Pluggable AI Analysis

Pluggable AI Analysis

From deterministic queries to multi-agent LangGraph workflows. Swappable analysis engines, zero vendor lock-in.

Module Ecosystem

Module Ecosystem

Real JavaScript plugins that extend the platform structure, backend logic, and frontend UI. Not templates.

Multi-Interface

Multi-Interface

GUI for security teams, CLI for CI/CD pipelines, Claude Code plugin and MCP protocol for AI agents. Same graph, same API.

Self-Hosted Deployment

Self-Hosted Deployment

Run the containerized stack on your own cloud, on-prem, or fully air-gapped — your models and data never leave your network.

Not another AI tool

Accelerated by AI. Grounded without it.

Model in a sitting instead of a week — the Claude Code plugin drafts from your real infrastructure. But nothing you ship rests on a model's opinion. Turn AI off and the platform is unchanged: the same deterministic graph, the same evidence-cited findings you can put in front of an auditor.

Deterministic core

Every exposure, control, and attack path is computed from your model and cited to real evidence — reproducible, inspectable, and the same on every run.

AI as accelerator

AI speeds the drafting and the questions — discovery, modeling, triage. It's an optional layer you control, never a dependency and never the source of truth.

Run dethernety yourself, or bring us in for architecture and threat analysis on your systems.

Security is a graph problem

Traditional tools treat components in isolation. Graphs reveal what connects them — and what an attacker can reach.

What you can ask a spreadsheet

  • List all high-severity vulnerabilities
  • Which components are internet-facing?
  • How many controls are assigned?
  • Sort risks by CVSS score

What you can ask a graph

  • Show every path from the internet to PII with fewer than 2 controls
  • If this API is compromised, what's the blast radius?
  • Which single control protects the most attack paths?
  • Where are the chokepoints an attacker must traverse?

DORA · NIS2 · customer security reviews

Evidence for your obligations, not another score.

Regulators, boards, and customers don't accept a percentage. dethernety turns your architecture into deterministic, citable evidence — every exposure mapped to MITRE ATT&CK, every control to the standard it satisfies — so the output survives a CFO and an auditor. It's the pack a CISO takes to the board, and the deliverable a consultant hands a client.

DORANIS2ISO 27001SOC 2PCI-DSSGDPR

The evidence foundation — ATT&CK / D3FEND mapping and control-coverage analysis — is available today. Dedicated DORA and NIS2 evidence packs are in development.

From model to remediation in four steps

01

Model

Drag-and-drop components, connect data flows, configure attributes.

02

Configure

Assign reusable security controls. Check auto-generated exposures.

03

Analyze

Run context-aware analysis across the full architecture graph.

04

Track

Create issues, sync to external trackers, track remediation.

Ready to see the graph?

Get a walkthrough of dethernety on your own architecture, or watch the demo.