Graph-native • Deterministic • Modular • Open-source • AI-accelerated
Threat modeling at the pace of change.
A deterministic, graph-native platform that keeps your model current as your architecture moves — every finding traced to real evidence, not a model's guess. Open-source to self-host; AI accelerates the work, it never decides it.
Built to analyze, not just document

Graph-Native Core
Model security as relationships, not rows. Attack paths, blast radius, and chokepoints are first-class graph operations.

MITRE ATT&CK Integration
Automatic exposure-to-ATT&CK and control-to-D3FEND mapping. Coverage gap analysis in seconds.

Pluggable AI Analysis
From deterministic queries to multi-agent LangGraph workflows. Swappable analysis engines, zero vendor lock-in.

Module Ecosystem
Real JavaScript plugins that extend the platform structure, backend logic, and frontend UI. Not templates.

Multi-Interface
GUI for security teams, CLI for CI/CD pipelines, Claude Code plugin and MCP protocol for AI agents. Same graph, same API.

Self-Hosted Deployment
Run the containerized stack on your own cloud, on-prem, or fully air-gapped — your models and data never leave your network.
Not another AI tool
Accelerated by AI. Grounded without it.
Model in a sitting instead of a week — the Claude Code plugin drafts from your real infrastructure. But nothing you ship rests on a model's opinion. Turn AI off and the platform is unchanged: the same deterministic graph, the same evidence-cited findings you can put in front of an auditor.
Deterministic core
Every exposure, control, and attack path is computed from your model and cited to real evidence — reproducible, inspectable, and the same on every run.
AI as accelerator
AI speeds the drafting and the questions — discovery, modeling, triage. It's an optional layer you control, never a dependency and never the source of truth.
Run dethernety yourself, or bring us in for architecture and threat analysis on your systems.

Security is a graph problem
Traditional tools treat components in isolation. Graphs reveal what connects them — and what an attacker can reach.
What you can ask a spreadsheet
- List all high-severity vulnerabilities
- Which components are internet-facing?
- How many controls are assigned?
- Sort risks by CVSS score
What you can ask a graph
- Show every path from the internet to PII with fewer than 2 controls
- If this API is compromised, what's the blast radius?
- Which single control protects the most attack paths?
- Where are the chokepoints an attacker must traverse?
DORA · NIS2 · customer security reviews
Evidence for your obligations, not another score.
Regulators, boards, and customers don't accept a percentage. dethernety turns your architecture into deterministic, citable evidence — every exposure mapped to MITRE ATT&CK, every control to the standard it satisfies — so the output survives a CFO and an auditor. It's the pack a CISO takes to the board, and the deliverable a consultant hands a client.
The evidence foundation — ATT&CK / D3FEND mapping and control-coverage analysis — is available today. Dedicated DORA and NIS2 evidence packs are in development.
From model to remediation in four steps
Model
Drag-and-drop components, connect data flows, configure attributes.
Configure
Assign reusable security controls. Check auto-generated exposures.
Analyze
Run context-aware analysis across the full architecture graph.
Track
Create issues, sync to external trackers, track remediation.
Ready to see the graph?
Get a walkthrough of dethernety on your own architecture, or watch the demo.
