Editions

Your threat model never leaves your infrastructure.

Dethernety runs on your machines, not ours. Start with the open-source core for free; add cloud-served module packages when you want them — and even then, only a closed vocabulary of attributes ever leaves your network. Your models, data, and findings never do.

A vertical data-boundary diagram. At the top, an optional 'Dethernety Cloud' zone serves module content, policy evaluation, and a knowledge graph, and holds no model data. At the bottom, the larger 'Your network' zone holds the Dethernety platform, your threat models, your data and findings, and a graph database you host. Across a horizontal boundary, only closed-vocabulary config attributes flow up to the cloud and only module content and verdicts flow back down — your models, findings, and free text never cross, and the cloud holds nothing tied to you.

What crosses the line, and what never does.

Sovereignty by default

Most security tools ask you to ship your architecture to their cloud. Dethernety works the other way around: you run the platform, and the cloud is an optional service that sends module content in and receives a closed set of attributes back — never your models, never your findings.

Four of the editions below are self-hosted. The cloud is something you add for convenience, not a place your data goes to live.

Own as much as
you want to.

A spectrum from fully self-hosted and free, to a managed service — with the data boundary moving only as far as you choose.

Open Source

Available nowYou host everything

The whole platform, self-hosted and free.

  • Run the full modeling and analysis platform on your own infrastructure — GUI, Dethereal, Threat Report.
  • Includes the open, vendor-neutral general module and the core capabilities.
  • Bring your own graph database; ships as a compose file and a bootc VM appliance.
  • Fully offline-capable — zero cloud calls unless you choose to add them.

BYODt

Coming soonYou host — cloud serves modules

Bring Your Own Dethernety — your platform, plus cloud-served module packages and evaluation.

  • Subscribe to specialized packages — AWS, Kubernetes, self-managed, and more — served from the cloud.
  • The curated knowledge graph and policy evaluation delivered as a service; you never maintain the threat intelligence.
  • Your models, data, and findings stay on your machine — only closed-vocabulary attributes leave, and nothing is stored.
  • For consultants and individuals running the open-source platform.

BYODt+

PlannedYou host — cloud serves modules

BYODt with multi-user team management.

  • Everything in BYODt, shared across a team.
  • Team subscription, member management, and shared package access.
  • The same data-sovereign boundary — nothing about your models is stored in the cloud.

Enterprise

Available — by contractYou host everything

Self-hosted under contract, on your terms.

  • Your own identity provider; air-gap-friendly deployment.
  • Signed module packages delivered through a contracted pipeline.
  • Dedicated support, deployment help, and individual terms.
  • Nothing leaves your environment — the contract is the enforcement.

Hosted SaaS

Planned — laterWe host

We host it — one isolated environment per customer.

  • A fully managed deployment for teams that would rather not host it themselves.
  • Per-customer isolation, not shared multi-tenancy — separate network, identity, storage, and compute for every tenant.
  • The boundaries are structural: one customer’s threat model can never reach another’s, even if a component is compromised.

How the cloud stays
at arm's length.

When you do add cloud modules, four properties keep your data on your side of the line.

Served, not downloaded

Module content is delivered per request, not shipped to your instance in bulk. Evaluation payloads are answered and discarded — no copy of your model is ever made.

Policies stay in the cloud

Evaluation rules run server-side and are never shipped to your instance — you get the verdict, not a copy of the logic to protect.

Attributes-only payloads

Evaluation sends a closed vocabulary of configuration attributes — never your architecture, your findings, or free text.

No background telemetry

The platform reaches the cloud only to fetch modules and request evaluations — on your action, never to report on you. It sends no telemetry or usage data on its own. What we measure comes from the account portal and billing, cloud-side.

To be precise about what the cloud does hold: your account, and coarse operational metadata for billing and abuse-prevention. It is not tied to your model, and it never records which classes you use.

How BYODt is packaged

Subscribe by domain, not by seat-count math.

Cloud modules are sold as packages — an AWS package, a Kubernetes package, and so on — each bundling the specialized modules for that domain. A simple monthly subscription with a free trial; a yearly option for the ones who stay.

Package composition and pricing are being finalized ahead of launch. Join early access to help shape the first packages and hear the numbers first.

Questions worth asking.

Do you store my threat models?

No. Your models, data, and findings stay on your infrastructure and never reach the cloud. The cloud holds your account and coarse operational metadata for billing and abuse-prevention — the evaluation attributes it receives are answered and not stored, and are never tied to your model.

Can I run it completely offline?

Yes. The open-source edition makes zero cloud calls. Cloud modules are opt-in configuration; without them, everything runs locally.

Why do I bring my own database?

The graph database is pulled from its own channel rather than bundled — its license does not permit redistribution, and it keeps your data entirely under your control. Setup guides cover the supported options.

When can I subscribe to BYODt?

It is in active development. Join early access and we will reach out as it opens — that also helps us shape the first module packages.

Start self-hosted, free.

Run the open-source platform on your own infrastructure today. Add cloud module packages the day BYODt opens — your data stays exactly where it is.