
The Platform
Model, analyze, and extend — on one graph.
Build a living threat model from the browser, your codebase, or a report — then analyze it with full architectural context and extend it to the technologies you actually run.
One graph, end to end
Model your architecture, analyze the risk in context, and extend to the technologies you actually run — one graph underneath every step.
Model
Turn your architecture into a living graph you can query.
Analyze
See attack paths, blast radius, and residual risk in context.
Extend
Cover the technologies you run, or author classes for anything we don't.
Graph-Native Foundation
Neo4j / Memgraph
Security relationships are first-class citizens, not JOIN operations. Attack paths, data flows, and escalation chains are stored as graph edges. Multi-hop analysis that would take hundreds of lines of SQL becomes a 4-line Cypher query.
- Relationships visible by default
- Real-time attack path traversal
- Cross-model graph queries

MITRE ATT&CK & D3FEND
Built-in, not bolted on
Exposures automatically map to ATT&CK techniques. Controls map to D3FEND countermeasures. Coverage gap analysis reveals which techniques are exposed and which controls address which threats.
- Automatic exposure-to-ATT&CK mapping
- Control-to-D3FEND countermeasures
- Coverage gap analysis in seconds

Module Ecosystem
Real plugins, not templates
JavaScript/TypeScript packages loaded at runtime. Design classes define component types with attributes and policies. Analysis classes create custom engines. Issue classes integrate with external trackers.
- Design, Analysis, and Issue classes
- OPA/Rego policy engine
- AI-assisted module creation via Studio

Pluggable Analysis
Context-aware, not component-only
Analysis sees the complete architecture graph, not isolated components. Choose from query-based deterministic analysis, single-agent AI acceleration, or multi-agent LangGraph workflows.
- Full model context analysis
- Swappable analysis engines
- Zero AI vendor lock-in

Issue Management
From finding to fix
Create actionable issues directly from analysis findings. Track remediation progress, assign ownership, and sync bidirectionally with external trackers through issue modules.
- One-click issue creation from findings
- Any tracker via issue modules
- Remediation tracking dashboard

Same graph, wherever you work
Design visually in the browser, automate in your CI/CD pipeline, or model conversationally in Claude Code — every surface reads and writes the one graph.

GUI
Security teams
Visual drag-and-drop threat modeling for security architects and compliance teams.

CLI
DevOps teams
Command-line automation for CI/CD pipelines. Threat-model-as-code with version control.

CC Plugin
AI-assisted workflows
Claude Code plugin for threat modeling and infrastructure discovery. Conversational threat modeling and infrastructure discovery.
Runs on your infrastructure
Self-host the containerized stack on your own cloud, on-prem, or fully air-gapped. Your models, data, and findings never leave your network.
Self-hosted by default
Deploy as a Compose stack or an immutable, image-based VM on infrastructure you control — cloud, on-prem, or fully offline.
Immutable Infrastructure
Container-optimized OS with no in-place patching. Entire instances are replaced, ensuring pristine state with no configuration drift.
Bring your own graph
You host the graph database. Cloud-served modules are optional, and even then only closed-vocabulary attributes ever leave your network.
Prefer a fully managed deployment? A per-customer-isolated Hosted SaaS edition is planned.
See it in action
Watch the platform demo or get in touch to discuss your threat modeling needs.





