Web Analyze · reporting Open source

Residual risk, without the flattering number.

Turn a threat model into a report you can drill, filter, and put in front of a board — MITRE coverage by tier, reachability to your crown jewels, boundary-policy verdicts, and a full residual-risk ledger, over one consistent snapshot. Every number traces back to your model, so nothing falls apart when someone pushes on it.

Fresh Reflects the model as of 22 Jul 2026 · 12 components · 4 boundaries
PostureCoverage & GapsReachabilityBoundary CrossingsResidual Risk
Live exposures
2
critical
5
high
9
medium
3
unknown
28 open9 reviewed7 boundary crossings carrying data2 of 5 crown jewels reachable from external entry

Illustrative — the report renders over a stored snapshot of your model.

Numbers you can defend

Hand this to a board or an auditor and it holds — because every figure traces back to something in your model, not to a black-box score. Where a reassuring average would paper over a gap, the report shows the gap; a threat model can only tell you what you have drawn, not what is true in production.

A scope-and-freshness banner sits above every view, surfacing what the report can and can’t speak to — a stale snapshot, missing boundaries, unclassified data — before you read a single count. Read it first, every time.

Five views over
one consistent snapshot.

Every tab renders over the same stored snapshot, so the whole report stays internally consistent as you move around it. Switch views in place, drill into any element, filter down to what matters, and export it as JSON or a self-contained HTML page.

Posture

The whole model at a glance — one click into any number.

The landing view rolls everything up: live exposures by severity band, coverage by tier, open and reviewed counts, crown-jewel reachability, and your top residual risks. Every statistic is a link that jumps you into the detailed view, already filtered.

  • Signals stay separate, and every figure links to the findings beneath it — so it holds when it’s questioned.
  • Affirmed findings stay live and counted; only muted ones drop off.
  • A separate defense-in-depth line counts controls, never folded into coverage.
The Posture tab of the Threat Report: a Fresh snapshot banner, live-exposure tiles for Critical, High, and Medium bands, a tier-segregated coverage line, open/reviewed counts, crown-jewel reachability, and a ranked list of top residual risks.
Coverage & Gaps

See exactly how strong each defense is — by technique, tier, and prevent-vs-detect.

A monochrome matrix charts your live exposures against the techniques they map to. Fill encodes the coverage tier; a single glyph says whether you can prevent the technique or only detect it. The off-grid line keeps the grid from ever reading as a false all-clear.

  • Three tiers — DIRECT, Mitigation, D3FEND — shown distinctly, so you can tell a solid control from a broad inference.
  • An uncovered + detect-only worklist: every technique you cannot currently prevent.
  • Off-grid counts (unmapped, Data, structural gaps) stay in view — a clean grid is not a clean model.
The Coverage & Gaps tab: a monochrome MITRE ATT&CK matrix of techniques by tactic, with an off-grid summary line counting unmapped, Data-mapped, and structural gaps, plus Legend, Tier, and uncovered + detect-only controls.
Reachability

Trace how data reaches your crown jewels — and find the one node that controls every route.

Pick an origin and trace the modeled data-flow routes to your crown jewels, between any two elements, or a node’s full blast radius. For each route: how many hops, where it crosses a boundary, the data sensitivity it carries, and the worst live threat on it.

  • Choke-point analysis — control one node and sever every modeled route to the asset.
  • Blast radius — pick a node and see everything a compromise could reach downstream.
  • Flow routes, not attack paths: a hop count is proximity, not attacker effort — and the tab says so up top.
The Reachability tab in crown-jewel mode: a faithful minimap of the model beside a From selector set to external entry-points, and per-jewel results showing each crown jewel as reachable with its shortest route in hops, boundary crossings, and worst threat band.
Boundary Crossings

Automatic verdicts on every crossing — checked against the segmentation you declared.

Each crossing carries two layers: the declared source-zone ↦ target-zone policy line, and the structural EXIT / ENTER membranes it pierces. Allowed crossings stay silent; only the ones that break your declared-zone policy raise a word.

  • VIOLATION, WARNING, and ADVISORY verdicts — declared intent, never verified enforcement.
  • Sensitivity chip per flow; ranked verdict-severity first, so violations surface to the top.
  • Conduit-error and dead-intent surfaces catch declarations that don’t match the model.
The Boundary Crossings tab: a summary line reading nine flows pierce membranes with three violations, a conduit-error panel, and a crossing showing a declared INTERNAL to UNTRUSTED VIOLATION with EXIT membranes and a live-on-boundary marker, beside a pinned minimap.
Residual Risk

Triage every finding in place — then drill into any element to see why.

Every finding, grouped per element, split into open and reviewed. Triage in place — affirm a confirmed risk, dispose with a reason, raise an issue — then drill into any element’s Component Profile to investigate in depth.

  • Score bands order the work for triage — a sort aid, not a grade stamped on your model.
  • Six disposition reasons; a compensating-control claim with no control gets flagged.
  • Stale dispositions surface when the underlying finding changed after your decision.
The Residual Risk ledger: a summary of 181 findings, whole-model severity and source filters, a collapsed zoning-advisories block, and findings grouped under the checkout-service component with score bands, ATT&CK technique chips, and per-row triage actions.

What the report
won't claim.

Every figure traces back to your model. Here's what it refuses to invent on your behalf — each omission is why a screenshot of the report can't be turned into a claim you never made.

No single risk score

Signals are kept separate instead of blended into one number — so nothing hides behind an average, and a weak spot can’t be averaged away.

No coverage percentage

Coverage is shown tier by tier and function by function. “80% covered” would blend DIRECT certainty with broad inference and bury detect-only gaps.

No attacker model

Reachability shows flow routes, not attack paths. It never models attacker effort, credential reuse, or exploit chaining. A hop count is proximity, not difficulty.

Not a live scan

Coverage is modeled / design-asserted, not telemetry from a running system. The report is a snapshot; edit the model and it flags itself stale until you recreate it.

Snapshot & freshness

A point in time, clearly labelled.

The report renders over the snapshot it stored when you generated it — that's what keeps every tab consistent with every other. Edit the model afterward and the banner switches from Fresh to an amber Stale marker, and the Generate button becomes Recreate. It never auto-updates behind your back, and never nags you for a save that changed nothing.

Export & share

Two formats, the same caveats.

Export JSON for machine-readable data — diff snapshots over time or feed other tools. Export HTML for a self-contained, printable page you can save as a PDF and hand to a stakeholder. Both carry the coverage facts, reachability rollup, boundary-crossing verdicts, and the ledger — and the same caveats shown on screen. Export is disabled while you have pending decisions, so you never share stale numbers.

Generate a report your board can defend.

The Threat Report is an analysis class in every model's Analysis tab. Build a model, run the analysis, and read your residual risk across five consistent views you can drill, export, and defend.