AI that reasons, not lists
Threats are generated from your actual component types, trust boundaries, data classifications and sequence flows, not generic bullets. Low-confidence results get re-prompted, and duplicates are blocked.
ThreatForge is an AI-native threat modeling platform for security architects and the engineers they work with. Draw the system or import it, and get a living security model: AI finds the threats, people review them, and every mitigation is tracked to done.

A thorough STRIDE model of a microservices system takes a trained architect two to three days. It ends up in a Word document that is stale by the next sprint, juniors can't do it without help, and it never connects to the compliance tracker.
ThreatForge lets AI do the first 80 percent of the analysis, makes it fast enough to run on every pull request, and connects the result straight to compliance evidence and remediation tickets.
Threats are generated from your actual component types, trust boundaries, data classifications and sequence flows, not generic bullets. Low-confidence results get re-prompted, and duplicates are blocked.
AI suggestions land as suggestions. People accept, modify or reject each one, edits are never overwritten by a later AI run, and auditors can see who decided what.
Import an SRS, Terraform or a GitHub repo into the same model. After a sprint, only components whose architecture changed are re-analyzed.



Each step feeds the next, and every version of the model is snapshotted so you can see how risk changed over time.
| Role | What they get |
|---|---|
| Security architect | AI-assisted STRIDE, PASTA and ATT&CK with a multi-pass expert pipeline |
| Developer | A guided wizard, STRIDE education and threat templates |
| Compliance | 12 frameworks, requirement traceability, gap analysis, PDF and CSV exports |
| Product | A risk dashboard, severity trends and executive summaries |
| DevOps | API tokens, CI scan endpoints and Terraform import |
| Admin | RBAC, SSO and SAML, SCIM and audit logs |
PDF, JSON, YAML, PNG and SVG, plus sequence diagrams linked to the threat model.
Source-available under FSL-1.1. Free to self-host and use internally. Each release converts to Apache 2.0 after two years.
Self-host it with Docker Compose, or try it at threatforge.bpmforge.com.