Coming soonNext.jsFastifyFSL-1.1

Threat modeling that keeps up.

ThreatForge is an AI-native threat modeling platform for security architects and the engineers they work with. Draw the system or import it, and get a living security model: AI finds the threats, people review them, and every mitigation is tracked to done.

threatforge · Online Checkout
ThreatForge canvas with a checkout system inside a trust boundary, and a threats panel listing 44 threats with severity and CVSS scores
Demo model. Threats are scoped to the components and boundaries you draw.
The problem

Everyone agrees on threat modeling. Almost nobody does it.

A thorough STRIDE model of a microservices system takes a trained architect two to three days. It ends up in a Word document that is stale by the next sprint, juniors can't do it without help, and it never connects to the compliance tracker.

ThreatForge lets AI do the first 80 percent of the analysis, makes it fast enough to run on every pull request, and connects the result straight to compliance evidence and remediation tickets.

What makes it different

Three things legacy tools don't do

Reason

AI that reasons, not lists

Threats are generated from your actual component types, trust boundaries, data classifications and sequence flows, not generic bullets. Low-confidence results get re-prompted, and duplicates are blocked.

Review

A human signs off

AI suggestions land as suggestions. People accept, modify or reject each one, edits are never overwritten by a later AI run, and auditors can see who decided what.

Living

Stays current

Import an SRS, Terraform or a GitHub repo into the same model. After a sprint, only components whose architecture changed are re-analyzed.

How it works

From diagram to tracked mitigation

Each step feeds the next, and every version of the model is snapshotted so you can see how risk changed over time.

  1. ModelDraw on the canvas, or import Terraform, an SRS or a repo scan
  2. AnalyzeSTRIDE, PASTA and ATT&CK analysis scoped to each component
  3. ReviewAccept, modify or reject every AI suggestion
  4. TrackAssign mitigations, sync to tickets, map to frameworks
Specs

Built for teams

Who it's for
RoleWhat they get
Security architectAI-assisted STRIDE, PASTA and ATT&CK with a multi-pass expert pipeline
DeveloperA guided wizard, STRIDE education and threat templates
Compliance12 frameworks, requirement traceability, gap analysis, PDF and CSV exports
ProductA risk dashboard, severity trends and executive summaries
DevOpsAPI tokens, CI scan endpoints and Terraform import
AdminRBAC, SSO and SAML, SCIM and audit logs
Stack
  • Next.js 16, React 19 and React Flow canvas
  • Fastify 5 API on Node 22, PostgreSQL 17
  • Real-time collaboration with Yjs
  • AI through Claude, OpenAI or local Ollama
Export

PDF, JSON, YAML, PNG and SVG, plus sequence diagrams linked to the threat model.

License

Source-available under FSL-1.1. Free to self-host and use internally. Each release converts to Apache 2.0 after two years.

Launching soon

Self-host it with Docker Compose, or try it at threatforge.bpmforge.com.

Visit ThreatForge