Hero image

Identify threats to your business

ThreatShield is an open-source, AI-assisted tool for threat modelling. Developed by Inspired Consulting and released under the MIT license. Build it, run it and host it yourself, free of charge.

What it does


AI-assisted threat modelling for your systems

Describe your systems and assets, let the AI suggest concrete threats, assess the risks and plan mitigations. Concrete examples instead of abstract checklists.

Preview image of the app interface

Features


From system description to mitigation plan

Robot icon Animated robot icon

AI-assisted threat identification

Describe a system and its assets. The AI assistant suggests concrete threats and gives you a quick start into threat modelling.

Shield icon Animated shield icon

Risk and mitigation management

Assess each threat, define countermeasures and track their status. Visualise risks and export the model to Excel.

Team icon Animated team icon

Collaboration across teams

Multiple organisations and role-based access let security, development and operations work on the same threat model.

Self-hosting


Run it yourself in three steps

ThreatShield is built with Elixir, Phoenix LiveView and PostgreSQL and ships with a Docker Compose setup. You need an OpenAI API key for the AI features.

Clone the repository

git clone https://github.com/inspired-consulting/threat_shield.git

Configure

Create a .env file with the PostgreSQL connection and your OpenAI API key. The README lists all variables.

Start

docker compose up --build

Open http://localhost:4000 and create your first organisation.

Demo instance


Try it without installing anything

We run a hosted instance at app.threatshield.eu for demonstration, testing and evaluation. It is free of charge and comes without any service guarantees.

Not for production data

  • Threat models are confidential information. Do not enter real system details or anything you would not share publicly.
  • Data on the demo instance may be reset or deleted at any time and is not backed up.
  • For real threat models, run your own instance. See Run it yourself.

Open source


Contributions welcome

ThreatShield is released under the MIT license. Bug reports, feature ideas and pull requests are welcome. A good place to start are the open issues on GitHub.

About


Built by Inspired Consulting

ThreatShield was developed by Inspired Consulting, a software and IT security consultancy in Cologne, Germany. Questions that do not fit into a GitHub issue? Write to [email protected].

inspired.consulting