What it does
AI-assisted threat modelling for your systems
Describe your systems and assets, let the AI suggest concrete threats, assess the risks and plan mitigations. Concrete examples instead of abstract checklists.
Features
From system description to mitigation plan
AI-assisted threat identification
Describe a system and its assets. The AI assistant suggests concrete threats and gives you a quick start into threat modelling.
Risk and mitigation management
Assess each threat, define countermeasures and track their status. Visualise risks and export the model to Excel.
Collaboration across teams
Multiple organisations and role-based access let security, development and operations work on the same threat model.
Self-hosting
Run it yourself in three steps
ThreatShield is built with Elixir, Phoenix LiveView and PostgreSQL and ships with a Docker Compose setup. You need an OpenAI API key for the AI features.
Clone the repository
git clone https://github.com/inspired-consulting/threat_shield.git
Configure
Create a .env file with the PostgreSQL connection and your OpenAI API key. The README lists all variables.
Start
docker compose up --buildOpen http://localhost:4000 and create your first organisation.
Demo instance
Try it without installing anything
We run a hosted instance at app.threatshield.eu for demonstration, testing and evaluation. It is free of charge and comes without any service guarantees.
Not for production data
- Threat models are confidential information. Do not enter real system details or anything you would not share publicly.
- Data on the demo instance may be reset or deleted at any time and is not backed up.
- For real threat models, run your own instance. See Run it yourself.
Open source
Contributions welcome
ThreatShield is released under the MIT license. Bug reports, feature ideas and pull requests are welcome. A good place to start are the open issues on GitHub.
About
Built by Inspired Consulting
ThreatShield was developed by Inspired Consulting, a software and IT security consultancy in Cologne, Germany. Questions that do not fit into a GitHub issue? Write to [email protected].
Repository