Threat model a real system on a real canvas
Draw your system — or seed a starting diagram from a URL or a short description — then get AI-suggested STRIDE (or LINDDUN) threats per element, each scored and tied to a mitigation and a control citation from NIST 800-53, CIS Controls v8, ISO 27001 or PCI DSS 4.0. Free with any signed-in PlayCISO account, free plan included.
What it gives you
System diagram canvas
Add processes, data stores, actors, external systems and trust boundaries, then drag connections between them to map how data actually flows.
Seed from a URL or a description
Paste a public site URL — it reads the page’s security headers and third-party calls and infers a starting diagram, without storing the page — or describe the system in a sentence and let AI draft it.
AI-suggested STRIDE or LINDDUN threats
Select an element and get threats scored qualitatively, by CVSS, or by DREAD, each with a mitigation and a control citation from NIST 800-53, CIS Controls v8, ISO 27001 or PCI DSS 4.0 — plus MITRE ATT&CK and CWE references where relevant.
Trust-boundary crossing checks
Mark trust boundaries and run an analysis that flags which data flows cross them, so a boundary you drew is more than decoration.
Disposition & residual risk
Mark each threat open, mitigated, accepted, transferred or avoided, with an owner and review date, and record the residual risk once a control is in place.
Exports that keep the work
PNG or SVG of the diagram, the full model as JSON, a CSV threat register, and a printable PDF threat register.
How it works
- 1Add elements to the canvas — processes, data stores, actors, external systems, trust boundaries — or seed a starting diagram from a URL or a short description.
- 2Classify each element’s data (public through confidential, PII, PHI, PCI, secret) and draw the data flows between them; run the boundary check to flag flows crossing a trust boundary.
- 3Select an element and hit “Suggest STRIDE threats” (or switch to LINDDUN) to get AI-suggested threats with likelihood/impact, a mitigation, and a control citation.
- 4Set each threat’s disposition, track residual risk, and export the diagram and threat register as PNG, SVG, JSON, CSV or PDF.
Honest about what this is
- A real diagramming canvas for threat modeling a system, alone or in a workshop, with threats grounded in named control frameworks rather than a generic checklist.
- Free with any signed-in PlayCISO account, free plan included — there is no paywall on the tool itself.
- ✕ Not an automated scanner of your live infrastructure — the URL seed only reads what a public page’s headers and network calls reveal; everything else on the canvas is what you draw.
- ✕ The AI-suggested threats and control citations are a fast first pass to review and adjust, not a certified assessment.
FAQ
What does Threat Model Studio actually do?
You build a system diagram — processes, data stores, actors, external systems and trust boundaries, connected by data flows — either by hand, from a pasted URL, or from a short text description. Select any element and it suggests STRIDE (or LINDDUN) threats scored by likelihood and impact, CVSS, or DREAD, each with a mitigation and a citation into a real control framework.
Is it free?
Yes. Any signed-in PlayCISO account, including the free tier, can open the workspace and use it — there is no plan or payment wall on the tool itself. A paid plan only matters if you want higher usage limits or the other studios as a team.
What does "real control citations" mean?
Each suggested threat’s mitigation is tied to a specific control ID from a named framework — NIST 800-53, CIS Controls v8, ISO/IEC 27001, or PCI DSS 4.0 — plus a MITRE ATT&CK technique ID and/or a CWE ID where one applies, instead of a generic "add a firewall" suggestion.
What happens when I seed a diagram from a URL?
It fetches the public page, reads its security headers and third-party calls, and infers a high-level starting diagram from that. The page itself isn’t stored — you’re expected to correct and extend whatever it produces.
What can I export?
The diagram as PNG or SVG, the full model as JSON, the threat register as CSV, and a printable PDF threat register.