STRIDE/NIST CSF 2.0/CIS Controls v8
Threat models you'd put your name on, in 90 seconds.
PathSecurity turns a short description of your system into a complete STRIDE threat model: attack graphs, a risk-scored register, and control-mapped mitigations. Export to PDF, DOCX, Markdown, or JSON.
human-reviewed assessments · or a free self-serve model, no card to try
- entry
- at-risk flow
- critical path
- crown jewel
the pipeline
Five reasoning stages, from system sketch to signed-off report
- 1stage_1
Decomposition
Break the system into components, data flows, and trust boundaries.
- 2stage_2
Threat enumeration
Enumerate concrete STRIDE threats per component and data flow.
- 3stage_3
Risk scoring
Score likelihood × impact into a prioritized composite risk.
- 4stage_4
Mitigation mapping
Map fixes to NIST CSF 2.0 and CIS Controls v8 by ID.
- 5stage_5
Deliverable assembly
Assemble a publication-quality report with diagrams and roadmap.
sample output
Benchmark systems, scored the way yours would be
pricing
Simple, self-serve pricing
Start free. Upgrade when a model needs to leave the building.