PathSecurity.

STRIDE/NIST CSF 2.0/CIS Controls v8

Threat models you'd put your name on, in 90 seconds.

PathSecurity turns a short description of your system into a complete STRIDE threat model: attack graphs, a risk-scored register, and control-mapped mitigations. Export to PDF, DOCX, Markdown, or JSON.

human-reviewed assessments · or a free self-serve model, no card to try

attack-path.svg
Attack graph for a typical web systemAn attack path traverses from the Internet through the Web SPA and API to the Postgres database, the crown-jewel asset. Nodes are grouped into public, internal, and data trust boundaries.publicinternaldataInternet, actor, component extInternetext · actorWeb / SPA, process, component c1Web / SPAc1 · processAPI, process, component c2APIc2 · processAuth, process, component c3Authc3 · processCache, cache, component c5Cachec5 · cachePostgres, crown-jewel data store, component c4Postgresc4 · store
  • entry
  • at-risk flow
  • critical path
  • crown jewel
the pipeline

Five reasoning stages, from system sketch to signed-off report

  1. 1stage_1

    Decomposition

    Break the system into components, data flows, and trust boundaries.

  2. 2stage_2

    Threat enumeration

    Enumerate concrete STRIDE threats per component and data flow.

  3. 3stage_3

    Risk scoring

    Score likelihood × impact into a prioritized composite risk.

  4. 4stage_4

    Mitigation mapping

    Map fixes to NIST CSF 2.0 and CIS Controls v8 by ID.

  5. 5stage_5

    Deliverable assembly

    Assemble a publication-quality report with diagrams and roadmap.

sample output

Benchmark systems, scored the way yours would be

Confidential1 critical
B2B SaaS Platform
React SPA + Node API + Postgres

SQL injection and cross-tenant IDOR lead the risk register.

6 threatsregister
Regulated PHI3 critical
Healthcare Patient Portal
Patient portal + FHIR API

PHI exposure and broken access control dominate under HIPAA.

11 threatsregister
Regulated PCI4 critical
Fintech Mobile Stack
Mobile app + microservices

Cardholder data flows drive PCI-scoped tampering threats.

14 threatsregister
pricing

Simple, self-serve pricing

Start free. Upgrade when a model needs to leave the building.

Free
$0/forever
Kick the tires. One model a month, watermarked PDF.

1 model / month

  • Full 5-stage STRIDE pipeline
  • Attack graphs + threat register
  • Watermarked PDF export
  • NIST CSF 2.0 + CIS v8 mapping
Pay-per-model
$29/per model
One high-stakes model, delivered to your inbox. No subscription.

1 model, email delivery

  • Single complete threat model
  • All export formats
  • Email delivery, no account required
  • 30-day money-back guarantee
Pro
Most popular
$99/per month
For the security engineer who ships models weekly.

20 models / month

  • 20 models per month
  • PDF · DOCX · Markdown · JSON export
  • Version history
  • Saved system profiles
Team
$299/per month
Shared workspace and API access for the whole security team.

100 models / month · 5 seats

  • 100 models per month
  • 5 seats, shared workspace
  • API access + keys
  • Everything in Pro