Model the system
A living picture of how data moves.
- Components, data stores and flows
- Trust boundaries drawn once and reused
- Import from existing diagrams
HashGo ยท Threat modeling
HashGo Threat Modeling turns your architecture into a model of components, data flows and trust boundaries. It then lists the threats that follow from the design and the controls that answer them.
In development. This page describes what we are building. Features may change before release.
Capabilities
Architecture turned into components, flows and trust boundaries, with the threats that follow and the controls that answer them.
A living picture of how data moves.
Threats that come from your architecture, not a generic list.
Every threat ends with something a team can build.
How it works
Add components, data stores and the flows between them.
Show where trust changes, such as the internet edge or a third party.
Review threats derived from the design and rank them.
Turn each threat into a control and a ticket.
Coverage
It is a structured way to ask what could go wrong with a system before it is built or changed, and what to do about it.
At design time, and again whenever the architecture changes in a meaningful way.
STRIDE first, with LINDDUN for privacy and PASTA for risk-centric reviews.
Mitigations from the model are planned to be verified by HashGo SAST and DAST, and tracked as controls in HashGo GRC.
It is in development. Write to us for early access.
Tell us about your environment and we will reach out when early access opens.
The HashGo suite