Pragma Core reads your repository and turns it into a data-flow diagram: the components, the data stores, the outside actors, and the trust boundaries between them. It runs STRIDE over that diagram, then lets AI agents add the architecture-level threats a fixed rule set would miss. The structure comes from your code first, the AI reasons on top of it, and the whole model is rebuilt on every full scan.
A data-flow diagram built from your code map, your dependencies, and your real attack surface. The architecture comes from analysis, not from an AI guessing what your system looks like.
Every element and data flow is checked against all six STRIDE categories. AI agents then add threats that depend on how your specific system is wired together.
| Element | STRIDE | Severity |
|---|---|---|
| Web client → Controllers | Spoofing | High |
| Controllers → PostgreSQL | Tampering | Critical |
| Billing service egress | Info disclosure | High |
| Session store (Redis) | Elevation | Medium |
| S3 upload flow | Repudiation | Medium |
| Public endpoints | Denial of svc | Low |
Discovery is not the model's job. The platform builds the architecture from your code, applies STRIDE to it, and only then lets AI agents reason on top. That keeps the model grounded in what you actually shipped instead of inventing it.
The model is never locked inside the platform. Download it in either of two standard formats and carry it straight into a design review or your existing threat modeling workflow.
Microsoft's STRIDE model maps six threat categories onto every element of a system. The platform applies all six to the components and flows it found in your code.
Connect a repository and the platform decomposes your architecture, runs STRIDE over it, and keeps the model current on every full scan.
Choose which categories you are happy to allow. You can change your mind at any time using the Cookie settings link in the footer.