Threat Model

A threat model that builds itself on every scan

Pragma Core reads your repository and turns it into a data-flow diagram: the components, the data stores, the outside actors, and the trust boundaries between them. It runs STRIDE over that diagram, then lets AI agents add the architecture-level threats a fixed rule set would miss. The structure comes from your code first, the AI reasons on top of it, and the whole model is rebuilt on every full scan.

Model your architecture View all features

System decomposition

A data-flow diagram built from your code map, your dependencies, and your real attack surface. The architecture comes from analysis, not from an AI guessing what your system looks like.

External
Web client
12 public endpoints
Process
Http / Controllers
auth boundary
Process
Billing service
Stripe egress
Trust boundary · internal network
Data store
PostgreSQL
orders, users
Data store
Redis
sessions, cache
Data store
AWS S3
user uploads

STRIDE threat matrix

Every element and data flow is checked against all six STRIDE categories. AI agents then add threats that depend on how your specific system is wired together.

ElementSTRIDESeverity
Web client → ControllersSpoofingHigh
Controllers → PostgreSQLTamperingCritical
Billing service egressInfo disclosureHigh
Session store (Redis)ElevationMedium
S3 upload flowRepudiationMedium
Public endpointsDenial of svcLow
Deterministic baseline plus AI-enriched threats

Deterministic decomposition, AI-enriched threats

Discovery is not the model's job. The platform builds the architecture from your code, applies STRIDE to it, and only then lets AI agents reason on top. That keeps the model grounded in what you actually shipped instead of inventing it.

1
Decompose the system
Modules and namespaces are clustered from your code map, data stores are read from your dependencies and SBOM, and endpoints are mapped to trust zones. This is pure code analysis, with no AI involved.
2
Apply STRIDE
Every component, data store, and data flow runs through the six STRIDE categories. The result is a baseline of threats tied to real elements of your architecture.
3
Enrich with AI
A pass of several agents reads the decomposition and adds threats a rule set cannot enumerate on its own, such as chained abuse across components, a missing boundary, or a trust assumption that does not hold.
4
Feed the scan
The model points the SAST Deep Dive at your highest-risk components. You can open it as an interactive diagram or export it to draw.io or the Microsoft Threat Modeling Tool, and it refreshes on every full scan, per branch.

More than a diagram you draw once and forget

Deterministic DFD
Components, data stores, outside actors, and trust boundaries all come from your actual code. Nothing is invented, and the same repository always produces the same diagram.
Full STRIDE coverage
Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege, applied to every element and data flow in the model.
Real trust boundaries
Trust zones come from your real attack surface: the public endpoints, the call graph, and the data stores your dependencies prove you use. They are not copied from a generic template.
AI enrichment
On top of the deterministic baseline, several agents reason about your specific architecture and add threats that only show up once components start talking to each other.
Export to draw.io and Microsoft TMT
Explore the diagram and STRIDE matrix in the app, or download the model as a draw.io file or a Microsoft Threat Modeling Tool (.tm7) file to keep working in the tool your team already uses.
Drives deeper scanning
The model is not a static artifact. It steers the SAST Deep Dive toward the components and flows that STRIDE flagged as highest risk, and it stays current per branch on every full scan.

Two exports, into the tools you already use

The model is never locked inside the platform. Download it in either of two standard formats and carry it straight into a design review or your existing threat modeling workflow.

draw.io / diagrams.net
A ready-to-edit diagram with the standard DFD shapes, so you can rearrange it, annotate it, or drop it into a document without redrawing anything.
Microsoft Threat Modeling Tool
A .tm7 file with the generic SDL stencils. Open it in the desktop tool and run Analyze to generate threats against your own template and rules.

STRIDE, applied to your real architecture

Microsoft's STRIDE model maps six threat categories onto every element of a system. The platform applies all six to the components and flows it found in your code.

S
Spoofing
Someone fakes an identity at a trust boundary, using forged tokens, a missing check on an exposed endpoint, or an impersonated service.
T
Tampering
Data is changed in transit or at rest, through injection into a store, mutable request parameters, or unsigned messages between services.
R
Repudiation
An action cannot be proven after the fact, because a sensitive flow has no audit log or an operation leaves no attributable trace.
I
Information Disclosure
Data reaches someone who should not see it, through verbose errors, an over-broad API response, or secrets leaking to a third party.
D
Denial of Service
A component is pushed offline by unbounded work on a public endpoint, a missing rate limit, or a resource an attacker can exhaust.
E
Elevation of Privilege
A lower-privileged actor gains higher rights through a missing authorization check or a trust assumption that crosses a boundary it should not.

Catch design flaws no line-level scanner can

Find the bugs that live between files
SAST finds a vulnerable line. A threat model finds a vulnerable design: a missing trust boundary, a service that trusts input it should validate, or a money-moving flow with no audit trail. It works at a different layer and catches a different class of bug.
Threat modeling without the all-day workshop
Traditional threat modeling means a whiteboard, a facilitator, and a diagram that is out of date by the next sprint. Here the model is rebuilt from the code on every full scan, so it does not drift away from what is actually running.
Prioritize by architecture, not just severity
A finding on a component that sits on a trust boundary and talks to your main data store matters more than one in an isolated helper. The model gives your triage the architectural context to tell the difference.
Evidence for design reviews and compliance
Export the diagram and STRIDE matrix to draw.io or the Microsoft Threat Modeling Tool and drop it into a design review, an SDLC gate, or a compliance pack. It is a current artifact generated from the code, not a hand-drawn guess.

Get a threat model on every scan

Connect a repository and the platform decomposes your architecture, runs STRIDE over it, and keeps the model current on every full scan.

Have questions? Get in touch →