Threat Modeling
What is Threat Modeling?
Threat modeling is the practice of looking at a system before it is attacked and asking what could go wrong. Instead of waiting for a scanner or a pentest to find problems in code that already exists, you reason about the design — and fix the problems while they are still cheap to fix.
You do not need to be a security specialist to do it. If you can explain how your system works, you can produce a threat model in the Conviso Platform.
How it works here
The platform turns your description of a system into a list of concrete security requirements your team can implement and prove. The path has four stages:
- Describe your system — upload an architecture diagram or write what the system does.
- Get an artifact — the platform produces a threat model with a scope and a set of requirements grouped by architecture component.
- Keep it alive — when the architecture changes, generate a new version. The platform records exactly what changed between versions.
- Execute — turn the requirements into a project where each activity is assigned, tracked and evidenced.
The result is not a document that ages on a shelf. It is a living record of your system's security design, with an audit trail.
Access the feature
Click Threat Modeling in the left-hand menu.
Start here
If this is your first time, follow these pages in order:
- Create a Threat Model — the fastest path from a diagram to a finished threat model.
- Read the artifact and its versions — understand what was generated and how to keep it current.
- Turn requirements into a project — put the requirements into your team's workflow.
Reference pages, for when you need them:
Related areas
Threat Modeling connects to:
Support
Should you have any questions or require assistance while using the Conviso Platform, feel free to reach out to our dedicated support team.
Contribute to the Docs
Found something outdated or missing? Help us improve the documentation with a quick suggestion or edit.
How to contributeResources
By exploring our content, you'll find resources that will enhance your understanding of the importance of a Security Application Program.
Conviso Blog: Explore our blog, which offers a collection of articles and posts covering a wide range of AppSec topics. The content on the blog is primarily in English.
Conviso's YouTube Channel: Access a wealth of informative videos covering various topics related to AppSec. Please note that the content is primarily in Portuguese.