ai governance · 25 threats · 8 system elements

AI threat
modeler

The four questions of threat modeling, applied to AI systems: describe what you are building, judge the candidate threats proposed for exactly those elements, decide what you will do, and check the work. STRIDE per trust boundary, mapped to the OWASP LLM Top 10 and the NIST AI RMF.

This tool asks before it answers: no threat is proposed until you describe the system, every proposal says which of your answers surfaced it, and every conclusion (applies, rating, treatment) is yours. Models live only in your browser; nothing is uploaded.