SIS-licensed ISO clauses and controls·an add-on inside the AI clients and agents you already use
    Workflow · Threat model

    STRIDE threat model

    Threats enumerated per component against a data-flow diagram you confirm, scored on impact and likelihood, then mapped to the controls and regimes that bear on them.

    Ansvar is a gateway for the AI assistant your team already uses — Claude, Microsoft Copilot, any MCP client. Connect it and your agent runs the workflow; the server enforces the stages and fetches every citation.

    Six STRIDE lensesspoofing through elevation of privilege, one specialist each
    You confirm twicethe diagram before analysis, the threat list before scoring
    Freeone run a month, on a system you describe

    The run draws the system before it analyses it: components, data flows, trust boundaries and assets, rendered as a diagram you approve. Six STRIDE specialists then work the six categories — in parallel where your client supports it — and merge into one threat list with a coverage matrix, which you review again: add what is missing, drop the false positives, challenge a rating. Only after that does scoring happen, on impact and likelihood, with a CVSS v4 vector where one applies. Threats then map to controls and to the regimes the run adjudicates. On Team and Company a control-investment simulation ranks what to buy first; below that the run says so and finishes without it. The OT and drone variants change the framing and the regimes, not the method.

    the family

    One STRIDE spine, a variant per system class

    STRIDE Threat Model

    The base: STRIDE against any system you can describe or document.

    OT / ICS Threat Model (STRIDE, zones-and-conduits)

    Plant and ICS, framed on IEC 62443 zones and conduits.

    UAS / Drone Threat Model (STRIDE, UAS-scoped)

    UAS platforms — the C2 link, ground control and the data chain — under Reg (EU) 2019/945 and 2019/947.

    Threat sources ground the enrichment stage: ATT&CK and ATLAS are free, and CWE, CAPEC and D3FEND open at Premium. Where no served source grounds a mapping, the run marks it unresolved rather than filling it in.

    how a run works

    Eight stages the server enforces

    1. 1
      System scoping & DFD

      components, flows, trust boundaries and assets, rendered as a diagram you confirm before any analysis runs

    2. 2
      Document collection

      optional; on Team and above the run grounds itself in your own architecture documents

    3. 3
      STRIDE analysis

      six specialists work the six categories, in parallel where your client supports it, and merge into one threat list with a coverage matrix

    4. 4
      Threat review

      you see every threat before it is scored — add, remove, or challenge a rating

    5. 5
      Threat enrichment & scoring

      each threat enriched from served sources, deduplicated, then scored on impact and likelihood

    6. 6
      Mitigation mapping

      threats mapped to controls, and to the regimes the run adjudicates — the applicability check itself is Team and above

    7. 7
      Remediation planning

      a control-investment simulation ranks what to buy first, on Team and Company; below that the run records the stage as not applicable and carries on

    8. 8
      Report

      the threat register — structured for your agent, rendered for your auditor

    ask your agent

    Paste one of these to start

    Using Ansvar, build a STRIDE threat model of our payments API. Start from a data-flow diagram and show me the threat list before you score anything.
    Using Ansvar, run an OT threat model for our bottling line on IEC 62443 zones and conduits, and map each mitigation to a control.
    install the skill

    A prompt starts one run. The skill is the same guidance installed once — the run loop, the evidence and citation rules, and the starters — so your agent works this way in every conversation, not only the ones you remember to paste into. Install it as a skill in Claude or Claude Code, or paste the same file into Microsoft Copilot or a custom GPT's instructions.

    Free gets one workflow run a month and Solo two, spendable on the base STRIDE threat model against a system you describe, and a Free or Solo run can also return a render carrying a self-asserted banner. Premium adds the OT/ICS and drone variants on five runs a month, along with the CWE, CAPEC and D3FEND corpora the enrichment stage draws on. Team and Company run them against your own architecture documents, add unwatermarked HTML, PDF and DOCX exports, and unlock the applicability check and control-investment simulation the last two stages use. Run allowances and what each tier adds live on the pricing page.

    Questions buyers ask first

    Which plan do I need to run one?
    Any of them, for part of the family. Free gets one workflow run a month and Solo two, spendable on the base STRIDE threat model against a system you describe. The OT/ICS and drone variants start at Premium, which also opens the CWE, CAPEC and D3FEND corpora the enrichment stage draws on. Team and Company add runs grounded in architecture documents you upload.
    Can an agent run this start to finish on its own?
    No, and that is deliberate. Several steps are review gates that fail closed: the diagram, the threat list and the scoring each stop until a person approves them. You are sitting in your own AI client while the run happens, so approving is a reply rather than a context switch. We would rather a threat model be slower than have one score a component nobody looked at.
    How is a STRIDE model different from a TARA?
    STRIDE enumerates threats per component and maps them to mitigations. A TARA produces a risk register — each risk banded for likelihood and consequence, scored against thresholds you set, with a recorded treatment. Teams often run STRIDE first and feed its threats into the TARA.
    Do you need our architecture documents?
    No. The diagram stage builds from a description you give in the interview. Uploading your own architecture documents is what Team adds: findings then anchor to the paragraph they came from, with a content hash, so a reviewer can check a threat against your own design note.
    What comes out at the end?
    A threat register: per-component threats with a STRIDE category, an impact and likelihood score, affected assets, mapped mitigations and the citations behind them. Every plan returns the complete register as structured data, which is what your agent reads. Rendered documents are the hand-off: Team and Company export unwatermarked HTML, PDF and DOCX, and a Free or Solo run can also return a render carrying a self-asserted banner.
    as a service

    Prefer we run it?

    Every workflow here is also an expert-run service: we run it against your systems, review the output as practitioners, and hand over the finished deliverable. See the services page for how engagements work, or contact us to scope one.

    Related: TARA workflows · DPIA workflows · Worked STRIDE run · LINDDUN privacy model · Industrial & OT sector · Drone & UAS sector · Control library · Workflow docs · Have us run it

    Run it against your own systems

    Connect the AI client you already use and ask your first cited question — Free, Solo, Premium and Team are self-serve.