Threatplane Threat modelling and risk assessments
Threatplane's platform unlocks threat modelling and business-centric risk assessments across your organisation.
Used across sectors including banking, luxury retail, transport, health and academia, it unlocks effective and powerful cyber risk assessments that allow you to prioritise the right initiatives to keep cyber threats at bay, while aligning with fast-moving needs.
Features
- Visual threat modeling with Draw.io and Lucidchart integration
- Automated threat assessment using industry methodologies and intelligence
- Risk assessment linking threats to business impact and controls
- Controls assessment evaluating security measures across technology architecture
- Prioritized remediation roadmap for systematic security improvements
- API integration enabling custom workflows, SSO, and automation
- Webhook support for GitHub, Slack, and development tools
- Architecture scoping for cloud, on-premises, SaaS, AI boundaries
- Asset inventory capturing systems, APIs, supply chain, business processes
- RROC framework translating controls into business risk metrics
Benefits
- Generate comprehensive threat models in weeks instead of months
- Scale security expertise across teams without hiring additional staff
- Focus engineering effort on high-impact threats, not arbitrary issues
- Integrate security assessments into development workflows without project delays
- Build compelling business cases with quantified security risk data
- Enable self-service security while maintaining centralized oversight and standards
- Accelerate compliance by automatically generating documentation for audit requirements
- Free security teams from bottlenecks to focus on strategy
- Make informed security decisions using evidence-based risk-return analysis
- Transform security from development constraint into competitive business advantage
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 2 8 9 1 3 3 5 7 8 6 1 7 9 0
Contact
STONESTHRO LTD
Andy Bates
Telephone: 07880783166
Email: andy.bates@stonesthro.co.uk
About your service
- Service categories
-
Applications
Production and operations
- Other operations
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- New users are required to complete a small on-boarding phase prior to use to ensure they can realise the benefits the platform offers. Support is available from us throughout to help embed this at any point.
- System requirements
- Chrome or Firefox
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- Within 48 hours.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Web chat is accessible from the application once the user has logged in.
- Web chat accessibility testing
- N/a, this is pending for 2026.
- Onsite support
- Yes, at extra cost
- Support levels
-
PLATFORM ONLY is designed for organisations comfortable with threat modelling and risk management and are largely self-serve. Working hours support for platform issues and feature requests.
ENHANCED is for organisations that are looking to build threat modelling capability but require hands-on support from our team to achieve this. Under this package we provide extensive training, consultancy and support.
FULLY MANAGED is for organisations who are keen to adopt threat modelling and its benefits, but rely on our expertise for the actual building and maintenance of the models. Under this service we provide a complete threat modelling and risk assessment service to your organisation with minimal skills or time required from your teams. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
For all customers we provide an online self-paced onboarding process designed to bring new users to the point they can confidently use the platform to create new assessments, see risk assessment outcomes and address risks/compliance gaps.
Our higher plans also include an optional threat assessment masterclass which equips users with the theory and practical skills to fully make use of the advanced features those plans provide for assessment cyber threats and capturing and analysing business risk. These masterclasses can scale to any team size and are delivered in an efficient, information-dense manner to ensure your people spend the minimum necessary time in training before they can productively use the platform.
Support is available through all our plans for users of the platform, and this includes asking questions of our in-house team of expert threat modellers to aid your assessments and keep quality high.
Our higher plans also include credits for our team to get involved directly in your assessments, either in a delivery or quality assurance/validation role, to give your teams the speed, capacity and confidence to complete assessments for any systems or processes in your business that could pose risks. - Service documentation
- Yes
- Documentation formats
- Other
- Other documentation formats
-
- Built into the platform - text
- Built into the platform - video walkthroughs
- End-of-contract data extraction
- All models are exportable in PDF and Excel format via the dashboard. We can also bulk-export data for you via a support ticket at any time.
- End-of-contract process
- We include bulk data export in PDF/Excel at no additional cost. If you require migration to a different platform we are able to provide this service at additional cost.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Accessible directly through the platform via a sidebar.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
-
Read threat models
Update threat models
Reporting: control gaps
Reporting: threats
Reporting: risk assessment - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- No
Scaling
- Independence of resources
- We regularly monitor resource usage and initiate optimisation and scaling where necessary. Our Advanced Plan includes an optional dedicated tenant which guarantees independent resources for your users. We also support on-prem/self-hosting deployment scenarios.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Threatplane
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
-
Threat models are individually exported to PDF/Excel via the dashboard. As our platform integrates draw.io directly, you are also able to export diagrams to various formats as supported by draw.io.
Our support team can also perform a bulk data export for you via a support ticket to these formats where required. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- Google Sheets
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Draw.io (XML, SVG & PNG)
- LucidChart
- Visio
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- Where the customer deploys to their own cloud environment or on-prem, they will have an additional array of options to control and secure traffic flow which we can assist with.
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We guarantee 99.9% availability across our platform. Our SLA cannot cover outages caused by factors beyond our reasonable control. These are:
- Third-Party Vendors (issues attributable to external providers, including Supabase, AWS, Cloudflare, GCP, Azure, GitHub, or other similar providers.)
- Integration Partners (failures related to third-party partners or other external service failures.)
- General Factors Outside Our Control (such as force majeure, internet service provider outages, or other issues outside our reasonable control.)
- Customer Actions or Inactions (resource limitations, misconfigurations, or failures to follow operational guidelines; issues caused by customer equipment/software; or account suspension or termination.)
Our support team targets the following initial response times for requests following triage:
Starter plan (business hours)
Urgent - 24 hours
High - 24 hours
Normal - 48 hours
Low - 72 hours
Plus plan (business hours)
Urgent - 24 hours
High - 24 hours
Normal - 48 hours
Low - 72 hours
Advanced plan (business hours)
Urgent - 1 hour
High - 2 hours
Normal - 8 hours
Low - 24 hours
Business hours are defined as 9am-5pm UK time and exclude bank holidays. - Approach to resilience
-
We host our services on public cloud providers with a resilient architecture that includes multi-region deployment as standard. All critical parts of our service are built on downstream cloud services that also utilise this pattern.
Our platform is hosted via leading cloud providers which utilise extensive physical safeguards to ensure resilience against hardware failure, network and power disruption (more information available on request).
All data is backed up daily for our Starter plan, with higher plans benefiting from higher backup frequencies and flexible restore options. - Outage reporting
- We host a public status page that tracks outages and other disruption. Users can request notifications via this for ongoing updates via email, Slack or Teams.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
-
We operate on a strict need to know basis across all business operations. Support staff can only access customer accounts when explicitly authorised by the customer, who maintains full visibility of when access is granted and at what level.
Customer data is automatically segregated within our platform through deny by default permissions and row level security. Users can only access data where explicitly granted, preventing accidental or unauthorised cross account exposure.
All customers and plans have granular control over access permissions within their account, allowing them to configure different levels of access for different areas of functionality. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
-
We comply with 12 of the 14 requirements under the Software Security Code of Practice, and are targeting full compliance in our product roadmap.
As a small cyber security organisation we take security very seriously and apply our own threat modelling and risk assessment methodologies to our platform architecture and business processes. All material platform changes trigger an automatic risk assessment and appropriate controls applied. - Information security policies and processes
-
We operate the following policies:
- Acceptable Use Policy (including AI governance)
- Network Security Policy
- Access Control Policy
- Data Management Policy
- Remote Access Policy
- Vendor Management Policy
All policies are kept under regular review in line with our wider approach to business strategy, workforce planning, technology evolution and risk management. - Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
All code and infrastructure changes originate from our formal product change process, ensuring traceability from requirement to deployment. Every modification is version controlled in Git with complete history, providing full auditability of who changed what and when.
Changes require peer review and must pass automated tests before merging to the main branch. Our CI/CD pipeline enforces these gates, blocking deployment until all checks succeed.
We maintain segregated development and production environments. Infrastructure is managed as code through Terraform, ensuring idempotent deployments with full audit trails and the flexibility to roll back to any previous state. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We conduct threat modelling to proactively identify risks beyond known vulnerabilities, informing our security priorities. Our tiered infrastructure places services behind managed load balancers, providing protection against network level and data parsing attacks.
We monitor threats through GitHub Dependabot, which alerts us to vulnerabilities in our dependencies. Key framework dependencies are kept current, with roadmap items created to resolve any blockers preventing immediate upgrades.
Our automated testing and deployment pipeline enables rapid response to security issues. When a vulnerability requires patching, we can test, validate and deploy fixes to production within hours of a fix becoming available. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Our threat modelling informs extensive logging and alerting at key data entry and exit points throughout our architecture, enabling early detection of anomalous activity and potential compromises.
We follow SANS Institute incident response methodology, progressing through identification, containment, eradication, recovery and lessons learned phases.
Customer data confidentiality is our absolute priority when considering measures to deploy at any stage of our response.
Our team responds to security alerts within 4 to 8 hours on standard plans. Advanced plan customers receive a higher tier service with response times under 2 hours. - Incident management type
- Supplier-defined controls
- Incident management approach
-
We follow SANS Institute incident response methodology, progressing through identification, containment, eradication, recovery and lessons learned phases.
Users can report incidents via either email or reporting directly in the platform. We provide regular updates on selected incidents via our status page and via email. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7.5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 18%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Eda8b040-5636-4501-8dfd-375f408288e3
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
-
- HIPAA via Zadara as primary cloud provider
- ISO27017 of our primary supplier Zadara
- SOC1 via Zadara primary cloud supplier
- SOC2 via Zadara primary cloud supplier
- ISO27018 via Zadara primary cloud supplier
- IRAP via Zadara primary cloud supplier
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-