Skip to main content

Help us improve the Digital Marketplace - send your feedback

STONESTHRO LTD

Threatplane Threat modelling and risk assessments

Threatplane's platform unlocks threat modelling and business-centric risk assessments across your organisation.

Used across sectors including banking, luxury retail, transport, health and academia, it unlocks effective and powerful cyber risk assessments that allow you to prioritise the right initiatives to keep cyber threats at bay, while aligning with fast-moving needs.

Features

  • Visual threat modeling with Draw.io and Lucidchart integration
  • Automated threat assessment using industry methodologies and intelligence
  • Risk assessment linking threats to business impact and controls
  • Controls assessment evaluating security measures across technology architecture
  • Prioritized remediation roadmap for systematic security improvements
  • API integration enabling custom workflows, SSO, and automation
  • Webhook support for GitHub, Slack, and development tools
  • Architecture scoping for cloud, on-premises, SaaS, AI boundaries
  • Asset inventory capturing systems, APIs, supply chain, business processes
  • RROC framework translating controls into business risk metrics

Benefits

  • Generate comprehensive threat models in weeks instead of months
  • Scale security expertise across teams without hiring additional staff
  • Focus engineering effort on high-impact threats, not arbitrary issues
  • Integrate security assessments into development workflows without project delays
  • Build compelling business cases with quantified security risk data
  • Enable self-service security while maintaining centralized oversight and standards
  • Accelerate compliance by automatically generating documentation for audit requirements
  • Free security teams from bottlenecks to focus on strategy
  • Make informed security decisions using evidence-based risk-return analysis
  • Transform security from development constraint into competitive business advantage

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andy.bates@stonesthro.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 2 8 9 1 3 3 5 7 8 6 1 7 9 0

Contact

STONESTHRO LTD Andy Bates
Telephone: 07880783166
Email: andy.bates@stonesthro.co.uk

About your service

Service categories

Applications

Production and operations

  • Other operations
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
Service constraints
New users are required to complete a small on-boarding phase prior to use to ensure they can realise the benefits the platform offers. Support is available from us throughout to help embed this at any point.
System requirements
Chrome or Firefox

User support

Email or online ticketing support
Yes, at extra cost
Support response times
Within 48 hours.
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
Web chat is accessible from the application once the user has logged in.
Web chat accessibility testing
N/a, this is pending for 2026.
Onsite support
Yes, at extra cost
Support levels
PLATFORM ONLY is designed for organisations comfortable with threat modelling and risk management and are largely self-serve. Working hours support for platform issues and feature requests.

ENHANCED is for organisations that are looking to build threat modelling capability but require hands-on support from our team to achieve this. Under this package we provide extensive training, consultancy and support.

FULLY MANAGED is for organisations who are keen to adopt threat modelling and its benefits, but rely on our expertise for the actual building and maintenance of the models. Under this service we provide a complete threat modelling and risk assessment service to your organisation with minimal skills or time required from your teams.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
For all customers we provide an online self-paced onboarding process designed to bring new users to the point they can confidently use the platform to create new assessments, see risk assessment outcomes and address risks/compliance gaps.

Our higher plans also include an optional threat assessment masterclass which equips users with the theory and practical skills to fully make use of the advanced features those plans provide for assessment cyber threats and capturing and analysing business risk. These masterclasses can scale to any team size and are delivered in an efficient, information-dense manner to ensure your people spend the minimum necessary time in training before they can productively use the platform.

Support is available through all our plans for users of the platform, and this includes asking questions of our in-house team of expert threat modellers to aid your assessments and keep quality high.

Our higher plans also include credits for our team to get involved directly in your assessments, either in a delivery or quality assurance/validation role, to give your teams the speed, capacity and confidence to complete assessments for any systems or processes in your business that could pose risks.
Service documentation
Yes
Documentation formats
Other
Other documentation formats
  • Built into the platform - text
  • Built into the platform - video walkthroughs
End-of-contract data extraction
All models are exportable in PDF and Excel format via the dashboard. We can also bulk-export data for you via a support ticket at any time.
End-of-contract process
We include bulk data export in PDF/Excel at no additional cost. If you require migration to a different platform we are able to provide this service at additional cost.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Accessible directly through the platform via a sidebar.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
Application to install
No
Designed for use on mobile devices
No
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
Read threat models
Update threat models
Reporting: control gaps
Reporting: threats
Reporting: risk assessment
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
No
Customisation available
No

Scaling

Independence of resources
We regularly monitor resource usage and initiate optimisation and scaling where necessary. Our Advanced Plan includes an optional dedicated tenant which guarantees independent resources for your users. We also support on-prem/self-hosting deployment scenarios.

Analytics

Service usage metrics
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Threatplane

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Physical access control, complying with SSAE-18 / ISAE 3402
Data sanitisation process
No
Equipment disposal approach
A third-party destruction service

Data importing and exporting

Data export approach
Threat models are individually exported to PDF/Excel via the dashboard. As our platform integrates draw.io directly, you are also able to export diagrams to various formats as supported by draw.io.

Our support team can also perform a bulk data export for you via a support ticket to these formats where required.
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • Excel
  • Google Sheets
Data import formats
  • CSV
  • Other
Other data import formats
  • Draw.io (XML, SVG & PNG)
  • LucidChart
  • Visio

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Where the customer deploys to their own cloud environment or on-prem, they will have an additional array of options to control and secure traffic flow which we can assist with.
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We guarantee 99.9% availability across our platform. Our SLA cannot cover outages caused by factors beyond our reasonable control. These are:

- Third-Party Vendors (issues attributable to external providers, including Supabase, AWS, Cloudflare, GCP, Azure, GitHub, or other similar providers.)
- Integration Partners (failures related to third-party partners or other external service failures.)
- General Factors Outside Our Control (such as force majeure, internet service provider outages, or other issues outside our reasonable control.)
- Customer Actions or Inactions (resource limitations, misconfigurations, or failures to follow operational guidelines; issues caused by customer equipment/software; or account suspension or termination.)

Our support team targets the following initial response times for requests following triage:

Starter plan (business hours)
Urgent - 24 hours
High - 24 hours
Normal - 48 hours
Low - 72 hours

Plus plan (business hours)
Urgent - 24 hours
High - 24 hours
Normal - 48 hours
Low - 72 hours

Advanced plan (business hours)
Urgent - 1 hour
High - 2 hours
Normal - 8 hours
Low - 24 hours

Business hours are defined as 9am-5pm UK time and exclude bank holidays.
Approach to resilience
We host our services on public cloud providers with a resilient architecture that includes multi-region deployment as standard. All critical parts of our service are built on downstream cloud services that also utilise this pattern.

Our platform is hosted via leading cloud providers which utilise extensive physical safeguards to ensure resilience against hardware failure, network and power disruption (more information available on request).

All data is backed up daily for our Starter plan, with higher plans benefiting from higher backup frequencies and flexible restore options.
Outage reporting
We host a public status page that tracks outages and other disruption. Users can request notifications via this for ongoing updates via email, Slack or Teams.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
We operate on a strict need to know basis across all business operations. Support staff can only access customer accounts when explicitly authorised by the customer, who maintains full visibility of when access is granted and at what level.

Customer data is automatically segregated within our platform through deny by default permissions and row level security. Users can only access data where explicitly granted, preventing accidental or unauthorised cross account exposure.

All customers and plans have granular control over access permissions within their account, allowing them to configure different levels of access for different areas of functionality.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
We comply with 12 of the 14 requirements under the Software Security Code of Practice, and are targeting full compliance in our product roadmap.

As a small cyber security organisation we take security very seriously and apply our own threat modelling and risk assessment methodologies to our platform architecture and business processes. All material platform changes trigger an automatic risk assessment and appropriate controls applied.
Information security policies and processes
We operate the following policies:
- Acceptable Use Policy (including AI governance)
- Network Security Policy
- Access Control Policy
- Data Management Policy
- Remote Access Policy
- Vendor Management Policy

All policies are kept under regular review in line with our wider approach to business strategy, workforce planning, technology evolution and risk management.
Software Security Code of Practice
No

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All code and infrastructure changes originate from our formal product change process, ensuring traceability from requirement to deployment. Every modification is version controlled in Git with complete history, providing full auditability of who changed what and when.

Changes require peer review and must pass automated tests before merging to the main branch. Our CI/CD pipeline enforces these gates, blocking deployment until all checks succeed.

We maintain segregated development and production environments. Infrastructure is managed as code through Terraform, ensuring idempotent deployments with full audit trails and the flexibility to roll back to any previous state.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We conduct threat modelling to proactively identify risks beyond known vulnerabilities, informing our security priorities. Our tiered infrastructure places services behind managed load balancers, providing protection against network level and data parsing attacks.

We monitor threats through GitHub Dependabot, which alerts us to vulnerabilities in our dependencies. Key framework dependencies are kept current, with roadmap items created to resolve any blockers preventing immediate upgrades.

Our automated testing and deployment pipeline enables rapid response to security issues. When a vulnerability requires patching, we can test, validate and deploy fixes to production within hours of a fix becoming available.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Our threat modelling informs extensive logging and alerting at key data entry and exit points throughout our architecture, enabling early detection of anomalous activity and potential compromises.

We follow SANS Institute incident response methodology, progressing through identification, containment, eradication, recovery and lessons learned phases.

Customer data confidentiality is our absolute priority when considering measures to deploy at any stage of our response.

Our team responds to security alerts within 4 to 8 hours on standard plans. Advanced plan customers receive a higher tier service with response times under 2 hours.
Incident management type
Supplier-defined controls
Incident management approach
We follow SANS Institute incident response methodology, progressing through identification, containment, eradication, recovery and lessons learned phases.

Users can report incidents via either email or reporting directly in the platform. We provide regular updates on selected incidents via our status page and via email.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
7.5%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
18%
Over £5,000,001
25%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Eda8b040-5636-4501-8dfd-375f408288e3
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
  • HIPAA via Zadara as primary cloud provider
  • ISO27017 of our primary supplier Zadara
  • SOC1 via Zadara primary cloud supplier
  • SOC2 via Zadara primary cloud supplier
  • ISO27018 via Zadara primary cloud supplier
  • IRAP via Zadara primary cloud supplier

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andy.bates@stonesthro.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.