ThreatOpus combines threat modelling with pull request security checks, returning PASS, WARN, or FAIL decisions in a CI pipeline. Teams can describe a system, import it from OpenAPI or Terraform, or link a GitHub repository; the tool then generates STRIDE threats and supports mitigation tracking. STRIDE is available on every plan, while Pro adds nine more threat modelling frameworks. Merge Guard checks pull requests against policy bundles and posts its decisions, with reasons, to CI checks. Listed source control and CI connections include GitHub, GitLab, Bitbucket, Jenkins, CircleCI, Azure DevOps, TeamCity, AWS CodeBuild, and Travis CI. Outcome notices can be sent to Slack and Microsoft Teams, and scoped API keys support custom pipeline steps or internal orchestration. Users can manage architecture-input retention, export their data as JSON, or delete content they created. A free plan and free trial are available; Starter is £129.99 per month. ThreatOpus says its generated threats and mitigations support security work but are not a substitute for professional assessment, penetration testing, or formal risk acceptance.
Who it is for
ThreatOpus describes its intended users as security teams, security champions, and platform engineers seeking governed threat models and clear merge decisions. It may suit teams that want threat modelling and pull request checks connected to their listed source control and CI tools.
What is good
- Generates STRIDE threats from descriptions, imports, or GitHub repositories.
- Merge Guard posts policy decisions and reasons to CI checks.
- Supports listed source control and CI integrations.
- Project settings provide input and output retention controls.
- Users can export data as JSON or delete created content.
What to know first
- Generated threats do not replace professional assessment.
- Starter allows 15 users and 10 repositories.
- Free plan allows five threat modelling generations monthly.
- Enterprise pricing is custom and not listed.
Verdict
ThreatOpus links threat modelling to pull request policy checks and offers retention and data controls. Treat its generated results as support for security work, not a replacement for professional assessment or testing.
ThreatOpus plans and pricing
All plansCompared on threat modeling software
- Free plan
- Yes
- Attack-path analysis
- Yes
- Risk prioritization
- Yes
- Collaborative review
- Yes
- Templates and frameworks
- Yes
- Modeling methods
- multiple
- Deployment
- both



