Diagramium

A free threat model maker that stays on your machine

Draw the data flows, mark the trust boundaries, and press Present to walk a review through each crossing and the threats that live there.

Present reveals your threat model one step at a time, on its own.

Live interactive diagramUse the player controls to follow the steps
Cloud SaaS platform threat model — the finished diagram this player draws step by step
Cloud SaaS platform threat modelPlaying silently in this guideWatch with narrationOpen in editor
This compact player stays quiet while you read. Open the full presentation when you want narration and the complete walkthrough.

A threat model is a diagram plus a disciplined argument: what are we building, what can go wrong, and what will we do about it. Free to draw here, no sign-up — and it never leaves your browser.

That matters more here than for any other diagram type. A threat model is a written inventory of your weaknesses; uploading it to a third-party service to draw it is a decision worth making consciously rather than by default.

Trust boundaries are the diagram

A threat model is built on a data flow diagram: processes, data stores, external entities and the flows between them. What turns it into a threat model is the trust boundary — the line marking where data moves between components that trust each other differently.

Every flow crossing a boundary is where threats concentrate: a browser to your API, your API to a third-party service, an admin tool to production. Elements wholly inside one boundary are rarely where the interesting problems are.

Draw the boundaries before you enumerate anything. A model that lists threats without them tends to produce a long, flat list where a login form and an internal cache read as equally risky.

STRIDE, applied per element

STRIDE gives six categories to test each element against: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service and Elevation of privilege.

Its value is that it is boring and exhaustive. Walking each element through six prompts surfaces the threats a team would not have thought of unprompted — and writing "not applicable, because…" is itself a useful record. Not every category applies to every element, and saying why is part of the model.

Present it boundary by boundary

Press Present and the model builds one element and one crossing at a time, narrated. A threat modelling session run this way keeps a room on a single flow until it is finished, which is the difference between a review and a group brainstorm.

How to make a threat model, start to export

Open the editor, draw the system as data flows, then add the trust boundaries. Walk each element and each crossing through STRIDE, recording threats and mitigations in the notes. Export a PDF for the security review, or keep it as a living document beside the design.

Free, private, and offline

Diagramium is free and there is no paid tier. Draw, present and export PNG or SVG without an account; a free account unlocks the animated export formats — GIF, video and animated SVG.

Your diagram is stored in your own browser, not on a server. It keeps working with the network off, and nothing is uploaded unless you choose to publish it.

Frequently asked questions

Is this threat model maker free?

Diagramium is free and there is no paid tier. Draw, present and export PNG or SVG without an account; a free account unlocks the animated export formats — GIF, video and animated SVG.

Does my threat model get uploaded anywhere?

No. It stays in your own browser and the editor works offline. For a document that inventories your weaknesses, that is the property that matters.

What is STRIDE?

Six threat categories — Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege — applied element by element so the analysis is systematic rather than reliant on who is in the room.

What is a trust boundary?

A line where data passes between components with different levels of trust: a browser and your API, your service and a third party, an admin tool and production. Flows crossing one are where threats concentrate.

When should I threat model?

At design time, while changing the diagram is still cheap, and again when the architecture changes materially. A model drawn after launch documents decisions instead of informing them.

More diagram makers

A flowchart maker that walks its own path · The sequence diagram maker that draws what you type · A mind map maker that turns brainstorms into walkthroughs · An architecture diagram maker that walks the request path · A UML diagram maker that walks through your design · An ER diagram maker that presents your schema step by step · A data flow diagram maker that presents the path data takes · The animated diagram maker where diagrams explain themselves · An AI Diagram Maker for the Assistant You Already Use · A free timeline maker for roadmaps, launches, and history · The Gantt Chart Maker That Explains Your Schedule · Software release plan maker: from code freeze to hotfix lane · RASCI matrix maker: one lane per role, every hand-off explicit · A free org chart maker that presents itself level by level · A free Venn diagram maker where the overlap is the point · A free process map maker for the way work actually runs · A free state machine diagram maker that walks every transition · A free concept map maker where every link says what it means · A free customer journey map maker that shows where it hurts · A free decision tree maker where every path reaches an answer · A free fishbone diagram maker for finding the actual cause · A free network diagram maker that keeps your topology private · A free use case diagram maker that shows who can do what · A free C4 model maker, one level at a time · A free BPMN diagram maker for processes two teams must agree on · A free kanban board maker for explaining how work flows · A free sitemap diagram maker for planning a site's structure