Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

Devici is a platform that helps teams move from inconsistent, document-based threat modeling to a clearer, more structured approach. It centers the work on a diagram, so AppSec and DevSecOps teams can map system behavior, add relevant attributes, and let the tool surface likely threats and recommended mitigations. This reduces the time spent interpreting static drawings or spreadsheets and gives teams a shared source of truth they can update as designs change. The workspace supports simultaneous editing, patterns for common system components, and templates that speed up modeling for recurring architectures. Security practitioners can define reusable elements, while developers can contribute without needing deep expertise in threat modeling tools. Devici also provides a maintained threat library, status tracking for each finding, and the option to integrate with issue trackers when teams need to push mitigation work into existing workflows. It offers a straightforward way to standardize threat modeling practices without introducing the overhead of heavier enterprise platforms, making it a practical option for organizations that need something accessible, collaborative, and easy to maintain.

Description

OWASP Threat Dragon serves as a modeling tool designed for creating diagrams that represent potential threats within a secure development lifecycle. Adhering to the principles of the threat modeling manifesto, Threat Dragon enables users to document potential threats and determine appropriate mitigation strategies, while also providing a visual representation of the various components and surfaces related to the threat model. This versatile tool is available as both a web-based application and a desktop version. The Open Web Application Security Project (OWASP) is a nonprofit organization dedicated to enhancing software security, and all of its projects, tools, documents, forums, and chapters are accessible for free to anyone eager to improve application security practices. By facilitating collaboration and knowledge sharing, OWASP encourages a community-focused approach to achieving higher security standards in software development.

API Access

Has API

API Access

Has API

Screenshots View All

Screenshots View All

Integrations

Amazon CodeWhisperer
Bizzy
CycloneDX
Escape
EthicalCheck
Jit
Kiuwan Code Security
SD Elements
Seconize DeRisk Center
SecureFlag
ShieldForce
Tenable AI Exposure
Zinc
esChecker

Integrations

Amazon CodeWhisperer
Bizzy
CycloneDX
Escape
EthicalCheck
Jit
Kiuwan Code Security
SD Elements
Seconize DeRisk Center
SecureFlag
ShieldForce
Tenable AI Exposure
Zinc
esChecker

Pricing Details

Free
Free Trial
Free Version

Pricing Details

No price information available.
Free Trial
Free Version

Deployment

Web-Based
On-Premises
iPhone App
iPad App
Android App
Windows
Mac
Linux
Chromebook

Deployment

Web-Based
On-Premises
iPhone App
iPad App
Android App
Windows
Mac
Linux
Chromebook

Customer Support

Business Hours
Live Rep (24/7)
Online Support

Customer Support

Business Hours
Live Rep (24/7)
Online Support

Types of Training

Training Docs
Webinars
Live Training (Online)
In Person

Types of Training

Training Docs
Webinars
Live Training (Online)
In Person

Vendor Details

Company Name

Security Compass

Founded

2004

Country

Canada

Website

www.securitycompass.com/devici/

Vendor Details

Company Name

OWASP

Founded

2001

Country

United States

Website

owasp.org/www-project-threat-dragon/

Product Features

Product Features

Alternatives

Alternatives

Devici Reviews

Devici

Security Compass
Fork Reviews

Fork

VerSprite Cybersecurity
Fork Reviews

Fork

VerSprite Cybersecurity