Skip to main content

Threat Modelling & Risk Management. One Platform. Your Infrastructure.

Five threat modelling methodologies (STRIDE, PASTA, LINDDUN, VAST, OCTAVE), attack tree analysis, data flow diagrams, risk registers with quantitative scoring, 72 compliance frameworks with 2,500+ requirements, SBOM supply chain risk, AI-driven threat generation, document analysis, 15 built-in playbooks, and CI/CD security gates — in a single self-hosted deployment. Your threat models, risk data, and compliance evidence stay on your infrastructure. We never access or store them.

No per-user SaaS fees. No threat data leaving your network. No vendor lock-in.

Coming Soon

This product is currently in development. Contact us to register your interest.

The Numbers Behind UmbraRisk

72

Compliance Frameworks

ISO 27001, NIST, PCI DSS, SOC 2, HIPAA, GDPR, FedRAMP, NIS2, DORA & 63 more

2,500+

Requirements

Compliance requirements mapped across all frameworks with gap analysis

220+

Built-in Threats

Threat catalog with MITRE ATT&CK, OWASP, CWE, and CAPEC mappings

270+

Built-in Controls

Preventive, detective, corrective, compensating & deterrent controls

100+

Playbooks

Remediation playbooks with step-by-step instructions & code examples

What UmbraRisk Does

Eight core capabilities. Each one replaces a standalone vendor tool. Together, they eliminate the need for a fragmented threat modelling and risk management stack.

🎯

Multi-Methodology Threat Modelling

Five threat modelling methodologies selectable per project: STRIDE, PASTA, LINDDUN, VAST, and OCTAVE. Automated threat generation runs for STRIDE today; automated engines for PASTA, LINDDUN, VAST and OCTAVE are coming soon. Automated threat identification per component with a 220+ threat catalog mapped to MITRE ATT&CK, OWASP Top 10, CWE, and CAPEC. Version-controlled models with full change history and diff views. AI-driven threat auto-generation identifies threats, maps recommended controls, and creates attack scenarios.

🌳

Attack Tree Analysis

Full attack tree lifecycle with AND/OR gates and bottom-up probability and cost calculation through tree propagation. Build trees visually or auto-generate from MITRE ATT&CK data. CWE weakness integration as leaf nodes. Each node tracks likelihood, impact, cost, and mitigation status. Attack trees link to threat models and risk registers for end-to-end traceability.

📊

Data Flow Diagrams & Trust Boundaries

Interactive DFD editor with drag-and-drop nodes: processes, data stores, external entities, and data flows. Hierarchical decomposition (Levels 0–10). Trust boundaries identify where data crosses security perimeters. Component detection parses architecture documents to auto-populate diagrams. Every data flow crossing a trust boundary generates STRIDE threat candidates automatically.

Risk Register & Quantification

Full risk lifecycle with likelihood and impact scoring, risk treatment plans, residual risk tracking, and risk heat maps. Quantitative risk analysis with Annual Loss Expectancy (ALE), Single Loss Expectancy (SLE), and Annual Rate of Occurrence (ARO). The rule engine automates classification, escalation, and notification. Risk appetite thresholds flag items exceeding organisational tolerance.

72 Compliance Frameworks

Automatically map controls to 72 frameworks with 2,500+ requirements: ISO 27001, NIST CSF, NIST SP 800-53, CIS Controls v8, PCI DSS, SOC 2 Type II, HIPAA, GDPR, CCPA, FedRAMP, HITRUST CSF, NIS2, DORA, and 59 more. Gap analysis reports identify requirements lacking evidence. Regulatory change tracker monitors framework updates and flags affected controls. Per-tenant compliance dashboards.

🚧

CI/CD Security Gates

Evaluate deployment-readiness by checking threat model approval, risk mitigation status, posture score thresholds, and compliance results. Gates block, warn, or pass deployments based on configurable policies. SVG status badges embed in README files. Integrates with Jenkins, GitLab CI, GitHub Actions, Azure Pipelines, and any webhook-capable pipeline.

🧠

AI-Driven Threat Intelligence

Four AI modules: Threat Auto-Generation identifies STRIDE threats per component and maps controls. Recommendation Engine analyses patterns across projects. Document Analysis extracts threats from Visio (.vsdx), Draw.io, PDF, Word, PowerPoint, and images using OCR and NLP. AI Accelerator detects Hailo NPU, NVIDIA GPU (CUDA/TensorRT), AMD ROCm, Intel OpenVINO, Apple Neural Engine, and CPU backends; hardware-accelerated inference is coming soon.

📈

Security Posture & SBOM

Aggregated A–F security posture scoring across projects, components, and compliance frameworks. SBOM analysis accepts CycloneDX and SPDX uploads, matches components against a built-in known-vulnerability set, analyses licence compliance, and calculates supply chain risk scores. Executive dashboards visualise risk trends, control effectiveness, and compliance coverage with scheduled report delivery.

Supply Chain Risk & Document Analysis

Analyse your software dependencies for vulnerabilities and extract threats from architecture documents automatically.

📦

SBOM Analysis

Upload Software Bills of Materials in CycloneDX or SPDX format. Automatic vulnerability matching against a built-in known-vulnerability set using Package URLs (PURLs). Licence analysis and compliance risk assessment. Severity distribution across critical, high, medium, and low vulnerabilities. Supply chain risk score calculation with trend tracking.

📄

Document Analysis

Upload architecture documents in Visio (.vsdx), Draw.io (.drawio/.xml), PDF, Word (.docx), PowerPoint (.pptx), or image formats (PNG, JPG, SVG). AI extracts components, connections, technology stacks, and data flows. Generates DFDs and threat models from documents with confidence scoring. 50 MB max file size with batch processing.

🔍

Attack Path Analysis

Automatic discovery of multi-step attack chains through component architectures. Path risk scoring and step-by-step visualisation showing each technique, component, and likelihood. Attack surface summary with total paths, critical paths, and most-targeted components. Mitigation tracking shows which controls block specific paths.

Threat Intelligence & Actor Profiles

Know your adversaries. Map their techniques, track their campaigns, and correlate threat actors across indicators.

🕵️

Threat Actor Profiles

Catalog of threat actors with aliases, TTPs, motivations, capability scoring, and geographic origin. Known campaigns and exploits tracked per actor. Multi-signal correlation links actors across indicators, campaigns, and risk events. Custom actor creation per tenant.

🗺️

MITRE ATT&CK Matrix

Interactive MITRE ATT&CK matrix visualisation. Map project threats to specific tactics and techniques. Tactic browser with full technique descriptions, prerequisites, and detection methods. Coverage tracking shows which MITRE techniques your controls address.

📚

Remediation Playbooks

15 curated playbooks with step-by-step remediation instructions and code examples in multiple languages. Categories: authentication, authorisation, injection, cryptography, configuration, network, data protection, supply chain, and cloud. Estimated hours per playbook. Auto-matched to identified threats.

Vendor Risk & Security Questionnaires

Assess third-party risk with conditional logic questionnaires that feed directly into risk scoring and compliance evidence.

📋

Questionnaire Builder

Build questionnaires with 10 question types: text, textarea, single/multi-choice, boolean, numeric, date, file upload, rating, matrix, and scale. Conditional logic shows or hides sections based on answers. Question weighting for scoring. Organised into sections with help text and guidance.

🏢

Vendor Assessments

Distribute questionnaires to third-party vendors via shareable links or direct email invitations. Track response completion status. Save-and-resume for respondents. Auto-scoring calculates vendor risk from responses. Vendor assessment history and trend tracking across assessment periods.

📊

Auto-Scoring & Threat Mapping

Automatic risk score calculation from questionnaire responses. Responses map to identified threats and derive severity levels. Results feed directly into the risk register and compliance evidence. Templates for vendor risk, application risk, compliance audits, and security reviews.

15+ Integrations & Automation

Connect UmbraRisk to your DevSecOps toolchain, issue trackers, vulnerability scanners, SIEM, and notification platforms.

🔧

Issue Tracking & DevOps

Jira, GitHub, GitLab, Azure DevOps, and ServiceNow. Create issues from risks and findings. Sync status bidirectionally. PR comments and webhook support for CI/CD pipelines. Pipeline metadata tracking with branch and pipeline ID.

🔍

Vulnerability Scanners & SIEM

Import vulnerability scan results from Tenable, Qualys, and Rapid7. Forward risk events to Splunk for SIEM monitoring. PagerDuty integration for incident alerting on critical risks. Custom webhooks for any HTTP endpoint with delivery tracking and retry logic.

📨

Notifications & Import/Export

Slack and Microsoft Teams for channel notifications. Email/SMTP for alert delivery. Import threat models from IriusRisk, Microsoft TMT, and OWASP Threat Dragon. Export to PDF, JSON, CSV, XML, and CycloneDX SBOM. Connection testing, sync management, and integration health monitoring.

One Platform to Replace Your Entire Threat Modelling Stack

Most security teams cobble together 6 to 10 separate tools for threat modelling, risk management, compliance tracking, and security assessments. UmbraRisk consolidates all of them.

Before UmbraRisk

  • Separate threat modelling tool (IriusRisk, Microsoft TMT, OWASP Threat Dragon)
  • Separate risk register (spreadsheets, RSA Archer, ServiceNow GRC)
  • Separate attack tree tool (AttackTree+, SecurITree)
  • Separate compliance platform (Drata, Vanta, OneTrust)
  • Separate DFD drawing tool (Visio, Lucidchart, draw.io)
  • Separate vulnerability scanner import (manual CSV)
  • Separate questionnaire tool (Google Forms, custom apps)
  • Separate SBOM tool (Syft, OWASP Dependency-Track)
  • Separate reporting tool (PowerBI, manual PowerPoint decks)

9+ vendors. 9+ data silos. No traceability between them.

After UmbraRisk

  • One codebase: 152+ Python modules and 208+ TypeScript/React components
  • One database: PostgreSQL with versioned Alembic migrations
  • One deployment: bare metal, Docker, Kubernetes, cloud VMs, VMs, or air-gapped
  • One API: 36 route modules with JWT + API key + OAuth + SAML authentication
  • One data model: threats, risks, controls, compliance, SBOM, and attack trees fully linked
  • One workflow: from DFD to STRIDE to risk register to compliance evidence, traceable end-to-end
  • 72 frameworks: compliance mapped automatically with 2,500+ requirements
  • One bill: your infrastructure costs (no per-user SaaS surcharges)

Unified threat and risk management is not a marketing slide. This is the engineering reality.

Collaboration, Authentication & Administration

Real-time collaboration, enterprise authentication, and full platform administration.

Real-Time Collaboration

Concurrent threat model editing with cursor tracking and change broadcasting. Threaded discussion comments on threats, risks, controls, and any object. Multi-stage review and approval workflows with configurable sign-off chains. Active user presence indicators per project.

Enterprise Authentication

Local credentials, OAuth 2.0 (Google, GitHub, Microsoft, custom providers), SAML 2.0 for enterprise SSO, and LDAP/Active Directory. TOTP multi-factor authentication with QR code enrolment. JWT session management with refresh token rotation. Password reset and change workflows.

Multi-Tenant Isolation

Row-level tenant isolation on every table. Custom roles with 20+ granular permissions. Hierarchical feature toggles at tenant, role, and user levels. API key management with scoped access. Per-tenant branding, configuration, and quota management. Backup and restore operations.

Custom Threat Libraries

Define custom threat categories, severity scales, and mitigation playbooks. Threat libraries scoped per project, domain, or team. Import industry-standard catalogs or build your own. The rule engine automates threat classification and escalation based on configurable policies.

Control Catalog & Playbooks

270+ built-in controls with implementation status, effectiveness ratings (0–100%), and evidence links. Automation levels: manual, semi-automated, fully automated. Controls map to compliance requirements automatically. 15 built-in playbooks with code examples and estimated hours.

Audit & Reporting

Immutable audit logging tracks every action with user, timestamp, IP address, and change detail. Report builder with 7 report types, scheduled delivery (cron-based), and multiple formats (PDF, HTML, JSON, CSV, XML). Executive dashboards with risk trends and compliance coverage.

All Features — Organised by Domain

Every feature listed below is implemented with dedicated database tables, API routes, service logic, and background workers.

Threat Modelling — 7 Features

Multi-Methodology (STRIDE/PASTA/LINDDUN/VAST/OCTAVE) Threat Model Versioning AI Threat Auto-Generation 220+ Threat Catalog Threat Actor Profiles & TTPs Multi-Signal Actor Correlation MITRE ATT&CK / OWASP / CWE / CAPEC Mapping

Five methodology support with per-project selection. Automated STRIDE identification with a 220+ threat catalog cross-referenced to MITRE ATT&CK, OWASP, CWE, and CAPEC. Version-controlled models with diff views. Threat actor profiles with TTPs, campaigns, geographic origin, and capability scoring. Multi-signal actor correlation across indicators and risk events.

Attack Analysis — 5 Features

Attack Tree Analysis (AND/OR Gates) Attack Path Visualisation Data Flow Diagrams (Levels 0–10) Trust Boundary Mapping MITRE & CWE Auto-Generation

Attack trees with bottom-up probability/cost propagation through AND/OR gates. Auto-generation from MITRE ATT&CK data with CWE leaf nodes. Attack path analysis builds directed graphs through component architectures. Interactive DFD editor with hierarchical decomposition. Trust boundaries generate STRIDE candidates automatically.

Risk Management — 6 Features

Risk Register Quantitative Risk (ALE/SLE/ARO) Risk Treatment Plans Risk Heat Maps Risk Appetite Thresholds Rule Engine Automation

Multi-register support with inherent vs. residual scoring. Quantitative analysis with ALE, SLE, and ARO calculations. Risk treatment options: mitigate, accept, transfer, avoid, monitor. Heat maps and trend analysis. Risk appetite thresholds per category with automatic alerting. Rule engine automates classification, escalation, and notification.

Controls & Security Posture — 6 Features

270+ Control Catalog Control Effectiveness (0–100%) A–F Posture Scoring 100+ Playbooks Knowledge Base Gap Analysis

270+ built-in controls (preventive, detective, corrective, compensating, deterrent) with effectiveness scoring and evidence links. Automation levels from manual to fully automated. A–F posture scoring aggregated across projects and frameworks. 15 built-in playbooks with code examples. Knowledge base with threat patterns, control templates, and best practices. Gap analysis identifies unmitigated threats.

Compliance & Regulatory — 7 Features

72 Compliance Frameworks 2,500+ Requirements Gap Analysis Reports Evidence Collection Regulatory Change Tracker Tenant Compliance Tracking Framework Cross-Walk

72 frameworks with 2,500+ requirements: ISO 27001, NIST CSF, NIST SP 800-53, CIS Controls v8, PCI DSS, SOC 2, HIPAA, GDPR, CCPA, FedRAMP, HITRUST, NIS2, DORA, NERC CIP, PIPEDA, LGPD, PDPA, CSA CAIQ, and 54 more. Automatic control-to-requirement mapping. Cross-framework requirement overlap analysis. Regulatory change tracker monitors updates and flags affected controls. Per-tenant compliance dashboards with coverage percentages.

AI & Document Intelligence — 6 Features

AI Threat Auto-Generation AI Recommendation Engine Document Analysis (Visio/Draw.io/PDF/Word/PPT) AI Accelerator (Inference Coming Soon) Cross-Project Pattern Analysis Component Classification Neural Net

AI Threat Auto-Generation identifies threats and maps controls. Document Analysis supports Visio, Draw.io, PDF, Word, PowerPoint, and images with OCR (Tesseract). Multi-stage pipeline: component detector, connection detector, text analyser, threat modeller, DFD generator. AI Accelerator provides hardware abstraction across Hailo NPU, NVIDIA CUDA/TensorRT, AMD ROCm, Intel OpenVINO, Apple Neural Engine, and CPU (ONNX). Rule-based fallback for air-gap deployments.

Supply Chain & SBOM — 4 Features

CycloneDX & SPDX Import CVE Vulnerability Matching Licence Compliance Analysis Supply Chain Risk Score

SBOM upload in CycloneDX and SPDX JSON formats. Automatic component parsing with PURL (Package URL) resolution. Vulnerability matching against CVE databases with severity distribution. Licence analysis and compliance risk assessment. Supply chain risk score with trending. Risk level assessment per component.

Collaboration & Workflow — 5 Features

Real-Time Collaborative Editing Threaded Comments Review & Approval Workflows Notifications (Email & In-App) Immutable Audit Logging

Session-based presence tracking with 2–3 second polling sync. Cursor position tracking and active user colours. Threaded comments on any entity. Multi-stage review with approval/rejection and decision notes. Email and in-app notifications for assignments, approvals, and deadlines. Immutable audit log with user, timestamp, IP address, and change detail.

Platform & Integration — 10 Features

Multi-Tenancy (Row-Level Isolation) Custom Roles & 20+ Permissions OAuth 2.0 / SAML 2.0 / LDAP TOTP MFA Feature Toggles CI/CD Security Gates & Badges 15+ Integrations Import/Export (IriusRisk/TMT/Threat Dragon) Report Builder & Scheduling Backup & Restore

Multi-tenant with row-level isolation and per-tenant configuration. OAuth 2.0, SAML 2.0, LDAP, and TOTP MFA. Custom roles with 20+ permissions. CI/CD gates with SVG badges. 13+ integrations (Jira, GitHub, GitLab, Azure DevOps, ServiceNow, Slack, Teams, Splunk, Tenable, Qualys, Rapid7, PagerDuty, custom webhooks). Import from IriusRisk, Microsoft TMT, OWASP Threat Dragon. Export to PDF, JSON, CSV, XML. Report builder with cron-based scheduling. Backup and restore with integrity verification.

Technical Specifications

How UmbraRisk compares to threat modelling and GRC alternatives.

Capability UmbraRisk IriusRisk Drata MS Threat Modeling Tool
Self-HostedYes (6 modes)Cloud + on-prem ($)Cloud onlyDesktop only
Air-Gap SupportYes (built-in)NoNoYes (offline)
MethodologiesSTRIDE/PASTA/LINDDUN/VAST/OCTAVESTRIDE/customN/ASTRIDE only
Threat Catalog220+ (MITRE/OWASP/CWE/CAPEC)CustomN/AMS-only
Attack TreesYes (AND/OR, probability)YesNoNo
Data Flow DiagramsYes (interactive, Levels 0–10)YesNoYes (Visio-style)
Risk RegisterYes (qualitative + quantitative)YesNoNo
Quantitative Risk (ALE/SLE)YesPartialNoNo
Compliance Frameworks72 (2,500+ requirements)Limited16+No
SBOM AnalysisYes (CycloneDX/SPDX)NoNoNo
AI Threat GenerationYes (self-hosted)Yes (cloud)NoNo
Document AnalysisVisio/Draw.io/PDF/Word/PPTNoNoNo
Remediation Playbooks100+ (with code examples)LimitedNoNo
Vendor Risk QuestionnairesYes (conditional logic)YesYesNo
CI/CD Security GatesYes (badges)YesNoNo
Integrations15+ (Jira/GitHub/Splunk/etc.)10+80+None
AuthenticationOAuth/SAML/LDAP/MFASSOSSON/A
Multi-TenantYes (row-level isolation)YesNoNo
Real-Time CollaborationYes (presence tracking)YesLimitedNo
Threat Actor IntelYes (TTPs, campaigns)NoNoNo
Per-User CostNonePer-seat ($)Per-seat ($)Free (limited)

Deployment Options

UmbraRisk runs wherever you need it. Every deployment includes the complete platform: all features, all API modules, all workers. No feature gating by deployment type.

🖥

Bare Metal

Ubuntu/Debian or RHEL/Rocky. PostgreSQL, Redis, and Nginx configured automatically. Systemd services for FastAPI and Celery workers.

📦

Docker

Three Docker Compose profiles: minimal, standard, and full. Health checks, restart policies, and volume mounts pre-configured.

Kubernetes

Helm chart with replicas, HPA, and resource limits. Tested on EKS, AKS, GKE, and bare-metal K8s clusters. Bitnami subcharts for PostgreSQL and Redis.

🔒

Air-Gapped

Pre-packaged Python wheels, container images, and system dependencies. Offline installation with full feature set. Nothing phones home.

Cloud VMs

AWS EC2, Azure VMs, GCP Compute Engine, or any IaaS provider. Same installer scripts work on physical or cloud-provisioned hosts.

🖥

Virtual Environments

VMware ESXi, Hyper-V, Proxmox VE, KVM/QEMU, and Xen. Snapshot, clone, and template using standard hypervisor tooling.

Why Your Threat Data Stays Yours

Three arguments that get stronger every year.

Threat Models Are Your Most Sensitive Data

A threat model is a detailed map of every weakness in your system. When you upload this to a SaaS vendor, you are handing an adversary's playbook to a third party whose infrastructure you do not control.

With UmbraRisk, threat models, risk registers, and compliance evidence never leave your network.

The tool that maps your vulnerabilities should not create new ones.

Compliance Evidence Requires Data Sovereignty

Regulated industries increasingly require that security assessment data remain within specific jurisdictions. GDPR, NIS2, DORA, and FedRAMP mandate control over where sensitive data is processed and stored.

UmbraRisk gives you complete control over data residency. Deploy in any jurisdiction, on any infrastructure.

Compliance is not just about what controls you have. It is about where your evidence lives.

Per-User Pricing Punishes Security Maturity

Per-user SaaS pricing penalises organisations that expand threat modelling beyond the security team. When developers, architects, and product managers participate, costs multiply.

UmbraRisk scales with compute and storage, not headcount. Broad participation improves security outcomes without inflating the budget.

Same platform at 10 users as at 10,000.

Under the Hood

Architecture details for the engineering team evaluating UmbraRisk.

Backend

LanguagePython 3.11+ with FastAPI (async)
DatabasePostgreSQL 14+ with async SQLAlchemy
Task QueueCelery with Redis broker (9 worker types)
API Surface36 route modules
AuthenticationJWT + API key + OAuth 2.0 + SAML 2.0 + LDAP + TOTP MFA
Multi-TenancyRow-level isolation on every table
AI EnginesThreat gen, recommendation, document analysis, accelerator (6 backends)
Integrations15+ (Jira, GitHub, GitLab, Azure DevOps, ServiceNow, Slack, Teams, Splunk, Tenable, Qualys, Rapid7, PagerDuty, webhooks)

Frontend

FrameworkReact 18 + TypeScript + Vite
StateZustand + React Query (@tanstack)
StylingTailwindCSS with light/dark theme
VisualisationRecharts, D3.js, @xyflow/react (DFD editor)
Pages68 page components across 14 feature areas
Components208+ TypeScript/React source files
AnimationsFramer Motion
FormsReact Hook Form with Zod validation

Frequently Asked Questions

What threat modelling methodologies does UmbraRisk support?

UmbraRisk supports five methodologies: STRIDE, PASTA, LINDDUN, VAST, and OCTAVE. Select the methodology at project creation. Automated threat identification with a 220+ threat catalog mapped to MITRE ATT&CK, OWASP, CWE, and CAPEC. Attack tree analysis with probability propagation and DFDs with trust boundary mapping are available across all methodologies.

How many compliance frameworks are included?

72 compliance frameworks with 2,500+ requirements out of the box: ISO 27001, NIST CSF, NIST SP 800-53, CIS Controls v8, PCI DSS, SOC 2, HIPAA, GDPR, CCPA, FedRAMP, HITRUST, NIS2, DORA, NERC CIP, and 58 more. Custom framework creation is also supported. Controls map to requirements automatically with gap analysis and evidence collection.

What document formats can UmbraRisk analyse?

Visio (.vsdx), Draw.io (.drawio/.xml), PDF, Word (.docx), PowerPoint (.pptx), and images (PNG, JPG, SVG). AI extracts components, connections, technology stacks, and data flows using OCR and NLP. Preview mode lets you validate results before importing. 50 MB max file size with batch processing.

What is SBOM supply chain risk analysis?

Upload Software Bills of Materials in CycloneDX or SPDX format. UmbraRisk parses software components, matches them against CVE databases, analyses licence compliance, and calculates a supply chain risk score with severity distribution across critical, high, medium, and low vulnerabilities.

What integrations are supported?

13+ integrations: Jira, GitHub, GitLab, Azure DevOps, ServiceNow for issue tracking. Slack and Microsoft Teams for notifications. Splunk for SIEM. Tenable, Qualys, Rapid7 for vulnerability import. PagerDuty for incident alerting. Custom webhooks for any endpoint. Import from IriusRisk, Microsoft TMT, OWASP Threat Dragon. Export to PDF, JSON, CSV, XML, CycloneDX.

What authentication methods are supported?

Local credentials, OAuth 2.0 (Google, GitHub, Microsoft, custom providers), SAML 2.0 for enterprise SSO, and LDAP/Active Directory. TOTP multi-factor authentication with QR code enrolment. JWT session management with configurable token expiry and refresh token rotation.

Can UmbraRisk run in an air-gapped environment?

Yes. Six deployment modes including fully air-gapped with pre-packaged Python wheels, container images, and system dependencies. Offline installation with the same feature set. AI inference falls back to CPU/ONNX when no GPU is available. Nothing phones home.

How does multi-tenancy work?

Row-level tenant isolation on every database table. Each tenant has independent projects, threat models, risks, controls, compliance, and reports. Custom roles with 20+ permissions. Feature toggles at tenant, role, and user levels. Per-tenant branding, API keys, and quota management.

Replace Your Threat Modelling Stack. Own Your Platform.

UmbraRisk is in active development. Request access to receive deployment documentation, architecture walkthroughs, and priority onboarding when the platform enters beta.

Contact Us

Get in touch to discuss your requirements.

UmbraRisk is part of the SOC-in-a-Box suite by SinonTech.

Self-hosted security infrastructure for organisations that take data sovereignty seriously.

SinonForge (Git) · SinonStore (Object Storage) · SinonMeet (Video Conferencing) · Umbra (SIEM) · SinonSentinel (MSP Platform) · UmbraShield (AppSec) · UmbraRisk (Threat & Risk)