Skip to content

Repository files navigation

Precogly

Latest ReleaseLicenseStarsDiscordOWASP Project

Important

Precogly is now an OWASP project! OWASP is the world's largest open-source application security community, and Precogly is proud to be part of it.

The open-source alternative to commercial threat modeling platforms

Quick Start

 git clone --branch v0.3.0 https://github.com/precogly/precogly.git
cd precogly
docker compose up --build

Open http://localhost:5173 and log in with admin@precogly.dev / admin123. Two further demo accounts are seeded so roles and multi-tenancy can be exercised locally; the seed prints all three when it finishes.

Documentation

precogly.github.io/precogly

Video Walkthrough

Precogly Walkthrough

Why Precogly?

Open-source threat modeling tools lack enterprise features. Commercial tools come with heavy price tags and vendor lock-in.

Precogly bridges this gap and democratizes threat modeling for every org in the world.

Key Features

  • Import and export TM-BOM style JSON files - improves interoperability with other threat modeling platforms
  • A threat modeling workspace allows for team collaboration
  • An advanced DFD editor (allows for nested components, trust zones with trust boundaries and much more)
  • Community library packs with links to taxonomies like MITRE ATT&CK, CAPEC, LINDDUN, STRIDE etc. - allows your team to quickly create high quality threat models

Who is Precogly for?

  • Security architects looking to scale threat modeling in their orgs.
  • Vibe coding security engineers who need a well-architected CRUD foundation on which they can build their AI threat modeling assistants.
  • Threat modeling consultants and trainers looking for a platform that supports reference images, team collaboration, and structured threat modeling programs.
  • Compliance professionals looking to link threat modeling with security requirements coming from standards like ASVS or laws like CRA and DORA

Precogly is designed for enterprise workflows, but smaller organizations can also find value in the DFD editor, library packs, and collaborative workspace.

How is Precogly different?

  • Compliance-aware — Built-in traceability to DORA, CRA, ASVS, NIST CSF, SOC 2, and more. Every threat and countermeasure maps to compliance requirements.
  • Structured library packs — Not just brainstorming. Curated packs with components, threats, countermeasures, and taxonomy links (MITRE ATT&CK, CAPEC, CWE, STRIDE) give your team a structured starting point.
  • AI-agent ready architecture — A clean REST API with full OpenAPI docs, designed to be a foundation for AI-powered threat modeling assistants.
  • Pack ecosystem — Community and official packs for AWS, Azure, GCP, banking, and compliance frameworks. Extend or create your own.

Our AI Philosophy

  1. AI agents need CRUD scaffolding — Before AI generates a single threat, the platform must let you create, store, update, and track its core objects.
  2. Ahead-of-time AI > just-in-time AI — You can point AI at a system during threat modeling, or use it ahead of time to build curated threat libraries linked to standards. The second wins. Fewer hallucinations, more consistency.
  3. The journey of understanding is the threat model — The value of the threat model lives in the shared comprehension that humans build along the way. That needs a common interface where humans and agents work from the same picture.

Tech Stack

  • Frontend: React 19, TypeScript, Tailwind CSS, shadcn/ui, React Flow
  • Backend: Django 5.1, Django REST Framework, PostgreSQL 16
  • Infrastructure: Docker, nginx (production)

Roadmap

See the v0.3.0 milestone for what's coming next.

Contributing

If you find Precogly useful, give the project a star!

Community

Join the conversation on Discord.

Need Help? Contact the Developer

Special Thanks

A special thanks to Jeroen Verwoest for generously sharing his knowledge about threat modeling at an enterprise-scale in a compliance-heavy environment.

License

Apache 2.0

About

Open-source, enterprise-grade threat modeling platform

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - jwsapienza/precogly: Open-source, enterprise-grade threat modeling platform · GitHub
Skip to content

Repository files navigation

Precogly

Latest ReleaseLicenseStarsDiscordOWASP Project

Important

Precogly is now an OWASP project! OWASP is the world's largest open-source application security community, and Precogly is proud to be part of it.

The open-source alternative to commercial threat modeling platforms

Quick Start

 git clone --branch v0.3.0 https://github.com/precogly/precogly.git
cd precogly
docker compose up --build

Open http://localhost:5173 and log in with admin@precogly.dev / admin123. Two further demo accounts are seeded so roles and multi-tenancy can be exercised locally; the seed prints all three when it finishes.

Documentation

precogly.github.io/precogly

Video Walkthrough

Precogly Walkthrough

Why Precogly?

Open-source threat modeling tools lack enterprise features. Commercial tools come with heavy price tags and vendor lock-in.

Precogly bridges this gap and democratizes threat modeling for every org in the world.

Key Features

  • Import and export TM-BOM style JSON files - improves interoperability with other threat modeling platforms
  • A threat modeling workspace allows for team collaboration
  • An advanced DFD editor (allows for nested components, trust zones with trust boundaries and much more)
  • Community library packs with links to taxonomies like MITRE ATT&CK, CAPEC, LINDDUN, STRIDE etc. - allows your team to quickly create high quality threat models

Who is Precogly for?

  • Security architects looking to scale threat modeling in their orgs.
  • Vibe coding security engineers who need a well-architected CRUD foundation on which they can build their AI threat modeling assistants.
  • Threat modeling consultants and trainers looking for a platform that supports reference images, team collaboration, and structured threat modeling programs.
  • Compliance professionals looking to link threat modeling with security requirements coming from standards like ASVS or laws like CRA and DORA

Precogly is designed for enterprise workflows, but smaller organizations can also find value in the DFD editor, library packs, and collaborative workspace.

How is Precogly different?

  • Compliance-aware — Built-in traceability to DORA, CRA, ASVS, NIST CSF, SOC 2, and more. Every threat and countermeasure maps to compliance requirements.
  • Structured library packs — Not just brainstorming. Curated packs with components, threats, countermeasures, and taxonomy links (MITRE ATT&CK, CAPEC, CWE, STRIDE) give your team a structured starting point.
  • AI-agent ready architecture — A clean REST API with full OpenAPI docs, designed to be a foundation for AI-powered threat modeling assistants.
  • Pack ecosystem — Community and official packs for AWS, Azure, GCP, banking, and compliance frameworks. Extend or create your own.

Our AI Philosophy

  1. AI agents need CRUD scaffolding — Before AI generates a single threat, the platform must let you create, store, update, and track its core objects.
  2. Ahead-of-time AI > just-in-time AI — You can point AI at a system during threat modeling, or use it ahead of time to build curated threat libraries linked to standards. The second wins. Fewer hallucinations, more consistency.
  3. The journey of understanding is the threat model — The value of the threat model lives in the shared comprehension that humans build along the way. That needs a common interface where humans and agents work from the same picture.

Tech Stack

  • Frontend: React 19, TypeScript, Tailwind CSS, shadcn/ui, React Flow
  • Backend: Django 5.1, Django REST Framework, PostgreSQL 16
  • Infrastructure: Docker, nginx (production)

Roadmap

See the v0.3.0 milestone for what's coming next.

Contributing

If you find Precogly useful, give the project a star!

Community

Join the conversation on Discord.

Need Help? Contact the Developer

Special Thanks

A special thanks to Jeroen Verwoest for generously sharing his knowledge about threat modeling at an enterprise-scale in a compliance-heavy environment.

License

Apache 2.0

About

Open-source, enterprise-grade threat modeling platform

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - jwsapienza/precogly: Open-source, enterprise-grade threat modeling platform · GitHub
Skip to content

Repository files navigation

Precogly

Latest ReleaseLicenseStarsDiscordOWASP Project

Important

Precogly is now an OWASP project! OWASP is the world's largest open-source application security community, and Precogly is proud to be part of it.

The open-source alternative to commercial threat modeling platforms

Quick Start

 git clone --branch v0.3.0 https://github.com/precogly/precogly.git
cd precogly
docker compose up --build

Open http://localhost:5173 and log in with admin@precogly.dev / admin123. Two further demo accounts are seeded so roles and multi-tenancy can be exercised locally; the seed prints all three when it finishes.

Documentation

precogly.github.io/precogly

Video Walkthrough

Precogly Walkthrough

Why Precogly?

Open-source threat modeling tools lack enterprise features. Commercial tools come with heavy price tags and vendor lock-in.

Precogly bridges this gap and democratizes threat modeling for every org in the world.

Key Features

  • Import and export TM-BOM style JSON files - improves interoperability with other threat modeling platforms
  • A threat modeling workspace allows for team collaboration
  • An advanced DFD editor (allows for nested components, trust zones with trust boundaries and much more)
  • Community library packs with links to taxonomies like MITRE ATT&CK, CAPEC, LINDDUN, STRIDE etc. - allows your team to quickly create high quality threat models

Who is Precogly for?

  • Security architects looking to scale threat modeling in their orgs.
  • Vibe coding security engineers who need a well-architected CRUD foundation on which they can build their AI threat modeling assistants.
  • Threat modeling consultants and trainers looking for a platform that supports reference images, team collaboration, and structured threat modeling programs.
  • Compliance professionals looking to link threat modeling with security requirements coming from standards like ASVS or laws like CRA and DORA

Precogly is designed for enterprise workflows, but smaller organizations can also find value in the DFD editor, library packs, and collaborative workspace.

How is Precogly different?

  • Compliance-aware — Built-in traceability to DORA, CRA, ASVS, NIST CSF, SOC 2, and more. Every threat and countermeasure maps to compliance requirements.
  • Structured library packs — Not just brainstorming. Curated packs with components, threats, countermeasures, and taxonomy links (MITRE ATT&CK, CAPEC, CWE, STRIDE) give your team a structured starting point.
  • AI-agent ready architecture — A clean REST API with full OpenAPI docs, designed to be a foundation for AI-powered threat modeling assistants.
  • Pack ecosystem — Community and official packs for AWS, Azure, GCP, banking, and compliance frameworks. Extend or create your own.

Our AI Philosophy

  1. AI agents need CRUD scaffolding — Before AI generates a single threat, the platform must let you create, store, update, and track its core objects.
  2. Ahead-of-time AI > just-in-time AI — You can point AI at a system during threat modeling, or use it ahead of time to build curated threat libraries linked to standards. The second wins. Fewer hallucinations, more consistency.
  3. The journey of understanding is the threat model — The value of the threat model lives in the shared comprehension that humans build along the way. That needs a common interface where humans and agents work from the same picture.

Tech Stack

  • Frontend: React 19, TypeScript, Tailwind CSS, shadcn/ui, React Flow
  • Backend: Django 5.1, Django REST Framework, PostgreSQL 16
  • Infrastructure: Docker, nginx (production)

Roadmap

See the v0.3.0 milestone for what's coming next.

Contributing

If you find Precogly useful, give the project a star!

Community

Join the conversation on Discord.

Need Help? Contact the Developer

Special Thanks

A special thanks to Jeroen Verwoest for generously sharing his knowledge about threat modeling at an enterprise-scale in a compliance-heavy environment.

License

Apache 2.0

About

Open-source, enterprise-grade threat modeling platform

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - jwsapienza/precogly: Open-source, enterprise-grade threat modeling platform · GitHub
Skip to content

Repository files navigation

Precogly

Latest ReleaseLicenseStarsDiscordOWASP Project

Important

Precogly is now an OWASP project! OWASP is the world's largest open-source application security community, and Precogly is proud to be part of it.

The open-source alternative to commercial threat modeling platforms

Quick Start

 git clone --branch v0.3.0 https://github.com/precogly/precogly.git
cd precogly
docker compose up --build

Open http://localhost:5173 and log in with admin@precogly.dev / admin123. Two further demo accounts are seeded so roles and multi-tenancy can be exercised locally; the seed prints all three when it finishes.

Documentation

precogly.github.io/precogly

Video Walkthrough

Precogly Walkthrough

Why Precogly?

Open-source threat modeling tools lack enterprise features. Commercial tools come with heavy price tags and vendor lock-in.

Precogly bridges this gap and democratizes threat modeling for every org in the world.

Key Features

  • Import and export TM-BOM style JSON files - improves interoperability with other threat modeling platforms
  • A threat modeling workspace allows for team collaboration
  • An advanced DFD editor (allows for nested components, trust zones with trust boundaries and much more)
  • Community library packs with links to taxonomies like MITRE ATT&CK, CAPEC, LINDDUN, STRIDE etc. - allows your team to quickly create high quality threat models

Who is Precogly for?

  • Security architects looking to scale threat modeling in their orgs.
  • Vibe coding security engineers who need a well-architected CRUD foundation on which they can build their AI threat modeling assistants.
  • Threat modeling consultants and trainers looking for a platform that supports reference images, team collaboration, and structured threat modeling programs.
  • Compliance professionals looking to link threat modeling with security requirements coming from standards like ASVS or laws like CRA and DORA

Precogly is designed for enterprise workflows, but smaller organizations can also find value in the DFD editor, library packs, and collaborative workspace.

How is Precogly different?

  • Compliance-aware — Built-in traceability to DORA, CRA, ASVS, NIST CSF, SOC 2, and more. Every threat and countermeasure maps to compliance requirements.
  • Structured library packs — Not just brainstorming. Curated packs with components, threats, countermeasures, and taxonomy links (MITRE ATT&CK, CAPEC, CWE, STRIDE) give your team a structured starting point.
  • AI-agent ready architecture — A clean REST API with full OpenAPI docs, designed to be a foundation for AI-powered threat modeling assistants.
  • Pack ecosystem — Community and official packs for AWS, Azure, GCP, banking, and compliance frameworks. Extend or create your own.

Our AI Philosophy

  1. AI agents need CRUD scaffolding — Before AI generates a single threat, the platform must let you create, store, update, and track its core objects.
  2. Ahead-of-time AI > just-in-time AI — You can point AI at a system during threat modeling, or use it ahead of time to build curated threat libraries linked to standards. The second wins. Fewer hallucinations, more consistency.
  3. The journey of understanding is the threat model — The value of the threat model lives in the shared comprehension that humans build along the way. That needs a common interface where humans and agents work from the same picture.

Tech Stack

  • Frontend: React 19, TypeScript, Tailwind CSS, shadcn/ui, React Flow
  • Backend: Django 5.1, Django REST Framework, PostgreSQL 16
  • Infrastructure: Docker, nginx (production)

Roadmap

See the v0.3.0 milestone for what's coming next.

Contributing

If you find Precogly useful, give the project a star!

Community

Join the conversation on Discord.

Need Help? Contact the Developer

Special Thanks

A special thanks to Jeroen Verwoest for generously sharing his knowledge about threat modeling at an enterprise-scale in a compliance-heavy environment.

License

Apache 2.0

About

Open-source, enterprise-grade threat modeling platform

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - jwsapienza/precogly: Open-source, enterprise-grade threat modeling platform · GitHub
Skip to content

Repository files navigation

Precogly

Latest ReleaseLicenseStarsDiscordOWASP Project

Important

Precogly is now an OWASP project! OWASP is the world's largest open-source application security community, and Precogly is proud to be part of it.

The open-source alternative to commercial threat modeling platforms

Quick Start

 git clone --branch v0.3.0 https://github.com/precogly/precogly.git
cd precogly
docker compose up --build

Open http://localhost:5173 and log in with admin@precogly.dev / admin123. Two further demo accounts are seeded so roles and multi-tenancy can be exercised locally; the seed prints all three when it finishes.

Documentation

precogly.github.io/precogly

Video Walkthrough

Precogly Walkthrough

Why Precogly?

Open-source threat modeling tools lack enterprise features. Commercial tools come with heavy price tags and vendor lock-in.

Precogly bridges this gap and democratizes threat modeling for every org in the world.

Key Features

  • Import and export TM-BOM style JSON files - improves interoperability with other threat modeling platforms
  • A threat modeling workspace allows for team collaboration
  • An advanced DFD editor (allows for nested components, trust zones with trust boundaries and much more)
  • Community library packs with links to taxonomies like MITRE ATT&CK, CAPEC, LINDDUN, STRIDE etc. - allows your team to quickly create high quality threat models

Who is Precogly for?

  • Security architects looking to scale threat modeling in their orgs.
  • Vibe coding security engineers who need a well-architected CRUD foundation on which they can build their AI threat modeling assistants.
  • Threat modeling consultants and trainers looking for a platform that supports reference images, team collaboration, and structured threat modeling programs.
  • Compliance professionals looking to link threat modeling with security requirements coming from standards like ASVS or laws like CRA and DORA

Precogly is designed for enterprise workflows, but smaller organizations can also find value in the DFD editor, library packs, and collaborative workspace.

How is Precogly different?

  • Compliance-aware — Built-in traceability to DORA, CRA, ASVS, NIST CSF, SOC 2, and more. Every threat and countermeasure maps to compliance requirements.
  • Structured library packs — Not just brainstorming. Curated packs with components, threats, countermeasures, and taxonomy links (MITRE ATT&CK, CAPEC, CWE, STRIDE) give your team a structured starting point.
  • AI-agent ready architecture — A clean REST API with full OpenAPI docs, designed to be a foundation for AI-powered threat modeling assistants.
  • Pack ecosystem — Community and official packs for AWS, Azure, GCP, banking, and compliance frameworks. Extend or create your own.

Our AI Philosophy

  1. AI agents need CRUD scaffolding — Before AI generates a single threat, the platform must let you create, store, update, and track its core objects.
  2. Ahead-of-time AI > just-in-time AI — You can point AI at a system during threat modeling, or use it ahead of time to build curated threat libraries linked to standards. The second wins. Fewer hallucinations, more consistency.
  3. The journey of understanding is the threat model — The value of the threat model lives in the shared comprehension that humans build along the way. That needs a common interface where humans and agents work from the same picture.

Tech Stack

  • Frontend: React 19, TypeScript, Tailwind CSS, shadcn/ui, React Flow
  • Backend: Django 5.1, Django REST Framework, PostgreSQL 16
  • Infrastructure: Docker, nginx (production)

Roadmap

See the v0.3.0 milestone for what's coming next.

Contributing

If you find Precogly useful, give the project a star!

Community

Join the conversation on Discord.

Need Help? Contact the Developer

Special Thanks

A special thanks to Jeroen Verwoest for generously sharing his knowledge about threat modeling at an enterprise-scale in a compliance-heavy environment.

License

Apache 2.0

About

Open-source, enterprise-grade threat modeling platform

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - jwsapienza/precogly: Open-source, enterprise-grade threat modeling platform · GitHub
Skip to content

Repository files navigation

Precogly

Latest ReleaseLicenseStarsDiscordOWASP Project

Important

Precogly is now an OWASP project! OWASP is the world's largest open-source application security community, and Precogly is proud to be part of it.

The open-source alternative to commercial threat modeling platforms

Quick Start

 git clone --branch v0.3.0 https://github.com/precogly/precogly.git
cd precogly
docker compose up --build

Open http://localhost:5173 and log in with admin@precogly.dev / admin123. Two further demo accounts are seeded so roles and multi-tenancy can be exercised locally; the seed prints all three when it finishes.

Documentation

precogly.github.io/precogly

Video Walkthrough

Precogly Walkthrough

Why Precogly?

Open-source threat modeling tools lack enterprise features. Commercial tools come with heavy price tags and vendor lock-in.

Precogly bridges this gap and democratizes threat modeling for every org in the world.

Key Features

  • Import and export TM-BOM style JSON files - improves interoperability with other threat modeling platforms
  • A threat modeling workspace allows for team collaboration
  • An advanced DFD editor (allows for nested components, trust zones with trust boundaries and much more)
  • Community library packs with links to taxonomies like MITRE ATT&CK, CAPEC, LINDDUN, STRIDE etc. - allows your team to quickly create high quality threat models

Who is Precogly for?

  • Security architects looking to scale threat modeling in their orgs.
  • Vibe coding security engineers who need a well-architected CRUD foundation on which they can build their AI threat modeling assistants.
  • Threat modeling consultants and trainers looking for a platform that supports reference images, team collaboration, and structured threat modeling programs.
  • Compliance professionals looking to link threat modeling with security requirements coming from standards like ASVS or laws like CRA and DORA

Precogly is designed for enterprise workflows, but smaller organizations can also find value in the DFD editor, library packs, and collaborative workspace.

How is Precogly different?

  • Compliance-aware — Built-in traceability to DORA, CRA, ASVS, NIST CSF, SOC 2, and more. Every threat and countermeasure maps to compliance requirements.
  • Structured library packs — Not just brainstorming. Curated packs with components, threats, countermeasures, and taxonomy links (MITRE ATT&CK, CAPEC, CWE, STRIDE) give your team a structured starting point.
  • AI-agent ready architecture — A clean REST API with full OpenAPI docs, designed to be a foundation for AI-powered threat modeling assistants.
  • Pack ecosystem — Community and official packs for AWS, Azure, GCP, banking, and compliance frameworks. Extend or create your own.

Our AI Philosophy

  1. AI agents need CRUD scaffolding — Before AI generates a single threat, the platform must let you create, store, update, and track its core objects.
  2. Ahead-of-time AI > just-in-time AI — You can point AI at a system during threat modeling, or use it ahead of time to build curated threat libraries linked to standards. The second wins. Fewer hallucinations, more consistency.
  3. The journey of understanding is the threat model — The value of the threat model lives in the shared comprehension that humans build along the way. That needs a common interface where humans and agents work from the same picture.

Tech Stack

  • Frontend: React 19, TypeScript, Tailwind CSS, shadcn/ui, React Flow
  • Backend: Django 5.1, Django REST Framework, PostgreSQL 16
  • Infrastructure: Docker, nginx (production)

Roadmap

See the v0.3.0 milestone for what's coming next.

Contributing

If you find Precogly useful, give the project a star!

Community

Join the conversation on Discord.

Need Help? Contact the Developer

Special Thanks

A special thanks to Jeroen Verwoest for generously sharing his knowledge about threat modeling at an enterprise-scale in a compliance-heavy environment.

License

Apache 2.0

About

Open-source, enterprise-grade threat modeling platform

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - jwsapienza/precogly: Open-source, enterprise-grade threat modeling platform · GitHub
Skip to content

Repository files navigation

Precogly

Latest ReleaseLicenseStarsDiscordOWASP Project

Important

Precogly is now an OWASP project! OWASP is the world's largest open-source application security community, and Precogly is proud to be part of it.

The open-source alternative to commercial threat modeling platforms

Quick Start

 git clone --branch v0.3.0 https://github.com/precogly/precogly.git
cd precogly
docker compose up --build

Open http://localhost:5173 and log in with admin@precogly.dev / admin123. Two further demo accounts are seeded so roles and multi-tenancy can be exercised locally; the seed prints all three when it finishes.

Documentation

precogly.github.io/precogly

Video Walkthrough

Precogly Walkthrough

Why Precogly?

Open-source threat modeling tools lack enterprise features. Commercial tools come with heavy price tags and vendor lock-in.

Precogly bridges this gap and democratizes threat modeling for every org in the world.

Key Features

  • Import and export TM-BOM style JSON files - improves interoperability with other threat modeling platforms
  • A threat modeling workspace allows for team collaboration
  • An advanced DFD editor (allows for nested components, trust zones with trust boundaries and much more)
  • Community library packs with links to taxonomies like MITRE ATT&CK, CAPEC, LINDDUN, STRIDE etc. - allows your team to quickly create high quality threat models

Who is Precogly for?

  • Security architects looking to scale threat modeling in their orgs.
  • Vibe coding security engineers who need a well-architected CRUD foundation on which they can build their AI threat modeling assistants.
  • Threat modeling consultants and trainers looking for a platform that supports reference images, team collaboration, and structured threat modeling programs.
  • Compliance professionals looking to link threat modeling with security requirements coming from standards like ASVS or laws like CRA and DORA

Precogly is designed for enterprise workflows, but smaller organizations can also find value in the DFD editor, library packs, and collaborative workspace.

How is Precogly different?

  • Compliance-aware — Built-in traceability to DORA, CRA, ASVS, NIST CSF, SOC 2, and more. Every threat and countermeasure maps to compliance requirements.
  • Structured library packs — Not just brainstorming. Curated packs with components, threats, countermeasures, and taxonomy links (MITRE ATT&CK, CAPEC, CWE, STRIDE) give your team a structured starting point.
  • AI-agent ready architecture — A clean REST API with full OpenAPI docs, designed to be a foundation for AI-powered threat modeling assistants.
  • Pack ecosystem — Community and official packs for AWS, Azure, GCP, banking, and compliance frameworks. Extend or create your own.

Our AI Philosophy

  1. AI agents need CRUD scaffolding — Before AI generates a single threat, the platform must let you create, store, update, and track its core objects.
  2. Ahead-of-time AI > just-in-time AI — You can point AI at a system during threat modeling, or use it ahead of time to build curated threat libraries linked to standards. The second wins. Fewer hallucinations, more consistency.
  3. The journey of understanding is the threat model — The value of the threat model lives in the shared comprehension that humans build along the way. That needs a common interface where humans and agents work from the same picture.

Tech Stack

  • Frontend: React 19, TypeScript, Tailwind CSS, shadcn/ui, React Flow
  • Backend: Django 5.1, Django REST Framework, PostgreSQL 16
  • Infrastructure: Docker, nginx (production)

Roadmap

See the v0.3.0 milestone for what's coming next.

Contributing

If you find Precogly useful, give the project a star!

Community

Join the conversation on Discord.

Need Help? Contact the Developer

Special Thanks

A special thanks to Jeroen Verwoest for generously sharing his knowledge about threat modeling at an enterprise-scale in a compliance-heavy environment.

License

Apache 2.0

About

Open-source, enterprise-grade threat modeling platform

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - jwsapienza/precogly: Open-source, enterprise-grade threat modeling platform · GitHub
Skip to content

Repository files navigation

Precogly

Latest ReleaseLicenseStarsDiscordOWASP Project

Important

Precogly is now an OWASP project! OWASP is the world's largest open-source application security community, and Precogly is proud to be part of it.

The open-source alternative to commercial threat modeling platforms

Quick Start

 git clone --branch v0.3.0 https://github.com/precogly/precogly.git
cd precogly
docker compose up --build

Open http://localhost:5173 and log in with admin@precogly.dev / admin123. Two further demo accounts are seeded so roles and multi-tenancy can be exercised locally; the seed prints all three when it finishes.

Documentation

precogly.github.io/precogly

Video Walkthrough

Precogly Walkthrough

Why Precogly?

Open-source threat modeling tools lack enterprise features. Commercial tools come with heavy price tags and vendor lock-in.

Precogly bridges this gap and democratizes threat modeling for every org in the world.

Key Features

  • Import and export TM-BOM style JSON files - improves interoperability with other threat modeling platforms
  • A threat modeling workspace allows for team collaboration
  • An advanced DFD editor (allows for nested components, trust zones with trust boundaries and much more)
  • Community library packs with links to taxonomies like MITRE ATT&CK, CAPEC, LINDDUN, STRIDE etc. - allows your team to quickly create high quality threat models

Who is Precogly for?

  • Security architects looking to scale threat modeling in their orgs.
  • Vibe coding security engineers who need a well-architected CRUD foundation on which they can build their AI threat modeling assistants.
  • Threat modeling consultants and trainers looking for a platform that supports reference images, team collaboration, and structured threat modeling programs.
  • Compliance professionals looking to link threat modeling with security requirements coming from standards like ASVS or laws like CRA and DORA

Precogly is designed for enterprise workflows, but smaller organizations can also find value in the DFD editor, library packs, and collaborative workspace.

How is Precogly different?

  • Compliance-aware — Built-in traceability to DORA, CRA, ASVS, NIST CSF, SOC 2, and more. Every threat and countermeasure maps to compliance requirements.
  • Structured library packs — Not just brainstorming. Curated packs with components, threats, countermeasures, and taxonomy links (MITRE ATT&CK, CAPEC, CWE, STRIDE) give your team a structured starting point.
  • AI-agent ready architecture — A clean REST API with full OpenAPI docs, designed to be a foundation for AI-powered threat modeling assistants.
  • Pack ecosystem — Community and official packs for AWS, Azure, GCP, banking, and compliance frameworks. Extend or create your own.

Our AI Philosophy

  1. AI agents need CRUD scaffolding — Before AI generates a single threat, the platform must let you create, store, update, and track its core objects.
  2. Ahead-of-time AI > just-in-time AI — You can point AI at a system during threat modeling, or use it ahead of time to build curated threat libraries linked to standards. The second wins. Fewer hallucinations, more consistency.
  3. The journey of understanding is the threat model — The value of the threat model lives in the shared comprehension that humans build along the way. That needs a common interface where humans and agents work from the same picture.

Tech Stack

  • Frontend: React 19, TypeScript, Tailwind CSS, shadcn/ui, React Flow
  • Backend: Django 5.1, Django REST Framework, PostgreSQL 16
  • Infrastructure: Docker, nginx (production)

Roadmap

See the v0.3.0 milestone for what's coming next.

Contributing

If you find Precogly useful, give the project a star!

Community

Join the conversation on Discord.

Need Help? Contact the Developer

Special Thanks

A special thanks to Jeroen Verwoest for generously sharing his knowledge about threat modeling at an enterprise-scale in a compliance-heavy environment.

License

Apache 2.0

About

Open-source, enterprise-grade threat modeling platform

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages