Thread models
Threat models still live as a whiteboard photo and a slide deck from the last architecture review. Threat actors, attack vectors, and mitigations are not fields, so a new feature ships without updating the model.
Hypervault stores the threat model name, system, actors, vectors, and mitigations in an encrypted EU vault, with permissions for security and the team that owns that application.
Why store Thread models in a digital vault
The whiteboard is the model
Photos rot in a channel. Model name, system, and notes in the vault are the durable analysis.
Actors and vectors are buried in a paragraph
You cannot filter ransomware vs insider. Threat actors and attack vectors as fields make reviews concrete.
Mitigations were 'we will add MFA'
Nobody checks they shipped. Mitigation strategies plus review date are the control loop.
Risk level is a gut feel in the meeting
Engineering cannot prioritise. Risk level on the item is what the backlog can read.
Who uses this template
Security architects
Keep threat actors, vectors, risk, and mitigations per system in the vault.
Product and engineering owners
Update the model when the system changes, under permissions, not a lost Miro board.
Auditors and customers asking 'do you threat-model?'
Show a dated, encrypted record instead of a workshop photo.
Fields in this template
Keep every record complete and easy to find. Existing fields stay as they are; extras are added only when a vault item would otherwise be incomplete.
- Model name
- System/Application
- Threat actors
- Attack vectors
- Risk level
- Mitigation strategies
- Review date
- Notes
How it works in Hypervault
Create from the template
Add an item from the Thread models template in your workspace.
Fill and attach
Complete the fields and attach supporting files where needed.
Share with the right roles
Give access only to the people who maintain or use this record.
Related templates
Passwords
Template for securely storing passwords, login credentials, and authentication information.
Penetration test reports
Template for storing penetration test results, security assessments, and vulnerability reports.
Security procedures
Template for documenting security procedures, protocols, and incident response plans.
Store it in a vault, not a spreadsheet
Create a workspace, pick this template, and keep credentials and supporting files encrypted in the EU.
