Precogly is now an official OWASP Project
Precogly Logo

Open-source, enterprise-grade threat modeling.

Free forever.Community-driven.Community-owned.
Now Available — Open Source under Apache 2.0

No install required. The demo is a shared instance and its data is reset periodically.

The Tooling Gap

Teams today often face a difficult trade-off:

Manual & Ad-hoc

Using whiteboards or simple diagramming tools that don't scale or integrate with code.

Closed & Expensive

Using powerful commercial platforms that are locked behind high licensing fees.

Precogly fills the gap

We provide an open foundation that supports enterprise scale without sacrificing accessibility or developer freedom.

See Precogly in Action

Built for Enterprise Threat Modeling

Advanced DFD Editor

Drag-and-drop component panel, trust zones, notation switching (DFD3 / Yourdon-DeMarco). Built on React Flow.

Community Library Packs

MITRE ATT&CK, CAPEC, CWE, MITRE ATLAS, LINDDUN, STRIDE, OWASP LLM Top 10. Packs for AWS, Azure, GCP, banking, and AI/ML.

TM-BOM Interoperability

CycloneDX 2.0 TM-BOM import/export. CSV and Word report generation. No vendor lock-in.

Compliance Mapping

DORA, CRA, ASVS, NIST CSF, SOC 2 traceability.

AI-Powered Threat Modeling

LLM threat suggestion, DFD generation from architecture diagrams, built-in MCP server, and bring-your-own-model support.

Team Collaboration

Workspace-based threat modeling with real-time collaboration.

Who Is Precogly For?

Security Architects

Scale threat modeling across your org.

Security Engineers

Build AI assistants on a structured CRUD foundation. REST API, OpenAPI, and built-in MCP server included.

Consultants & Trainers

Deliver workshops with reference images, collaboration, structured programs.

Compliance Professionals

Link threat models to ASVS, CRA, DORA, NIST CSF, SOC 2.

Get Started in 60 Seconds

Don't want to install anything?

Open the hosted demo in your browser. Shared instance, reset periodically — explore freely, but keep real threat models on your own deployment.

Live Demo
terminal
git clone --branch v0.4.0 https://github.com/precogly/precogly.git
cd precogly
docker compose up --build

Open http://localhost:5173 and log in with admin@precogly.dev / admin123

For Collaborators

Architect the Standard

Don't just consume the tools. Build them. We're inviting select security engineers to define the primitives of the next generation of threat modeling.

  • Influence the core architecture and data models.
  • Shape workflows before they're set in stone.
  • Contribute to the core platform and library packs.
For Practitioners

Practitioner Directory

Offer threat modeling services using the industry's first open-source, enterprise-grade threat modeling tool. Get listed and connect with organizations looking for expert help.

  • Provide training, customization, integration, and consulting services.
  • Get listed in our practitioner directory and grow your visibility.
  • Join a growing ecosystem of security professionals using Precogly.

Project Roadmap

v0.4.0 Released

AI-powered threat suggestion, MCP server, CycloneDX 2.0, risk register, and OAuth 2.1.

Library Packs & Taxonomies

AWS, Azure, GCP, banking, AI/ML, CAPEC, CWE, MITRE ATLAS, and OWASP LLM Top 10 packs.

AI Agent Integration

Built-in MCP server, bring-your-own-model, DFD generation from architecture diagrams.

Community Growth

Growing contributor ecosystem and partner network.

Frequently Asked Questions

Yes. Released under Apache 2.0. Full source on GitHub.

Precogly is compliance-aware out of the box, ships with structured library packs (MITRE ATT&CK, STRIDE, LINDDUN, and more), includes AI-powered threat suggestion with bring-your-own-model support, a built-in MCP server for AI agent integration, CycloneDX 2.0 TM-BOM interoperability, and has no licensing fees. It fills the gap between ad-hoc open tools and expensive commercial platforms.

Vikramaditya - Threat Modeling Connect Chapter Lead (Bangalore) and an experienced developer. Advised by senior practitioners from Fortune 500 enterprises.

Yes. app.precogly.org is a hosted demo you can open in your browser. It is a shared instance and its data is reset periodically, so use it to evaluate the tool and self-host once you want to keep your threat models.

Docker and Docker Compose. Clone the repo, run docker compose up --build, and open localhost:5173. Three commands to a running instance.

Absolutely. We welcome contributions to the core platform, library packs, documentation, and bug reports. Head to GitHub to get started.

MITRE ATT&CK, CAPEC, CWE, MITRE ATLAS, LINDDUN, STRIDE, and OWASP LLM Top 10 for threat identification. DORA, CRA, ASVS, NIST CSF, and SOC 2 for compliance mapping. A vendor-neutral AI/ML threat library pack is also included. More packs are added by the community.