• Home
  • Pricing
  • Docs
  • About
  • Launch
Community preview
Security starts before the first commit
Lantern is a threat modeling tool for teams building secure systems.
Launch now Watch demo
Threat models that scale with your project
Every change to your project can shift its security landscape. Lantern keeps everything connected and up to date.
Consistency
Keep your threat model consistent and up to date

Lantern stores your threat model as a single structured project graph. Assets, system elements, threats, mitigations, assessments, and diagrams all draw from the same source of truth, so changes stay consistent across the entire project.

  • Reuse system elements across multiple diagrams
  • Trace assets through processes, stores, and flows
  • Track assessment status across the project
  • Reports and machine-readable exports
Perspective
Break complex systems down with automatically laid-out diagrams

Describe the system and let the layout handle itself. From high-level overviews to focused views of individual features or workflows.

  • Quickly create focused views for specific areas
  • Build multiple diagrams from shared project data
  • Layout and drawing is fully automated
  • Step through ordered flows interactively
Control
Manage threats and risks all the way from discovery to resolution

Identify and assess threats in the context of the system. Link them to affected elements, calculate risk from likelihood and impact, and track their treatment over time.

  • Build on a maintained library of known threats
  • Link threats to affected system elements
  • Track threat and mitigation status
  • Detect when changes require reassessment
Local first

Runs locally in your browser. Optional online features are additive, not required.

AI supported, but optional

Use AI when it helps, while retaining full control over whether and how project data is exposed.

Full portability

Store and exchange the complete threat model as structured JSON, without proprietary lock-in.

Project insights

See what has been covered, which threats remain open, and where follow-up is still needed.

Shareable reports

Create downloadable reports for reviews, presentations, releases, and follow-up.

Threat suggestions

Use element metadata and established weakness catalogs to find threats that may apply.

FAQ
Is Lantern an AI tool?

No.

But that doesn't mean you cannot use AI with it.

The thing is, generative AI can be very useful for threat modeling. But that doesn't necessarily mean every tool has to come with a built-in model or AI buttons everywhere.

So Lantern takes a slightly different approach (at least for now). Instead of tying you to a specific provider or workflow, it focuses on portability and lets you decide whether to use AI at all, which model to use, and where and how your data is shared.

Projects can be exported together with a schema that describes the expected structure. The schema also provides some hints that machines can use. You can provide both to any AI model, along with your own instructions, to generate content and import the result back into Lantern.

This may not be as convenient as first-class LLM support, but it gives you complete freedom and control. And who knows what the future may bring?

What methodologies are supported?

For now, only STRIDE. Attack trees are around the corner. Experiments are being made with integrating other methodologies as well.

Where is my data stored?

Threat models often contain sensitive information about your systems, architecture, and security controls. You should always know where that data is stored.

You can use Lantern in three ways:

  • Local: Your threat models remain in your browser's local storage (IndexDB) and are never uploaded anywhere.
  • Cloud (coming soon): Projects are securely stored on Lantern's servers to support collaboration across your team. You can export the full data model at any time.
  • On-premises (coming soon): All project data is stored within your own infrastructure.
Can I export my data?

Yes. Lantern is designed for full portability.

You can export and import your projects, store them in version control, convert them to other formats, or build custom tools and workflows around them. Your data is not, and will never be, locked into Lantern.

Is Lantern production ready?

This is a community release. A public beta. Take it for a spin and see how you feel.

Lantern is currently being evaluated in several pilot projects at Fortune 500 companies.

It is not perfect. The list of planned improvements is still longer than the list of completed features.

That said, Lantern is already being used and remains under active development. Your work is also fully portable: you can export it and convert it to other formats at any time.

Can I model things other than software?

Yes. Lantern is designed for both IT and OT environments, but it is not limited to software or technical systems.

You can use it to model infrastructure, industrial processes, business workflows, data flows, and other systems where assets, interactions, trust boundaries, and potential threats need to be understood.

Can I influence the future development of Lantern?

Yes! Community feedback plays a very important role in shaping Lantern's development.

Please report bugs and share feedback using the links in the footer. Your input helps guide future improvements and development priorities.

Start designing secure systems
Launch now
No account required. Your data stays local.
Security starts before
the first commit
Site
  • Home
  • Pricing
  • Docs
  • About
Support
  • Feature suggestion
  • Bug report
  • Support request
Social
  • Codeberg
© 2026
Privacy policy Terms of use
  • Home
  • Pricing
  • Docs
  • About
Security starts before
the first commit
Launch Lantern
Privacy policy Terms of use