Introduction

Oplane is a threat modeling platform that helps development teams identify and address security risks in their architecture — in minutes, not weeks.

What Oplane Does

Oplane analyses how your systems interact and where data flows, identifying potential security threats at the architectural level. Unlike scanners that look for code-level vulnerabilities, Oplane focuses on design-level risks: broken access control, insecure data flows, missing authentication boundaries.

Every finding includes a specific security requirement and implementation guidance tailored to your codebase.

How It Fits Your Workflow

While you code

Connect Oplane to your IDE via MCP. Describe what you're building and get security requirements in real time — before you even open a PR.

Threat model auth changes
+×
MCP setup →

On every PR & MR

Connect your GitHub or GitLab repositories. Oplane reviews every pull request and posts security requirements as inline comments on the affected lines.

oplane reviewed your pull request
HighMissing rate limiting on authentication endpoint🔴
MediumSession tokens not invalidated on password change🟡
LowError responses expose internal service names
PR reviews →

Organisation Security Posture

Beyond individual requirements, Oplane gives you a birds-eye view of your organisation's security posture. The analytics dashboard tracks:

  • PR resolution rate — how quickly security requirements get addressed across your repositories
  • Requirements completion — percentage of security requirements implemented vs. outstanding
  • Team adoption — which teams are actively using Oplane and how engagement trends over time
  • Threat model coverage — breakdown of sources (automated PR reviews vs. manual/MCP) and scope coverage

Filter by time period, workspace, or team to drill into specific areas. Export data for compliance reporting or security audits.

Analytics dashboard →

Get Started

Ready to try it? The Quick Start guide walks you through both paths in under 5 minutes.

Go to Quick Start