Threat Canvas for Jira and Confluence
Turn AI system models into Jira-ready security work and Confluence evidence.
Use Threat Canvas to model AI architecture, trust boundaries, flows, risks, controls, and ownership—then turn approved outcomes into Jira-ready remediation and Confluence-ready security design records.
AI product launch review
Structure design review for an AI-enabled release and preserve the risks, controls, owners, and review decisions required by the release gate.
RAG application threat model
Model retrieval components, data flows, identities, authorization boundaries, provenance controls, and candidate abuse scenarios.
SaaS architecture review
Model tenant boundaries, external providers, identity transitions, data movement, agent actions, and control ownership.
Secure design review before release
Turn design-level security decisions into assigned remediation work and a durable review record.
Compliance and assurance evidence
Produce reviewed design evidence that can support SOC 2, ISO 27001, ISO 42001, customer review, and internal assurance without claiming that the canvas itself certifies compliance.
Threat Canvas
AI System Threat Model
User Browser
External Entity
LLM Gateway
AI Process
RAG Pipeline
AI Process
Vector Store
Data Store
Tool Executor
Process
Audit Log
Data Store
Trust boundary: AI inference layer
Identified risks
Prompt injection via user input
HIGHRetrieval context leakage
MEDExcessive agent permissions
HIGHAudit log tampering
LOW4 risks · 2 controls mapped · Jira-ready
Core capabilities
What Threat Canvas for Jira and Confluence does.
System and flow model
Represent external entities, applications, models, data stores, retrieval systems, agents, tools, trust zones, flows, and risks in a structured canvas.
Threat discovery
Apply STRIDE-compatible and AI-specific threat patterns to the modeled components, boundaries, and flows.
AI application templates
Start from structured patterns for model gateways, RAG pipelines, tool calls, agent actions, memory, provider boundaries, and consequential outputs.
Jira work generation
Create structured remediation work containing component context, affected flow, severity, owner, recommended control, and evidence requirements.
Confluence design records
Publish a readable security design record containing the model, risks, controls, decisions, open work, evidence, and reviewer sign-off.
Trust-boundary modeling
Show where identity, authorization, data classification, privilege, ownership, logging, or external dependency requirements change.
The problem
Threat models should drive engineering work and preserve decisions.
Threat modeling is too often trapped in workshops, whiteboards, and stale diagrams. Engineering teams need clear Jira work. Security teams need review evidence. Leaders need a readable risk picture.
Diagrams go stale
Architecture changes quickly. Threat models require ownership, linked work, and review state to remain useful.
Tickets lose context
Security tickets lose value when they no longer explain the component, flow, trust boundary, precondition, or control decision that produced them.
Design decisions lose their evidence
Security, assurance, and customer review require a durable record of what was modeled, what was accepted, what changed, and what remains open.
AI systems make it harder
Modern AI products add flows and failure modes that traditional architecture diagrams do not capture: prompt construction, retrieved context, model provider boundaries, tool calls, agent actions, memory reads, and side-effect outputs.
- Prompt injection via user and retrieved content
- Retrieval context leakage across tenants
- Excessive agency from tool-enabled agents
- Unsafe output handling and data exfiltration
- Model provider trust boundary violations
- Audit log gaps and side-effect traceability
Outcomes
From connected model to engineering action.
Model the system and its flows
Sketch your architecture as a system and flow canvas: external entities, processes, data stores, trust boundaries, and flows.
Identify risks and candidate abuse scenarios
STRIDE-compatible threat discovery across every flow and boundary. AI systems get first-class templates for prompt injection, retrieval leakage, and excessive agency.
Assign controls, owners, and evidence requirements
Attach mitigations, ownership, and evidence expectations directly to the relevant components, flows, boundaries, and scenarios.
Create Jira-ready remediation work
Convert risks into structured Jira issues with context, severity, ownership, and remediation guidance — not vague risk language.
Publish the Confluence-ready design record
Export a Confluence-ready security design record with controls, evidence, risk summary, and reviewer sign-off.
Designed for Jira and Confluence workflows
Built for the tools your teams already use.
Threat models that live inside Jira and Confluence stay connected to engineering work. Risks become tickets. Decisions become design records. Evidence is always traceable to the model that produced it.
Confluence
- Security design record page
- Threat model snapshot and summary
- Control and evidence tables
- Architecture reviewer sign-off
- Living document — updates with the model
Jira
- Risk-to-ticket with full context
- Severity, component, and owner fields
- Linked back to the canvas model
- Remediation guidance in description
- Tracks to sprint and release
Who benefits
Security teams
Auditable evidence of design review, control coverage, and risk disposition.
Engineers
Clear Jira tickets with architectural context and remediation guidance — not abstract risk language.
Engineering managers
A prioritized security backlog that connects to sprints and release gates.
Leaders and auditors
An executive risk summary and a structured record of threat modeling decisions.
Compliance teams
Design-time evidence for SOC 2, ISO 27001, and ISO 42001 controls without a heavyweight GRC system.
AI systems
Threat modeling for RAG, agents, and AI-enabled products.
AI-specific risk surfaces
AI systems introduce new flows and failure modes that normal architecture diagrams do not capture. The canvas has first-class support for every layer of the modern AI stack.
Prompt construction layer
Prompt injection, template injection, context manipulation
Retrieval / RAG pipeline
Context leakage, cross-tenant retrieval, poisoning
LLM gateway and model providers
Trust boundary violations, model substitution
Tool calls and agent actions
Excessive agency, unsafe tool permissions
Memory and session state
State poisoning, session fixation, replay attacks
Output handling and side effects
Data exfiltration, unsafe code execution, SSRF
Audit and observability layer
Log tampering, traceability gaps, evidence loss
The canvas treats AI systems as first-class threat model subjects. Pre-built templates surface the risk taxonomy for LLM applications, RAG pipelines, and agent-enabled products — so teams do not start from a blank STRIDE spreadsheet.
AI template
LLM gateway review
Map prompt flows, system prompt exposure, user trust levels, and output routing. Identify prompt injection and model substitution risks.
AI template
RAG pipeline model
Canvas the retrieval path: query, embedding, vector store, context window, and response. Surface leakage and poisoning exposure.
AI template
Agent threat model
Model agent tool permissions, action chains, memory reads, and side effects. Identify excessive agency and unsafe tool use.
AI template
AI product launch review
Full pre-launch threat model with Jira remediation backlog and Confluence evidence record. Evidence of security review before ship.
Framework alignment
AI risk templates align with OWASP LLM Top 10, MITRE ATLAS AI adversarial techniques, and NIST AI RMF governance controls — so evidence produced connects to the frameworks your buyers and auditors already reference.
Features
What Threat Canvas adds to Jira and Confluence workflows.
System and flow model
Represent external entities, applications, models, data stores, retrieval systems, agents, tools, trust zones, flows, and risks in a structured canvas.
Threat discovery
Apply STRIDE-compatible and AI-specific threat patterns to the modeled components, boundaries, and flows.
AI application templates
Start from structured patterns for model gateways, RAG pipelines, tool calls, agent actions, memory, provider boundaries, and consequential outputs.
Jira work generation
Create structured remediation work containing component context, affected flow, severity, owner, recommended control, and evidence requirements.
Confluence design records
Publish a readable security design record containing the model, risks, controls, decisions, open work, evidence, and reviewer sign-off.
Trust-boundary modeling
Show where identity, authorization, data classification, privilege, ownership, logging, or external dependency requirements change.
Workflow
Threat modeling in one flow.
Import or sketch architecture
Start from an existing Confluence diagram, an architecture description, or draw the system from scratch on the canvas.
Mark trust boundaries and data classes
Define perimeters, privilege zones, and data sensitivity across every flow and storage layer.
Generate or review threats
Use STRIDE templates and AI-assisted threat generation to identify risks, or walk through the model manually.
Map controls and evidence
Attach existing controls, record gaps, and link to test results or audit evidence directly on the canvas.
Create Jira issues
Convert open risks into Jira tickets with full context: component, flow, severity, owner, and recommended remediation.
Publish the Confluence design record
Export a structured security design document to Confluence. Living models update as the architecture evolves.
Differentiation
A threat model that stays connected to work and evidence.
Threat Canvas connects components, flows, boundaries, risks, controls, owners, remediation work, and evidence state. The objective is not another drawing. It is a living security decision record that engineering teams can act on.
vs. Diagramming tools
Diagrams do not drive remediation. There is no risk registry, no Jira integration, and no evidence output. They produce pictures, not work.
vs. GRC platforms
GRC systems are too heavy for design-time product security. They track compliance programs, not architecture-level threat models.
vs. AI chatbots
A chatbot generates threat ideas without durable context. There is no canvas, no trust boundary model, no Jira output, and no evidence record.
vs. Spreadsheets
Spreadsheets do not connect risks to architecture. They go stale immediately and produce no Jira work or Confluence evidence.
What makes it different
Structured security data-flow canvas — not a whiteboard, not a chat window.
Risks are linked to specific components, flows, and trust boundaries in the model.
Jira issues carry full canvas context: component, flow, severity, and remediation.
Confluence records are generated from the model, not written from scratch.
Evidence is always traceable back to the threat model that produced it.
Living models update as architecture evolves — not a one-time snapshot.
Use cases
Where security teams deploy it.
Use case
AI product launch review
Structure design review for an AI-enabled release and preserve the risks, controls, owners, and review decisions required by the release gate.
Use case
RAG application threat model
Model retrieval components, data flows, identities, authorization boundaries, provenance controls, and candidate abuse scenarios.
Use case
SaaS architecture review
Model tenant boundaries, external providers, identity transitions, data movement, agent actions, and control ownership.
Use case
Secure design review before release
Turn design-level security decisions into assigned remediation work and a durable review record.
Use case
Compliance and assurance evidence
Produce reviewed design evidence that can support SOC 2, ISO 27001, ISO 42001, customer review, and internal assurance without claiming that the canvas itself certifies compliance.
Early access
Bring the threat model into engineering and review workflows.
What early access includes
Threat models that produce assigned work and durable evidence.
Join the early access list to be first to run a structured AI threat model for your system — with Jira-ready remediation work and a Confluence security design record.
Platform delivery
Web application
Hosted canvas available now for standalone use — no Atlassian account required.
Open canvas demoConfluence macro
Planned Confluence packaging would place risks and evidence next to architecture docs. Current access is direct scoping, not a live marketplace listing.
View marketplace ecosystemJira integration
Create and track Jira issues directly from the canvas model. Risks become sprint-ready security work.
Scope an AI Security ReviewAI SECURITY WORKBENCH
Ready to connect Threat Canvas to engineering work?
Start with one bounded application, workflow, tool set, or security decision. Use the relevant Workbench experience to produce connected context, reviewable findings, assigned controls, and explicit next steps.
Continue through the Workbench
Continue through the Workbench
Threat Canvas
Model the system, boundaries, flows, risks, and controls.
Continue through the Workbench
Authority Graph
Add effective authority, approval, credential, and downstream-action context.
Continue through the Workbench
AI Security Program Scorecard
Connect design findings to broader ownership and control priorities.
Continue through the Workbench
Evidence System
Turn reviewed decisions, remediation, and retest results into audience-specific evidence.