Security — STRIDE risk matrix
A typed threat model rendered as a risk matrix. Typed FlowScript for threat modelling. Keywords: threat model, STRIDE, risk matrix, security.
Make it your own.
threat_model signup {
framework: "STRIDE"
title: "User sign-up + email verification"
scope: "Public sign-up endpoint, email verification, password reset"
}
asset pii {
name: "User PII (email + password hash)"
value: "Direct user impact; SOC2 in scope"
classification: "confidential"
}
asset session {
name: "Auth session JWT"
value: "Account takeover vector"
classification: "restricted"
}
threat brute_force {
title: "Credential stuffing on /signin"
asset: pii
category: "spoofing"
likelihood: 5
impact: 4
}
threat token_leak {
title: "Session token leaked via XSS"
asset: session
category: "elevation"
likelihood: 3
impact: 5
}
threat email_takeover {
title: "Email enumeration via signup error"
asset: pii
category: "info-disclosure"
likelihood: 4
impact: 2
}
threat replay {
title: "Email-verification link replayed"
asset: session
category: "tampering"
likelihood: 3
impact: 3
}
threat dos {
title: "Sign-up form rate exhaustion"
asset: pii
category: "dos"
likelihood: 4
impact: 2
}
control rate_limit {
title: "Per-IP rate limit on /signin + /signup"
mitigates: [brute_force, dos]
type: "preventive"
coverage: 0.7
owner: "platform"
}
control csp {
title: "Strict CSP (no inline scripts)"
mitigates: [token_leak]
type: "preventive"
coverage: 0.6
}
control single_use {
title: "Single-use signed magic links"
mitigates: [replay]
type: "preventive"
coverage: 0.85
}
control generic_errors {
title: "Generic 'check your inbox' error"
mitigates: [email_takeover]
type: "preventive"
coverage: 0.9
}
view risk: risk_matrix