TrustStencil icon
One-time iPhone and iPad app

TrustStencil

Build inspectable trust-boundary maps, derive architecture prompts, prioritize STRIDE threats, trace attack paths, and export a private review packet.

Focused field tools

Scope and Assets

Name the system boundary, crown-jewel assets, excluded components, review owner, and decision being supported.

Trust Boundaries

Record where identity, administration, tenancy, network, or operational authority changes.

Data Flows

Keep source, destination, payload, protocol, direction, authentication, encryption, and boundary crossing explicit.

STRIDE Prompts

Use spoofing, tampering, repudiation, disclosure, denial, and elevation as prompts rather than a substitute for architecture knowledge.

Identity

Distinguish human, workload, device, and partner identity plus issuance, rotation, revocation, and replay controls.

Authorization

Map each privileged operation to a policy decision, enforcement point, resource, and audit record.

TrustStencil structures threat-model evidence; it does not prove a system secure. Validate architecture, assets, assumptions, controls, test evidence, and residual risk with the accountable security team.