Skip to main content
Get security threat modeling running in your workflow in under 5 minutes. Choose your path below.

Local with MCP

Run threat models directly in Cursor, GitHub Copilot, Claude Code, or opencode while you write code.~2 min setup

Connect GitHub

Automated threat modeling on every pull request with a summary review comment.~5 min setup

Connect GitLab

Automated threat modeling on every merge request. No app install needed.~3 min setup

How Oplane works

1

Describe what changed

Oplane reads your code diff or you describe the feature you’re building.
2

Get security requirements

Oplane generates requirements targeted at what you actually changed rather than a generic checklist.
3

Implement & resolve

Get implementation advice, mark requirements as resolved, or accept risks with justification.
4

Track your security posture

View organisation-wide analytics covering resolution rates, requirement completion, and how adoption is spreading across teams.

Two ways to use Oplane

In your IDE

Connect via MCP and threat model while you code. Works with Cursor, GitHub Copilot, Claude Code, opencode, and any MCP-compatible client. No Git provider connection needed.

Threat model from your IDE

Connect Oplane to your IDE for in-editor threat modeling.

On PRs & MRs

Automated reviews run on every pull request and merge request and post a single summary comment with all the findings, and you can also trigger one on demand with @oplane.

How reviews work

What triggers a review and what it produces.

Review pull and merge requests

Set up reviews on GitHub pull requests and GitLab merge requests.
Use both together for full coverage, so you catch issues locally as you develop and automated reviews still catch anything that slips through in code review.