Local with MCP
Run threat models directly in Cursor, GitHub Copilot, Claude Code, or opencode while you write code.~2 min setup
Connect GitHub
Automated threat modeling on every pull request with a summary review comment.~5 min setup
Connect GitLab
Automated threat modeling on every merge request. No app install needed.~3 min setup
How Oplane works
1
Describe what changed
Oplane reads your code diff or you describe the feature you’re building.
2
Get security requirements
Oplane generates requirements targeted at what you actually changed rather than a generic checklist.
3
Implement & resolve
Get implementation advice, mark requirements as resolved, or accept risks with justification.
4
Track your security posture
View organisation-wide analytics covering resolution rates, requirement completion, and how adoption is spreading across teams.
Two ways to use Oplane
In your IDE
Connect via MCP and threat model while you code. Works with Cursor, GitHub Copilot, Claude Code, opencode, and any MCP-compatible client. No Git provider connection needed.Threat model from your IDE
Connect Oplane to your IDE for in-editor threat modeling.
On PRs & MRs
Automated reviews run on every pull request and merge request and post a single summary comment with all the findings, and you can also trigger one on demand with@oplane.
How reviews work
What triggers a review and what it produces.
Review pull and merge requests
Set up reviews on GitHub pull requests and GitLab merge requests.