> ## Documentation Index
> Fetch the complete documentation index at: https://www.oplane.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Quick start guide for Oplane threat modeling

> Set up Oplane threat modeling in under 5 minutes: connect your GitHub or GitLab repository, run your first scan, and review security findings on a PR.

Get security threat modeling running in your workflow in under 5 minutes. Choose your path below.

<CardGroup cols={3}>
  <Card title="Local with MCP" icon="terminal" href="/docs/find/mcp">
    Run threat models directly in Cursor, GitHub Copilot, Claude Code, or opencode while you write code.

    \~2 min setup
  </Card>

  <Card title="Connect GitHub" icon="github" href="/docs/connect/github">
    Automated threat modeling on every pull request with a summary review comment.

    \~5 min setup
  </Card>

  <Card title="Connect GitLab" icon="gitlab" href="/docs/connect/gitlab">
    Automated threat modeling on every merge request. No app install needed.

    \~3 min setup
  </Card>
</CardGroup>

## How Oplane works

<Steps>
  <Step title="Describe what changed">
    Oplane reads your code diff or you describe the feature you're building.
  </Step>

  <Step title="Get security requirements">
    Oplane generates requirements targeted at what you actually changed rather than a generic checklist.
  </Step>

  <Step title="Implement & resolve">
    Get implementation advice, mark requirements as resolved, or accept risks with justification.
  </Step>

  <Step title="Track your security posture">
    View organisation-wide analytics covering resolution rates, requirement completion, and how adoption is spreading across teams.
  </Step>
</Steps>

## Two ways to use Oplane

#### In your IDE

Connect via MCP and threat model while you code. Works with Cursor, GitHub Copilot, Claude Code, opencode, and any MCP-compatible client. No Git provider connection needed.

<Card title="Threat model from your IDE" icon="terminal" href="/docs/find/mcp">
  Connect Oplane to your IDE for in-editor threat modeling.
</Card>

#### On PRs & MRs

Automated reviews run on every pull request and merge request and post a single summary comment with all the findings, and you can also trigger one on demand with `@oplane`.

<CardGroup cols={2}>
  <Card title="How reviews work" icon="lightbulb" href="/docs/how-it-works/reviews">
    What triggers a review and what it produces.
  </Card>

  <Card title="Review pull and merge requests" icon="git-pull-request" href="/docs/find/pull-and-merge-requests">
    Set up reviews on GitHub pull requests and GitLab merge requests.
  </Card>
</CardGroup>

<Tip>
  Use both together for full coverage, so you catch issues locally as you develop and automated reviews still catch anything that slips through in code review.
</Tip>

## Read next

* [How reviews work](/docs/how-it-works/reviews)
* [Respond to requirements](/docs/find/respond-to-requirements)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.