vertotechTrust Intelligence. Secure Every Outcome.
Aether · AI & agentic threat modeling

Model the threats before you build the agent.

Aether turns an AI architecture into a clear data-flow diagram, treats agents, models, RAG and MCP servers as first-class components, and maps threats to MITRE ATLAS, OWASP and a control catalogue — with provenance on every mapping. Design-time threat modeling that complements Provenant's build-time assurance.

MITRE ATLASOWASP LLM Top 10OWASP AgenticSTRIDENIST AI RMF

A walkthrough of the AI & agentic threat-modeling workflow

What it does

Agentic threat modeling, visualized

Aether reasons over components, data flows and trust boundaries — with AI agents, models, RAG and MCP servers treated as first-class citizens.

Auto-arranged data-flow diagram

Describe or import an architecture and Aether lays out a DFD with real provider icons, explicit trust boundaries, and numbered flows — then plays the data flow step by step.

Agents as first-class components

Capture each agent's identity, goals, permissions, tools, MCP servers, data access, autonomy level and approval boundaries, with an autonomy risk index.

Threats → controls, with provenance

Threats are mapped to MITRE ATLAS, OWASP LLM Top 10 and Agentic, and a technical-control catalogue. Every control and framework reference is looked up, never invented.

Attack paths & residual risk

End-to-end attack paths from untrusted entry points to high-value assets for red-team planning, plus control gaps and residual-risk reasoning.

Cloud-agnostic core

The engine reasons over logical component types, not vendors. Model the same system on AWS, Azure or Google Cloud — the provider only changes the icon.

Light-touch or full assessment

A light-touch pass for early architecture, and a full assessment that feeds red-team planning, an assessment dashboard and an exportable report.

Design-time and build-time

Two views of the same estate

Aether — design time

Threat-model an architecture as you design it: diagram, agentic assessment, threats, controls and attack paths — before a line of agent configuration ships.

Provenant — build time

Red-team the MCP servers, tools and agent configurations you actually run, enforce policy before release, and sign evidence of exactly what was checked.

Pricing

Aether is free. Provenant is in early access.

The full Aether tool is free with no account. The Provenant enterprise platform — accounts, findings, remediation and reporting — is in development; request early access.

Most popular

Aether · Free

The full tool, no account.

$0
  • Architecture & DFD
  • Agentic assessment
  • Threats → controls & attack paths
  • Framework crosswalk (provenance)
  • Report & JSON export
  • AWS · Azure · GCP examples
Try Aether free

Provenant · Platform

The enterprise platform — in development.

Early access
  • Corporate accounts, SSO & RBAC
  • Findings lifecycle & dispositions
  • Remediation → Jira / ServiceNow
  • Evidence, audit & compliance
  • Executive reporting
  • Threat & control intelligence
Request early access

Enterprise

Governance at scale.

Custom
  • Self-host or private cloud
  • SCIM provisioning
  • API & CI/CD integration
  • Custom control frameworks
  • Audit & attestation support
Contact sales

See your agentic system's threats in minutes.

Load an AWS, Azure or GCP example, or import your own architecture. Aether generates the diagram, the threats, the controls and the attack paths.