Local-first · nothing leaves your machine

The architecture
workbench

Generate a STRIDE threat model from the C4 diagram you already drew. Design agent systems in a notation built for it. 109 templates covering PlantUML, D3, ArchiMate and AWS, all rendering offline on your machine.

Gnomon
An agent system designed in Gnomon. The analysis panel shows two of eleven exit types never modelled, 86% determinism, and a requirement that is only instructed, not enforced.

Three things nobody else combines

A diagram editor draws what you tell it. This reads what you drew.

Threat models from your C4

Trust boundaries and data flows are exactly what STRIDE needs, and you already drew them. Get a threat register out of the architecture instead of a blank page and a workshop.

A notation for agent systems

There is no C4 for agentic systems. This is one: thirteen element kinds, eleven ways a run can end, and analyses that show which exits you never modelled and which requirements nothing actually enforces.

Nothing leaves the machine

Rendering, indexing and analysis all run locally. No account, no upload, no telemetry by default. For most architecture that is the only way it is allowed to be looked at.

And a serious editor underneath

Table stakes, done properly. Browse all 109 templates →

109 templates

C4, UML, ArchiMate, AWS, Azure, integration patterns, threat models, agentic architecture plus ADRs, RFCs and post-mortems in Markdown.

Renders offline, instantly

PlantUML runs in-process rather than shelling out to Java, so preview keeps up with typing. No server round trip, no JRE to install.

D3 for what PlantUML can’t draw

Sankey flows, treemaps, force graphs, calendar heatmaps: thirty of them, as real D3 you can edit, sandboxed so a diagram can never reach your machine.

Try it on a system you already have

Point it at an architecture you have drawn before and see what it says about it. Thirty days free, with no card, no account and nothing uploaded.