Security
TTModeler Pro is designed to support the secure creation, storage, and management of threat models and related data. To help protect sensitive information, users should follow the security recommendations outlined below.
This page covers the following topics:
- Reporting Security Issues
- Technical Support and Security Updates
- Intended Use, Intended Operational Environment, and Foreseeable Circumstances
- Verifying Download Integrity and Authenticity
- Updates
- Impact of Product Changes on Data Security
- Handling Project and Configuration Files
- Secure Use of TTModeler Pro
Reporting Security Issues
If you discover a potential security vulnerability, security weakness, or other security-related issue in TTModeler, please report it through the official security contact page:
See also: security.txt
Technical Support and Security Updates
Technical support is available via email and phone using the Contact Information provided by emgarde. Security-related reports, vulnerability disclosures, and support requests are handled without unnecessary delay.
Confirmed security vulnerabilities are investigated and, where applicable, corrective actions and security updates are provided as soon as reasonably possible.
Security Updates, bug fixes, and feature releases are provided for TTModeler Pro throughout the duration of an active subscription.
Intended Use, Intended Operational Environment, and Foreseeable Circumstances
Intended Purpose
TTModeler Pro is a professional software tool for performing threat analysis and risk assessments of systems and products. It supports security engineering activities throughout the development lifecycle and may be used for a wide range of domains, including embedded systems, IoT devices, automotive components, industrial systems, desktop applications, cloud services, and other software-intensive systems.
TTModeler Pro is not an active security protection product and does not monitor, detect, prevent, or respond to cyberattacks within operational systems. Instead, it supports the identification, assessment, and documentation of cybersecurity risks during design, development, and assessment activities.
Essential Functionalities
The essential functions of TTModeler Pro include:
- System description and documentation.
- Asset identification.
- System and architecture modeling.
- Threat identification and automated threat generation.
- Risk assessment and risk evaluation.
- Definition and management of mitigations and security requirements.
- Automated generation of mitigation recommendations.
- Report generation and documentation export.
Security Properties
TTModeler Pro provides the following security-relevant properties:
- Verification of software authenticity through digitally signed installation packages (see below).
- Provision of software updates, including security-related fixes, through the standard update process (see below).
- Optional password-based encryption of project files to protect stored project information against unauthorized access (see below).
Intended Security Environment
TTModeler Pro is intended to be used by trained and instructed personnel in professional environments. Users are expected to possess appropriate knowledge of system development, threat modeling, cybersecurity, or risk assessment methodologies.
The software is intended to operate on supported and up-to-date Microsoft Windows and Linux operating systems that are maintained according to the operating system vendor's recommendations.
Organizations using TTModeler Pro are expected to:
- Protect workstations and operating systems using appropriate security measures.
- Store project and configuration files securely.
- Apply suitable information protection and access control measures.
- Use secure communication channels when exchanging project data.
- Protect backups according to the sensitivity of the stored information.
TTModeler Pro may optionally connect to external systems such as GitLab, GitHub, or Azure DevOps for project integration and workflow support. When such integrations are used, users are responsible for securely generating, storing, and managing access tokens and credentials.
The security, availability, configuration, and maintenance of connected third-party systems are outside the scope of TTModeler Pro and remain the responsibility of the respective system operators. Users should ensure that connected systems are maintained and updated according to the recommendations of their respective providers.
Foreseeable Circumstances Leading to Cybersecurity Risks
The following circumstances may result in increased cybersecurity risks when using TTModeler Pro:
Use of Untrusted Project Files
Opening project or configuration files received from untrusted or unverified sources may expose users to maliciously crafted content or inaccurate security information. Users should only open files obtained from trusted sources and through authorized communication channels. For further information, see below.
Insufficient Protection of Project Data
TTModeler Pro projects may contain sensitive information, including system architectures, assets, threats, vulnerabilities, mitigation measures, and risk assessments. Unauthorized access to project files may result in information disclosure or intellectual property loss. Users should classify project information appropriately and apply suitable protection measures for storage, backup, transmission, and access control. For further information, see below.
Failure to Install Updates
Failure to install updated versions of TTModeler Pro may leave known vulnerabilities unaddressed. Users should install new releases without undue delay to ensure that security improvements and vulnerability remediations are applied. For further information, see below.
Insecure Credential Management
When TTModeler Pro is connected to external systems such as GitLab, GitHub, or Azure DevOps, users are responsible for the secure creation, storage, and management of access tokens, credentials, and permissions. Compromised credentials may allow unauthorized access to connected third-party systems.
Use on Inadequately Secured Systems
TTModeler Pro relies on the security of the underlying operating system and computing environment. The use of unsupported, outdated, or inadequately protected operating systems may increase the risk of unauthorized access to project data. Users should operate TTModeler Pro on supported and up-to-date systems that are protected in accordance with organizational security policies.
Loss of Encryption Passwords
Where password-based project encryption is used, loss of the associated password may result in permanent loss of access to encrypted project data. Users are responsible for securely managing and retaining encryption passwords. The use of a password manager is recommended.
Verifying Download Integrity and Authenticity
TTModeler installation packages can be downloaded as described in the Getting Started.
To help ensure that downloaded files have not been modified or corrupted, each release is accompanied by a SHA-256 checksum. In addition, distributed binaries are digitally signed to provide authenticity verification.
Verify the SHA-256 Checksum
After downloading a TTModeler installation package, verify that its SHA-256 checksum matches the value published for the release.
Windows
Open PowerShell and execute:
Get-FileHash TTModeler-Pro_1.15.1-Setup.exe -Algorithm SHA256
Example output:
Algorithm : SHA256
Hash : A9B8...
Path : C:\Downloads\TTModeler-Pro_1.15.1-Setup.exe
Compare the displayed hash with the SHA-256 checksum provided on the download page. The values must match exactly.
Linux
Open a terminal and execute:
sha256sum ttmodeler-pro_1.15.1_amd64.deb
Example output:
2545... ttmodeler-pro_1.15.1_amd64.deb
Compare the calculated hash with the published SHA-256 checksum. The values must be identical.
Verify Digital Signatures
Digital signatures help confirm that the file was created by the TTModeler publisher and has not been tampered with after signing.
Windows Code Signing
Windows installation packages and executables are digitally signed using a code-signing certificate.
To verify the signature:
- Right-click the downloaded executable.
- Select Properties.
- Open the Digital Signatures tab.
- Select the signature and choose Details.
- Verify that Windows reports the signature as valid.
Alternatively, the signature can be verified using PowerShell:
Get-AuthenticodeSignature .\TTModeler-Pro_1.15.1-Setup.exe
A valid signature should report a status of Valid.
Linux Package Signatures
TTModeler Debian packages (.deb) are digitally signed.
The package signature can be verified using standard Debian package verification tools and the publisher's Public Key.
Smart App Control and Reputation-Based Warnings
Although TTModeler Pro executables are digitally signed, Microsoft Windows reputation-based protection mechanisms, such as Smart App Control or Microsoft Defender SmartScreen, may still display warnings.
This can occur for newly released versions or software with relatively low download volumes, where insufficient reputation data has been accumulated.
If such a warning appears:
- Verify the SHA-256 checksum.
- Verify that the digital signature is valid.
- Confirm that the installer was downloaded from the official TTModeler distribution source.
A reputation-based warning does not necessarily indicate that the software is malicious. However, users should always verify the authenticity and integrity of downloaded files before proceeding with installation.
Updates
TTModeler Pro is regularly updated to provide bug fixes, security improvements, compatibility enhancements, and new features.
Update Availability
TTModeler Pro includes an update mechanism that checks whether a newer version is available. By default, automatic update checks are enabled on all supported platforms. Users may disable these checks if required.
The update settings can be accessed via:
Help > Updates > Check for Updates
Automatic Updates
The following distribution methods support automatic installation of updates (see also Getting Started):
- Windows Installer (Setup Version)
- Linux Debian Repository Packages (.deb)
Update Notifications
The following distribution methods do not install updates automatically:
- Windows Standalone Version
- Linux AppImage
For these versions, TTModeler Pro notifies the user when a newer version is available. Users must download and install the updated version manually.
Security Updates
TTModeler Pro does not distinguish between security updates, bug-fix releases, maintenance releases, or feature releases. All updates are distributed through the standard release process.
Security patches are therefore not provided separately from regular software updates.
Users are encouraged to install new releases without undue delay to benefit from security improvements, vulnerability remediations, bug fixes, and product enhancements.
Security Fix Information
The product changelog documents significant changes included in each release. Where applicable, the changelog identifies resolved security vulnerabilities and security-related improvements.
Users should review the changelog when updating TTModeler Pro to understand any security-relevant changes included in a release.
Impact of Product Changes on Data Security
Changes to TTModeler Pro, including software updates, patches, and new releases, may affect the security of project data. Updates may introduce security improvements, remediate vulnerabilities, strengthen cryptographic algorithms, or address newly identified security risks.
Users are encouraged to install security updates and new releases without undue delay to ensure that project data continues to benefit from the latest available security measures.
Failure to apply security updates may expose users to vulnerabilities that have been corrected in newer versions of TTModeler Pro.
Handling Project and Configuration Files
Project and configuration files may contain sensitive information about systems, architectures, security controls, assets, threats, or other confidential data.
Open Files Only from Trusted Sources
Only open project or configuration files received from trusted and verified sources.
Before opening a file:
- Verify the sender's identity.
- Confirm the file was received through an authorized communication channel.
- Exercise caution when handling files received via email, messaging platforms, or external storage devices.
Opening files from untrusted sources may expose your organization to security risks or unreliable data.
Classify Information Appropriately
Organizations should define an information classification scheme and assign an appropriate classification level to TTModeler projects and configuration files.
Examples of classification levels may include:
- Public
- Internal
- Confidential
The selected classification should determine the required protection measures for storage, access, transmission, and backup procedures.
Secure Storage and Transmission
Project and configuration files should be protected according to their information classification.
Recommended practices include:
- Store files only in approved and access-controlled locations.
- Limit access to authorized personnel.
- Use secure communication channels when transferring files.
- Protect backups using the same security controls as the original files.
- Follow organizational policies and regulatory requirements regarding data retention and protection.
Encrypt Sensitive Projects
For additional protection, TTModeler Pro supports password-based Encryption of Project Files.
When handling confidential or restricted information:
- Enable file encryption whenever appropriate.
- Use strong and unique passwords.
- Share passwords through a separate, secure communication channel.
- Manage passwords according to your organization's security policies.
Encryption helps protect project data from unauthorized access if files are accidentally disclosed, lost, or intercepted during transmission.
Secure Installation, Operation and Decommissioning of TTModeler Pro
The following recommendations help ensure the secure installation, operation, and removal of TTModeler Pro within your organization.
Installation
When installing TTModeler Pro:
- Download installation packages only from official TTModeler distribution sources.
- Verify the SHA-256 checksum of downloaded files before installation.
- Verify the digital signature of executables and installation packages.
- Review and follow your organization's software installation and approval procedures.
- Be aware that Microsoft Smart App Control or SmartScreen may display warnings for newly released versions or software with limited reputation data, even when the installer is correctly signed.
Operation
When using TTModeler Pro:
- Keep TTModeler Pro updated to the latest available version.
- Open project and configuration files only from trusted and verified sources.
- Classify project data according to your organization's information classification policy.
- Store and transmit project and configuration files using appropriate security controls.
- Use file encryption for projects containing sensitive or restricted information.
- Apply your organization's security, access-control, and data-protection policies.
- Regularly review user permissions and access rights.
- Report suspected security incidents, vulnerabilities, or misuse promptly.
Decommissioning
When TTModeler Pro is no longer required:
- Reset the software to default via Account > Reset TTModeler to Default.
- Remove the software in accordance with your organization's asset and software management processes.
- Review and remove unnecessary user access rights.
- Archive or securely dispose of project and configuration files according to their information classification and retention requirements.
- Ensure that backups containing TTModeler Pro data are managed in accordance with organizational policies.
- Securely delete sensitive information that is no longer required.
By following these recommendations, organizations can reduce the risk of unauthorized access, data leakage, and accidental disclosure of sensitive information throughout the entire lifecycle of TTModeler Pro.