According to a recent LinkedIn post from depthfirst, the company is highlighting a new feature called Threat Model, described as a set of living security artifacts tailored to each code repository. The post suggests this capability maps architecture, trust boundaries, attacker-controlled inputs, and assumptions so vulnerability discovery more closely reflects how an application actually operates.
The post contrasts Threat Model with traditional security tools that typically treat each finding in isolation, requiring teams to reconstruct reachability, attacker control, and impact on every scan. By maintaining durable security context per repository and allowing teams to review and update assumptions as the codebase evolves, depthfirst appears to be positioning Threat Model as a way to streamline and enrich future security scans.
As shared in the post, findings can be evaluated against the application’s real architecture and security model, implying potential efficiency gains for security teams and more accurate risk prioritization. For investors, this suggests depthfirst is investing in differentiated, context-aware security tooling that could improve customer stickiness, expand usage within existing accounts, and strengthen the company’s competitive stance in application security.
The post further notes that Threat Model is currently available in Private Preview for depthfirst customers, indicating the feature is in an early but usable stage. If the preview phase leads to successful adoption and validates the promised workflow improvements, this offering could support future product monetization, deepen enterprise relationships, and enhance perceived value in a crowded DevSecOps market.

