/notations/security

Security and data flow in Arq

Draw trust boundaries as containers and data flows with their classification. Arq finds every flow that crosses a boundary, flags the ones no control protects, suggests STRIDE threats per crossing and writes the threat report.

/01 Fidelity

L1 Allowed relationships, containment and validation are enforced.

Arq declares a level only when its test fixtures prove it, and raises it the same way.

/02 What you can model

business
Business Actor
data
Data Store
application
Application Component, API
technology
Trust Boundary, Node
security
Asset, Threat, Threat Actor, Control, Vulnerability, Risk

Preferred relationships: flows to, contains, protects, mitigates, exposes, hosted on, accesses, uses.

/03 Interchange

Threat reportMarkdown, per model
SVG and PNGExport per view

Every notation draws the same model: an element on this Security / data flow view can appear on views in other notations too. More in the documentation.