The automotive CSMS — ISO/SAE 21434 · UN R155 · GB 44495 · EU CRA

A new CVE just dropped. Impact traced before the meeting starts.

TARA, SBOM, attack paths, incidents and compliance work products live in one knowledge graph — affected components, projects and vehicles traced in minutes, with audit-ready evidence attached.

app.threatz.io/project-overview
ThreatZ
Programs/ EV Platform Gen-4/ Telematics Control Unit
Search… ⌘K
LK
Telematics Control Unit
Development
Overview
Project Overview
Design
System Modeling
Software Composition
Threat Modeling
Attack Tree
Engineering
Risk Traceability
Security Assurance
Validation & Testing BETA
Attack Simulation BETA
Operations
Supplier & Vuln Monitoring
Incident Management BETA
Compliance Reporting
Documents BETA
Project Overview

ISO/SAE 21434 readiness · Baseline B-2.4 (Frozen) · Last activity 12 min ago

Compliance readiness 87% ISO/SAE 21434 · 142/163 work products
Open risks 23 3 critical — treatment overdue
TARA coverage 64/71 threat scenarios assessed
SBOM components 1,284 17 with open CVEs
Open risks by level Risk Traceability →
3 Critical8 High9 Medium3 Low
Module progress
System Modeling
100%
Threat Modeling (TARA)
90%
Risk Treatment
74%
Security Assurance
61%
Validation & Testing
38%
Recent activity
CVE-2026-31842 matched wpa_supplicant 2.10 — impact analysis queued 12 min ago · Vulnerability Monitoring
Risk R-014 treatment claim CLM-07 verified by test TC-231 1 h ago · Security Assurance
Baseline B-2.4 frozen for Design phase gate review 3 h ago · Baselines
Threat scenario TS-058 (Tampering, CAN gateway) awaiting review 5 h ago · Threat Modeling
CycloneDX SBOM re-import: 1,284 components, 12 new Yesterday · Software Composition
Attack path AP-09 mitigated — feasibility recalculated Yesterday · Attack Tree
ISO/SAE 21434 (clauses 5–15) UN R155-aligned monitoring GB 44495-2024 EU CRA — SBOM + VEX TISAX AL3 assessed Private cloud / on-prem / air-gap

Two seats at the same table

Built for both sides of the supply chain.

For OEMs

Assemble type-approval evidence across every supplier program.

Program-level vehicle architecture spanning projects, with freeze/release baseline gates
Fleet monitoring and incident command — from vehicle SOC event to affected component in one trace
R155 audit evidence generated from real engineering work, not written after the fact
The OEM workflow →
For Tier-1 suppliers

Answer OEM cybersecurity requirements per component — and prove it.

Per-component TARA, SBOM and validation evidence mapped to OEM CS requirements
Supplier workspace: share evidence upstream without handing over your whole project
One assessment, five standards — reuse work products across customer programs
The Tier-1 workflow →

The graph argument

One graph. Every attack surface. Live.

ThreatZ is built on a native Neo4j knowledge graph — not tables stitched together with reports. Every asset, threat scenario, risk, control, SBOM component, test result and incident is a node with typed relationships.

CVE → component → software unit → ECU → project → vehicle program, in one query
Every risk keeps its chain: threat scenario → risk → goal → requirement → control → claim → test
Baselines freeze the graph per phase gate — evidence is reproducible at audit time
CVE impact trace — example
CVE CVE-2026-31842 · wpa_supplicant 2.10
SBOM component wpa_supplicant (BusyBox rootfs)
Software unit Connectivity Stack v3.2
ECU Telematics Control Unit
Vehicle program EV Platform Gen-4 · 3 projects affected
Time from CVE publication to fleet-level impact answer: under 4 hours — with the evidence chain attached.

Complete platform

Every module, mapped to your lifecycle.

The same rail your engineers see in the product — grouped by Design, Engineering and Operations phases.

Design 4 modules
System Modeling
Vehicle architecture canvas — EA XMI & MATLAB System Composer import
Software Composition
Architecture × SBOM per software unit
Threat Modeling
STRIDE TARA with AI-assisted threat scenarios
Attack Tree
Aggregated attack paths, feasibility per step
Engineering 4 modules
Risk Traceability
ISO/SAE 21434 risk values with full evidence chains
Security Assurance
Risk → goal → requirement → control → claim
Validation & Testing BETA
Verification evidence linked to claims
Attack Simulation BETA
Lab campaigns from attack paths + protocol fuzzing
Operations 4 modules
Supplier & Vuln Monitoring
CVE watch across the SBOM, supplier shares
Incident Management BETA
Project incidents; program-level incident command
Compliance Reporting
UN R155 / ISO/SAE 21434 / GB 44495 work products on demand
Documents BETA
Project docs & knowledge base on the graph

Validation & Testing · TestBench Agent

From attack path to lab campaign — automatically.

Generate penetration campaigns straight from your attack-path analysis, run protocol fuzzing on the bench, and feed results back as verification evidence on the same graph.

See the protocol coverage matrix →
CAN / CAN-FD UDS SOME/IP DoIP Automotive Ethernet LIN FlexRay MQTT BLE Wi-Fi +30 more
40+ protocol packs · Vector CANoe integration · UDS & CAN-classic fuzzing

Pricing

Plans that scale with your programs.

Team For a single project team getting TARA and SBOM under control.
TARA & threat modeling
System modeling canvas
SBOM import & CVE matching
Compliance work products
Start free trial
Most popular Professional For departments running multiple projects with shared evidence.
Everything in Team
Security assurance chains
Supplier & vulnerability monitoring
Risk traceability & baselines
RBAC & SSO
Book a demo
Enterprise For OEM programs: fleet, incident command and supplier network.
Everything in Professional
Program layer & vehicle architecture
Fleet map & incident command
Supplier workspace & sharing
On-prem / air-gap deployment
Talk to sales

All plans deploy to private cloud or on-premise — air-gapped supported. Add-ons: TestBench Agent, PRC-region deployment for GB 44495-2024.

What ThreatZ is not

Not a scan-and-forget vulnerability scanner — it manages the engineering work around findings.
Not a document generator that writes your CSMS for you — it turns real work into evidence.
Not a replacement for your pentest lab — it feeds it campaigns and consumes its results.
Not a magic AI auditor — AI assists TARA and impact analysis; engineers stay in control.

We'd rather you know exactly what you're buying. Ask us the hard questions in a demo.

Compliance · Engineering · Deployment

ISO/SAE 21434 UN R155 GB 44495-2024 * EU CRA Annex I TISAX AL3 On-prem & air-gap

GB 44495-2024 compliance support is available via PRC-region deployment.

See your own architecture
in the graph.

Demos are role-specific — tell us whether you're an OEM or a Tier-1 supplier and we'll show the workflows that match your job.