The automotive CSMS — ISO/SAE 21434 · UN R155 · GB 44495 · EU CRA
A new CVE just dropped.Impact traced before the meeting starts.
TARA, SBOM, attack paths, incidents and compliance work products live in one knowledge graph — affected components, projects and vehicles traced in minutes, with audit-ready evidence attached.
ThreatZ is built on a native Neo4j knowledge graph — not tables stitched together with reports. Every asset, threat scenario, risk, control, SBOM component, test result and incident is a node with typed relationships.
CVE → component → software unit → ECU → project → vehicle program, in one query
Every risk keeps its chain: threat scenario → risk → goal → requirement → control → claim → test
Baselines freeze the graph per phase gate — evidence is reproducible at audit time
Time from CVE publication to fleet-level impact answer: under 4 hours — with the evidence chain attached.
Complete platform
Every module, mapped to your lifecycle.
The same rail your engineers see in the product — grouped by Design, Engineering and Operations phases.
Design4 modules
System Modeling
Vehicle architecture canvas — EA XMI & MATLAB System Composer import
Software Composition
Architecture × SBOM per software unit
Threat Modeling
STRIDE TARA with AI-assisted threat scenarios
Attack Tree
Aggregated attack paths, feasibility per step
Engineering4 modules
Risk Traceability
ISO/SAE 21434 risk values with full evidence chains
Security Assurance
Risk → goal → requirement → control → claim
Validation & TestingBETA
Verification evidence linked to claims
Attack SimulationBETA
Lab campaigns from attack paths + protocol fuzzing
Operations4 modules
Supplier & Vuln Monitoring
CVE watch across the SBOM, supplier shares
Incident ManagementBETA
Project incidents; program-level incident command
Compliance Reporting
UN R155 / ISO/SAE 21434 / GB 44495 work products on demand
DocumentsBETA
Project docs & knowledge base on the graph
Validation & Testing · TestBench Agent
From attack path to lab campaign — automatically.
Generate penetration campaigns straight from your attack-path analysis, run protocol fuzzing on the bench, and feed results back as verification evidence on the same graph.