Theme
Compare Plans
Built for ISO/SAE 21434

ThreatZ Automotive Cybersecurity
Platform for
ISO/SAE 21434, R155 & GB 44495

ThreatZ is the comprehensive CSMS (Cybersecurity Management System) for automotive manufacturers and Tier-1 suppliers. Automate TARA, manage SBOMs, track vulnerabilities, and unify compliance operations in one platform.

Compare Plans
500+ Registered Users
Built for ISO/SAE 21434
TISAX AL3 Assessed
EU CRA Compliant
EN, DE, ZH — 3 Languages
Uraeus.ThreatZ Dashboard
Real-time Security Overview
98%
Compliance Score
24
Active Monitors
Threat Models 7
Risk Assessments 12
Compliance Checks 156
Built for engineers, not just auditors

Six daily-user roles. One platform. One traversable graph.

Cybersecurity engineers, pentest leads, SBOM managers, vehicle SOC analysts, security architects, and Tier-1 program managers all work in the same knowledge graph — compliance evidence is what comes out the other end.

See the six workflows →

Built for the automotive cybersecurity community

Used by automotive OEMs, Tier-1 ECU suppliers, and mobility platforms across Europe, China, and APAC.

OEMs — vehicle programs Tier-1 ECU & software suppliers Charging & mobility platforms 500+ registered users
85%
Faster TARA Completion
500+
Cybersecurity Professionals
30+
Tool Integrations
5
Compliance Standards

Compliance · Engineering · Deployment

ISO/SAE 21434 (clauses 5–15) UN R155-aligned monitoring GB 44495* EU CRA Annex I — SBOM + VEX disclosures Native Neo4j knowledge graph Vector CANoe + Tier-A protocol packs EA XMI + MATLAB System Composer ingest Private cloud or on-premise — air-gap supported

* GB 44495 compliance support is available via PRC-region deployment.

Complete Platform

Fifteen Integrated
Security Modules

End-to-end automotive cybersecurity management — from program-level vehicle architecture and TARA to SBOM supply chain, network communication analysis, baselines, and compliance reporting.

TARA Threat Modeling

Visual STRIDE analysis with automated risk scoring

TARA Guide →
Risk Assessment
Visual Diagrams
Auto Scoring

Risk Assessment

Real-time TARA calculations and mitigation tracking

Automating TARA →
TARA Analysis
Real-time Updates
Mitigation Plans

Requirements Management

ISO/SAE 21434 compliance with full traceability

ISO/SAE 21434
Traceability
Audit Trails

Architecture Analysis

Interactive system diagrams with security layers

System Maps
Security Layers
Dependencies

Vulnerability Management

Automated CVE scanning and prioritization

Vulnerability Lifecycle →
CVE Tracking
Auto Scanning
Prioritization

Incident Response

Streamlined security operations workflow

Response Playbooks →
Response Plans
Team Coordination
Escalation

Compliance Reporting

Automated audit documentation generation

CSMS Audit Prep →
Auto Reports
Regulatory
Documentation

System Modeling

Define vehicle architecture, assets and trust boundaries

Component Trees
Interface Mapping
Trust Boundaries

Risk Treatment

Define cybersecurity controls with full traceability

Security Controls
Requirement Linking
Residual Risk

SBOM & Supply Chain

Software bill of materials with dependency analysis

SBOM Import
Weakness Tree
License Compliance

Validation & Testing

Security test campaigns with the Test Bench Agent

Test Campaigns
AI Test Agent
Evidence Collection

AI Assistant

AI-powered intelligence across every workflow

Smart Suggestions
Auto Classification
Context-Aware

Programs & Vehicle Architecture

Top-level program management with 3D vehicle architecture canvas

ECU Hierarchy
Security Blueprints
Platform Reuse

Baselines & Release Management

Point-in-time release snapshots with auto-versioning and comparison

Release Snapshots
Baseline Comparison
Freeze / Unfreeze

Network Communication Matrix

Signal-level security for CAN, LIN, FlexRay & Ethernet networks

Network communication matrix
COVESA VSS v6.0 signal taxonomy with requirement traceability
STRIDE Auto-Threats

Ready to secure your vehicle lifecycle?

See how these modules work together to provide comprehensive cybersecurity management. Get personalized recommendations for your specific use case.

Complete platform demo walkthrough
Personalized security assessment
ISO/SAE 21434 compliance roadmap
Custom implementation timeline

Get Platform Demo

Schedule a personalized walkthrough of all security modules

Compare Plans
✓ No credit card required ✓ 14-day free trial ✓ Expert support included
Eight Integrated Pillars

Built for Modern
Automotive Security

A complete CSMS — not a point tool. From governance and system design through post-production operations and compliance evidence, ThreatZ covers the full ISO/SAE 21434 lifecycle with eight integrated pillars.

Built for ISO/SAE 21434 Always-Current Threat Intelligence Enterprise-Grade Security Multi-Language (EN / DE / 中文)
Who is ThreatZ for?

Six daily-user roles — one knowledge graph

Engineers and operations teams who actually live in the platform every day. Compliance officers see the receipt at the bottom.

Cybersecurity Engineer

Your TARA. Living, not locked.

“Architecture changed last week. The TARA still reflects Q1.”

Attack paths, feasibility scores, and compliance gaps re-evaluate the moment the model changes — no catch-up sprint.

Pentest / V&V Lead

Model-to-bus, one platform.

“The threat model arrives as a PDF, then we start from scratch on the bench.”

TARA attack paths feed your campaign structure. Findings return as first-class graph records, not a spreadsheet emailed back.

SBOM / Vulnerability Manager

Know the blast radius before they ask.

“A CVE lands. We have a SBOM file. We don’t have an answer yet.”

The graph walks from component to every affected ECU and requirement in one traversal. CVE response drops from days to hours.

Vehicle SOC / PSIRT Manager

Field incidents back to the TARA.

“Something happens in the field. The risk treatment document is in SharePoint.”

Incidents link to risks, SBOM components, and security goals in the graph. R155-aligned monitoring — without a separate tool.

Security Architect

One graph across programs.

“Program two starts with a blank TARA because program one lives in Word.”

Security Catalog carries validated controls, goals, requirements, and threats across programs. Program two starts at reuse, not zero.

Tier-1 Multi-OEM Program Manager

One TARA. Four OEM programs.

“Every OEM customer wants the same work in a different format, portal, and cadence.”

One project graph, scoped per OEM, with a supplier portal that isolates each OEM relationship. The engineering is done once; the evidence adapts.

Engineering Surface

Beyond the eight pillars — the depth underneath

The capabilities that make the daily engineering work fast: model ingest, baseline tracking, reuse, attack simulation, code-finding routing, and AI assistance grounded in your own knowledge.

Bring your existing models

Imports EA XMI (architecture) and MATLAB System Composer .slx (function & behavior). Tool dialect auto-detected; nothing silently dropped; staged review on production projects.

Baselines & part-number per VIN

Project baselines aren’t just snapshots: they reconcile supplier ECU part numbers down to the VIN that received them. P1–P4 violation alerts when a new finding affects a deployed release.

Reuse across programs Beta

Security Catalog (org-level controls, threats, damage scenarios), Blueprints (publish a project as a template), and variant management. Program two starts at reuse, not zero.

Diagnostic & legacy imports Beta

ODX / PDX / CDD diagnostic descriptions: DIDs become security assets with SecurityAccess, RoutineControl, Session evidence. Legacy TARA spreadsheet import; OpenXSAM export.

Attack Simulation Beta

Auto-generate penetration campaign proposals from your TARA attack paths. Proposal → draft campaign workflow with 4-eyes V&T handoff. Protocol-fuzzing drafts derived from attack-path step templates.

SW Composition × SBOM

UML/AUTOSAR software composition co-displayed with the SBOM graph. Confidence-rated auto-matching links modules to SBOM components. Blast radius from a module through reachable CVEs.

SAST / SCA / Binary findings

Any SARIF 2.1.0-compatible tool can feed findings into the graph. Findings deduplicate against existing risks; new findings auto-draft as linked Threats in the affected project. Roll-ups feed ISO 21434 §13 test evidence.

TARA-to-HIL verification bridge

Coverage-guided fuzzer across the supported protocol matrix. Runs on Vector, PEAK, Kvaser, IXXAT, SocketCAN hardware. Configurable safety guardrails: high-criticality PDUs require manual promotion before any fuzz campaign targets them.

Beta indicates a capability is shipping today to opted-in tenants under the Beta support tier: full SLA applies, evidence outputs are eligible for compliance use, and the API contract is locked. Roadmap to GA is on the next quarterly release.

How It Works in Practice

Engineering Outcomes — Not Just Audit Outputs

< 4h

From CVE landing to scoped OTA campaign

A new CVE drops. The graph walks SBOM component → software unit → ECU → part number → affected VINs in one query. No spreadsheet sprint.

Mechanism: blast-radius graph traversal across the live knowledge graph.
~80%

Reuse on the second program

Org-level Security Catalog carries validated controls, requirements, threats and damage scenarios across every program. Program two starts at ~80% reuse, not zero.

Mechanism: shared catalog nodes referenced (not copied) per project in the graph.
8

Workflows on one knowledge graph

Design, governance, TARA, SBOM, security testing, operations, compliance and collaboration: one traversable data model. Architecture change re-evaluates everything downstream automatically.

Mechanism: native Neo4j graph backbone, per-tenant isolated.
Live Knowledge Graph

One graph. Every attack surface. Live.

Architecture entities, SBOM components, CVE feeds, and incident reports all land in the same Neo4j knowledge graph. Impact analysis is a traversal, not a Jira hunt.

Knowledge graph backbone

Continuous re-evaluation across the engineering plane

Change anything (an architecture entity, a SBOM component, a CVE feed) and the graph propagates the impact automatically.

  • CVE blast radius is a graph walk — no re-export, no snapshot lag.
  • Impacted ISO 21434 clauses re-evaluate when an architecture entity changes — with fix suggestions; continuous, not audit-time.
  • Multi-hop attack-path analysis, feasibility-scored across the 5 ISO 21434 factors; supplier boundaries stop traversal.
Graph traversal: SystemComponent → SoftwareUnit → SBOMComponent → CVE
FleetMap & per-VIN traceability

From CVE to affected VINs — one live query

Live world map of every vehicle, every risk, every CVE across markets. The same graph that holds your TARA also holds your fleet exposure.

  • FleetMap UI — live geographic visualization with KPIs, risk-band filtering, per-region layers (Vehicles / Risk / CVEs).
  • Per-VIN Traceability (Enterprise tier) — anchor on a finding, walk to every affected VIN, scope an OTA campaign by market.
  • No batch jobs, no spreadsheets — in seconds, not in batch jobs.
Fleet traversal: 6-hop walk in one live query
Product Demos

See ThreatZ
In Action

13 step-by-step walkthroughs covering every module, from TARA threat modeling to compliance reporting

ThreatZ platform walkthrough demo video 7:42

ThreatZ Walkthrough Demo

End-to-end platform tour covering all modules and core workflows

Platform Overview
Threat modeling with STRIDE in ThreatZ 5:18

Threat Modeling in ThreatZ

STRIDE-based threat analysis with attack path visualization

TARA
ISO/SAE 21434 risk assessment in ThreatZ 4:55

Risk Assessment in ThreatZ

ISO/SAE 21434 risk scoring with impact and feasibility analysis

TARA
SBOM management and vulnerability tracking 6:10

SBOM Management in ThreatZ

Import SBOMs, track vulnerabilities, and manage license compliance

Supply Chain
Compliance reporting for ISO/SAE 21434 and R155 4:30

Compliance Reporting in ThreatZ

Generate audit-ready reports for ISO/SAE 21434, R155 & GB 44495

Compliance
System modeling for automotive cybersecurity 5:45

System Modeling in ThreatZ

Define assets, interfaces and trust boundaries for your vehicle architecture

Foundation
Risk treatment and cybersecurity requirements 4:15

Risk Treatment in ThreatZ

Define cybersecurity requirements and controls with full traceability

TARA
Security validation and testing in ThreatZ 5:30

Validation and Testing in ThreatZ

Create and execute security test campaigns with the Test Bench Agent

V&T
Security operations module in ThreatZ 4:48

Operations Module in ThreatZ

Threat intelligence, incident response and security event monitoring

Operations
Security catalog with threats, risks and controls 3:52

Security Catalog of ThreatZ

Pre-defined threats, controls, security goals and cybersecurity claims

Foundation
Import legacy TARA projects from Excel 3:20

Import Legacy Project to ThreatZ

Migrate existing TARA projects from Excel or legacy tools

Migration
Policy management for automotive cybersecurity 3:40

Policy Management in ThreatZ

Define cybersecurity policies and organizational security governance

Governance
ThreatZ home page and dashboard overview 2:55

ThreatZ Home Page Overview

Dashboard navigation and key platform features at a glance

Platform Overview

Seen enough? Get hands-on with ThreatZ.

Transparent Pricing

Enterprise-Grade Platform.
Accessible Pricing.

The complete automotive cybersecurity platform. From your first TARA to full lifecycle operations.

Monthly
Annual Save 17%

Also available through your AWS account — consolidates on your existing AWS bill and counts toward EDP commit.

Available on AWS Marketplace

AWS Marketplace list price: Team $17,868/yr · Professional $31,680/yr (includes AWS billing fees)

Team

Get to a compliant TARA and audit-ready reporting fast.
$1,199 /month
Unlimited users · Billed annually ($14,388/yr)
Includes
  • Unlimited internal users
  • Up to 3 projects (+$99/mo each)
  • Full security catalog (threats, damage scenarios, controls, goals, requirements, claims)
  • System scoping + threat modeling
  • STRIDE threat identification
  • Risk assessment + heatmaps
  • Risk treatment planning
  • Attack path analysis
  • Risk relationship graph
  • Vehicle architecture canvas
  • Vehicle → SubSystem → ECU hierarchy
  • Compliance reporting (ISO/SAE 21434)
  • MATLAB System Composer import
  • RBAC (basic roles)
  • Team collaboration + report history
  • PDF + Excel exports
  • Email support (48h SLA)
  • Multi-language (EN, DE, ZH)
Enterprise
Full platform at OEM/Tier-1 scale with advanced controls.
Custom
Starting at $100K/year
Everything in Professional, plus
  • Unlimited programs + vehicle architecture
  • Unlimited users + projects
  • SSO / OIDC authentication
  • Advanced RBAC + governance controls
  • REST API access (rate-limited, scoped)
  • Email notifications (SendGrid / SMTP)
  • Custom integrations
  • Advanced reporting + audit trails
  • AI Power Pack included
  • VSOC integration (2 connectors included)
  • Ops data retention (6–36 months)
  • Multi-source threat intel ingestion
  • STIX / AUTOSAR export formats
  • Dedicated Customer Success Manager
  • SLA: 4h response, 99.9% uptime
  • On-premise deployment available
  • Custom rollout planning
  • Multi-language (EN, DE, ZH)

Add-ons

Available for Professional and Enterprise tiers

AI Power Pack

Free 1st year, then $29/user/mo

AI threat recommendations, risk scoring assistance, test case generation, and finding correlation. Gifted for the first year on all plans.

VSOC Connector

+$500/month

Bidirectional integration to external VSOC/SIEM systems. Webhooks, REST, MQTT. Enterprise includes 2 connectors.

Managed TARA Service

From $5,000/project

ThreatZ experts perform your TARA assessment using the platform. Full deliverable ready for audit.

Training & Onboarding

From $2,000

Live training sessions, workshop facilitation, custom template creation, and team onboarding.

Additional Projects

$99/project/month

Need more than your plan's included projects? Add extra project slots to any Team or Professional subscription.

On-Premise Deployment

Enterprise only

Air-gapped, self-hosted deployment. Multi-year terms. Pricing indicative — final terms in Order Form.

Custom Integration

$2,500/story point

Bespoke integration development consumed as story points. Connect ThreatZ to your proprietary toolchain, PLM, or internal systems.

Starter Package

$7,900 one-time

Full onboarding and migration service. We set up your workspace, configure vehicle architectures, and migrate existing projects so you can hit the ground running.

Compare Plans

Team Professional Enterprise
Platform
Multi-language support (EN, DE, ZH)
UsersUnlimited5–50Unlimited
Projects3 (+$99/mo)15Unlimited
RBACBasic rolesFull rolesAdvanced + governance
Two-Factor Auth (2FA)
SSO / OIDC
REST API Access
Email Notifications
Advanced Reporting
Foundation
Security Catalog Full Full Full
Policy Manager Unlimited Unlimited Unlimited
Compliance ReportingISO/SAE 21434Multi-frameworkCustom frameworks
PDF / Excel Exports
ReqIF Export
Programs & Vehicle Architecture
ProgramsUnlimited
3D Vehicle Architecture Canvas
Vehicle → SubSystem → ECU Hierarchy
Security Blueprints library
Baselines & Release Management
Release Snapshots + Auto-Versioning
Baseline Comparison
Project Freeze / Unfreeze
Metrics Tracking (12+ metrics)
Network Communication Matrix
Signal-Level Security (CAN/LIN/FlexRay/Ethernet)
DBC File Import + Parsing
COVESA VSS v6.0 Signal Mapping
STRIDE Auto-Threat Generation (Signals)
Multi-Standard Automotive Compliance (ISO/SAE 21434, R155, GB 44495, EU CRA)
SOME/IP & DDS Service Modeling
TARA
System Modeling
STRIDE Threat Modeling
Risk Assessment + Heatmaps
Risk Relationship Graph
Attack Path Analysis
Risk Treatment Planning
Weakness Tree (SBOM + TARA)
Report Export (PDF)
Report Sharing (LiveLink + Snapshot)
Integrations
MATLAB System Composer (Native)
SW Architecture Import (EA, Rhapsody, Cameo, SysML)
Jira Integration
GitHub / GitLab
Vector CANoe via Test Bench Agent (CAPL + Python)
VSOC / SIEM IntegrationAdd-on 2 included
Custom Integrations
SBOM / Supply Chain
SBOM Management
SARIF findings ingest (SCA / SAST / Binary)
Vulnerability Tracking
License Tracking
Validation & Testing (V&T) / Operations
Security Testing Campaigns
ThreatZ Test Bench Agent (Desktop App)
Threat Intelligence Multi-source
Incident Management At scale
Security Event Monitoring
Ops Data Retention90 days6–36 months
STIX / AUTOSAR Exports
AI
AI Power Pack Free 1st year Free 1st year Included
Support
Support ChannelEmail (48h)Email (24h)Dedicated CSM (4h)
OnboardingSelf-serveGuidedWhite-glove
Private Cloud (+10%)
On-Premise Option

Frequently Asked Questions

Can I switch plans later?
Yes. You can upgrade at any time and your billing will be prorated. Downgrading takes effect at the end of your current billing cycle.
What's the difference between Team and Professional?
Team gives you everything needed for TARA and ISO/SAE 21434 compliance with unlimited users at a flat monthly rate. Professional adds per-user pricing with SBOM/supply chain management, operations (testing, incidents, threat intel), additional integrations (Jira, GitHub, GitLab, architecture import), and multi-framework compliance.
Do you offer discounts for startups or academic institutions?
Yes. We offer 50% off Professional for companies under 50 employees, and free Professional access for accredited universities. Contact us for details.
What compliance frameworks are supported?
ISO/SAE 21434, UNECE R155, GB 44495, and EU CRA. Team includes ISO/SAE 21434 reporting; Professional and Enterprise support all four automotive cybersecurity frameworks. Enterprise customers can also create custom compliance frameworks. (Note: GDPR governs VxLabs as a data processor and is covered in our Privacy Policy — it is not a vehicle cybersecurity framework.)
Can I get a volume or multi-year discount?
Yes. We offer 5% off for 2-year commitments and 10% off for 3-year commitments. For large teams on Professional, contact us for volume pricing.
Is on-premise deployment available?
Deployment is private cloud or on-premise — air-gapped supported. On-premise is reserved for Enterprise customers with strict deployment, residency or air-gap requirements; pricing is indicative and final terms are set in the Order Form.
What does "Unlimited internal users" mean on Team?
Every member of your organization can access the platform at no additional per-user cost. Team is priced per-workspace, not per-user, so your entire cybersecurity team can collaborate from day one.
How does the free trial work?
Team and Professional plans come with a 14-day free trial. No credit card required. Full access to all tier features. Your data carries over when you subscribe.
What is ISO/SAE 21434?
ISO/SAE 21434 is the international standard for automotive cybersecurity engineering. It defines requirements for a Cybersecurity Management System (CSMS) covering the entire vehicle lifecycle — from concept and development through production, operation, and decommissioning. ThreatZ accelerates ISO/SAE 21434 work — built-in TARA workflows, risk assessment, and traceability — with engineers approving every scenario before it enters the risk register.
What is TARA in automotive cybersecurity?
TARA (Threat Analysis and Risk Assessment) is the core security analysis activity defined in ISO/SAE 21434. It involves identifying assets, analyzing threat scenarios, assessing attack feasibility, determining risk levels, and defining cybersecurity goals and risk treatment decisions. ThreatZ accelerates TARA with AI-assisted threat modeling using the STRIDE methodology — engineers approve every scenario before it enters the risk register.
What is a CSMS (Cybersecurity Management System)?
A CSMS (Cybersecurity Management System) is the organizational framework required by UNECE R155 and defined in ISO/SAE 21434 for managing automotive cybersecurity across the vehicle lifecycle. It encompasses policies, processes, and tools for threat analysis, risk management, incident response, and continuous monitoring. ThreatZ provides the complete CSMS platform for OEMs and Tier-1 suppliers.
How does ThreatZ automate TARA analysis?
ThreatZ uses AI to automatically identify assets from system models, generate threat scenarios using the STRIDE methodology, assess attack feasibility and impact, calculate risk levels per ISO/SAE 21434, and suggest cybersecurity goals and risk treatment options — with full traceability from assets to controls. What traditionally takes weeks of manual effort can be completed in hours.
What is the STRIDE methodology?
STRIDE stands for Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. It is the threat classification framework used in ThreatZ for systematic automotive threat modeling. Each STRIDE category maps to specific cybersecurity goals, enabling comprehensive threat coverage and structured risk assessment aligned with ISO/SAE 21434.
Product Overview

Download Our One Pager

Get a comprehensive overview of the ThreatZ platform in a single document.

Your AI. Your Models. Your Knowledge Base.

AI you can actually trust in procurement

Bring your own LLM endpoint. Ground the assistant in your org and project documents. Every recommendation requires human review — no AI writes to your compliance record without explicit approval.

BYO LLM endpoint

Point ThreatZ at your OpenAI, Azure OpenAI, or self-hosted model endpoint. SSRF-guarded; per-call audit events; per-tenant flag to ramp at your pace.

Org + project KB grounding

Upload your security standards, internal guides, and project documents. The assistant retrieves from your knowledge base, not generic web data — answers are grounded in your context.

Audit trail per AI call

Every prompt, retrieval, and recommendation logged with per-call HMAC integrity. Procurement-grade evidence for your AI governance — including responses that customers chose to ignore.

What ThreatZ is not

Disqualifying the wrong buyer up-front builds more trust than hiding it. If any of these are you, we’re not the right fit — yet.

Not a replacement for Enterprise Architect or MATLAB System Composer. ThreatZ ingests from them and keeps the security layer synchronized with your model of record — it doesn’t replace the modeling tools your systems engineers already use.

Not an SBOM scanner or generator. ThreatZ ingests CycloneDX and SPDX from your existing build pipeline, then matches against vulnerability feeds and your architecture — it doesn’t replace your SBOM-producing toolchain.

Not a web-app pentest tool. ThreatZ is built specifically for automotive ECU and in-vehicle network attack surfaces — CAN, UDS, DoIP, SecOC, SOME/IP, and the rest of the supported protocol matrix.

Looking for runtime vehicle monitoring and fleet protection? Explore SentraX Fleet XDR →
Join 500+ Registered Users

Secure Your Vehicle
Ecosystem Today

Cut TARA cycle time, close ISO/SAE 21434 evidence gaps, and connect your architecture, SBOM and testing in one live knowledge graph — without the manual hand-offs that slow every other CSMS workflow.

Built for ISO/SAE 21434
TISAX AL3 Assessed
Supports R155 / GB 44495
VxLabs GDPR-compliant (data processor)
EU CRA Compliant
Available in EN, DE & ZH

Everything you need to succeed:

Free 14-day trial with full platform access
Dedicated cybersecurity expert onboarding
ISO/SAE 21434 compliance templates included
Priority support and training sessions
Custom integration with your existing tools

Start your 14-day free trial today. No credit card required. Cancel anytime. Your data stays secure with enterprise-grade encryption.