Your TARA. Living, not locked.
“Architecture changed last week. The TARA still reflects Q1.”
Attack paths, feasibility scores, and compliance gaps re-evaluate the moment the model changes — no catch-up sprint.
ThreatZ is the comprehensive CSMS (Cybersecurity Management System) for automotive manufacturers and Tier-1 suppliers. Automate TARA, manage SBOMs, track vulnerabilities, and unify compliance operations in one platform.
Cybersecurity engineers, pentest leads, SBOM managers, vehicle SOC analysts, security architects, and Tier-1 program managers all work in the same knowledge graph — compliance evidence is what comes out the other end.
See the six workflows →Built for the automotive cybersecurity community
Used by automotive OEMs, Tier-1 ECU suppliers, and mobility platforms across Europe, China, and APAC.
Compliance · Engineering · Deployment
* GB 44495 compliance support is available via PRC-region deployment.
End-to-end automotive cybersecurity management — from program-level vehicle architecture and TARA to SBOM supply chain, network communication analysis, baselines, and compliance reporting.
ISO/SAE 21434 compliance with full traceability
Interactive system diagrams with security layers
Define vehicle architecture, assets and trust boundaries
Define cybersecurity controls with full traceability
Software bill of materials with dependency analysis
Security test campaigns with the Test Bench Agent
AI-powered intelligence across every workflow
Top-level program management with 3D vehicle architecture canvas
Point-in-time release snapshots with auto-versioning and comparison
Signal-level security for CAN, LIN, FlexRay & Ethernet networks
See how these modules work together to provide comprehensive cybersecurity management. Get personalized recommendations for your specific use case.
Schedule a personalized walkthrough of all security modules
A complete CSMS — not a point tool. From governance and system design through post-production operations and compliance evidence, ThreatZ covers the full ISO/SAE 21434 lifecycle with eight integrated pillars.
3D vehicle modeling, system architecture canvas, and ECU → SBOM → CVE traceability across in-vehicle bus, diagnostics, service IPC and security protocols.
Learn more →Versioned security catalogs, project blueprints, approval workflows, and security baselines with regression tracking.
Learn more →AI-assisted STRIDE threat modeling, attack path analysis, CAL 1–4 risk determination, with end-to-end traceability.
Learn more →CycloneDX / SPDX ingest, NVD & GHSA vulnerability feeds (additional feeds configurable), and SBOM-to-architecture mapping.
Learn more →Penetration, fuzz, robustness, and compliance campaigns linked to TARA. Coverage-guided fuzzer across CAN, CAN-FD, UDS, ISO-TP, DoIP, XCP, CCP, OBD, J1939, CANopen, SecOC and E2E. Runs on Vector, PEAK, Kvaser, IXXAT and SocketCAN hardware.
Learn more →Post-production event ingestion, P1–P4 anomaly detection, VSOC export (JSON/AUTOSAR/STIX), and incident lifecycle.
Learn more →Tracks and evidences ISO/SAE 21434 work products across UNECE R155 and GB 44495 — with compliance report export in ISO 21434 and ReqIF formats; SBOM & VEX disclosures support EU CRA Annex I.
Learn more →Real-time co-editing with presence indicators, two-tier RBAC, multi-tenant supplier portal, and open APIs with HMAC webhooks.
Learn more →Engineers and operations teams who actually live in the platform every day. Compliance officers see the receipt at the bottom.
“Architecture changed last week. The TARA still reflects Q1.”
Attack paths, feasibility scores, and compliance gaps re-evaluate the moment the model changes — no catch-up sprint.
“The threat model arrives as a PDF, then we start from scratch on the bench.”
TARA attack paths feed your campaign structure. Findings return as first-class graph records, not a spreadsheet emailed back.
“A CVE lands. We have a SBOM file. We don’t have an answer yet.”
The graph walks from component to every affected ECU and requirement in one traversal. CVE response drops from days to hours.
“Something happens in the field. The risk treatment document is in SharePoint.”
Incidents link to risks, SBOM components, and security goals in the graph. R155-aligned monitoring — without a separate tool.
“Program two starts with a blank TARA because program one lives in Word.”
Security Catalog carries validated controls, goals, requirements, and threats across programs. Program two starts at reuse, not zero.
“Every OEM customer wants the same work in a different format, portal, and cadence.”
One project graph, scoped per OEM, with a supplier portal that isolates each OEM relationship. The engineering is done once; the evidence adapts.
The capabilities that make the daily engineering work fast: model ingest, baseline tracking, reuse, attack simulation, code-finding routing, and AI assistance grounded in your own knowledge.
Imports EA XMI (architecture) and MATLAB System Composer .slx (function & behavior). Tool dialect auto-detected; nothing silently dropped; staged review on production projects.
Project baselines aren’t just snapshots: they reconcile supplier ECU part numbers down to the VIN that received them. P1–P4 violation alerts when a new finding affects a deployed release.
Security Catalog (org-level controls, threats, damage scenarios), Blueprints (publish a project as a template), and variant management. Program two starts at reuse, not zero.
ODX / PDX / CDD diagnostic descriptions: DIDs become security assets with SecurityAccess, RoutineControl, Session evidence. Legacy TARA spreadsheet import; OpenXSAM export.
Auto-generate penetration campaign proposals from your TARA attack paths. Proposal → draft campaign workflow with 4-eyes V&T handoff. Protocol-fuzzing drafts derived from attack-path step templates.
UML/AUTOSAR software composition co-displayed with the SBOM graph. Confidence-rated auto-matching links modules to SBOM components. Blast radius from a module through reachable CVEs.
Any SARIF 2.1.0-compatible tool can feed findings into the graph. Findings deduplicate against existing risks; new findings auto-draft as linked Threats in the affected project. Roll-ups feed ISO 21434 §13 test evidence.
Coverage-guided fuzzer across the supported protocol matrix. Runs on Vector, PEAK, Kvaser, IXXAT, SocketCAN hardware. Configurable safety guardrails: high-criticality PDUs require manual promotion before any fuzz campaign targets them.
Beta indicates a capability is shipping today to opted-in tenants under the Beta support tier: full SLA applies, evidence outputs are eligible for compliance use, and the API contract is locked. Roadmap to GA is on the next quarterly release.
From CVE landing to scoped OTA campaign
A new CVE drops. The graph walks SBOM component → software unit → ECU → part number → affected VINs in one query. No spreadsheet sprint.
Reuse on the second program
Org-level Security Catalog carries validated controls, requirements, threats and damage scenarios across every program. Program two starts at ~80% reuse, not zero.
Workflows on one knowledge graph
Design, governance, TARA, SBOM, security testing, operations, compliance and collaboration: one traversable data model. Architecture change re-evaluates everything downstream automatically.
Architecture entities, SBOM components, CVE feeds, and incident reports all land in the same Neo4j knowledge graph. Impact analysis is a traversal, not a Jira hunt.
Change anything (an architecture entity, a SBOM component, a CVE feed) and the graph propagates the impact automatically.
Live world map of every vehicle, every risk, every CVE across markets. The same graph that holds your TARA also holds your fleet exposure.
13 step-by-step walkthroughs covering every module, from TARA threat modeling to compliance reporting
7:42
End-to-end platform tour covering all modules and core workflows
5:18
STRIDE-based threat analysis with attack path visualization
4:55
ISO/SAE 21434 risk scoring with impact and feasibility analysis
6:10
Import SBOMs, track vulnerabilities, and manage license compliance
4:30
Generate audit-ready reports for ISO/SAE 21434, R155 & GB 44495
5:45
Define assets, interfaces and trust boundaries for your vehicle architecture
Seen enough? Get hands-on with ThreatZ.
The complete automotive cybersecurity platform. From your first TARA to full lifecycle operations.
Also available through your AWS account — consolidates on your existing AWS bill and counts toward EDP commit.
AWS Marketplace list price: Team $17,868/yr · Professional $31,680/yr (includes AWS billing fees)
Available for Professional and Enterprise tiers
AI threat recommendations, risk scoring assistance, test case generation, and finding correlation. Gifted for the first year on all plans.
Bidirectional integration to external VSOC/SIEM systems. Webhooks, REST, MQTT. Enterprise includes 2 connectors.
ThreatZ experts perform your TARA assessment using the platform. Full deliverable ready for audit.
Live training sessions, workshop facilitation, custom template creation, and team onboarding.
Need more than your plan's included projects? Add extra project slots to any Team or Professional subscription.
Air-gapped, self-hosted deployment. Multi-year terms. Pricing indicative — final terms in Order Form.
Bespoke integration development consumed as story points. Connect ThreatZ to your proprietary toolchain, PLM, or internal systems.
Full onboarding and migration service. We set up your workspace, configure vehicle architectures, and migrate existing projects so you can hit the ground running.
| Team | Professional | Enterprise | |
|---|---|---|---|
| Platform | |||
| Multi-language support (EN, DE, ZH) | ✓ | ✓ | ✓ |
| Users | Unlimited | 5–50 | Unlimited |
| Projects | 3 (+$99/mo) | 15 | Unlimited |
| RBAC | Basic roles | Full roles | Advanced + governance |
| Two-Factor Auth (2FA) | |||
| SSO / OIDC | |||
| REST API Access | |||
| Email Notifications | |||
| Advanced Reporting | |||
| Foundation | |||
| Security Catalog | Full | Full | Full |
| Policy Manager | Unlimited | Unlimited | Unlimited |
| Compliance Reporting | ISO/SAE 21434 | Multi-framework | Custom frameworks |
| PDF / Excel Exports | |||
| ReqIF Export | |||
| Programs & Vehicle Architecture | |||
| Programs | Unlimited | ||
| 3D Vehicle Architecture Canvas | |||
| Vehicle → SubSystem → ECU Hierarchy | |||
| Security Blueprints library | |||
| Baselines & Release Management | |||
| Release Snapshots + Auto-Versioning | |||
| Baseline Comparison | |||
| Project Freeze / Unfreeze | |||
| Metrics Tracking (12+ metrics) | |||
| Network Communication Matrix | |||
| Signal-Level Security (CAN/LIN/FlexRay/Ethernet) | |||
| DBC File Import + Parsing | |||
| COVESA VSS v6.0 Signal Mapping | |||
| STRIDE Auto-Threat Generation (Signals) | |||
| Multi-Standard Automotive Compliance (ISO/SAE 21434, R155, GB 44495, EU CRA) | |||
| SOME/IP & DDS Service Modeling | |||
| TARA | |||
| System Modeling | |||
| STRIDE Threat Modeling | |||
| Risk Assessment + Heatmaps | |||
| Risk Relationship Graph | |||
| Attack Path Analysis | |||
| Risk Treatment Planning | |||
| Weakness Tree (SBOM + TARA) | |||
| Report Export (PDF) | |||
| Report Sharing (LiveLink + Snapshot) | |||
| Integrations | |||
| MATLAB System Composer (Native) | |||
| SW Architecture Import (EA, Rhapsody, Cameo, SysML) | |||
| Jira Integration | |||
| GitHub / GitLab | |||
| Vector CANoe via Test Bench Agent (CAPL + Python) | |||
| VSOC / SIEM Integration | Add-on | 2 included | |
| Custom Integrations | |||
| SBOM / Supply Chain | |||
| SBOM Management | |||
| SARIF findings ingest (SCA / SAST / Binary) | |||
| Vulnerability Tracking | |||
| License Tracking | |||
| Validation & Testing (V&T) / Operations | |||
| Security Testing Campaigns | |||
| ThreatZ Test Bench Agent (Desktop App) | |||
| Threat Intelligence | Multi-source | ||
| Incident Management | At scale | ||
| Security Event Monitoring | |||
| Ops Data Retention | 90 days | 6–36 months | |
| STIX / AUTOSAR Exports | |||
| AI | |||
| AI Power Pack | Free 1st year | Free 1st year | Included |
| Support | |||
| Support Channel | Email (48h) | Email (24h) | Dedicated CSM (4h) |
| Onboarding | Self-serve | Guided | White-glove |
| Private Cloud (+10%) | |||
| On-Premise Option | |||
Get a comprehensive overview of the ThreatZ platform in a single document.
Expert guides on automotive cybersecurity standards and best practices from the Uraeus knowledge hub.
Bring your own LLM endpoint. Ground the assistant in your org and project documents. Every recommendation requires human review — no AI writes to your compliance record without explicit approval.
Point ThreatZ at your OpenAI, Azure OpenAI, or self-hosted model endpoint. SSRF-guarded; per-call audit events; per-tenant flag to ramp at your pace.
Upload your security standards, internal guides, and project documents. The assistant retrieves from your knowledge base, not generic web data — answers are grounded in your context.
Every prompt, retrieval, and recommendation logged with per-call HMAC integrity. Procurement-grade evidence for your AI governance — including responses that customers chose to ignore.
Disqualifying the wrong buyer up-front builds more trust than hiding it. If any of these are you, we’re not the right fit — yet.
Not a replacement for Enterprise Architect or MATLAB System Composer. ThreatZ ingests from them and keeps the security layer synchronized with your model of record — it doesn’t replace the modeling tools your systems engineers already use.
Not an SBOM scanner or generator. ThreatZ ingests CycloneDX and SPDX from your existing build pipeline, then matches against vulnerability feeds and your architecture — it doesn’t replace your SBOM-producing toolchain.
Not a web-app pentest tool. ThreatZ is built specifically for automotive ECU and in-vehicle network attack surfaces — CAN, UDS, DoIP, SecOC, SOME/IP, and the rest of the supported protocol matrix.
Cut TARA cycle time, close ISO/SAE 21434 evidence gaps, and connect your architecture, SBOM and testing in one live knowledge graph — without the manual hand-offs that slow every other CSMS workflow.
Start your 14-day free trial today. No credit card required. Cancel anytime. Your data stays secure with enterprise-grade encryption.