Your E/E architecture
is the database.
This page is wired like your harness: one bus, four stations. Follow the line — vehicle, item, system, software — and watch what each station emits into the graph.
47 ECUs. 9 buses. Drawn once.
Import EA XMI or System Composer, or draw on the 2D canvas. This is the program-level source — every project below taps this line.
A selection, not a Word document.
Drag a boundary on the canvas. ThreatZ instantiates the project with exactly those ECUs, buses and interfaces as analysis scope.
Ports, interfaces, data flows. Typed.
Each project details its slice: components, ports, signals per bus with security grading. TARA scenarios attach to these nodes — architecture edits re-flag them, never orphan them.
SBOMs that know which vehicle they're in.
Software Composition joins architecture × SBOM per unit. A CVE lands on a real node — the route to affected projects and vehicles is one query, not a spreadsheet week.