Your whole fleet.One living graph.
Eight workflows, one knowledge graph. Your suppliers execute your CSMS process, on your platform. Type approval months ahead. CVE response in hours. Private cloud or air-gapped on-premise.
●●● = how much this area matters to an OEM. Same platform, different job: the Tier-1 view reads differently on purpose.
Import your vehicle architecture once and every downstream artefact derives from it. When the auditor asks why a threat exists, the answer is a path through your own model — not a spreadsheet row someone typed last quarter.
Suppliers' models arrive in the formats they already work in. You govern one architecture instead of reconciling ARXML against a functional spec in another tool that disagrees with it.
Diagnostic surface is where a physically-present attacker starts. Importing it puts that surface in the model, not in an engineer's memory.
Your fleet speaks COVESA VSS and your data team ships a VDM in GraphQL SDL — ThreatZ reads both planes into one signal catalog, with provenance and a security grade per signal. The data your vehicles emit becomes part of the threat model, not a parallel spreadsheet owned by another department.
Threats are generated from your architecture and stay bound to it. When a component changes you can see which threats moved — instead of discovering it during audit prep.
Attack paths are derived from your model, not drawn from memory. Every hop carries a named technique and a rated feasibility, so the aggregated tree is defensible line by line in a type-approval review. Five ISO 21434 feasibility factors; CAL 1–4 derived from them.
Risk is computed from the analysis, not asserted in a workshop. Change a feasibility rating and the register moves — which is what keeps the risk position defensible months later.
Residual-risk acceptance is where type approval is won or lost. Risk → goal → requirement → control → claim is traversable both ways, and a safety-coupled policy stops an engineer quietly retaining a high risk your governance says must be reduced — the ISO 26262 ↔ CSMS interface enforced in-product, not in a review meeting.
A CVE lands and the question is which vehicles, which suppliers, which attack paths, do we disclose. Because components link to the architecture, that's a query, not a project — 14 days becomes under four hours.
Coverage is expressed against your controls, so "is this requirement actually verified" stops being answered by reading a test report PDF.
Ask a supplier why they tested what they tested and the honest answer is scope negotiation. Campaigns derived from attack paths make the answer "because this path rated feasible."
Your team spends more time assembling type-approval evidence than engineering security. Six §-numbered work products generated from the live model turns a 6–10 week reconstruction into a report you run.
Type approval is granted against a specific configuration. Baselines make "what exactly was approved" a retrievable state rather than archaeology — with a four-eyes gate on the approval itself.
Type approval in three regions, evidence in five formats. One model producing each region's package is the difference between 2–4 FTE per region per program and a generation step. China-resident deployment available.
This is where your CSMS methodology actually lives. Author it once as versioned policy and it's enforced in the product across every program and supplier — not distributed as a PDF and hoped for. Mandatory enforcement blocks non-conforming decisions at the API.
Segregation of duties is an audit finding waiting to happen. Four-eyes gates and an entity-level audit trail mean "who approved this, and could they have?" has an answer that predates the question — including time-boxed, audited vendor support access.
200 suppliers returning PDFs gives you no live view of where anyone is. Federated, they execute your process on your platform — and audit evidence assembles itself as they work. Today: 3–5 FTE on supplier program management.
The gap nobody owns is between the architecture you approved and the software that shipped. Drift detection tells you they've diverged within an hour — while it's still a change request.
R155 Annex 5 doesn't end at start of production. Incidents bound to components feed back into the risk model, so post-production monitoring is a closed loop in the same platform rather than a separate obligation.
A CVE drops Tuesday and §7.3 wants a position by Friday. The chain from vulnerability to affected fleet to disclosure package is already assembled — the decision becomes judgement, not archaeology.
The AI doesn't form TARA opinions — it traces relationships in your graph, and every claim carries a link an auditor can follow. AI accelerates; your engineers approve. That's the only version that survives an audit.
Your SVP Engineering vetoes anything putting vehicle data in someone else's cloud, and China programs must stay in-country. Private cloud or on-premise — air-gapped supported. For sovereignty, and for China. Customer-owned data plane.
Command the fleet,
not the paperwork.
45 minutes with an engineer, on your program's shape — not a slide deck.
Book an OEM demo