For OEMs

Your whole fleet.One living graph.

Eight workflows, one knowledge graph. Your suppliers execute your CSMS process, on your platform. Type approval months ahead. CVE response in hours. Private cloud or air-gapped on-premise.

app.threatz.io/programs/ev-gen4/fleet-map
Fleet Map · EV Platform Gen-4 241,502 VEHICLES · 3 ACTIVE INCIDENTS
INC-2031 · Telematics
EVENT FEED
INC-2031 opened
Telematics · 1,204 vehicles scoped · 2 programs
UDS probe pattern detected
Region DE-South · 17 vehicles · watching
CVE-2026-31842 fleet impact traced
3 projects affected · supplier notified
OTA mitigation confirmed
INC-2028 · 98.2% fleet coverage
HOURS not 14 days — CVE to fleet answer MONTHS ahead on type-approval evidence 3–5 FTE of supplier program management, federated away AIR-GAP supported · customer-owned data plane
DESIGN the model everything derives from
System Modeling ●●●
→ Audit answers become paths through your own model

Import your vehicle architecture once and every downstream artefact derives from it. When the auditor asks why a threat exists, the answer is a path through your own model — not a spreadsheet row someone typed last quarter.

ARXML / System Composer / Simulink Ingest ●●
→ One architecture governed — zero reconciliation

Suppliers' models arrive in the formats they already work in. You govern one architecture instead of reconciling ARXML against a functional spec in another tool that disagrees with it.

Diagnostic & Signal Ingest (ODX/PDX/CDD, DBC) ●●
→ Physical attack surface in the model, not in memory

Diagnostic surface is where a physically-present attacker starts. Importing it puts that surface in the model, not in an engineer's memory.

Vehicle Signal Modeling (VSS/VISS · VDM/S2DM) ●●●
→ The vehicle's data plane modeled signal by signal

Your fleet speaks COVESA VSS and your data team ships a VDM in GraphQL SDL — ThreatZ reads both planes into one signal catalog, with provenance and a security grade per signal. The data your vehicles emit becomes part of the threat model, not a parallel spreadsheet owned by another department.

TARA computed, defensible, bound to the model
Threat Modeling ●●●
→ Component changes show you which threats moved

Threats are generated from your architecture and stay bound to it. When a component changes you can see which threats moved — instead of discovering it during audit prep.

Attack Path Analysis & Aggregated Attack Tree ●●●
→ Defensible line by line in type-approval review

Attack paths are derived from your model, not drawn from memory. Every hop carries a named technique and a rated feasibility, so the aggregated tree is defensible line by line in a type-approval review. Five ISO 21434 feasibility factors; CAL 1–4 derived from them.

Risk Assessment ●●●
→ The register moves with the analysis — defensible months later

Risk is computed from the analysis, not asserted in a workshop. Change a feasibility rating and the register moves — which is what keeps the risk position defensible months later.

Risk Treatment & Assurance Chain ●●●
→ Non-conforming risk retention blocked at the API

Residual-risk acceptance is where type approval is won or lost. Risk → goal → requirement → control → claim is traversable both ways, and a safety-coupled policy stops an engineer quietly retaining a high risk your governance says must be reduced — the ISO 26262 ↔ CSMS interface enforced in-product, not in a review meeting.

SBOM the query, not the project
SBOM Management & Vulnerability Matching ●●●
→ 14 days → under 4 hours to a fleet answer

A CVE lands and the question is which vehicles, which suppliers, which attack paths, do we disclose. Because components link to the architecture, that's a query, not a project — 14 days becomes under four hours.

TESTING coverage against controls
Validation & Testing ●●
→ Verification status without reading test-report PDFs

Coverage is expressed against your controls, so "is this requirement actually verified" stops being answered by reading a test report PDF.

Penetration & Fuzz Campaigns ●●
→ Supplier test scope justified by rated feasibility

Ask a supplier why they tested what they tested and the honest answer is scope negotiation. Campaigns derived from attack paths make the answer "because this path rated feasible."

COMPLIANCE evidence as a render step
ISO 21434 Work Products & Report Templates ●●●
→ 6–10 week evidence reconstruction → a report you run

Your team spends more time assembling type-approval evidence than engineering security. Six §-numbered work products generated from the live model turns a 6–10 week reconstruction into a report you run.

Baselines, Variants & Releases ●●
→ “What exactly was approved” is a retrievable state

Type approval is granted against a specific configuration. Baselines make "what exactly was approved" a retrievable state rather than archaeology — with a four-eyes gate on the approval itself.

Multi-region (R155 · GB 44495 · CRA) ●●●
→ 2–4 FTE per region per program → a generation step

Type approval in three regions, evidence in five formats. One model producing each region's package is the difference between 2–4 FTE per region per program and a generation step. China-resident deployment available.

GOVERNANCE your CSMS, enforced in-product
Policy Manager & Security Catalog ●●●
→ Your methodology enforced in-product, not hoped for

This is where your CSMS methodology actually lives. Author it once as versioned policy and it's enforced in the product across every program and supplier — not distributed as a PDF and hoped for. Mandatory enforcement blocks non-conforming decisions at the API.

RBAC, audit trail & approval gates ●●●
→ Answers that predate the auditor’s question

Segregation of duties is an audit finding waiting to happen. Four-eyes gates and an entity-level audit trail mean "who approved this, and could they have?" has an answer that predates the question — including time-boxed, audited vendor support access.

COLLABORATION suppliers on your platform
Supplier Federation ●●●
→ 3–5 FTE of supplier program management recovered

200 suppliers returning PDFs gives you no live view of where anyone is. Federated, they execute your process on your platform — and audit evidence assembles itself as they work. Today: 3–5 FTE on supplier program management.

Architecture Mapping Studio ●●
→ Architecture drift detected within an hour

The gap nobody owns is between the architecture you approved and the software that shipped. Drift detection tells you they've diverged within an hour — while it's still a change request.

OPERATIONS R155 does not end at SOP
Monitoring, Incidents & V-SOC ●●●
→ Post-production monitoring as a closed loop, same platform

R155 Annex 5 doesn't end at start of production. Incidents bound to components feed back into the risk model, so post-production monitoring is a closed loop in the same platform rather than a separate obligation.

Disclosure Workflow (R155 §7.3) ●●●
→ A §7.3 position by Friday — judgement, not archaeology

A CVE drops Tuesday and §7.3 wants a position by Friday. The chain from vulnerability to affected fleet to disclosure package is already assembled — the decision becomes judgement, not archaeology.

AI LAYER accelerates; engineers approve
AI Assistant & Recommender ●●
→ Every AI claim carries a link an auditor can follow

The AI doesn't form TARA opinions — it traces relationships in your graph, and every claim carries a link an auditor can follow. AI accelerates; your engineers approve. That's the only version that survives an audit.

PLATFORM & DEPLOYMENT sovereignty by default
Deployment, Sovereignty & Integrations ●●●
→ The sovereignty veto answered before it’s raised

Your SVP Engineering vetoes anything putting vehicle data in someone else's cloud, and China programs must stay in-country. Private cloud or on-premise — air-gapped supported. For sovereignty, and for China. Customer-owned data plane.

Command the fleet,
not the paperwork.

45 minutes with an engineer, on your program's shape — not a slide deck.

Book an OEM demo