Back to vendors
T

ThreatModeler

Also known as: ThreatModeler Nexus, IriusRisk

Visit site
Entry priceNot public; quoted through enterprise engagement after a solutions engineering sessionFull pricing detail

Governed agentic threat modeling platform whose multi agent system builds, maintains, and reports on threat models grounded in a persistent Secure Design Graph, threat modeling applications, cloud, OT, and AI agents at enterprise scale with a deterministic framework and Bring Your Own AI.

ThreatModeler, based in Jersey City and founded in 2010, builds agentic threat modeling and secure design software that uses AI to find design flaws before software ships. In January 2026 ThreatModeler acquired IriusRisk, another early automated threat modeling vendor, and iriusrisk.com now describes IriusRisk as part of ThreatModeler. The combined company draws on a curated library of threats, security requirements and modeled components. Its premise is that as AI writes a growing share of production code, finding flaws has become cheap, and the harder work is confirming what matters, catching what is missing and proving it to auditors.

Its flagship, ThreatModeler Nexus, pairs three named agents with a deterministic framework. A System Mapping Agent builds a system map from architecture artifacts or infers one from code, a Graph Agent grounds and updates that work in the customer's environment, and a Reporting Agent produces audit evidence, all working on the Secure Design Graph, a maintained representation of systems, threats, controls and compliance mappings.

The platform threat models applications, cloud infrastructure, operational technology and AI agents, imports from ticketing, diagramming and enterprise architecture tools, runs in CI/CD pipelines, and takes a Bring Your Own AI approach so the customer chooses the model. Every threat, control and decision traces back to architecture, and deployment is offered as SaaS, on premises or in a private cloud. ThreatModeler names an MCP Server, but its page returns a 404, so its endpoint, authentication and tools are not confirmed.

ThreatModeler lists ISO 27001:2022 and SOC 2 Type II, and FedRAMP Moderate availability through a partner environment; no published page documents customer facing SSO, roles or audit logs. The product does not document an approval step before agent output is committed, so human review sits in the customer's own process. It fits security organizations that need repeatable, auditable threat models across a large portfolio of applications, cloud and AI systems; a small team wanting a quick one off diagram will find it built for enterprise process.

Vendor details

Canonical URL

https://www.threatmodeler.ai

Category

Security / SOC agent

Subcategory

Agentic threat modeling and secure design

Funding status

Independent and privately held, headquartered in Jersey City, New Jersey, founded in 2010. In January 2026 ThreatModeler acquired IriusRisk, combining the two companies' threat libraries and technology; iriusrisk.com now describes IriusRisk as part of ThreatModeler. ThreatModeler has cited thirteen granted patents, more than a decade of curated research, and customers in regulated industries including Charles Schwab.

Company status

acquired

Use cases & customers

Primary use cases

automated threat modelingsecure by design developmentcloud and IaC risk analysiscompliance and audit evidence

Target customers

enterprise security and AppSec teamsregulated financial services and healthcareDevSecOps and cloud security teams

Deployment options

SaaScloudon premisehybrid

Integrations

ThreatModeler imports from ticketing, diagramming and enterprise architecture tools, runs in CI/CD pipelines and against Infrastructure as Code, and connects to live cloud infrastructure for continuous risk identification. It names an MCP Server for IDEs and AI coding agents, whose page returns a 404, and pushes security requirements into developer sprints.

In practice

Your AI copilots ship code faster than your security team can review the designs behind it, so threat modeling becomes a stale, manual bottleneck. ThreatModeler's agents build and continuously update models from your architecture and code automatically.

You need to prove your security posture to auditors across many systems and frameworks, but evidence is scattered and inconsistent. ThreatModeler's Secure Design Graph is a system of record where every threat and control traces to architecture and maps to compliance.

You want to use AI for threat modeling without model lock in or inconsistent, unrepeatable results. ThreatModeler's Bring Your Own AI and deterministic framework ensure the same architecture in produces the same threats out, every time.

Agentic Index coverage score

10.0 / 14 capabilities · 71%

Integrations & Tool Calling Full

Integrations for ticketing, diagram and enterprise architecture import, CI/CD and cloud, plus the ThreatModeler MCP Server that brings threat modeling into AI assistants, GitHub and IDEs.

Sourcethreatmodeler.ai/platformread 2026-09-28

Workflow Orchestration Full

Three agents hand work along under a deterministic framework. The System Mapping Agent turns documents and diagrams into models, the Graph Agent enriches the Secure Design Graph with components and threats, and the Reporting Agent produces audit ready reports.

Sourcethreatmodeler.ai/platformread 2026-09-28

Knowledge Grounding & RAG Full

The Secure Design Graph is a persistent single source of truth connecting the customer's architectures, components, threats, controls and security decisions, grounded in a curated threat library, and every agent works on it.

Sourcethreatmodeler.ai/platformread 2026-09-28

Human Oversight & Guardrails Partial

A deterministic framework governs what the agents produce, so the same architecture gives the same threats and controls, which constrains the agents. No step where a person reviews or approves a generated model before it is committed is documented.

Sourcethreatmodeler.ai/platformread 2026-09-28

Security, Identity & Governance Partial

ThreatModeler lists ISO 27001:2022 and SOC 2 Type II for ThreatModeler Nexus, and FedRAMP Moderate availability through a partner environment. No SSO, SCIM or role model for the platform is published.

Sourcethreatmodeler.airead 2026-09-28

Observability & Auditability Full

Every decision the agents make traces back to the architecture, controls and compliance requirements behind it, with audit ready evidence produced by the Reporting Agent.

Sourcethreatmodeler.ai/platformread 2026-09-28

Memory & State Persistence Not documented

The Secure Design Graph, which the vendor says improves every future model, is the platform's knowledge base rather than agent memory. No agent memory with a scope or lifetime is documented.

Sourcethreatmodeler.ai/platformread 2026-09-28

Deployment & Data Residency Full

ThreatModeler Nexus is offered as SaaS, on premises or in a private cloud, with regional flexibility.

Sourcethreatmodeler.ai/platformread 2026-09-28

Prebuilt Agents, Templates & Packs Full

A curated library of threats, controls and components that customers adopt into their models, reports mapped to more than 180 compliance frameworks, and three named agents with separate jobs.

Sourcethreatmodeler.airead 2026-09-28

Triggers & Channel Coverage Full

Threat modeling runs from the CI/CD pipeline and on diagram and architecture imports, so changes start the work rather than a person. The exact trigger events are not listed.

Sourcethreatmodeler.ai/platformread 2026-09-28

Model Flexibility & Routing Full

Customers bring their own model and the platform's agents run on it under one governance, so the customer chooses. The supported providers are not listed.

Sourcethreatmodeler.ai/platformread 2026-09-28

APIs, SDKs & MCP Extensibility Partial

The platform names its own MCP Server for AI assistants, GitHub and IDEs, but no endpoint, authentication scheme, tool list or API reference is published, and the MCP Server page does not load.

Sourcethreatmodeler.ai/platformread 2026-09-28

Testing, Debugging & Optimization Partial

Outputs are deterministic, with the same architecture in giving the same threats and controls out, which makes results repeatable. No evaluation harness, scored test cases or gate for a change to the agents or model is documented.

Sourcethreatmodeler.ai/platformread 2026-09-28

Browser & Computer Use Not documented

No page documents an agent driving a browser, desktop or remote computer. The agents work from design, code and cloud artifacts.

Sourcethreatmodeler.ai/platformread 2026-09-28

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-07-07·Security / enterprisePartially Verified

ThreatModeler updated its Intelligent Threat Engine (ITE) to detect advanced AI-specific threats at the architectural design stage. The release introduces curated threat libraries that map agentic tool compromise and Model Context Protocol (MCP) vulnerabilities to industry frameworks such as MITRE ATLAS and OWASP Agentic AI Threats.

Bears on: Security / enterprise

View source
View all 1 change for ThreatModeler →Tracked since Jul 2026 · Verified from public vendor sources

Pricing

Not public; quoted through enterprise engagement after a solutions engineering session

enterprise subscription; basis not disclosed

What is public

No list pricing. ThreatModeler sells to enterprises through direct engagement and a solutions engineering session, but rates are not public.

Billing mechanics

Rates and billing basis are not disclosed. Inference, not stated by the vendor: an enterprise subscription scaled to the applications, users and modules deployed across applications, cloud, OT and AI coverage.

Cost watchouts

Inference, not stated by the vendor: cost may scale with the number of applications and systems modeled, users, and modules, so broad enterprise rollouts could grow the total.

Variable cost rationale

Inference, not stated by the vendor: likely priced against applications modeled, users and modules, so cost would grow as threat modeling scales across a larger portfolio.

Additional watchouts

Confirm whether pricing is per application, per user, or a platform subscription, and how coverage across cloud, OT, and AI agents affects the quote.

Sales call required

Yes, required for paid access

Free / trial

Book a session with a solutions engineer; no public free tier

Key ambiguities

No public rate is disclosed, and whether pricing is per application, per user, or a platform subscription with modules is not clear.

Agentic Index verified 2026-09-28

Alternatives to ThreatModeler

The closest documented capability profiles to ThreatModeler among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Crogl9.0 / 14A lighter documented profile than ThreatModeler
  • UnderDefense8.5 / 14A lighter documented profile than ThreatModeler
  • ContraForce11.0 / 14Fuller documented coverage on Human Oversight & Guardrails and Security, Identity & Governance
  • CrowdStrike12.0 / 14Adds documented Memory & State Persistence
  • Cyware10.0 / 14Fuller documented coverage on Human Oversight & Guardrails and APIs, SDKs & MCP Extensibility
  • Ghost Security10.0 / 14Fuller documented coverage on Human Oversight & Guardrails and APIs, SDKs & MCP Extensibility

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Head to head

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.