Skip to content
    Security risk and threat intelligence · Ansvar Security

    Know what you are exposed to, and what to fix first.

    Vulnerability lookups on every plan. Threat models and TARAs your own agent runs end to end. From Premium, a vulnerability assessment, an ICS advisory run or a deferral dossier scores each finding against the system you described, so the queue is ordered by exposure.

    The free run is a threat model on a system you describe, watermarked. CVE, KEV, EPSS, exploit and CISA ICS advisory lookups come with every plan, Free included.

    CVE-2021-44228
    Apache Log4j2 remote code execution, CVSS 10.0KEV: listed
    EPSS
    0.99999, top 1% most likely to be exploited in the next 30 daysFIRST.org
    context
    Portal API, internet-facing, restricted datayour model
    verdict
    Fix first: reachable from the internet and in the ransomware cataloguecritical
    export
    Review decision recorded, exported as OpenVEXopenvex
    CISA KEV, added 2021-12-10EPSS read 2026-09-21
    Effective risk for portal-api, finding 1 of 14. Illustrative example; the CVE and KEV rows are served records.
    What you get

    The lookup, the method, and the score that orders the queue.

    Your agent reads the vulnerability record, the threat knowledge behind it and the system you described, then says which finding to take first.

    Vulnerability lookups, on every plan

    CVE records, CISA KEV status, EPSS probability, known exploits, and the CISA ICS and OT advisories for the plant. Free tier included, each row cited to CISA, NVD or FIRST.org.

    Connect and ask
    ICSA
    ICSA-26-237-03 · Siemens SIMATIC IoT2050 Advanced
    max CVSS 10.0 · released 2026-08-25
    CISA
    ICSA
    ICSA-26-258-05 · Siemens Reyrolle 7SR5
    max CVSS 9.8 · 14 CVEs
    CISA
    KEV
    CVE-2021-44228 · Apache Log4j2 remote code execution
    added to the catalogue 2021-12-10 · known ransomware use
    CISA

    Served rows, read on 21 September 2026

    Threat knowledge behind the finding

    MITRE ATT&CK and ATLAS are served on every plan. From Premium the same question also reaches CAPEC attack patterns, CWE weaknesses and D3FEND countermeasures, so a threat model cites the technique rather than recalling it.

    What each plan reaches
    ATT&CK
    T0819 · Exploit Public-Facing Application
    ICS technique · attack.mitre.org
    MITRE
    ATLAS
    AML.T0049 · Exploit Public-Facing Application
    adversarial machine learning · atlas.mitre.org
    MITRE
    ATLAS
    AML.T0093 · Prompt Infiltration via Public-Facing Application
    adversarial machine learning · atlas.mitre.org
    MITRE

    Served rows, read on 21 September 2026

    The catalogue

    One method per question, with variants per system.

    Each family is a fixed method your agent walks through with you. The variants carry what the domain expects, so an automotive TARA and a drone threat model ask different questions and cite different sources.

    FamilyVariantsInputFrom
    Threat modelSTRIDE, LINDDUN, AI systems, OT, dronesA described system, or your architecture workspace brought by your agentFree teaser · Premium
    TARAAutomotive (ISO/SAE 21434, R155), UAS, rail, robot, OTA described system, or your architecture workspace brought by your agentPremium
    Adversary tabletop and vulnerability assessmentVulnerability assessment and deferral dossier (Premium), adversary tabletop (Team)A described system; findings and scoring context inside the runPremium · Team
    ICS advisory to riskA CISA ICS or OT advisory turned into scored findings for your plantAn advisory reference and the system it touchesPremium

    The served catalogue is what your agent lists when it calls the gateway; this table follows it. Workflow directory · Gap analyses, DPIAs and conformity runs

    How a scored decision works

    Look it up, place it in your system, score it, decide, export.

    1. Look up

      Your agent fetches the CVE record, its KEV status, its EPSS probability and any ICS advisory that names it. Nothing is answered from model memory.

    2. Place it

      The finding is placed in the system you described: which component runs it, whether it faces the internet, what data sits behind it.

    3. Score

      From Premium, inside a vulnerability assessment, an ICS advisory run or a deferral dossier, each finding is scored in that context. The vulnerability assessment and the deferral dossier also compare the candidate fixes.

    4. Decide

      From Team, a reviewer records the disposition against the finding, with the reason kept as written.

    5. Export

      From Team, the dispositions leave as an OpenVEX document your build and your customers can read.

    CVE-2021-44228
    Apache Log4j2 remote code execution, CVSS 10.0KEV: listed
    EPSS
    0.99999, top 1% most likely to be exploited in the next 30 daysFIRST.org
    context
    Portal API, internet-facing, restricted datayour model
    verdict
    Fix first: reachable from the internet and in the ransomware cataloguecritical
    export
    Review decision recorded, exported as OpenVEXopenvex
    CISA KEV, added 2021-12-10EPSS read 2026-09-21
    Effective risk for portal-api, finding 1 of 14. Illustrative example; the CVE and KEV rows are served records.
    The living threat model lives in the architecture workspace, which you host yourself. Threats attach to components, and when a component changes the assessments that rest on it are marked stale and a review is proposed. Living security architecture
    Beyond the run

    The model, the controls and the people.

    Living threat model

    Your architecture workspace holds the components and the threats that attach to them. It runs on your own machine or in your cluster, never hosted by us.

    The workspace

    Control library

    From Team: one NIST 800-53 spine under CSF 2.0, with reviewed mappings to ISO 27001, C5, NIS2, DORA and CRA. A finding lands on a control you already run.

    The spine and its mappings

    Expert review

    Our team reviews a threat model or a TARA, or runs it for you. Scope agreed before work starts.

    Expert delivery
    Plans

    Lookups and a teaser run on every plan. The catalogue from Premium.

    Free and Solo read the vulnerability record and the ATT&CK technique. Premium runs the threat model, the TARA and the vulnerability assessment; scoring happens inside a vulnerability assessment, an ICS advisory run or a deferral dossier, not in every run. Team adds your own scoring contexts, recorded review decisions and OpenVEX export.

    Every plan and limit

    Run a free threat model.

    On a system you describe. Watermarked, cited, yours.