Know what you are exposed to, and what to fix first.
Vulnerability lookups on every plan. Threat models and TARAs your own agent runs end to end. From Premium, a vulnerability assessment, an ICS advisory run or a deferral dossier scores each finding against the system you described, so the queue is ordered by exposure.
The free run is a threat model on a system you describe, watermarked. CVE, KEV, EPSS, exploit and CISA ICS advisory lookups come with every plan, Free included.
- CVE-2021-44228
- Apache Log4j2 remote code execution, CVSS 10.0KEV: listed
- EPSS
- 0.99999, top 1% most likely to be exploited in the next 30 daysFIRST.org
- context
- Portal API, internet-facing, restricted datayour model
- verdict
- Fix first: reachable from the internet and in the ransomware cataloguecritical
- export
- Review decision recorded, exported as OpenVEXopenvex
The lookup, the method, and the score that orders the queue.
Your agent reads the vulnerability record, the threat knowledge behind it and the system you described, then says which finding to take first.
Vulnerability lookups, on every plan
CVE records, CISA KEV status, EPSS probability, known exploits, and the CISA ICS and OT advisories for the plant. Free tier included, each row cited to CISA, NVD or FIRST.org.
Connect and askServed rows, read on 21 September 2026
Threat knowledge behind the finding
MITRE ATT&CK and ATLAS are served on every plan. From Premium the same question also reaches CAPEC attack patterns, CWE weaknesses and D3FEND countermeasures, so a threat model cites the technique rather than recalling it.
What each plan reachesServed rows, read on 21 September 2026
One method per question, with variants per system.
Each family is a fixed method your agent walks through with you. The variants carry what the domain expects, so an automotive TARA and a drone threat model ask different questions and cite different sources.
| Family | Variants | Input | From |
|---|---|---|---|
| Threat model | STRIDE, LINDDUN, AI systems, OT, drones | A described system, or your architecture workspace brought by your agent | Free teaser · Premium |
| TARA | Automotive (ISO/SAE 21434, R155), UAS, rail, robot, OT | A described system, or your architecture workspace brought by your agent | Premium |
| Adversary tabletop and vulnerability assessment | Vulnerability assessment and deferral dossier (Premium), adversary tabletop (Team) | A described system; findings and scoring context inside the run | Premium · Team |
| ICS advisory to risk | A CISA ICS or OT advisory turned into scored findings for your plant | An advisory reference and the system it touches | Premium |
The served catalogue is what your agent lists when it calls the gateway; this table follows it. Workflow directory · Gap analyses, DPIAs and conformity runs
Look it up, place it in your system, score it, decide, export.
Look up
Your agent fetches the CVE record, its KEV status, its EPSS probability and any ICS advisory that names it. Nothing is answered from model memory.
Place it
The finding is placed in the system you described: which component runs it, whether it faces the internet, what data sits behind it.
Score
From Premium, inside a vulnerability assessment, an ICS advisory run or a deferral dossier, each finding is scored in that context. The vulnerability assessment and the deferral dossier also compare the candidate fixes.
Decide
From Team, a reviewer records the disposition against the finding, with the reason kept as written.
Export
From Team, the dispositions leave as an OpenVEX document your build and your customers can read.
- CVE-2021-44228
- Apache Log4j2 remote code execution, CVSS 10.0KEV: listed
- EPSS
- 0.99999, top 1% most likely to be exploited in the next 30 daysFIRST.org
- context
- Portal API, internet-facing, restricted datayour model
- verdict
- Fix first: reachable from the internet and in the ransomware cataloguecritical
- export
- Review decision recorded, exported as OpenVEXopenvex
The model, the controls and the people.
Living threat model
Your architecture workspace holds the components and the threats that attach to them. It runs on your own machine or in your cluster, never hosted by us.
The workspaceControl library
From Team: one NIST 800-53 spine under CSF 2.0, with reviewed mappings to ISO 27001, C5, NIS2, DORA and CRA. A finding lands on a control you already run.
The spine and its mappingsExpert review
Our team reviews a threat model or a TARA, or runs it for you. Scope agreed before work starts.
Expert deliveryLookups and a teaser run on every plan. The catalogue from Premium.
Free and Solo read the vulnerability record and the ATT&CK technique. Premium runs the threat model, the TARA and the vulnerability assessment; scoring happens inside a vulnerability assessment, an ICS advisory run or a deferral dossier, not in every run. Team adds your own scoring contexts, recorded review decisions and OpenVEX export.
Run a free threat model.
On a system you describe. Watermarked, cited, yours.