Your whole fleet.One living graph.
Eight workflows, one knowledge graph. Your suppliers execute your CSMS process, on your platform. Type approval months ahead. CVE response in hours. Private cloud or air-gapped on-premise.
●●● = how much this area matters to an OEM. Same platform, different job: the Tier-1 view reads differently on purpose.
DESIGN
the model everything derives fromSystem Modeling
●●●Import your vehicle architecture once and every downstream artefact derives from it. When the auditor asks why a threat exists, the answer is a path through your own model — not a spreadsheet row someone typed last quarter.
ARXML / System Composer / Simulink Ingest
●●●Suppliers' models arrive in the formats they already work in. You govern one architecture instead of reconciling ARXML against a functional spec in another tool that disagrees with it.
Diagnostic & Signal Ingest (ODX/PDX/CDD, DBC)
●●●Diagnostic surface is where a physically-present attacker starts. Importing it puts that surface in the model, not in an engineer's memory.
Vehicle Signal Modeling (VSS/VISS · VDM/S2DM)
●●●Your fleet speaks COVESA VSS and your data team ships a VDM in GraphQL SDL — ThreatZ reads both planes into one signal catalog, with provenance and a security grade per signal. The data your vehicles emit becomes part of the threat model, not a parallel spreadsheet owned by another department.
TARA
computed, defensible, bound to the modelThreat Modeling
●●●Threats are generated from your architecture and stay bound to it. When a component changes you can see which threats moved — instead of discovering it during audit prep.
Attack Path Analysis & Aggregated Attack Tree
●●●Attack paths are derived from your model, not drawn from memory. Every hop carries a named technique and a rated feasibility, so the aggregated tree is defensible line by line in a type-approval review. Five ISO 21434 feasibility factors; CAL 1–4 derived from them.
Risk Assessment
●●●Risk is computed from the analysis, not asserted in a workshop. Change a feasibility rating and the register moves — which is what keeps the risk position defensible months later.
Risk Treatment & Assurance Chain
●●●Residual-risk acceptance is where type approval is won or lost. Risk → goal → requirement → control → claim is traversable both ways, and a safety-coupled policy stops an engineer quietly retaining a high risk your governance says must be reduced — the ISO 26262 ↔ CSMS interface enforced in-product, not in a review meeting.
SBOM
the query, not the projectSBOM Management & Vulnerability Matching
●●●A CVE lands and the question is which vehicles, which suppliers, which attack paths, do we disclose. Because components link to the architecture, that's a query, not a project — 14 days becomes under four hours.
TESTING
coverage against controlsValidation & Testing
●●●Coverage is expressed against your controls, so "is this requirement actually verified" stops being answered by reading a test report PDF.
Penetration & Fuzz Campaigns
●●●Ask a supplier why they tested what they tested and the honest answer is scope negotiation. Campaigns derived from attack paths make the answer "because this path rated feasible."
COMPLIANCE
evidence as a render stepISO 21434 Work Products & Report Templates
●●●Your team spends more time assembling type-approval evidence than engineering security. Six §-numbered work products generated from the live model turns a 6–10 week reconstruction into a report you run.
Baselines, Variants & Releases
●●●Type approval is granted against a specific configuration. Baselines make "what exactly was approved" a retrievable state rather than archaeology — with a four-eyes gate on the approval itself.
Multi-region (R155 · GB 44495 · CRA)
●●●Type approval in three regions, evidence in five formats. One model producing each region's package is the difference between 2–4 FTE per region per program and a generation step. China-resident deployment available.
GOVERNANCE
your CSMS, enforced in-productPolicy Manager & Security Catalog
●●●This is where your CSMS methodology actually lives. Author it once as versioned policy and it's enforced in the product across every program and supplier — not distributed as a PDF and hoped for. Mandatory enforcement blocks non-conforming decisions at the API.
RBAC, audit trail & approval gates
●●●Segregation of duties is an audit finding waiting to happen. Four-eyes gates and an entity-level audit trail mean "who approved this, and could they have?" has an answer that predates the question — including time-boxed, audited vendor support access.
COLLABORATION
suppliers on your platformSupplier Federation
●●●200 suppliers returning PDFs gives you no live view of where anyone is. Federated, they execute your process on your platform — and audit evidence assembles itself as they work. Today: 3–5 FTE on supplier program management.
Architecture Mapping Studio
●●●The gap nobody owns is between the architecture you approved and the software that shipped. Drift detection tells you they've diverged within an hour — while it's still a change request.
OPERATIONS
R155 does not end at SOPMonitoring, Incidents & V-SOC
●●●R155 Annex 5 doesn't end at start of production. Incidents bound to components feed back into the risk model, so post-production monitoring is a closed loop in the same platform rather than a separate obligation.
Disclosure Workflow (R155 §7.3)
●●●A CVE drops Tuesday and §7.3 wants a position by Friday. The chain from vulnerability to affected fleet to disclosure package is already assembled — the decision becomes judgement, not archaeology.
AI LAYER
accelerates; engineers approveAI Assistant & Recommender
●●●The AI doesn't form TARA opinions — it traces relationships in your graph, and every claim carries a link an auditor can follow. AI accelerates; your engineers approve. That's the only version that survives an audit.
PLATFORM & DEPLOYMENT
sovereignty by defaultDeployment, Sovereignty & Integrations
●●●Your SVP Engineering vetoes anything putting vehicle data in someone else's cloud, and China programs must stay in-country. Private cloud or on-premise — air-gapped supported. For sovereignty, and for China. Customer-owned data plane.
Command the fleet,
not the paperwork.
45 minutes with an engineer, on your program's shape — not a slide deck.
Book an OEM demo