Continuous Application Threat Modeling at Scale

Fork is the threat modeling software that empowers your security teams with continuous, data-driven threat assessments using proven PASTA methodology.

by VerSprite

Risk centric threat modeling under two hours

Identify risks that are most likely to happen and which create the biggest impact. Harnesses our industry-focused threat libraries and integrate real-time vulnerability data and threat intelligence.

Threat-Informed Defense
Stay ahead of evolving risks with up-to-date, industry-specific threat insights forming a solid foundation for your security strategy.
Proprietary Residual Risk Formula
Ensure relevant threats are quantified accurately and mitigated effectively.

A single pane of glass for security insights

Unveil a new perspective on your application's security posture with our unified view. Transform intricate threat data into actionable insights, by merging relevant industry threats with your application's attack surface, and cyber threat intelligence.

Integrated Industry Taxonomies
Our platform automatically correlates threat data with trusted frameworks and standards from MITRE and OWASP including CWE, CVE with EPSS, CAPEC, ATT&CK, D3FEND and ASVS to drive targeted mitigations and actionable insights.
On-Demand Security Testing
Substantiate the viability of potential threats by requesting targeted testing of specific weaknesses, vulnerabilities, and attack patterns directly from your threat models.

Threat modeling from Sprint 1

Harnesses the proven benefits of threat modeling, enabling your teams to identify and integrate security-driven design principles directly into your software from day one.

Relevant in every stage
Adapt your threat models to your application's current lifecycle stage - from planning and design to maintenance, ensuring every assessment is contextually applicable and practical.
On-Demand Security Testing
Substantiate the viability of potential threats by requesting targeted testing of specific weaknesses, vulnerabilities, and attack patterns directly from your threat models.

Integrations

Supercharge your threat modeling process by integrating Fork with your existing AppSec tooling.

ServiceNow
ServiceNow
Automatically sync threats and risk metrics to ServiceNow.
Veracode
Veracode
Integrate SCA, SAST, and DAST findings into your threat models.
OpenAI
OpenAI
Powers Fork's AI-assisted threat modeling and DFD generation.

Leverage the PASTA Methodology

Brought to you by a co-author of the Process for Attack Simulation and Threat Analysis (PASTA) methodology, our platform is a practical implementation of the renowned risk-centric, business-aligned threat modeling framework that raises the bar far beyond traditional approaches.

Stages of PASTA Methodology:

Define Objectives
Define Attack Surface
Decompose Application
Threat Analysis
Weakness and Vulnerability Analysis
Attack Modeling and Simulation
Risk and Impact Analysis

Simple Pricing, Powerful Security

Get started for free with our threat modeling platform for a single application, or scale up with Fork Enterprise, starting at $75,000/year, to secure your entire organization.

Fork Community

Free

Fork Enterprise

From $75,000/yr

Fork Enterprise PT

Contact Sales

See Full Pricing

Frequently Asked Questions

Answers to common questions about Fork and the PASTA methodology behind it.


What is Fork?
Fork is a continuous application threat modeling platform built on the PASTA methodology. It gives security teams data-driven threat assessments powered by industry-focused threat libraries and real-time vulnerability data, so risk stays visible as your applications evolve.

What is the PASTA methodology?
PASTA (Process for Attack Simulation and Threat Analysis) is a risk-centric, business-aligned threat modeling framework, co-authored by a member of Fork's team. It runs through seven stages, from defining objectives to risk and impact analysis, prioritizing threats by business impact rather than technical severity alone.

How long does it take to build a threat model in Fork?
Fork's guided automation walks teams through all seven PASTA stages and produces a first threat model in under two hours. Models don't stop there: Fork resurfaces relevant stages automatically as your application changes.

What's included in Fork Community?
Fork Community is free and covers one application threat model for a single team member, with vulnerability ingestion via SBOM, SARIF, or OVAL. It's built for teams getting started with threat modeling on a single application before scaling further.

What does Fork Enterprise add?
Fork Enterprise unlocks unlimited applications and team members, access to all AI capabilities including the Sous-Chef, documentation analysis, DFD generation, the ability to activate multiple threat libraries at once, access to every integration, granular access controls and permissions, SSO via SAML or OIDC, and full audit logs — built for organizations securing an entire application portfolio.

What tools does Fork integrate with?
Fork connects with ServiceNow, Veracode, GitLab Secure, OpenAI, Tavily, and OpenCTI today, correlating findings and threat intelligence directly into your models. It also maps threat data to MITRE and OWASP standards, including CWE, CVE, CAPEC, ATT&CK, D3FEND, MITRE ATLAS, NIST SP 800-53 (Revision 5), and ASVS.

Can Fork be used throughout the software lifecycle?
Yes. Fork's threat models adapt to your application's current stage, from planning and design through maintenance, so every assessment stays contextually relevant as the application — and the risk landscape around it — continues to evolve.

Is there a service beyond the self-serve platform?
Yes. Threat Modeling as a Service pairs Fork with VerSprite's security champions for portfolio-wide modeling, expert-led training, and human-readable or API-integrated reports, with 1–4 day SLA delivery for teams that want hands-on support.
What is continuous threat modeling?
Continuous threat modeling means threat models are built once and kept current automatically as an application changes, rather than produced in a single point-in-time workshop that goes stale the moment the architecture shifts. Fork resurfaces relevant PASTA stages as your application evolves, so the model stays an accurate, living picture instead of a static document.
How is Fork different from IriusRisk or ThreatModeler?
Fork is built natively around PASTA as its entire workflow, while IriusRisk and ThreatModeler (now the same company after a January 2026 acquisition) are STRIDE/VAST-first and offer PASTA only as one optional template. Fork also includes a free Community tier and an optional expert-led service, Threat Modeling as a Service, for teams that want hands-on support.
Is Fork free? How much does Fork cost?
Fork Community is free — one application threat model, one user, and vulnerability ingestion via SBOM, SARIF, or OVAL, no credit card required. Fork Enterprise starts at $75,000 per year for up to 500 threat models, scaling to $150,000 per year for 500–2,000 models. Fork Enterprise PT is quoted based on your testing needs.
How is PASTA different from STRIDE?
STRIDE categorizes threats into six technical types (spoofing, tampering, and so on) and is typically applied per component. PASTA is risk-centric and business-aligned: it ties technical threats back to business impact through a structured seven-stage process, rather than working from a fixed technical checklist alone.