Frequently Asked Questions
Answers to common questions about Fork and the PASTA methodology behind it.
- What is Fork?
- Fork is a continuous application threat modeling platform built on the PASTA methodology. It gives security teams data-driven threat assessments powered by industry-focused threat libraries and real-time vulnerability data, so risk stays visible as your applications evolve.
- What is the PASTA methodology?
- PASTA (Process for Attack Simulation and Threat Analysis) is a risk-centric, business-aligned threat modeling framework, co-authored by a member of Fork's team. It runs through seven stages, from defining objectives to risk and impact analysis, prioritizing threats by business impact rather than technical severity alone.
- How long does it take to build a threat model in Fork?
- Fork's guided automation walks teams through all seven PASTA stages and produces a first threat model in under two hours. Models don't stop there: Fork resurfaces relevant stages automatically as your application changes.
- What's included in Fork Community?
- Fork Community is free and covers one application threat model for a single team member, with vulnerability ingestion via SBOM, SARIF, or OVAL. It's built for teams getting started with threat modeling on a single application before scaling further.
- What does Fork Enterprise add?
- Fork Enterprise unlocks unlimited applications and team members, access to all AI capabilities including the Sous-Chef, documentation analysis, DFD generation, the ability to activate multiple threat libraries at once, access to every integration, granular access controls and permissions, SSO via SAML or OIDC, and full audit logs — built for organizations securing an entire application portfolio.
- What tools does Fork integrate with?
- Fork connects with ServiceNow, Veracode, GitLab Secure, OpenAI, Tavily, and OpenCTI today, correlating findings and threat intelligence directly into your models. It also maps threat data to MITRE and OWASP standards, including CWE, CVE, CAPEC, ATT&CK, D3FEND, MITRE ATLAS, NIST SP 800-53 (Revision 5), and ASVS.
- Can Fork be used throughout the software lifecycle?
- Yes. Fork's threat models adapt to your application's current stage, from planning and design through maintenance, so every assessment stays contextually relevant as the application — and the risk landscape around it — continues to evolve.
- Is there a service beyond the self-serve platform?
- Yes. Threat Modeling as a Service pairs Fork with VerSprite's security champions for portfolio-wide modeling, expert-led training, and human-readable or API-integrated reports, with 1–4 day SLA delivery for teams that want hands-on support.
- What is continuous threat modeling?
- Continuous threat modeling means threat models are built once and kept current automatically as an application changes, rather than produced in a single point-in-time workshop that goes stale the moment the architecture shifts. Fork resurfaces relevant PASTA stages as your application evolves, so the model stays an accurate, living picture instead of a static document.
- How is Fork different from IriusRisk or ThreatModeler?
- Fork is built natively around PASTA as its entire workflow, while IriusRisk and ThreatModeler (now the same company after a January 2026 acquisition) are STRIDE/VAST-first and offer PASTA only as one optional template. Fork also includes a free Community tier and an optional expert-led service, Threat Modeling as a Service, for teams that want hands-on support.
- Is Fork free? How much does Fork cost?
- Fork Community is free — one application threat model, one user, and vulnerability ingestion via SBOM, SARIF, or OVAL, no credit card required. Fork Enterprise starts at $75,000 per year for up to 500 threat models, scaling to $150,000 per year for 500–2,000 models. Fork Enterprise PT is quoted based on your testing needs.
- How is PASTA different from STRIDE?
- STRIDE categorizes threats into six technical types (spoofing, tampering, and so on) and is typically applied per component. PASTA is risk-centric and business-aligned: it ties technical threats back to business impact through a structured seven-stage process, rather than working from a fixed technical checklist alone.