Continuous Application Threat Modeling at Scale

Empower your security teams with continuous, data-driven threat assessments using proven PASTA methodology.

by VerSprite

Risk centric threat modeling under two hours

Identify risks that are most likely to happen and which create the biggest impact. Harnesses our industry-focused threat libraries and integrate real-time vulnerability data and threat intelligence.

Threat-Informed Defense
Stay ahead of evolving risks with up-to-date, industry-specific threat insights forming a solid foundation for your security strategy.
Proprietary Residual Risk Formula
Ensure relevant threats are quantified accurately and mitigated effectively.
Quality Gates
Enforce rigorous security standards at every stage of the threat modeling process, ensuring consistent, high-quality assessments.
Business Impact Analysis
Gain insight into how fundamental security pillars are affected and understand the potential financial implications of data breaches and downtime to your organization.

A single pane of glass for security insights

Unveil a new perspective on your application's security posture with our unified view. Transform intricate threat data into actionable insights, by merging relevant industry threats with your application's attack surface, and cyber threat intelligence.

Integrated Industry Taxonomies
Our platform automatically correlates threat data with trusted frameworks and standards from MITRE and OWASP including CWE, CVE with EPSS, CAPEC, ATT&CK, D3FEND and ASVS to drive targeted mitigations and actionable insights.
On-Demand Security Testing
Substantiate the viability of potential threats by requesting targeted testing of specific weaknesses, vulnerabilities, and attack patterns directly from your threat models.
Collaborative Workflows
Empower your security and product teams with integrated workflows that allow you to dismiss items, create custom entries and relationships, all in real-time.

Threat modeling from Sprint 1

Harnesses the proven benefits of threat modeling, enabling your teams to identify and integrate security-driven design principles directly into your software from day one.

Relevant in every stage
Adapt your threat models to your application's current lifecycle stage - from planning and design to maintenance, ensuring every assessment is contextually applicable and practical.
Build once, evolve continuously
Develop your threat model at the outset and update it as your application progresses, keeping your security approach focused on the evolving risk landscape.
Threat Modeling for Every Role
Built on threat modeling principles that streamline workflows for diverse stakeholders, from product teams and security experts to business operations.

Integrations

Supercharge your threat modeling process by integrating Fork with your existing AppSec tooling.

ServiceNow
ServiceNow
Automatically sync threats and risk metrics to ServiceNow.
Veracode
Veracode
Integrate SCA, SAST, and DAST findings into your threat models.
GitLab Secure
GitLab Secure
Integrate SAST, DAST, SCA, IaC and Secret Detection findings from GitLab Secure into your application threat models.
OpenCTI
OpenCTI
Source real-time threat intelligence information from OpenCTI.
Archer
Archer
Sync threat insights and risk data, streamlining risk management.
Mandiant
Mandiant
Embed real-time threat intelligence and incident response data into your threat models.
Qualys
Qualys
Ingest your vulnerability scans and compliance reports.
Tenable
Tenable
Import continuous vulnerability assessments and asset risk scores.
Checkmarx
Checkmarx
Integrate static code analysis results and secure coding insights.
AltorCloud
AltorCloud
Import cloud security posture management data and compliance reports.

Leverage the PASTA Methodology

Brought to you by a co-author of the Process for Attack Simulation and Threat Analysis (PASTA) methodology, our platform is a practical implementation of the renowned risk-centric, business-aligned threat modeling framework that raises the bar far beyond traditional approaches.

Stages of PASTA Methodology:

Define Objectives
Define Attack Surface
Decompose Application
Threat Analysis
Weakness and Vulnerability Analysis
Attack Modeling and Simulation
Risk and Impact Analysis
Risk-Centric Focus
Prioritizes threats based on business impact rather than just technical vulnerabilities.
Real-World Simulation
Emulates realistic attack scenarios to uncover potential weaknesses.
Comprehensive Analysis
Merges technical and business perspectives for a well-rounded threat assessment.
Iterative Process
Allows continuous refinement and adaptation as threats evolve.
Download the PASTA eBook Learn more about PASTA

Simple Pricing, Powerful Security

Get started for free with threat modeling for a single application, or scale up with our Enterprise subscription designed to secure your entire organization.

Fork Community

Essential threat modeling functionalities designed to help you secure your application for free.

  • One application threat model
  • Single user in the team
  • Vulnerability ingestion via SBOM or OVAL
Sign-up for FREE

Fork Enterprise

Unlock enterprise-grade threat modeling capabilities for scale.

  • Unlimited applications and threat models
  • Unlimited team members and organizational units
  • Access to all integrations
  • Granular access controls and permissions
  • SSO with SAML or OIDC
  • Audit logs and edit history
Contact sales

Fork Enterprise PT

Extend your SaaS subscription with our managed service option.

  • Everything from Fork Enterprise
  • Request on-demand security testing directly from your application threat models
  • In-depth exploitability analysis
  • Real-time status updates
Contact sales

Threat Modeling as a Service

Accelerate your security journey by leveraging our expert security champions to train, build, and manage your threat models.

  • Portfolio-wide application threat modeling
  • Expert-led training sessions
  • 1–4 day SLA delivery times
  • Human-readable reports or API-integrated outputs
  • Ongoing support and remediation guidance

Frequently Asked Questions

Answers to common questions about Fork and the PASTA methodology behind it.


What is Fork?
Fork is a continuous application threat modeling platform built on the PASTA methodology. It gives security teams data-driven threat assessments powered by industry-focused threat libraries and real-time vulnerability data, so risk stays visible as your applications evolve.

What is the PASTA methodology?
PASTA (Process for Attack Simulation and Threat Analysis) is a risk-centric, business-aligned threat modeling framework, co-authored by a member of Fork's team. It runs through seven stages, from defining objectives to risk and impact analysis, prioritizing threats by business impact rather than technical severity alone.

How long does it take to build a threat model in Fork?
Fork's guided automation walks teams through all seven PASTA stages and produces a first threat model in under two hours. Models don't stop there: Fork resurfaces relevant stages automatically as your application changes.

What's included in Fork Community?
Fork Community is free and covers one application threat model for a single team member, with vulnerability ingestion via SBOM, SARIF, or OVAL. It's built for teams getting started with threat modeling on a single application before scaling further.

What does Fork Enterprise add?
Fork Enterprise unlocks unlimited applications and team members, access to all AI capabilities including the Sous-Chef, documentation analysis, DFD generation, the ability to activate multiple threat libraries at once, access to every integration, granular access controls and permissions, SSO via SAML or OIDC, and full audit logs — built for organizations securing an entire application portfolio.

What tools does Fork integrate with?
Fork connects with ServiceNow, Veracode, GitLab Secure, OpenAI, Tavily, and OpenCTI today, correlating findings and threat intelligence directly into your models. It also maps threat data to MITRE and OWASP standards, including CWE, CVE, CAPEC, ATT&CK, D3FEND, MITRE ATLAS, NIST SP 800-53 (Revision 5), and ASVS.

Can Fork be used throughout the software lifecycle?
Yes. Fork's threat models adapt to your application's current stage, from planning and design through maintenance, so every assessment stays contextually relevant as the application — and the risk landscape around it — continues to evolve.

Is there a service beyond the self-serve platform?
Yes. Threat Modeling as a Service pairs Fork with VerSprite's security champions for portfolio-wide modeling, expert-led training, and human-readable or API-integrated reports, with 1–4 day SLA delivery for teams that want hands-on support.