An Honest Look at Threat Modeling Platforms
Fork, IriusRisk, ThreatModeler, and SD Elements all sell "threat modeling," but they're built on different methodologies, ownership structures, and workflows. Here's how they actually compare.
No spin. Where a competitor does something well, we say so.
In January 2026, ThreatModeler acquired IriusRisk for a reported $100 million-plus, combining what had been the two largest independent threat modeling vendors into a single company. That leaves fewer independent options in a market that now has one dominant, consolidated player.
Fork is built and owned by VerSprite, independent of that combined entity, and built specifically around PASTA rather than as a general-purpose, methodology-agnostic platform. That's the honest starting point for everything below.
It's not the only consolidation in this space. Security Compass, the company behind SD Elements, acquired Devici in June 2025, pairing collaborative diagram-based modeling with SD Elements' requirements engine under one roof. Between the two deals, four of the names most commonly cited alongside Fork now sit inside just two parent companies.
Based on each vendor's own published materials as of August 2026. Vendor-reported figures are marked as such — verify current specifics directly with each company, since pricing and features change quickly in this market.
See a live model built on your own application
Two newer names come up often alongside the big four above. Neither is PASTA-based, but both are worth knowing where they sit.
A diagram-focused, collaborative threat modeling tool built around STRIDE and LINDDUN, with a free tier for up to three models and three users. Devici was acquired by Security Compass in June 2025 and now integrates directly with SD Elements, so a Devici diagram can feed straight into SD Elements' requirements engine. No native PASTA support is documented.
An AI-native Security Design Review platform, founded by former Razorpay and Synopsys security leaders. Seezo ingests existing PRDs, Jira epics, and design docs to generate STRIDE-based threat models and security requirements before code is written, with findings routed into Jira, Slack, or Google Docs. Like Devici, it's built around STRIDE rather than PASTA.
"PASTA threat modeling tool" is a narrower search than "threat modeling tool" generally, because most platforms on the market weren't built around it. Here's an honest rundown of where PASTA actually shows up in each product today.
PASTA is the entire workflow — all seven stages, end to end — built by a team that includes a co-author of the methodology. There's no "select a methodology" step, because PASTA is the product.
Explicitly lists PASTA as one of several supported methodologies, alongside STRIDE, TRIKE, and OCTAVE, as part of a broader "methodology-agnostic" platform. If your team wants PASTA specifically without other templates in the mix, this is a general-purpose tool adapted to it rather than a PASTA-native one.
Built around STRIDE and its own proprietary VAST methodology. No native PASTA workflow is documented in current product materials.
Takes a requirements-and-questionnaire approach rather than a diagram-and-methodology approach, so PASTA (or STRIDE, for that matter) isn't really the frame it operates in.
Both are built around STRIDE (Devici also supports LINDDUN). Neither documents native PASTA support as of this writing.
The three most-used free and open-source options. All three are built around STRIDE (Threat Dragon also supports LINDDUN and CIA), and none offer built-in PASTA automation, stage guidance, or a residual risk calculation. See the section below for more on each.
Not every team needs a commercial platform. Here's where the free and open-source options stand.
An open-source, MIT-licensed toolkit that models architecture as a YAML file rather than a diagram, then runs a rule engine against it to generate risks, mitigation advice, and data-flow diagrams. It runs via command line, Docker, or as a REST server — a fit for DevSecOps teams that want threat models version-controlled alongside code, at the cost of needing technical proficiency to maintain the model and its rules.
A free, open-source diagramming tool that runs as a web or desktop app, supporting STRIDE, LINDDUN, CIA, and a few other frameworks, with a rule engine that auto-generates threats and mitigations. It's widely considered the most-adopted open-source option and a reasonable first stop for teams starting without budget for a commercial platform.
A free, open-source, Windows desktop application built around STRIDE, and a component of Microsoft's own Security Development Lifecycle. It creates threat models from data-flow diagrams and integrates with IriusRisk and Black Duck Seeker, but is limited to Windows and doesn't run as a web app.
Read more about the PASTA methodology behind Fork, explore the full feature set, or check pricing for your team's size.
Bring your current tool, your current process, or neither — we'll show you what a PASTA-native model looks like.
30-minute conversation. No commitment required.