Fork vs. the Field

An Honest Look at Threat Modeling Platforms

Fork, IriusRisk, ThreatModeler, and SD Elements all sell "threat modeling," but they're built on different methodologies, ownership structures, and workflows. Here's how they actually compare.

No spin. Where a competitor does something well, we say so.

A Market That Just Consolidated

In January 2026, ThreatModeler acquired IriusRisk for a reported $100 million-plus, combining what had been the two largest independent threat modeling vendors into a single company. That leaves fewer independent options in a market that now has one dominant, consolidated player.

Fork is built and owned by VerSprite, independent of that combined entity, and built specifically around PASTA rather than as a general-purpose, methodology-agnostic platform. That's the honest starting point for everything below.

It's not the only consolidation in this space. Security Compass, the company behind SD Elements, acquired Devici in June 2025, pairing collaborative diagram-based modeling with SD Elements' requirements engine under one roof. Between the two deals, four of the names most commonly cited alongside Fork now sit inside just two parent companies.

Feature-by-Feature Comparison

Based on each vendor's own published materials as of August 2026. Vendor-reported figures are marked as such — verify current specifics directly with each company, since pricing and features change quickly in this market.

Primary Methodology
Fork: PASTA is the core workflow, not an optional template.
IriusRisk: Methodology-agnostic; STRIDE, TRIKE, OCTAVE, and PASTA available as selectable templates.
ThreatModeler: Built around STRIDE plus a proprietary VAST methodology.
SD Elements: Not diagram/methodology-based; generates requirements from a project questionnaire.
Ownership
Fork: Built and owned by VerSprite, independent.
IriusRisk: Acquired by ThreatModeler, January 2026 — now the same company.
ThreatModeler: Acquired IriusRisk, January 2026 — now the same company.
SD Elements: Owned by Security Compass, independent of the ThreatModeler/IriusRisk group.
Free Tier
Fork: Fork Community — free, one application, SBOM/SARIF/OVAL ingestion.
IriusRisk: Community Edition — free, template-based modeling.
ThreatModeler: No published free tier; subscription licensing.
SD Elements: No published free tier; enterprise licensing.
Diagram-Based Modeling
Fork: Yes — a structured threat model per application.
IriusRisk: Yes — automated diagram analysis, plus Draw.io integration.
ThreatModeler: Yes — cloud-native architecture templates for AWS, Azure, GCP.
SD Elements: Not natively; pairs with sibling product Devici for diagramming.
Time to First Model
Fork: Under two hours (Fork's own published figure).
IriusRisk: Vendor reports up to 90% faster than manual methods.
ThreatModeler: Vendor reports up to 10x productivity gains for customers.
SD Elements: Not publicly benchmarked in comparable terms.
Notable Integrations
Fork: ServiceNow, Veracode, GitLab Secure, OpenAI, Tavily, OpenCTI.
IriusRisk: Jira, Azure DevOps, ServiceNow, Draw.io.
ThreatModeler: DevSecOps toolchains, cloud provider templates.
SD Elements: Jira, GitHub, Azure DevOps; Devici for diagramming.
Talk to Our Team

See a live model built on your own application

Where Devici and Seezo Fit

Two newer names come up often alongside the big four above. Neither is PASTA-based, but both are worth knowing where they sit.

Devici

A diagram-focused, collaborative threat modeling tool built around STRIDE and LINDDUN, with a free tier for up to three models and three users. Devici was acquired by Security Compass in June 2025 and now integrates directly with SD Elements, so a Devici diagram can feed straight into SD Elements' requirements engine. No native PASTA support is documented.

Seezo

An AI-native Security Design Review platform, founded by former Razorpay and Synopsys security leaders. Seezo ingests existing PRDs, Jira epics, and design docs to generate STRIDE-based threat models and security requirements before code is written, with findings routed into Jira, Slack, or Google Docs. Like Devici, it's built around STRIDE rather than PASTA.

PASTA Threat Modeling Tools: Who Actually Supports It

"PASTA threat modeling tool" is a narrower search than "threat modeling tool" generally, because most platforms on the market weren't built around it. Here's an honest rundown of where PASTA actually shows up in each product today.

Fork

PASTA is the entire workflow — all seven stages, end to end — built by a team that includes a co-author of the methodology. There's no "select a methodology" step, because PASTA is the product.

IriusRisk (now part of ThreatModeler)

Explicitly lists PASTA as one of several supported methodologies, alongside STRIDE, TRIKE, and OCTAVE, as part of a broader "methodology-agnostic" platform. If your team wants PASTA specifically without other templates in the mix, this is a general-purpose tool adapted to it rather than a PASTA-native one.

ThreatModeler

Built around STRIDE and its own proprietary VAST methodology. No native PASTA workflow is documented in current product materials.

SD Elements

Takes a requirements-and-questionnaire approach rather than a diagram-and-methodology approach, so PASTA (or STRIDE, for that matter) isn't really the frame it operates in.

Devici and Seezo

Both are built around STRIDE (Devici also supports LINDDUN). Neither documents native PASTA support as of this writing.

Threagile, OWASP Threat Dragon, and Microsoft Threat Modeling Tool

The three most-used free and open-source options. All three are built around STRIDE (Threat Dragon also supports LINDDUN and CIA), and none offer built-in PASTA automation, stage guidance, or a residual risk calculation. See the section below for more on each.

Open-Source and Free Alternatives

Not every team needs a commercial platform. Here's where the free and open-source options stand.

Threagile

An open-source, MIT-licensed toolkit that models architecture as a YAML file rather than a diagram, then runs a rule engine against it to generate risks, mitigation advice, and data-flow diagrams. It runs via command line, Docker, or as a REST server — a fit for DevSecOps teams that want threat models version-controlled alongside code, at the cost of needing technical proficiency to maintain the model and its rules.

OWASP Threat Dragon

A free, open-source diagramming tool that runs as a web or desktop app, supporting STRIDE, LINDDUN, CIA, and a few other frameworks, with a rule engine that auto-generates threats and mitigations. It's widely considered the most-adopted open-source option and a reasonable first stop for teams starting without budget for a commercial platform.

Microsoft Threat Modeling Tool

A free, open-source, Windows desktop application built around STRIDE, and a component of Microsoft's own Security Development Lifecycle. It creates threat models from data-flow diagrams and integrates with IriusRisk and Black Duck Seeker, but is limited to Windows and doesn't run as a web app.

Frequently Asked Questions

What are the alternatives to IriusRisk now that ThreatModeler has acquired it?
Fork, Devici, and Seezo are the main alternatives. Fork is PASTA-native and independently owned by VerSprite. Devici, now owned by Security Compass alongside SD Elements, offers diagram-based STRIDE modeling with a free tier. Seezo is an AI-native design-review platform built for teams that want threat modeling generated from existing PRDs and architecture docs before code ships.
Which threat modeling tools support PASTA?
Fork is PASTA-native — the seven-stage methodology is the entire workflow, built by a team including a PASTA co-author. IriusRisk offers PASTA as one of several selectable templates within a broader, methodology-agnostic platform. ThreatModeler, SD Elements, Devici, Seezo, Threagile, OWASP Threat Dragon, and Microsoft Threat Modeling Tool are all built around STRIDE or other frameworks, with no native PASTA support documented.
How does Fork compare to Devici?
Devici is a diagram-focused, collaborative threat modeling tool built around STRIDE and LINDDUN, with a free tier for small teams and paid tiers for growing programs. Fork is built specifically around PASTA's seven-stage, risk-centric methodology rather than a STRIDE diagram workflow. Devici is now owned by Security Compass, the same company behind SD Elements; Fork remains independently owned by VerSprite.
Is there an open-source alternative to ThreatModeler?
Yes. OWASP Threat Dragon and Microsoft Threat Modeling Tool are both free, open-source diagram tools built around STRIDE, while Threagile takes a code-based approach, modeling architecture as YAML and running automated risk rules. None replicate ThreatModeler's proprietary VAST methodology or cloud-native templates, and none currently support PASTA, so teams often pair them with a commercial platform for methodology depth.

See It for Yourself

Read more about the PASTA methodology behind Fork, explore the full feature set, or check pricing for your team's size.

See How Fork Compares on Your Own Application

Bring your current tool, your current process, or neither — we'll show you what a PASTA-native model looks like.

Contact Us

30-minute conversation. No commitment required.