Fork vs. the Field

An Honest Look at Threat Modeling Platforms

Fork, IriusRisk, ThreatModeler, and SD Elements all sell "threat modeling," but they're built on different methodologies, ownership structures, and workflows. Here's how they actually compare.

No spin. Where a competitor does something well, we say so.

A Market That Just Consolidated

In January 2026, ThreatModeler acquired IriusRisk for a reported $100 million-plus, combining what had been the two largest independent threat modeling vendors into a single company. That leaves fewer independent options in a market that now has one dominant, consolidated player.

Fork is built and owned by VerSprite, independent of that combined entity, and built specifically around PASTA rather than as a general-purpose, methodology-agnostic platform. That's the honest starting point for everything below.

Feature-by-Feature Comparison

Based on each vendor's own published materials as of August 2026. Vendor-reported figures are marked as such — verify current specifics directly with each company, since pricing and features change quickly in this market.

Primary Methodology
Fork: PASTA is the core workflow, not an optional template.
IriusRisk: Methodology-agnostic; STRIDE, TRIKE, OCTAVE, and PASTA available as selectable templates.
ThreatModeler: Built around STRIDE plus a proprietary VAST methodology.
SD Elements: Not diagram/methodology-based; generates requirements from a project questionnaire.
Ownership
Fork: Built and owned by VerSprite, independent.
IriusRisk: Acquired by ThreatModeler, January 2026 — now the same company.
ThreatModeler: Acquired IriusRisk, January 2026 — now the same company.
SD Elements: Owned by Security Compass, independent of the ThreatModeler/IriusRisk group.
Free Tier
Fork: Fork Community — free, one application, SBOM/SARIF/OVAL ingestion.
IriusRisk: Community Edition — free, template-based modeling.
ThreatModeler: No published free tier; subscription licensing.
SD Elements: No published free tier; enterprise licensing.
Diagram-Based Modeling
Fork: Yes — a structured threat model per application.
IriusRisk: Yes — automated diagram analysis, plus Draw.io integration.
ThreatModeler: Yes — cloud-native architecture templates for AWS, Azure, GCP.
SD Elements: Not natively; pairs with sibling product Devici for diagramming.
Time to First Model
Fork: Under two hours (Fork's own published figure).
IriusRisk: Vendor reports up to 90% faster than manual methods.
ThreatModeler: Vendor reports up to 10x productivity gains for customers.
SD Elements: Not publicly benchmarked in comparable terms.
Notable Integrations
Fork: ServiceNow, Veracode, GitLab Secure, OpenAI, Tavily, OpenCTI.
IriusRisk: Jira, Azure DevOps, ServiceNow, Draw.io.
ThreatModeler: DevSecOps toolchains, cloud provider templates.
SD Elements: Jira, GitHub, Azure DevOps; Devici for diagramming.
Talk to Our Team

See a live model built on your own application

PASTA Threat Modeling Tools: Who Actually Supports It

"PASTA threat modeling tool" is a narrower search than "threat modeling tool" generally, because most platforms on the market weren't built around it. Here's an honest rundown of where PASTA actually shows up in each product today.

Fork

PASTA is the entire workflow — all seven stages, end to end — built by a team that includes a co-author of the methodology. There's no "select a methodology" step, because PASTA is the product.

IriusRisk (now part of ThreatModeler)

Explicitly lists PASTA as one of several supported methodologies, alongside STRIDE, TRIKE, and OCTAVE, as part of a broader "methodology-agnostic" platform. If your team wants PASTA specifically without other templates in the mix, this is a general-purpose tool adapted to it rather than a PASTA-native one.

ThreatModeler

Built around STRIDE and its own proprietary VAST methodology. No native PASTA workflow is documented in current product materials.

SD Elements

Takes a requirements-and-questionnaire approach rather than a diagram-and-methodology approach, so PASTA (or STRIDE, for that matter) isn't really the frame it operates in.

Generic diagramming tools

Tools like OWASP Threat Dragon or draw.io can be used to sketch a PASTA-style model manually, but they don't provide built-in PASTA automation, stage guidance, or a residual risk calculation.

See It for Yourself

Read more about the PASTA methodology behind Fork, explore the full feature set, or check pricing for your team's size.

See How Fork Compares on Your Own Application

Bring your current tool, your current process, or neither — we'll show you what a PASTA-native model looks like.

Contact Us

30-minute conversation. No commitment required.