Threat modeling, guided by AI.
Two assessments in one workspace: STRIDE threat models for connected products, scored per ETSI TS 102 165-1, and IEC/EN 62443 risk analysis for industrial and OT environments — zones and conduits, ICS threats and target security levels. The assistant drafts, scores and explains every step.
Product threat modeling
For connected products and embedded devices, aligned to prEN 40000-1-2 §6.
- · STRIDE enumeration per asset
- · ETSI TS 102 165-1 likelihood × impact scoring
- · MITRE EMB3D threat and mitigation catalogue
- · Risk register, criteria, treatment and §6.x coverage report
OT risk analysis (IEC/EN 62443)
For plants, utilities and industrial control systems, following the 62443-3-2 flow.
- · Asset inventory by Purdue level with C/I/A ratings
- · Zones & conduits, initial and detailed risk
- · Threats from MITRE ATT&CK for ICS, countermeasures from D3FEND
- · Target Security Levels per foundational requirement, plus sign-off log
How it works
Paste a product description or a site and process overview. The assistant interviews you for what is missing.
Scope, assets, zones, threats and risk ratings are proposed for you — you review and adjust.
A print-ready assessment report with the full risk register, treatment decisions and review log.
Paste a product description. The assistant interviews you for missing context.
Spoofing, Tampering, Repudiation, Info disclosure, DoS, Elevation — grouped by asset.
Likelihood × Impact (1–5), with residual risk once mitigations are in place.
Group OT assets into zones by Purdue level and document every conduit between them.
Pick ICS techniques from the MITRE matrix, or let the assistant propose the relevant ones.
SL-T 1–4 per zone across the seven foundational requirements of 62443-3-3.
Who it's for
Simple pricing
Both modules — product threat modeling and OT risk analysis — are included in every plan. Start free with 1 product and 1 saved assessment. Upgrade to Pro at €250/month for more products, PDF export and higher AI limits.