Fork vs. IriusRisk
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
Fork vs. IriusRisk: Which Threat Modeling Platform Fits Your Program?
Fork and IriusRisk both help organizations scale threat modeling, but they are built around different starting points.
Fork is a continuous application threat modeling platform built around PASTA, the seven-stage Process for Attack Simulation and Threat Analysis. It emphasizes business context, relevant threat intelligence, weakness and vulnerability data, attack viability, business impact, residual risk, and an evolving view of application risk.
IriusRisk presents itself as a methodology-agnostic, AI-assisted secure-design and threat modeling platform. It emphasizes architecture diagramming, automated threat and countermeasure generation, reusable security content, developer self-service, compliance support, integrations, and enterprise-wide secure-design workflows.
The better fit depends on what an organization expects threat modeling to accomplish. Teams that want PASTA operationalized as a risk-centric process may favor Fork. Teams that prioritize diagram-led secure design, broad methodology flexibility, and AI-assisted model creation may favor IriusRisk.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
Fork and IriusRisk at a Glance

- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
The Main Difference Between Fork and IriusRisk
Fork begins with risk-centric PASTA analysis.
Fork is designed to move through business objectives, technical scope, application decomposition, threat analysis, weakness and vulnerability analysis, attack modeling, and risk and impact analysis. Its central question is not only “What threats exist?” but “Which realistic attack scenarios matter most to this application and business?”
IriusRisk begins with secure design and architecture.
IriusRisk helps users create or import an architecture, describe components and trust zones, and use rules, content libraries, questionnaires, and AI assistance to generate relevant threats and countermeasures. Its platform is intended to make secure-design work repeatable and accessible across security and engineering teams.
The practical distinction
Fork is more prescriptive about the PASTA process. IriusRisk is more flexible about methodology and offers a strong diagram-led, secure-design operating model. Organizations should decide whether methodological consistency or methodology flexibility is more important to their program.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
Methodology: PASTA Versus a Methodology-Agnostic Platform
How Fork uses PASTA
Fork presents itself as a practical implementation of PASTA. The methodology connects business objectives with technical scope, application architecture, relevant threats, weaknesses, attack scenarios, controls, and business impact. This gives teams an explicit path from context to residual risk.
How IriusRisk approaches methodology
IriusRisk describes itself as methodology-agnostic. Organizations can configure diagrams, components, trust zones, risk patterns, workflows, permissions, content, and rules to align the platform with their preferred process. This can suit enterprises that already have an established threat modeling method or need different approaches across teams.
Which approach is better?
A prescriptive PASTA foundation can improve consistency when the organization wants a risk-centric process tied to business impact and realistic attack analysis. A methodology-agnostic platform can provide more flexibility when teams have existing practices, regulatory requirements, or architecture standards they do not want to replace.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
Business Context and Risk Prioritization
Fork’s risk-centric emphasis
Fork highlights business impact analysis, industry-focused threat intelligence, a proprietary residual risk formula, quality gates, real-time vulnerability data, and the ability to prioritize risks that are both likely and consequential. Its value proposition depends on connecting security findings to application and business context.
IriusRisk’s secure-design emphasis
IriusRisk focuses on identifying design risks, generating countermeasures, surfacing compliance gaps, and helping teams make earlier security decisions. Its AI-powered Smart Views are positioned to help users focus on critical threats, mitigation, and compliance actions.
Buyer consideration
Ask both vendors to demonstrate the full reasoning behind a priority. The platform should show which context, threat, weakness, control, likelihood, feasibility, and impact factors influence the result. A score without explainable inputs is not enough for an enterprise risk decision.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
Architecture Modeling and Application Decomposition
Fork
Fork supports application and component-level threat modeling and aligns application decomposition with PASTA. Its documentation emphasizes attack surface, application lifecycle, threat libraries, vulnerability data, business context, and evolving application risk.
IriusRisk
IriusRisk offers integrated Draw.io functionality, data-flow diagrams, trust zones, questionnaires, templates, component libraries, and imports from architecture and infrastructure-as-code sources. It can generate threats and countermeasures from the architecture represented in the model.
AI-Assisted Threat Modeling
Fork automation and intelligence
Fork emphasizes threat intelligence, industry-specific libraries, vulnerability ingestion, automated taxonomy mapping, risk calculations, quality gates, notifications, and continuous synchronization. Buyers should verify which current Fork functions use generative AI versus deterministic rules, correlations, and external intelligence.
IriusRisk Jeff AI
IriusRisk’s Jeff AI can use prompts, documentation, user stories, meeting transcripts, code, or images to assist with diagram and threat-model creation. IriusRisk states that users remain in control, and its Smart Views can focus attention on mitigation, compliance, or critical threats.
Buyer consideration
AI speed should not be the only selection criterion. Ask how outputs are grounded, reviewed, versioned, explained, approved, and audited. Determine whether AI recommendations can be traced to architecture, threat sources, controls, and risk assumptions.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
Threat Intelligence, Libraries, and Taxonomy Mapping
Fork
Fork documents automated correlation across sources and taxonomies including CWE, CVE with EPSS, CAPEC, MITRE ATT&CK, D3FEND, and OWASP ASVS. It also emphasizes industry-focused threat libraries and real-time threat intelligence.
IriusRisk
IriusRisk uses a rules engine, reusable threat and countermeasure libraries, risk patterns, standards, and compliance content. It also provides specialized content, including resources for AI and machine learning systems.
Buyer consideration
Compare content quality rather than content volume. Ask how often libraries are updated, whether sources are visible, how false positives are handled, whether proprietary content can be added, and how changes affect existing models.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
Vulnerability Data and Security Tool Integration
Fork
Fork documents integrations or planned integrations with tools such as ServiceNow, Veracode, GitLab Secure, OpenCTI, Archer, Mandiant, Qualys, and Tenable. It is designed to ingest SAST, DAST, SCA, IaC, secret-detection, vulnerability, SBOM, OVAL, penetration-testing, and threat-intelligence data depending on edition and connector availability.
IriusRisk
IriusRisk documents integrations with development, issue tracking, scanning, architecture, cloud, and infrastructure-as-code workflows. It emphasizes two-way issue tracking, architecture imports, and exporting threat-model data to other security or business systems.
Buyer consideration
Ask for a live demonstration of the exact integration you need. Confirm what data enters the model, what can be written back, how conflicts are resolved, how frequently synchronization occurs, and whether the integration is generally available or planned.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
Continuous Threat Modeling
Fork
Continuous application threat modeling is Fork’s primary positioning. The platform is designed to build a model once and evolve it as applications, vulnerabilities, intelligence, controls, and risk conditions change. Fork also documents notifications, quality gates, and historical risk tracking.
IriusRisk
IriusRisk describes its models as living and iterative. Architecture updates, integrations, workflow changes, countermeasure status, AI analysis, and team collaboration can keep the model aligned with development.
Buyer consideration
Both vendors use continuous-modeling language. Require each to demonstrate how a model changes after an architecture update, a new vulnerability, a closed ticket, a changed security control, and new threat intelligence. Continuity should be observable, not just a marketing description.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
Collaboration, Governance, and Enterprise Scale
Fork
Fork Enterprise documents unlimited applications and threat models, unlimited team members and organizational units, granular access controls, permissions, SSO through SAML or OIDC, audit logs, edit history, and access to integrations.
IriusRisk
IriusRisk documents centralized workflows, permissions, reusable content, collaboration, self-service threat modeling, portfolio scale, training, and integrations intended to distribute secure-design work beyond a small central security team.
Buyer consideration
Compare approval workflows, ownership, role design, separation of duties, audit evidence, reusable patterns, exceptions, risk acceptance, reporting, and administration. Enterprise scale is an operating-model question, not merely a license limit
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
Community and Entry-Level Options
Fork Community
Fork offers a free Community option for one application and one user, with vulnerability ingestion through SBOM or OVAL listed among its core capabilities.
IriusRisk Community Edition
IriusRisk offers a free Community Edition and promotes access to Jeff AI, training, diagrams, selected libraries, and threat-modeling capabilities.
Buyer consideration
Community editions are useful for learning workflows, but they may not represent enterprise governance, integration, deployment, support, or scale. Use them to evaluate usability and modeling logic, then validate enterprise requirements separately.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
Deployment, Data Control, and Security
Fork
Fork is described as a SaaS platform. Enterprise buyers should confirm hosting regions, private deployment options, encryption, data retention, backup, access controls, logging, export, and security assurance directly with Fork.
IriusRisk
IriusRisk publicly presents multiple hosting locations and on-premises availability. Buyers should confirm which options apply to their required edition, geography, architecture, and regulatory obligations.
Buyer consideration
Threat models can reveal sensitive architecture, weaknesses, controls, and business impact. Treat platform security and data portability as selection criteria equal to product functionality.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
Services and Adversarial Validation
Fork and VerSprite
Fork Enterprise PT extends the platform with on-demand security testing and exploitability analysis. VerSprite also offers Threat Modeling as a Service for portfolio-wide modeling, training, managed delivery, and remediation guidance.
IriusRisk
IriusRisk offers onboarding, training, documentation, and enterprise support resources. Buyers requiring expert-led facilitation, model validation, or adversarial testing should confirm the current services available through IriusRisk and the combined ThreatModeler organization.
Buyer consideration
Software can standardize and accelerate a process, but high-risk systems may still require experienced threat modelers and offensive-security practitioners to challenge assumptions and validate attack viability.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
How the ThreatModeler Acquisition of IriusRisk Affects This Comparison
ThreatModeler announced its acquisition of IriusRisk on January 8, 2026. IriusRisk continues to maintain its own product website and documentation, while ThreatModeler has described the transaction as bringing together two enterprise threat modeling platforms.
The acquisition does not, by itself, determine whether IriusRisk is a good or poor choice. It does create additional due-diligence questions for buyers:
- Will IriusRisk remain a distinct platform?
- How will the IriusRisk and ThreatModeler roadmaps be coordinated?
- Will licensing, packaging, support, or deployment options change?
- Will customers need to migrate models, content, integrations, or workflows?
- Which product will receive new capabilities first?
- How will data, support, and account responsibilities be managed across the combined organization?
- What contractual protections exist if the product strategy changes?
Organizations that prefer an independent platform built specifically around PASTA may include Fork in their evaluation. The comparison should remain focused on methodology, capabilities, operating model, and verified customer requirements rather than speculation about the acquisition.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
When Fork May Be the Better Fit
Fork may be the stronger candidate when the organization:
- Wants a platform explicitly structured around all seven stages of PASTA
- Needs business impact and residual risk to drive prioritization
- Wants to connect threat modeling with vulnerability data and threat intelligence
- Needs to examine realistic attack paths and exploitability
- Wants threat models to evolve continuously with application and security data
- Values integrated offensive-security testing or expert-led threat modeling services
- Prefers an independent threat modeling product outside the ThreatModeler and IriusRisk combination
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
When IriusRisk May Be the Better Fit
IriusRisk may be the stronger candidate when the organization:
- Prioritizes diagram-led secure-design workflows
- Wants integrated Draw.io functionality and broad architecture import options
- Needs a methodology-agnostic platform that can adapt to established internal practices
- Wants generative AI assistance for creating diagrams and threat models
- Needs reusable content, rules, countermeasures, and compliance mappings
- Plans to distribute self-service threat modeling across development and engineering teams
- Requires on-premises or specific regional hosting options and confirms those options are available
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
Questions to Ask During a Fork or IriusRisk Demonstration
- Show how the platform moves from business context to prioritized risk.
- Demonstrate how a new application architecture is created or imported.
- Explain which methodology drives the workflow and how it can be changed.
- Show why a specific threat applies to a component or data flow.
- Demonstrate how weaknesses and vulnerability findings alter the threat model.
- Show an end-to-end attack scenario and the controls that interrupt it.
- Explain the risk formula and every factor influencing the score.
- Demonstrate how residual risk changes after a control is implemented.
- Show how the model changes after an architecture update.
- Demonstrate the exact integrations required by the organization.
- Show audit history, approvals, permissions, and risk-acceptance workflows.
- Explain how AI-generated content is grounded, reviewed, and governed.
- Show what data can be exported if the organization changes platforms.
- Explain current deployment, hosting, retention, and data-security options.
- Provide the current roadmap and explain how the IriusRisk acquisition affects it.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
Fork vs. IriusRisk: Final Assessment
Fork and IriusRisk address overlapping enterprise threat modeling requirements, but their philosophies are different.
Fork operationalizes PASTA as a continuous, risk-centric application threat modeling process. Its differentiation is strongest when an organization wants to connect business context, industry threats, weaknesses, vulnerability data, attack scenarios, security controls, and residual risk in one evolving model.
IriusRisk operationalizes secure design through architecture modeling, automated threat and countermeasure generation, reusable content, integrations, AI assistance, and methodology flexibility. Its differentiation is strongest when teams want a diagram-led platform that can distribute secure-design work across engineering and security users.
The selection should be based on a representative application and a documented evaluation scorecard. Ask each vendor to model the same architecture, use the same business context, ingest the same findings, and explain the resulting priorities. The better platform is the one that produces a threat model your teams can understand, defend, maintain, and act on.
Evaluate Fork against your threat modeling requirements
See how Fork applies PASTA to business-aligned, continuous application threat modeling.
Explore Fork
Talk With a Threat Modeling Expert
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
Frequently Asked Questions
What is the main difference between Fork and IriusRisk?
Fork is built around the seven-stage PASTA methodology and emphasizes business context, attack viability, vulnerability correlation, business impact, and residual risk. IriusRisk is methodology-agnostic and emphasizes architecture-led secure design, automated threats and countermeasures, reusable security content, integrations, and AI-assisted model creation.
Is Fork an alternative to IriusRisk?
Yes. Fork is an IriusRisk alternative for organizations seeking a continuous application threat modeling platform built specifically around PASTA. The best fit depends on methodology, architecture workflow, AI requirements, integrations, governance, deployment, and the organization’s approach to risk.
Does IriusRisk support PASTA?
IriusRisk describes its platform as methodology-agnostic, which suggests organizations can configure it around different approaches. Buyers requiring full PASTA execution should ask IriusRisk to demonstrate how all seven PASTA stages are represented, governed, and reported within the platform.
Does Fork support AI threat modeling?
Fork emphasizes automated threat intelligence correlation, industry threat libraries, vulnerability ingestion, taxonomy mapping, risk calculations, and continuous updates. Organizations specifically seeking generative AI features should verify Fork’s current capabilities and roadmap directly with the vendor.
Which platform is better for business-risk analysis?
Fork is explicitly positioned around risk-centric PASTA analysis, business impact, attack feasibility, and residual risk. IriusRisk also supports risk views, threats, countermeasures, and compliance analysis. Buyers should require both platforms to explain their risk calculations using the same representative application.
Which platform is better for architecture diagramming?
IriusRisk has a clearly documented architecture-led workflow with integrated Draw.io functionality, trust zones, data-flow diagrams, components, questionnaires, templates, and imports. Fork supports application decomposition and component-level modeling, but buyers should compare the specific diagramming and import workflow against their architecture practices.
Can Fork and IriusRisk integrate with DevSecOps tools?
Both platforms document integrations with engineering and security workflows. Fork emphasizes vulnerability, AppSec, threat intelligence, and service-management data. IriusRisk emphasizes issue tracking, architecture, infrastructure as code, scanning, and development workflows. Availability and depth should be verified for each required connector.
Are Fork and IriusRisk free?
Both provide limited free entry points. Fork Community supports one application and one user. IriusRisk offers a Community Edition with selected capabilities and access to Jeff AI. Enterprise governance, integrations, support, scale, and deployment options require separate evaluation.
Who owns IriusRisk?
ThreatModeler announced that it acquired IriusRisk on January 8, 2026. IriusRisk continues to maintain product-facing resources. Buyers should confirm the current product roadmap, licensing, support, and integration strategy with the combined organization.
Is Fork independent of ThreatModeler and IriusRisk?
Yes. Fork is a VerSprite product and is independent of the ThreatModeler and IriusRisk organization. It is built around PASTA, which was co-created by VerSprite CEO Tony UcedaVélez and Marco M. Morana.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
Resources
We’re Not a Vendor – We’re Your Security Partner
- Risk-centric security
- True extension of your team
- Executive-level experience