Fork and IriusRisk both help organizations scale threat modeling, but they are built around different starting points.
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

Fork and IriusRisk at a Glance

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

The Main Difference Between Fork and IriusRisk

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

Methodology: PASTA Versus a Methodology-Agnostic Platform

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

Business Context and Risk Prioritization

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

Architecture Modeling and Application Decomposition

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

AI-Assisted Threat Modeling

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

Threat Intelligence, Libraries, and Taxonomy Mapping

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

Vulnerability Data and Security Tool Integration

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

Continuous Threat Modeling

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

Collaboration, Governance, and Enterprise Scale

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

Community and Entry-Level Options

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

Deployment, Data Control, and Security

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

Services and Adversarial Validation

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

How the ThreatModeler Acquisition of IriusRisk Affects This Comparison

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

When Fork May Be the Better Fit

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

When IriusRisk May Be the Better Fit

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

Questions to Ask During a Fork or IriusRisk Demonstration

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

Fork vs. IriusRisk: Final Assessment

Frequently Asked Questions

Fork, built by VerSprite — whose CEO co-created the PASTA methodology — is structured around the seven-stage PASTA methodology and emphasizes business context, attack viability, vulnerability correlation, business impact, and residual risk. IriusRisk is methodology-agnostic and emphasizes architecture-led secure design, automated threats and countermeasures, reusable security content, integrations, and AI-assisted model creation.

Yes. Fork, developed by VerSprite — whose CEO co-created the PASTA methodology — is an IriusRisk alternative for organizations seeking a continuous application threat modeling platform built specifically around PASTA. The best fit depends on methodology, architecture workflow, AI requirements, integrations, governance, deployment, and the organization’s approach to risk.

IriusRisk describes its platform as methodology-agnostic, which suggests organizations can configure it around different approaches. Buyers requiring full PASTA execution should ask IriusRisk to demonstrate how all seven PASTA stages are represented, governed, and reported within the platform.

Fork emphasizes automated threat intelligence correlation, industry threat libraries, vulnerability ingestion, taxonomy mapping, risk calculations, and continuous updates. Organizations specifically seeking generative AI features should verify Fork’s current capabilities and roadmap directly with the vendor.

Fork is explicitly positioned around risk-centric PASTA analysis, business impact, attack feasibility, and residual risk. IriusRisk also supports risk views, threats, countermeasures, and compliance analysis. Buyers should require both platforms to explain their risk calculations using the same representative application.

IriusRisk has a clearly documented architecture-led workflow with integrated Draw.io functionality, trust zones, data-flow diagrams, components, questionnaires, templates, and imports. Fork supports application decomposition and component-level modeling, but buyers should compare the specific diagramming and import workflow against their architecture practices.

Both platforms document integrations with engineering and security workflows. Fork emphasizes vulnerability, AppSec, threat intelligence, and service-management data. IriusRisk emphasizes issue tracking, architecture, infrastructure as code, scanning, and development workflows. Availability and depth should be verified for each required connector.

Both provide limited free entry points. Fork Community supports one application and one user. IriusRisk offers a Community Edition with selected capabilities and access to Jeff AI. Enterprise governance, integrations, support, scale, and deployment options require separate evaluation.

ThreatModeler announced that it acquired IriusRisk on January 8, 2026. IriusRisk continues to maintain product-facing resources. Buyers should confirm the current product roadmap, licensing, support, and integration strategy with the combined organization.

Yes. Fork, built by VerSprite — whose CEO Tony UcedaVélez co-created the PASTA methodology with Marco M. Morana — is independent of the ThreatModeler and IriusRisk organization and is built around PASTA.

ci cd security, devsecops ci/cd, web app pen testing

We’re Not a Vendor – We’re Your Security Partner

  • Risk-centric security
  • True extension of your team
  • Executive-level experience