For IriusRisk Customers
ThreatModeler + IriusRisk. Now Nexus.
The merger of two threat modeling leaders created something neither could build alone. Here's what it means for you — and the answers to the questions you're asking.
What the merger made possible
Two leaders. One thing neither could build alone.
ThreatModeler and IriusRisk had each separately built highly capable platforms for the enterprise. Together, we built what neither could create independently: a single governed platform that connects system architecture to AI, runs continuously across the SDLC, and makes defensible threat modeling accessible to every team. Your decade of work with IriusRisk is foundational to it.
The Secure Design Graph
Over a decade of verified relationships between components, threats, controls, and compliance — consolidated into one connected asset no competitor can rebuild from public sources.
Agentic AI, built in
Three specialized agents that model your architecture, enrich the Graph, and generate reports continuously — with no blank canvas or manual diagramming to start.
Enterprise at scale
MCP server, RBAC, Bring Your Own AI, and 180+ compliance frameworks — all governed, auditable, and built for the way the largest enterprises actually operate.
Your questions
A safe home for your questions.
Everything you need to know about what changes, what doesn't, and what comes next.
Yes. Your immediate post-sale team is not changing right now, so please continue to work with the CSM and TAM you currently rely on. We understand the value of the relationships and institutional knowledge you've built with your team, and as integration moves forward we'll allow adequate time for any necessary training and knowledge transfer.
No. Rather than retiring one product in favor of the other, we're merging the capabilities of both into a single, best-in-class platform — informed by you, our customer advisory board, and the Threat Modeling Connect community. ThreatModeler Nexus is a new agentic platform built on a decade of work from both teams, not a relabel.
Your Customer Success team owns the upgrade conversation and the materials that go with it, working alongside the technical teams who handle the implementation. You always have a single point of contact for the move.
At a high level, the upgrade is designed to preserve the configuration you depend on:
- Custom states (up to 20) and flexible workflow are retained, with new permission overrides.
- Custom fields support regex, conditional display, and actions via the Rules Engine.
- Enhanced RBAC governs custom field permissions and project collaboration controls.
- Threat and Security Requirement data mapping is consolidated (Security Requirement is the term used in the platform for what you may know as a countermeasure).
- Multiple ALM integrations can be configured for a single project.
Your CSM will share the detailed compatibility guide and release notes as part of your upgrade conversation.
No. Migration will not be forced. Existing IriusRisk customers follow a phased upgrade path, and each customer is assessed individually based on configuration complexity. When you decide to upgrade, your Customer Success Manager coordinates the process with you and the technical teams.
Continue working with your existing Customer Success Manager or account contact — they're your best route for anything specific to your environment or upgrade. Media and analyst inquiries can be directed to marketing@threatmodeler.com.
Over the coming months we're building a unified, comprehensive knowledge base, academy, and community program that bring together the best of both teams. You'll have access to everything you need to use every aspect of the platform, and the ThreatModeler and Threat Modeling Connect communities keep growing rather than fragmenting.
All active engagements continue as planned. The same teams, timelines, and commitments remain in place, and there's no disruption to in-flight work.
Your existing security controls, data protection practices, and compliance commitments remain in place. If any changes are considered in the future, they'll be communicated clearly and implemented with appropriate safeguards.
For now, everything continues to function as it does today — including your integrations, departments, groups, and users. As we progress on merging the two platforms, we'll work directly with you to ensure a smooth transition.
No. Both products already support importing each other's formats, and we will ensure no degradation of data as our platforms merge.
Both products already support importing each other's formats. Providing a simple upgrade path to the combined platform, with your existing threat modeling work kept intact, is a top priority. You won't be left to port everything over on your own.
Yes. Your current avenues for contacting support, along with your service levels and SLAs, remain the same as we begin merging our internal systems. Our goal is for your support experience to maintain the same high quality you expect.
No. This does not change your current licensing model. Your existing contracts and agreements remain intact.
Yes. Bring Your Own AI is a built-in capability. You can connect your own model, including frontier models, and the deterministic framework governs the output regardless of which model responds — so AI use stays inside your enterprise policy.
Yes. Outputs are deterministic and grounded in the Secure Design Graph: the same question produces the same governed answer every time, with no variance between sessions. Every output traces back to the same source of truth as the model itself, making it defensible in a compliance or audit conversation.
No capability is lost. The AI is no longer a separate assistant you have to invoke — it's built directly into the platform, available at every step, as three specialized agents that map systems, enrich the Secure Design Graph, and generate reports. Everything you relied on is still there, now deeper, more reliable, and governed by the Graph with consistent, traceable outputs.
You're getting an evolution of the platform you already use, with four headline additions:
- Three integrated AI agents: System Mapping, Graph, and Reporting — working directly on the Secure Design Graph with deeper, more governed capabilities than the assistants they replace.
- The Secure Design Graph: a connected asset model representing over a decade of curated security knowledge, mapping components, threats, controls, and compliance requirements.
- Enterprise governance: granular RBAC, SSO/SAML integration, full audit trails, and Bring Your Own AI support.
- Expanded pipeline integration: the MCP Server, connecting threat modeling directly to IDEs and CI/CD pipelines.
Still have a questions?
Can't find the answer to your question? Contact us and we'll get back to you as soon as possible!
What this means for you
The short version: nothing you rely on breaks.
The transition to ThreatModeler Nexus is designed to be seamless. Your subscription, your team, and your work product are protected. You gain a more capable platform — on a timeline we set together.
01
Your license is unchanged
This affect your current subscription or your licensing model.
02
Your team stays the same
Keep working with the same CSM, TAM, and support contacts you rely on today. SLAs are unchanged.
03
Your work carries over
Your existing models, content, and configurations move with you — with no degradation of data.
04
Migration is never forced
Each customer is assessed individually. You upgrade when it's right for you, with CS managing the process.