IriusRisk is an automated threat modeling platform that utilizes AI to generate threat models from user stories, documentation, and code, significantly reducing modeling time from 80 hours to just 8 hours. The platform enables organizations to integrate security into their development processes, achieving a 203% ROI and $4.9 million in cost savings from remediation avoidance over three years.
Funding
$54.9M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.




Founders
Product
Problem
Organizations face challenges in integrating security into their software development lifecycle (SDLC), leading to delayed deployments and increased remediation costs. Manual threat modeling is time-consuming and requires specialized expertise, creating bottlenecks and hindering agility. Identifying and addressing potential security flaws early in the design phase is critical but often overlooked due to resource constraints and complex processes.
Solution
IriusRisk offers an automated threat modeling platform that enables organizations to shift security left by integrating it directly into the SDLC. The platform uses AI to generate threat models from user stories, documentation, and code, significantly reducing the time required for threat modeling. By automating the threat modeling process, IriusRisk helps development teams identify potential vulnerabilities early in the design phase and implement appropriate countermeasures. The platform's integration capabilities and comprehensive content library facilitate compliance with industry standards and regulatory frameworks, ensuring consistent and repeatable results.
Target Audience
IriusRisk is designed for developers, security teams, and CISOs seeking to integrate security into their SDLC, reduce remediation costs, and ensure compliance with industry standards and regulations.
Features
- AI-powered threat model generation from user stories, documentation, and code
- Automated identification of threats and recommended countermeasures
- Integration with popular development tools such as Jira for seamless workflow integration
- Customizable risk libraries to define organization-specific risk profiles
- Comprehensive content library with industry standards and regulatory frameworks (OWASP, NIST, GDPR, CCPA, HIPAA)
- Bi-directional integration with CI/CD tools, issue trackers, and scanning software
- Support for threat modeling of Infrastructure as Code (IaC)
- Role-based access control and permissions management