IriusRisk
IriusRisk, headquartered in Huesca, Spain, built an automated threat modeling platform used by application security teams to identify design-level security flaws early in the…
Visit Website ↗ + Add to CompareOverview
IriusRisk, headquartered in Huesca, Spain, built an automated threat modeling platform used by application security teams to identify design-level security flaws early in the software development lifecycle, including an AI assistant (‘Jeff’) that helps generate threat models from natural-language descriptions and diagrams — a capability the company credited with contributing to over 50% annual recurring revenue growth.
ThreatModeler acquired IriusRisk in early 2026, combining the two leading independent automated threat modeling platforms into a single company. IriusRisk’s own website now carries a banner confirming the acquisition and directing existing customers to information about the combined offering.
Innovation Matrix Assessment
Shipped an AI-assisted threat modeling capability that the company credits with driving over 50% annual recurring revenue growth prior to its acquisition.
Gives AppSec teams a concrete way to generate and maintain threat models automatically as software architecture evolves, directly reducing manual security-review workload.
Disclosed 50%+ ARR growth and a consolidating acquisition by direct category competitor ThreatModeler together represent real, if partially self-reported, commercial momentum.
Automated, AI-assisted threat modeling meaningfully speeds up a traditionally manual security-architecture practice, though threat modeling automation itself is an established category with a small number of competitors.
Disclosed ARR growth is a positive signal, though it is company-reported rather than independently audited, and no third-party benchmarking of threat-model accuracy is available.
Shift-left, design-stage security practices like threat modeling remain a durable and growing AppSec priority as software delivery accelerates.
Why CISOs Should Care
Gives application security teams automated, AI-assisted threat modeling that surfaces design-level security flaws before code is written, rather than relying solely on downstream code scanning and penetration testing.
What Makes It Different
Uses an AI assistant to generate threat models directly from natural-language descriptions and architecture diagrams, automating a step that traditionally required manual security-architecture review.
The Matrix Verdict
58/100 — INCREMENTAL INNOVATOR
An established automated threat modeling platform with disclosed 50%+ ARR growth, combined with a direct category competitor (ThreatModeler) to consolidate the space; Meaningful Innovator given the disclosed growth metric and category-consolidating nature of the deal.
Editorial Note: Claims vs. Verified Findings
The acquisition is confirmed directly via a banner on IriusRisk's own website ('IriusRisk is now part of ThreatModeler'); the 50%+ ARR growth figure is a company-disclosed claim from an October 2024 GlobeNewswire release, not independently audited.
Sources
Alternatives to IriusRisk
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…