ThreatModeler
AI-assisted, DevSecOps-integrated threat modeling platform that recently combined with IriusRisk under Invictus Growth Partners ownership.
Visit Website ↗ + Add to CompareOverview
ThreatModeler provides a threat modeling platform that lets development and security teams build and maintain structured threat models of applications and cloud environments as part of the software development lifecycle, rather than as a one-off design-review exercise. The platform uses generative and adaptive AI to help identify risks and recommend mitigations directly against architecture diagrams, aiming to make threat modeling a continuous, code-integrated practice rather than a periodic manual whiteboarding session, which is where most organizations’ threat modeling programs stall.
Founded in 2010 and headquartered in Jersey City, New Jersey, ThreatModeler raised a $60 million round in 2024 led by Invictus Growth Partners, with continued participation from earlier investors Inveready Asset Management and Paladin Capital Group. That capital funded ThreatModeler’s combination with IriusRisk, another established threat modeling vendor, consolidating two of the category’s more recognized platforms under common ownership, with Invictus as majority owner.
The IriusRisk combination is a genuine consolidation of category leadership rather than a distressed acquisition, both companies were independently viable threat modeling vendors beforehand, giving the combined entity meaningfully more scale and customer base than either had alone, while raising the usual integration questions that follow any merger of competing product lines.
Innovation Matrix Assessment
Has continued layering generative and adaptive AI onto its core threat modeling engine and executed a significant inorganic move (the IriusRisk combination) rather than remaining static on its original architecture.
Covers design-to-code-to-cloud threat modeling across common architecture and cloud patterns, and the IriusRisk combination broadens its combined feature set and customer-support footprint.
A $60M round in 2024 led by Invictus Growth Partners, plus continued backing from Inveready and Paladin Capital, and the subsequent IriusRisk combination are independently reported and represent real, substantial capital and category consolidation.
Threat modeling as a discipline is well-established rather than novel, and the IriusRisk merger is a consolidation of two existing category leaders rather than a fundamentally new approach to the problem.
Long operating history (since 2010) and continued investor backing through multiple rounds suggest sustained customer value, but no independent, named case study or third-party benchmark of threat-detection accuracy was found.
Shift-left, DevSecOps-integrated threat modeling remains a recognized need as organizations try to catch design-level security flaws before they reach production, and consolidation with IriusRisk increases the combined platform's relevance and scale.
Why CISOs Should Care
Provides an established, well-funded platform for embedding threat modeling into the SDLC at scale, now backed by the combined customer base and capability of ThreatModeler and IriusRisk.
What Makes It Different
One of a small number of dedicated threat modeling platforms, now consolidated with a former competitor (IriusRisk) rather than competing against it, giving it outsized scale in a narrow category.
The Matrix Verdict
60/100 — INCREMENTAL INNOVATOR
A well-capitalized, established threat modeling platform that just consolidated with a direct competitor; solid fundamentals and real scale, though the category itself is mature rather than newly disruptive.
Editorial Note: Claims vs. Verified Findings
The $60M funding round, investor list, and IriusRisk combination are independently reported by multiple financial and trade press outlets (Yahoo Finance, Rimon Law, Paladin Capital Group); no vendor efficacy claims beyond general platform descriptions were treated as verified fact.
Sources
Alternatives to ThreatModeler
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…