Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
IriusRisk is an open Threat Modeling platform that can be used by any development and operations team – even those without prior security training. Whether your organization follows a framework or not, we can work with all the threat modeling methodologies, such as STRIDE, TRIKE, OCTAVE and PASTA. We support organisations in financial services, insurance, industrial automation, healthcare, private sector and more.
IriusRisk is the industry's leading threat modeling and secure design solution in Application Security. With enterprise clients including Fortune 500 banks, payments, and technology providers, it empowers security and development teams to ensure applications have security built-in from the start - using its powerful threat modeling platform.
Whether teams are implementing threat modeling from scratch, or scaling-up their existing operations, the IriusRisk approach results in improved speed-to-market, collaboration across security and development teams, and the avoidance of costly security flaws.
Description
SD Elements helps AppSec teams cope with fast-growing development demands by spelling out which security controls each project needs at the design stage. It follows a Security by Design approach, meaning it looks at architecture, data use, and compliance needs early, identifies relevant risks, and turns them into concrete requirements while changes are still cheap and low-friction. Many teams see security review time drop by 30–50% and fewer late surprises before release.
The platform generates project-specific requirements mapped to standards such as NIST, OWASP, PCI, and ISO, and pairs them with concise implementation guidance developers can act on. This lets small AppSec groups support security for portfolios of 100+ applications without adding headcount, while driving consistent, policy-aligned expectations across teams and products instead of ad hoc checklists.
SD Elements connects to Jira, CI/CD pipelines, and other engineering tools so security work is delivered and tracked in the same systems developers already use. Traceability is a core capability: every requirement is linked to its underlying risk, relevant standards, and evidence of implementation. AppSec leaders and directors get clear views of coverage, posture, and progress across applications, making it easier to reduce risk, support audits, and report meaningful security metrics to senior leadership.
API Access
Has API
Yes
API Access
Has API
Yes
Integrations
GitHub
Yes
Jira Service Management
Yes
ServiceNow
Yes
ThreadFix
Yes
Amazon Web Services (AWS)
Yes
Archer
No
CA Flowdock
Yes
Devici
No
Digital.ai Application Protection
No
FortifyData
Yes
Integrations
GitHub
Yes
Jira Service Management
Yes
ServiceNow
Yes
ThreadFix
Yes
Amazon Web Services (AWS)
No
Archer
Yes
CA Flowdock
No
Devici
Yes
Digital.ai Application Protection
Yes
FortifyData
No
Pricing Details
Enterprise licences can vary depending on integrations and threat modeling requirements. Please do contact us for a more detailed breakdown. Pricing is done by threat model and not by user to keep costs manageable and predictable.
Free Trial
No
Free Version
Yes
Pricing Details
Please contact us for pricing
Free Trial
No
Free Version
No
Deployment
Web-Based
Yes
On-Premises
Yes
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Customer Support
Business Hours
Yes
Live Rep (24/7)
Yes
Online Support
Yes
Customer Support
Business Hours
Yes
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
Yes
Live Training (Online)
Yes
In Person
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
Yes
Vendor Details
Company Name
IriusRisk
Country
Spain
Website
www.iriusrisk.com/
Vendor Details
Company Name
Security Compass
Founded
2004
Country
Canada
Website
www.securitycompass.com/sdelements/
Product Features
Risk Management
Alerts/Notifications
Yes
Auditing
Yes
Business Process Control
Yes
Compliance Management
Yes
Corrective Actions (CAPA)
Yes
Dashboard
Yes
Exceptions Management
Yes
IT Risk Management
Yes
Internal Controls Management
Yes
Legal Risk Management
No
Mobile Access
No
Operational Risk Management
Yes
Predictive Analytics
Yes
Reputation Risk Management
No
Response Management
No
Risk Assessment
Yes
Product Features
Risk Management
Alerts/Notifications
No
Auditing
No
Business Process Control
No
Compliance Management
No
Corrective Actions (CAPA)
No
Dashboard
No
Exceptions Management
No
IT Risk Management
No
Internal Controls Management
No
Legal Risk Management
No
Mobile Access
No
Operational Risk Management
No
Predictive Analytics
No
Reputation Risk Management
No
Response Management
No
Risk Assessment
No