Buyer's Guide

What the ThreatModeler–IriusRisk merger means for your program.

Two threat modeling platforms are becoming one, and existing IriusRisk customers still don't have a public migration timeline.

Get our evaluation checklist: the questions to ask your account team, what to verify before renewal, and how to compare your options side by side.

Get the checklist

The facts so far

Deal closed January 2026. Nexus launched June 2026. No published migration path for IriusRisk users.

Prefer to see an option first?

Watch a 4-minute walkthrough of DevArmor, from design review to pull-request enforcement. No call needed. Use it as one reference point while you evaluate what comes next for your team.

Corporate consolidation isn't technical continuity

Five questions to ask before you renew.

Before signing another year, get written answers on:
1. How existing threat models and reports will transfer
2. Which integrations (Jira, CI/CD, IaC) will be kept
3. What happens to custom API work
4. The timeline for one unified product
5. How pricing changes at renewal

Whatever you decide, these answers protect your team. The checklist turns them into an RFP-ready template you can send to any vendor, including us.

Free resource

Threat Modeling Platform Evaluation Checklist

RFP questions, a migration-risk checklist and a scoring sheet for comparing platforms.

Built for AppSec leads and GRC teams reviewing their threat modeling vendor after the merger.

Further reading

How the options compare

Our comparison covers integrations, pull-request enforcement and agentic development, including where ThreatModeler/IriusRisk is the better fit.

Read it before your next vendor call.