From first concept to end of life.
The security lifecycle, managed.
Concept, development, production, operations, decommission — every phase in one platform. TARA is one module of many, and every decision leaves automotive teams traceable, audit-ready evidence.
- Tier-1 supplier-grade
- Traceable to every clause
- Tenant-isolated data
CONCEPT
Built for the regulated stack.
- ISO/SAE 21434
- UNECE R155
- UNECE R156
- ISO 26262
- ASPICE
- IEC 62443
- TISAX
Automotive cybersecurity teams are drowning in spreadsheets.
R155 entered into force in 2024 across UNECE members. Every type-approved vehicle now needs a Cybersecurity Management System spanning concept, development, production, and post-production phases.
The reality on most programs: TARA lives in branched Excel workbooks, attack trees in Visio, scenarios in Word, reviews in email. Nothing reconciles. Nothing audits.
SecForge SPLM is one structured workbench for the entire ISO/SAE 21434 lifecycle — built so an Officer, a Manager, and an Engineer all see the same truth.
- Before14 Excel files per programAfter1 workbench
- BeforeManual mapping to R155 §AfterAuto-traced
- BeforeReview by emailAfterTickets with state machine
- BeforeReports in WordAfterOne-click export
One traceable thread, from concept to decommission.
Five phases, one continuous chain of evidence. Every work product carries into the next phase — nothing gets re-typed, nothing gets lost between gates.
Six modules, one continuous lifecycle.
Each module owns a phase of ISO/SAE 21434 and hands its evidence to the next. TARA is one link in the chain, not the whole product.
TOE & asset modeling
Draw the item under analysis on a canvas: ECUs, buses, assets, and their CIA properties, versioned per program.
Damage & threat scenarios
Rate every damage scenario on safety, financial, operational, and privacy impact, then link the threats that cause it.
Attack trees
Break each threat into AND/OR steps and score attack feasibility, so risk rests on evidence instead of opinion.
Risk assessment & treatment
Impact times feasibility on a matrix you configure. Accept, reduce, or transfer — and derive the security goals that follow.
Review ticketing
Phase gates from CSPR to CSAR. Findings become tickets, decisions become snapshots, and nothing advances unsigned.
Question library
Over 170 review questions, versioned and editable, so every audit asks the same thing the same way.
Watch a program move through the lifecycle.
One vehicle program, start to finish: model the TOE, run the TARA, clear the phase gate, and export the evidence.
Built for the way automotive cybersecurity teams actually work.
Each role gets a workspace tuned to their decisions — and they all see the same evidence underneath.
Platform Admin
Owns the tenant. Provisions teams, organizations, and access.
- Tenant configuration
- User & role management
- Audit logs
- Provision tenants and organizations
- Assign roles and access scopes
- Review the audit log weekly
Cybersecurity Officer
Sets policy. Signs off on dossiers. Owns standards alignment.
- Org-level dashboards
- Policy gates
- Compliance posture
- Approve policy and phase gates
- Sign off release dossiers
- Track compliance posture across programs
Cybersecurity Manager
Runs the program. Coordinates milestones, reviews, supply chain.
- Milestone tracking
- Review orchestration
- Supply-chain CS
- Plan milestones and review cycles
- Chase supplier cybersecurity agreements
- Report program risk to the officer
Cybersecurity Engineer
Ships the analysis. TOE, threats, attack trees, security goals.
- TARA modeling
- Attack tree authoring
- Security concepts
- Model the TOE and its assets
- Author attack trees, rate feasibility
- Derive security goals and requirements
Designed against the standards your team is already chasing.
Every artifact in SecForge SPLM traces back to a clause. Evidence packs export ready for type approval.
ISO/SAE 21434
Coverage of §8 (Concept) through §10 (Cybersecurity Validation). Every artifact in the workbench traces back to a clause.
UNECE R155
Annex 5 threat categories pre-mapped. CSMS evidence packs export-ready for type approval.
UNECE R156
Software update governance: version traceability, OTA campaign manifest, post-production change auditing.
- ISO/SAE 21434 §9
Concept phase
Item definition, cybersecurity goals and the security concept exported as one linked, reviewer-signed work product.
- ISO/SAE 21434 §15
Threat analysis and risk assessment
Damage scenarios, threat scenarios, attack feasibility and risk values, each traced back to the asset that produced it.
- UNECE R155 Annex 5
Threat mitigation coverage
Every Annex 5 threat pre-mapped to your scenarios, with uncovered entries flagged before the approval audit.
- UNECE R156
Software update management
Update campaign manifests, RXSWIN-linked configuration records, and a post-production change history that survives audit.
Sits alongside the systems you already trust.
No data lock-in. Every artifact exports as ReqIF, xlsx, or JSON. SSO via your existing IdP.
Built like the systems you're shipping it for.
Tenant-isolated by JWT. Audited end-to-end. Hosted in your region.
Read the full trust center- ActiveTC-01
Tenant-isolated data
Every query filtered by JWT-bound tenant ID. No cross-tenant joins exist in the codebase.
- ActiveTC-02
SSO via Keycloak / OIDC
Production SSO with Microsoft Entra, Okta, Auth0, and Google Workspace.
- ActiveTC-03
Full audit trail
Every state change snapshotted with author, timestamp, and before/after diff.
- EU · USTC-04
EU + US data residency
Pick your region at provisioning. Frankfurt and Virginia available; APAC on roadmap.
- TC-05
SOC 2 Type II in progress
Audit period H1 2026. Q3 2026 attestation expected.
In progress - ActiveTC-06
At-rest + in-transit encryption
AES-256 at rest. TLS 1.3 in transit. KMS-managed keys.
What teams ask before adopting.
Stay current on the standards your buyers ask about.
Long-form guides, blog posts, and the live changelog.
Guides, blog posts, and the changelog are on the way.
One place for every phase of the security lifecycle.
One workbench. Four roles. Every artifact traceable.