SecForge SPLM · ISO/SAE 21434 · UNECE R155/R156

From first concept to end of life.
The security lifecycle, managed.

Concept, development, production, operations, decommission — every phase in one platform. TARA is one module of many, and every decision leaves automotive teams traceable, audit-ready evidence.

  • Tier-1 supplier-grade
  • Traceable to every clause
  • Tenant-isolated data

CONCEPT

Compromise CAN bus
AT-01Spoof gateway ECU
AT-02Replay diag command
AT-03Bypass auth challenge
S4Safety
F2Financial
O3Operational
P1Privacy
RiskHigh
Feasibility4.2

Built for the regulated stack.

  • ISO/SAE 21434
  • UNECE R155
  • UNECE R156
  • ISO 26262
  • ASPICE
  • IEC 62443
  • TISAX
The TARA bottleneck

Automotive cybersecurity teams are drowning in spreadsheets.

R155 entered into force in 2024 across UNECE members. Every type-approved vehicle now needs a Cybersecurity Management System spanning concept, development, production, and post-production phases.

The reality on most programs: TARA lives in branched Excel workbooks, attack trees in Visio, scenarios in Word, reviews in email. Nothing reconciles. Nothing audits.

SecForge SPLM is one structured workbench for the entire ISO/SAE 21434 lifecycle — built so an Officer, a Manager, and an Engineer all see the same truth.

  • Before14 Excel files per programAfter1 workbench
  • BeforeManual mapping to R155 §AfterAuto-traced
  • BeforeReview by emailAfterTickets with state machine
  • BeforeReports in WordAfterOne-click export
The lifecycle

One traceable thread, from concept to decommission.

Five phases, one continuous chain of evidence. Every work product carries into the next phase — nothing gets re-typed, nothing gets lost between gates.

Item definition & TARAP01
GATEWAY
Central Gateway
BCM
Body Control
ADAS
ADAS Domain
TCU
Telematics
CAN-HS
100BASE-T1
LIN-2
Inside the platform

Six modules, one continuous lifecycle.

Each module owns a phase of ISO/SAE 21434 and hands its evidence to the next. TARA is one link in the chain, not the whole product.

TOE & asset modeling

Draw the item under analysis on a canvas: ECUs, buses, assets, and their CIA properties, versioned per program.

Damage & threat scenarios

Rate every damage scenario on safety, financial, operational, and privacy impact, then link the threats that cause it.

Attack trees

Break each threat into AND/OR steps and score attack feasibility, so risk rests on evidence instead of opinion.

Risk assessment & treatment

Impact times feasibility on a matrix you configure. Accept, reduce, or transfer — and derive the security goals that follow.

Review ticketing

Phase gates from CSPR to CSAR. Findings become tickets, decisions become snapshots, and nothing advances unsigned.

Question library

Over 170 review questions, versioned and editable, so every audit asks the same thing the same way.

Product walkthrough

Watch a program move through the lifecycle.

One vehicle program, start to finish: model the TOE, run the TARA, clear the phase gate, and export the evidence.

SecForge SPLM · Walkthrough
One platform, four roles

Built for the way automotive cybersecurity teams actually work.

Each role gets a workspace tuned to their decisions — and they all see the same evidence underneath.

PA

Platform Admin

Owns the tenant. Provisions teams, organizations, and access.

  • Tenant configuration
  • User & role management
  • Audit logs
  • Provision tenants and organizations
  • Assign roles and access scopes
  • Review the audit log weekly
View workflow
CSO

Cybersecurity Officer

Sets policy. Signs off on dossiers. Owns standards alignment.

  • Org-level dashboards
  • Policy gates
  • Compliance posture
  • Approve policy and phase gates
  • Sign off release dossiers
  • Track compliance posture across programs
View workflow
CSM

Cybersecurity Manager

Runs the program. Coordinates milestones, reviews, supply chain.

  • Milestone tracking
  • Review orchestration
  • Supply-chain CS
  • Plan milestones and review cycles
  • Chase supplier cybersecurity agreements
  • Report program risk to the officer
View workflow
CSE

Cybersecurity Engineer

Ships the analysis. TOE, threats, attack trees, security goals.

  • TARA modeling
  • Attack tree authoring
  • Security concepts
  • Model the TOE and its assets
  • Author attack trees, rate feasibility
  • Derive security goals and requirements
View workflow
Aligned, not improvised

Designed against the standards your team is already chasing.

Every artifact in SecForge SPLM traces back to a clause. Evidence packs export ready for type approval.

ISO/SAE 21434

Coverage of §8 (Concept) through §10 (Cybersecurity Validation). Every artifact in the workbench traces back to a clause.

UNECE R155

Annex 5 threat categories pre-mapped. CSMS evidence packs export-ready for type approval.

UNECE R156

Software update governance: version traceability, OTA campaign manifest, post-production change auditing.

  1. ISO/SAE 21434 §9

    Concept phase

    Item definition, cybersecurity goals and the security concept exported as one linked, reviewer-signed work product.

  2. ISO/SAE 21434 §15

    Threat analysis and risk assessment

    Damage scenarios, threat scenarios, attack feasibility and risk values, each traced back to the asset that produced it.

  3. UNECE R155 Annex 5

    Threat mitigation coverage

    Every Annex 5 threat pre-mapped to your scenarios, with uncovered entries flagged before the approval audit.

  4. UNECE R156

    Software update management

    Update campaign manifests, RXSWIN-linked configuration records, and a post-production change history that survives audit.

Plays with the toolchain

Sits alongside the systems you already trust.

No data lock-in. Every artifact exports as ReqIF, xlsx, or JSON. SSO via your existing IdP.

Polarion (Siemens)
ALM
Available
Jira
Issue tracking
Available
Confluence
Documentation
Available
DOORS Next
Requirements
Available
Jenkins / GitLab CI
Pipeline events
Available
Microsoft Entra ID
SSO
Available
Keycloak
SSO
Available
SCIM 2.0Beta
Security & trust

Built like the systems you're shipping it for.

Tenant-isolated by JWT. Audited end-to-end. Hosted in your region.

Read the full trust center
Security postureLive
  • TC-01

    Tenant-isolated data

    Every query filtered by JWT-bound tenant ID. No cross-tenant joins exist in the codebase.

    Active
  • TC-02

    SSO via Keycloak / OIDC

    Production SSO with Microsoft Entra, Okta, Auth0, and Google Workspace.

    Active
  • TC-03

    Full audit trail

    Every state change snapshotted with author, timestamp, and before/after diff.

    Active
  • TC-04

    EU + US data residency

    Pick your region at provisioning. Frankfurt and Virginia available; APAC on roadmap.

    EU · US
  • TC-05

    SOC 2 Type II in progress

    Audit period H1 2026. Q3 2026 attestation expected.

    In progress
  • TC-06

    At-rest + in-transit encryption

    AES-256 at rest. TLS 1.3 in transit. KMS-managed keys.

    Active
6/6 controls attestedJWT-scoped · region-pinned
FAQ

What teams ask before adopting.

Resources

Stay current on the standards your buyers ask about.

Long-form guides, blog posts, and the live changelog.

Browse the library
Coming soon

Guides, blog posts, and the changelog are on the way.

One place for every phase of the security lifecycle.

One workbench. Four roles. Every artifact traceable.