The offline TARA tool for ISO/SAE 21434 + UN R155 — on your own machine.
A fast, fully-offline TARA tool for Windows — a desktop workbench with an on-device AI assistant — that takes you from item definition to a signed, auditor-ready Threat Analysis & Risk Assessment mapped to ISO/SAE 21434, UN R155 and the EU Cyber Resilience Act (CRA), without an enterprise cloud platform or a consulting engagement.
Your TARA never leaves your network. No cloud. No telemetry. No per-analysis fees.
Two editions
Two editions, one method
TARAexl comes in two editions that share the same ISO/SAE 21434 workflow, the same evidence, and the same file format.
TARAexl Studio
The offline desktop workbench for an individual analyst. Everything runs on your machine, with no account and no cloud.
- Windows desktop app, portable — unzip and run
- Single analyst, no server to operate
- Work stored in a local project file you own
TARAexl Hub Early access
The on-premise team server for organisations that need shared projects, roles, sign-off and traceability across a group — still entirely inside your own network.
- Reached from a browser on your own server
- Six roles, spaces, and an approval workflow
- Active Directory / LDAP and OIDC single sign-on
The problem
Every road-vehicle programme now needs a TARA. Today the options are bad.
ISO/SAE 21434 requires a Threat Analysis & Risk Assessment, and UN R155 demands one for type approval. Teams are left with three bad options:
Enterprise cloud platforms
Powerful, but priced for large OEMs — and they put your most sensitive design data in someone else's cloud.
General-purpose tools
Spreadsheets and threat-modeling apps that weren't built for 21434/R155 — so the method, the work products and the report are all manual.
Consultants
Expensive — and the knowledge walks out the door when the engagement ends.
Meanwhile Tier-2/3 suppliers, smaller OEMs, and teams on air-gapped networks need the same audit-ready evidence — on a realistic budget, without sending their IP to the cloud. That gap is exactly where TARAexl sits.
What TARAexl is
The full ISO/SAE 21434 TARA method — as a guided desktop workflow.
A single-user Windows desktop application that implements the full 21434 TARA method and produces the auditor-ready deliverables at the end. It ships as a portable Windows x64 zip — unzip and run, no installer, no account, no auto-update — and stores everything locally in a project file you own.
- Runs 100% offline — it works on a machine that has never touched the internet.
- Portable zip: unzip and run; everything stored locally in a project file you own.
- Full interface in English, German, French and Japanese.
- Speaks UN R155 (Annex 5 Part-A coverage) and ISO/DIS 24882 — road vehicles and off-highway/agricultural programmes alike.
Preview blurred to protect proprietary detail — book a demo to see it live.
A command-center built for the work
The whole method, one window
- A fixed sidebar rail groups the app into Workbench · Evidence · Deliver · Tools, with the 6-step workflow ladder numbered, gated, and ticked off as steps are approved.
- The Project Overview is a KPI dashboard — completion ring, deep-linking risk tiles, and an interactive impact × attack-feasibility risk matrix where every cell opens the risk register.
- An always-visible search opens the Ctrl+K command palette; a first-run onboarding tour orients new engineers; dark and light themes; comfortable / compact density.
- Fast at scale — on a 1,000+-entity stress project (measured on our reference hardware; timings vary by machine): opening ~1.6 s, the TARA workbench ~1.5 s, a full export ~3 s.
- Fully keyboard-operable (including the Relationship Map, Attack Trees and architecture graphs) — a WCAG 2.1 A/AA + EN 301 549 self-assessment is available on request.
Capabilities
The heavy lifting, automated
Guided 21434 workflow
Item definition · architecture & data-flow modelling · assets → damage → threat scenarios → attack paths → feasibility → risk → treatment → cybersecurity concept. Each step gates the next, with an approval / sign-off trail.
Method, done right
Attack feasibility by ISO/IEC 18045 attack potential (Annex G — the five factors) or the CVSS v3.1 exploitability sub-score. Systematic STRIDE elicitation. CAL derived per Annex E Table E.1, with the numeric risk value 1–5 alongside. 15 work-product coverage areas mapped to ISO/SAE 21434 Table A.1 and ISO/DIS 24882 Annex D, with 7 completeness checks running live.
Evidence & traceability
End-to-end traceability graph (asset → … → claim), coverage / gap analysis, baselines and an append-only audit trail. One-click DOCX + XLSX with your branding — a 21-sheet TARA workbook (incl. the UN R155 Annex 5 coverage sheet) and the Cybersecurity Concept. Document control on every cover; "Release as a version" stamps the control block and snapshots a baseline.
Evidence Binder & interop
A one-click Evidence Binder zip — the XLSX report, the DOCX concept, the project file and a manifest.json with a SHA-256 per artifact, byte-identical to the standalone exports. ReqIF (OMG) import/export for OEM↔supplier requirement exchange, designed for loss-free round-trips of TARAexl-managed fields.
Offline AI assistant
A bundled on-device model (IBM Granite 3.3 2B, Apache-2.0) drafts damage scenarios, threats, controls and rationale — every suggestion enters as an editable draft to approve. A runtime backend selector (Auto / CUDA / Vulkan / CPU) with one-click "switch to CPU & retry". No cloud, no data egress.
Trust by architecture
100% offline · zero telemetry · Ed25519-signed per-seat licensing · content encrypted at rest · a cryptographically signed per-customer watermark on exports · evidence binders verifiable per-artifact by SHA-256 · a copyleft-free open-source BOM (MIT / Apache-2.0 / BSD only).
Standards & threat intelligence
Built in — not bolted on
Curated catalogues with real public identifiers, so treatment decisions stand on citable ground.
UN R155 Annex 5, complete
All 30 Part A threats (groups 4.3.1–4.3.7) with per-threat tagging and a live coverage / gap view — supporting the §7.3.3 evidence type-approval auditors ask for — plus all 23 Part B/C mitigations, each mapped to a control (a mapping verified by an automated test in our release suite).
30-control security catalog
v1.2 across 15 categories, every control citing public references — NIST SP 800-53 Rev 5, AUTOSAR SecOC, ISO 14229 UDS, TLS 1.3 (RFC 8446), Uptane, EVITA HSM, UN R156, OWASP, NCSC, IEEE 802.15.4z UWB.
Curated threat packs
46 MITRE EMB3D threats (genuine TIDs), 34 Automotive Threat Matrix techniques across Auto-ISAC's 14 tactics, 28 automotive CAPEC patterns and a 13-template generic library — all STRIDE-categorised and cross-linked.
SBOM & offline CVE matching
Import SBOMs in CycloneDX and SPDX (JSON, auto-detected) with fully offline CVE matching — compile an OSV/NVD snapshot on any online machine and side-load it, so air-gapped fleets stay current without the tool touching a network.
EU CRA readiness
On machinery projects the Coverage view maps the documented risk assessment to the Cyber Resilience Act Art. 13(2)–(3) for the Annex VII technical documentation. (CRA applies from 11 Dec 2027; type-approved road vehicles remain under UN R155.)
ISO/DIS 24882 as a real profile
Annex D work-product codes, the standard's Likelihood and Availability terminology, and Table 11 risk values — switched automatically by project domain, not just a label.
Inside TARAexl Studio
See the method at work
Screens from the current build — previews are intentionally blurred to protect proprietary detail. Book a demo to see them in full.
Threat scenarios — STRIDE & CAPEC
Attack trees — AND/OR-gated per threat
Coverage — work-product completeness
Traceability — risk → goals → requirements
Relationship map — the analysis as one graph
Export — reports & machine-readable formats
Start screen — new, open & recent projects
Licensing, AI model & compute backend
Your team's TARA server, inside your own network
When more than one person works the analysis, Hub puts the same TARAexl workflow on a server behind your firewall. The team works in a browser, roles and approvals are enforced on the server, and the data never leaves your infrastructure.
Not a cloud service. Hub is deployed on your own hardware and runs air-gapped.
Reached from a browser
Team members open the Hub in a web browser pointed at your server. Reviewers and managers install nothing. The Studio desktop app stays the separate offline edition.
Runs on your infrastructure, fully air-gapped
Hub deploys as a Docker stack — the application server, a PostgreSQL database and a nightly backup — with a single docker compose up. Load it once from an offline image bundle and it needs no internet: no telemetry, no licence call-home, nothing fetched at run time.
Roles, spaces and single sign-on
Six roles — admin, cybersecurity manager, reviewer, author, viewer, guest — are enforced on the server, not just hidden in the UI. Projects are grouped into spaces, and a person's role can differ per space. People sign in with local accounts, your Active Directory / LDAP, or OIDC single sign-on.
Controlled collaboration with a full audit trail
One person edits a given project at a time under a four-hour editing lock that releases on its own, and every save is version-checked so no one's work is overwritten. The review discussion (open points) is shared live, so reviewers raise and close items together. Every change is recorded in the audit log.
Fits your toolchain
Push released work to Jira or an ALM tool over OSLC, or drop evidence to an SFTP share, under a policy that controls exactly which fields are allowed to leave the Hub.
An eight-tab admin console
Users, audit log, connectors, spaces, API keys, OIDC, LDAP and webhooks — the whole server is administered from the browser, by your own administrators, on your own network.
Sign in from a browser — nothing to install
Review & sign-off with risk posture
Spaces — per-space access & sharing policy
OIDC SSO — group → role mapping
Audit log — every change recorded
Connectors — Jira / ALM over OSLC
TARAexl Hub is in early access — capabilities described here may evolve before general availability. Hub is deployed with Docker on your own server; there is no cloud or hosted option by design.
Which edition
Studio or Hub
Same method, same evidence, same file format. The difference is who works on it, and where it runs.
| Aspect | Studio | Hub |
|---|---|---|
| Runs on | Your desktop (Windows) | Your server (Docker, on-premise) |
| Users | Single analyst | Team, role-based |
| Access | Desktop app | Web browser |
| Data | On your machine | In your database, behind your firewall |
| Roles & sign-off | Personal workflow | Six roles, spaces, approval workflow |
| Identity | n/a | Local, Active Directory / LDAP, OIDC SSO |
| Connectors | Export files | Jira / ALM (OSLC), SFTP |
| Collaboration | n/a | One editor per project (lock) + live review discussion |
| Offline | 100% | 100% (air-gapped) |
Who it's for
Built for the whole supply chain
- Tier-1 / Tier-2 / Tier-3 automotive suppliers producing TARAs for OEM programmes.
- Smaller & emerging OEMs that need 21434/R155 evidence without an enterprise platform spend.
- Cybersecurity engineers & managers who want the method enforced and the report generated — not hand-built.
- Teams on air-gapped / restricted networks (defence-adjacent, IP-sensitive) that cannot use cloud tools.
- Off-highway & agricultural machinery makers working to ISO/DIS 24882.
Why TARAexl
How it compares
| Capability | Cloud lifecycle platforms | Spreadsheets / generic tools | Consultants | TARAexl |
|---|---|---|---|---|
| ISO 21434 method built-in | ✓ | ✗ | n/a | ✓ |
| UN R155 coverage | ✓ | ✗ | depends | ✓ |
| Runs fully offline / air-gap | ✗ | ✓ | n/a | ✓ |
| Your data stays on your machine | ✗ | ✓ | ✗ | ✓ |
| Auditor-ready report out-of-the-box | ✓ | ✗ | ✓ | ✓ |
| Affordable per-seat | ✗ | ✓ | ✗ | ✓ |
| Knowledge stays in-house | partial | ✓ | ✗ | ✓ |
The offline, affordable TARA workbench that helps automotive teams get ISO 21434 + R155 audit-ready on their own machines — the method, the evidence and the report, without the cloud or the consultant.
Trust & security
Private by default — buyers will ask
100% offline
No account, no server, no online activation, no auto-update. The renderer is locked down (connect-src 'none') and the on-device AI model ships inside the portable package — the app never needs a network connection at all.
Zero telemetry
We collect nothing. Your TARA is yours.
Your work survives a crash
Atomic saves with backup recovery, and project-file locks that self-heal — designed so a killed instance never blocks reopening your project.
Your IP stays yours
Proprietary catalogs and methodology data are encrypted at rest in the install; official exports carry a cryptographically signed per-customer watermark.
Licensing that respects you
Per-seat, node-locked, Ed25519-signed (the signing key never ships). When a licence lapses the app drops to read-only — designed so you can still open and export your existing work, not be locked out of your own data.
Honest about limits
The licence is a strong deterrent plus tamper-evident per-customer traceability — not an "uncrackable" DRM claim. We'd rather tell you the truth than oversell.
Where this goes
Local, affordable, method-complete — private by default
Becoming the definitive offline TARA workbench
Richer threat catalogs (MITRE EMB3D alongside CAPEC), attack-tree / attack-path assists, ReqIF import/export for OEM↔supplier exchange, an even stronger evidence binder, and an AI assistant that genuinely saves hours per analysis.
Munimentx — the product-security suite
An offline companion for the organisational layer — ISO/SAE 21434 §5 + UN R155 Annex-5 CSMS: governance, evidence register, audit-readiness dashboard and a one-click R155 evidence binder. TARAexl proves the product; Munimentx proves the organisation.
The lifecycle, end to end, on your terms
Continuous activities recorded locally (monitoring, vulnerability triage, incidents, R156 updates), multi-framework coverage (ASPICE-for-Cybersecurity, ISO 27001) — while never compromising the promise: your data never leaves your machine.
Horizons 2–3 describe our roadmap and may evolve. What we'll deliberately never build: cloud monitoring / vSOC / telemetry ingestion, or anything that requires your design data to leave your control.
Questions
Frequently asked about TARAexl
Does TARAexl work fully offline, including on an air-gapped network?
Yes. TARAexl ships as a portable Windows x64 zip — unzip and run, with no installer, no account and no auto-update. There is no cloud service behind it and no telemetry, so it is designed to run on air-gapped and restricted engineering networks. Your work stays in a local project file you own.
Can TARAexl replace a spreadsheet-based TARA?
That is why most teams move to it. A spreadsheet can hold the data, but it can't maintain traceability between damage scenarios, threat scenarios, attack paths and requirements, show coverage status, or produce a consistent auditor-ready export. TARAexl keeps the ISO/SAE 21434 method, the links and the evidence in one place — and still exports to Excel and Word.
Which standards and regulations does TARAexl support?
ISO/SAE 21434 (the full TARA method and cybersecurity concept), UN R155 including Annex 5 coverage and gap analysis, the EU Cyber Resilience Act (Art. 13(2)–(3) mapping for the Annex VII technical documentation), and ISO/DIS 24882 as a real profile. TARAexl supports your work towards these standards; audit and type-approval outcomes remain the responsibility of your assessors and approval authorities.
How can there be an AI assistant if the tool is offline?
The model runs on your own machine, on-device. It drafts threat scenarios, controls and rationale from your project data, and nothing is uploaded — there is no call to an external AI service. You choose the compute backend.
Does any of my design data leave my machine?
No. There is no cloud sync, no telemetry and no per-analysis fees. Everything is stored locally in a project file you control, proprietary catalogs are encrypted at rest, and exports are produced locally.
What does TARAexl produce for an audit?
An Excel risk report, a Word cybersecurity concept, and a one-click Evidence Binder zip containing the report, the concept, the project file and a manifest.json with a SHA-256 per artifact, so every item can be verified independently. ReqIF import/export is available for OEM↔supplier requirement exchange.
Do I need a subscription or a cloud account?
No. Licensing is per-seat and offline (Ed25519-signed) — there is no account to create and no subscription. Request a trial or book a walkthrough to try it on your own machine.
Who is TARAexl for?
Tier-N suppliers, smaller OEMs, and engineering or consulting teams who must produce the same ISO/SAE 21434 and UN R155 evidence as a large OEM — on a realistic budget, and often on networks where a cloud platform is not an option. See the guide to choosing an offline TARA tool for how to compare the options.
Can a whole team work on the same TARA?
Yes — that is what TARAexl Hub is for. Hub runs on your own server behind your firewall and the team reaches it from a browser, with six server-enforced roles, projects grouped into spaces, approval sign-off and a full audit log. To be precise about how it works: one person edits a given project at a time under a four-hour lock that releases on its own, and every save is version-checked, while the review discussion is shared live. It is not simultaneous co-editing of the analysis itself.
Is TARAexl Hub a cloud service?
No. Hub is deployed on your own infrastructure as a Docker stack (application server, PostgreSQL database and a nightly backup) and is designed to run fully air-gapped — loaded once from an offline image bundle, with no telemetry and no licence call-home. There is no hosted or SaaS option, by design.
Build your auditor-ready TARA on your own machine.
Request a trial or book a 20-minute walkthrough — and see a full ISO 21434 + R155 TARA produced offline, end to end.
TARAexl supports your ISO/SAE 21434, UN R155 and EU CRA work. Audit and type-approval outcomes remain the responsibility of your assessors and approval authorities.