TARAexl

The offline TARA tool for ISO/SAE 21434 + UN R155 — on your own machine.

A fast, fully-offline TARA tool for Windows — a desktop workbench with an on-device AI assistant — that takes you from item definition to a signed, auditor-ready Threat Analysis & Risk Assessment mapped to ISO/SAE 21434, UN R155 and the EU Cyber Resilience Act (CRA), without an enterprise cloud platform or a consulting engagement.

Your TARA never leaves your network. No cloud. No telemetry. No per-analysis fees.

TARAexl Studio — project overview with risk posture, treatment coverage and the guided ISO/SAE 21434 workflow

Two editions

Two editions, one method

TARAexl comes in two editions that share the same ISO/SAE 21434 workflow, the same evidence, and the same file format.

TARAexl Studio

The offline desktop workbench for an individual analyst. Everything runs on your machine, with no account and no cloud.

  • Windows desktop app, portable — unzip and run
  • Single analyst, no server to operate
  • Work stored in a local project file you own

TARAexl Hub Early access

The on-premise team server for organisations that need shared projects, roles, sign-off and traceability across a group — still entirely inside your own network.

  • Reached from a browser on your own server
  • Six roles, spaces, and an approval workflow
  • Active Directory / LDAP and OIDC single sign-on

See TARAexl Hub →

The problem

Every road-vehicle programme now needs a TARA. Today the options are bad.

ISO/SAE 21434 requires a Threat Analysis & Risk Assessment, and UN R155 demands one for type approval. Teams are left with three bad options:

Enterprise cloud platforms

Powerful, but priced for large OEMs — and they put your most sensitive design data in someone else's cloud.

General-purpose tools

Spreadsheets and threat-modeling apps that weren't built for 21434/R155 — so the method, the work products and the report are all manual.

Consultants

Expensive — and the knowledge walks out the door when the engagement ends.

Meanwhile Tier-2/3 suppliers, smaller OEMs, and teams on air-gapped networks need the same audit-ready evidence — on a realistic budget, without sending their IP to the cloud. That gap is exactly where TARAexl sits.

What TARAexl is

The full ISO/SAE 21434 TARA method — as a guided desktop workflow.

A single-user Windows desktop application that implements the full 21434 TARA method and produces the auditor-ready deliverables at the end. It ships as a portable Windows x64 zip — unzip and run, no installer, no account, no auto-update — and stores everything locally in a project file you own.

  • Runs 100% offline — it works on a machine that has never touched the internet.
  • Portable zip: unzip and run; everything stored locally in a project file you own.
  • Full interface in English, German, French and Japanese.
  • Speaks UN R155 (Annex 5 Part-A coverage) and ISO/DIS 24882 — road vehicles and off-highway/agricultural programmes alike.
TARAexl Studio risk dashboard — risk posture, matrix and top risks (blurred preview)

Preview blurred to protect proprietary detail — book a demo to see it live.

A command-center built for the work

The whole method, one window

  • A fixed sidebar rail groups the app into Workbench · Evidence · Deliver · Tools, with the 6-step workflow ladder numbered, gated, and ticked off as steps are approved.
  • The Project Overview is a KPI dashboard — completion ring, deep-linking risk tiles, and an interactive impact × attack-feasibility risk matrix where every cell opens the risk register.
  • An always-visible search opens the Ctrl+K command palette; a first-run onboarding tour orients new engineers; dark and light themes; comfortable / compact density.
  • Fast at scale — on a 1,000+-entity stress project (measured on our reference hardware; timings vary by machine): opening ~1.6 s, the TARA workbench ~1.5 s, a full export ~3 s.
  • Fully keyboard-operable (including the Relationship Map, Attack Trees and architecture graphs) — a WCAG 2.1 A/AA + EN 301 549 self-assessment is available on request.

Capabilities

The heavy lifting, automated

Guided 21434 workflow

Item definition · architecture & data-flow modelling · assets → damage → threat scenarios → attack paths → feasibility → risk → treatment → cybersecurity concept. Each step gates the next, with an approval / sign-off trail.

Method, done right

Attack feasibility by ISO/IEC 18045 attack potential (Annex G — the five factors) or the CVSS v3.1 exploitability sub-score. Systematic STRIDE elicitation. CAL derived per Annex E Table E.1, with the numeric risk value 1–5 alongside. 15 work-product coverage areas mapped to ISO/SAE 21434 Table A.1 and ISO/DIS 24882 Annex D, with 7 completeness checks running live.

Evidence & traceability

End-to-end traceability graph (asset → … → claim), coverage / gap analysis, baselines and an append-only audit trail. One-click DOCX + XLSX with your branding — a 21-sheet TARA workbook (incl. the UN R155 Annex 5 coverage sheet) and the Cybersecurity Concept. Document control on every cover; "Release as a version" stamps the control block and snapshots a baseline.

Evidence Binder & interop

A one-click Evidence Binder zip — the XLSX report, the DOCX concept, the project file and a manifest.json with a SHA-256 per artifact, byte-identical to the standalone exports. ReqIF (OMG) import/export for OEM↔supplier requirement exchange, designed for loss-free round-trips of TARAexl-managed fields.

Offline AI assistant

A bundled on-device model (IBM Granite 3.3 2B, Apache-2.0) drafts damage scenarios, threats, controls and rationale — every suggestion enters as an editable draft to approve. A runtime backend selector (Auto / CUDA / Vulkan / CPU) with one-click "switch to CPU & retry". No cloud, no data egress.

Trust by architecture

100% offline · zero telemetry · Ed25519-signed per-seat licensing · content encrypted at rest · a cryptographically signed per-customer watermark on exports · evidence binders verifiable per-artifact by SHA-256 · a copyleft-free open-source BOM (MIT / Apache-2.0 / BSD only).

Standards & threat intelligence

Built in — not bolted on

Curated catalogues with real public identifiers, so treatment decisions stand on citable ground.

UN R155 Annex 5, complete

All 30 Part A threats (groups 4.3.1–4.3.7) with per-threat tagging and a live coverage / gap view — supporting the §7.3.3 evidence type-approval auditors ask for — plus all 23 Part B/C mitigations, each mapped to a control (a mapping verified by an automated test in our release suite).

30-control security catalog

v1.2 across 15 categories, every control citing public references — NIST SP 800-53 Rev 5, AUTOSAR SecOC, ISO 14229 UDS, TLS 1.3 (RFC 8446), Uptane, EVITA HSM, UN R156, OWASP, NCSC, IEEE 802.15.4z UWB.

Curated threat packs

46 MITRE EMB3D threats (genuine TIDs), 34 Automotive Threat Matrix techniques across Auto-ISAC's 14 tactics, 28 automotive CAPEC patterns and a 13-template generic library — all STRIDE-categorised and cross-linked.

SBOM & offline CVE matching

Import SBOMs in CycloneDX and SPDX (JSON, auto-detected) with fully offline CVE matching — compile an OSV/NVD snapshot on any online machine and side-load it, so air-gapped fleets stay current without the tool touching a network.

EU CRA readiness

On machinery projects the Coverage view maps the documented risk assessment to the Cyber Resilience Act Art. 13(2)–(3) for the Annex VII technical documentation. (CRA applies from 11 Dec 2027; type-approved road vehicles remain under UN R155.)

ISO/DIS 24882 as a real profile

Annex D work-product codes, the standard's Likelihood and Availability terminology, and Table 11 risk values — switched automatically by project domain, not just a label.

Inside TARAexl Studio

See the method at work

Screens from the current build — previews are intentionally blurred to protect proprietary detail. Book a demo to see them in full.

Threat scenarios with STRIDE and CAPEC elicitation (blurred preview)

Threat scenarios — STRIDE & CAPEC

Attack trees with AND/OR gates per threat (blurred preview)

Attack trees — AND/OR-gated per threat

Coverage — work-product completeness against the standard (blurred preview)

Coverage — work-product completeness

Traceability from risk to goals, requirements and claims (blurred preview)

Traceability — risk → goals → requirements

Relationship map showing the whole analysis as one graph (blurred preview)

Relationship map — the analysis as one graph

Export — reports and machine-readable formats (blurred preview)

Export — reports & machine-readable formats

Start screen — new project, open, load demo and recent projects (blurred preview)

Start screen — new, open & recent projects

Licensing, the on-device AI model and the compute-backend selector (blurred preview)

Licensing, AI model & compute backend

TARAexl Hub Early access

Your team's TARA server, inside your own network

When more than one person works the analysis, Hub puts the same TARAexl workflow on a server behind your firewall. The team works in a browser, roles and approvals are enforced on the server, and the data never leaves your infrastructure.

Not a cloud service. Hub is deployed on your own hardware and runs air-gapped.

TARAexl Hub admin console — users and their roles, with the audit, connectors, spaces, API keys, SSO, LDAP and webhooks tabs

Reached from a browser

Team members open the Hub in a web browser pointed at your server. Reviewers and managers install nothing. The Studio desktop app stays the separate offline edition.

Runs on your infrastructure, fully air-gapped

Hub deploys as a Docker stack — the application server, a PostgreSQL database and a nightly backup — with a single docker compose up. Load it once from an offline image bundle and it needs no internet: no telemetry, no licence call-home, nothing fetched at run time.

Roles, spaces and single sign-on

Six roles — admin, cybersecurity manager, reviewer, author, viewer, guest — are enforced on the server, not just hidden in the UI. Projects are grouped into spaces, and a person's role can differ per space. People sign in with local accounts, your Active Directory / LDAP, or OIDC single sign-on.

Controlled collaboration with a full audit trail

One person edits a given project at a time under a four-hour editing lock that releases on its own, and every save is version-checked so no one's work is overwritten. The review discussion (open points) is shared live, so reviewers raise and close items together. Every change is recorded in the audit log.

Fits your toolchain

Push released work to Jira or an ALM tool over OSLC, or drop evidence to an SFTP share, under a policy that controls exactly which fields are allowed to leave the Hub.

An eight-tab admin console

Users, audit log, connectors, spaces, API keys, OIDC, LDAP and webhooks — the whole server is administered from the browser, by your own administrators, on your own network.

TARAexl Hub sign-in page, opened in a web browser on the company server

Sign in from a browser — nothing to install

Review and sign-off panel with risk posture and matrix (blurred preview)

Review & sign-off with risk posture

Spaces administration — per-space organisation and sharing policy (blurred preview)

Spaces — per-space access & sharing policy

OIDC single sign-on configuration with group-to-role mapping (blurred preview)

OIDC SSO — group → role mapping

Hub audit log of every change (blurred preview)

Audit log — every change recorded

Connectors for Jira and ALM over OSLC (blurred preview)

Connectors — Jira / ALM over OSLC

TARAexl Hub is in early access — capabilities described here may evolve before general availability. Hub is deployed with Docker on your own server; there is no cloud or hosted option by design.

Which edition

Studio or Hub

Same method, same evidence, same file format. The difference is who works on it, and where it runs.

Comparison of TARAexl Studio and TARAexl Hub
Aspect Studio Hub
Runs onYour desktop (Windows)Your server (Docker, on-premise)
UsersSingle analystTeam, role-based
AccessDesktop appWeb browser
DataOn your machineIn your database, behind your firewall
Roles & sign-offPersonal workflowSix roles, spaces, approval workflow
Identityn/aLocal, Active Directory / LDAP, OIDC SSO
ConnectorsExport filesJira / ALM (OSLC), SFTP
Collaborationn/aOne editor per project (lock) + live review discussion
Offline100%100% (air-gapped)

Who it's for

Built for the whole supply chain

  • Tier-1 / Tier-2 / Tier-3 automotive suppliers producing TARAs for OEM programmes.
  • Smaller & emerging OEMs that need 21434/R155 evidence without an enterprise platform spend.
  • Cybersecurity engineers & managers who want the method enforced and the report generated — not hand-built.
  • Teams on air-gapped / restricted networks (defence-adjacent, IP-sensitive) that cannot use cloud tools.
  • Off-highway & agricultural machinery makers working to ISO/DIS 24882.

Why TARAexl

How it compares

Feature comparison with alternative approaches
Capability Cloud lifecycle platforms Spreadsheets / generic tools Consultants TARAexl
ISO 21434 method built-inn/a
UN R155 coveragedepends
Runs fully offline / air-gapn/a
Your data stays on your machine
Auditor-ready report out-of-the-box
Affordable per-seat
Knowledge stays in-housepartial

The offline, affordable TARA workbench that helps automotive teams get ISO 21434 + R155 audit-ready on their own machines — the method, the evidence and the report, without the cloud or the consultant.

Trust & security

Private by default — buyers will ask

100% offline

No account, no server, no online activation, no auto-update. The renderer is locked down (connect-src 'none') and the on-device AI model ships inside the portable package — the app never needs a network connection at all.

Zero telemetry

We collect nothing. Your TARA is yours.

Your work survives a crash

Atomic saves with backup recovery, and project-file locks that self-heal — designed so a killed instance never blocks reopening your project.

Your IP stays yours

Proprietary catalogs and methodology data are encrypted at rest in the install; official exports carry a cryptographically signed per-customer watermark.

Licensing that respects you

Per-seat, node-locked, Ed25519-signed (the signing key never ships). When a licence lapses the app drops to read-only — designed so you can still open and export your existing work, not be locked out of your own data.

Honest about limits

The licence is a strong deterrent plus tamper-evident per-customer traceability — not an "uncrackable" DRM claim. We'd rather tell you the truth than oversell.

Where this goes

Local, affordable, method-complete — private by default

Horizon 1 · now → next

Becoming the definitive offline TARA workbench

Richer threat catalogs (MITRE EMB3D alongside CAPEC), attack-tree / attack-path assists, ReqIF import/export for OEM↔supplier exchange, an even stronger evidence binder, and an AI assistant that genuinely saves hours per analysis.

Horizon 2

Munimentx — the product-security suite

An offline companion for the organisational layer — ISO/SAE 21434 §5 + UN R155 Annex-5 CSMS: governance, evidence register, audit-readiness dashboard and a one-click R155 evidence binder. TARAexl proves the product; Munimentx proves the organisation.

Explore Munimentx →

Horizon 3

The lifecycle, end to end, on your terms

Continuous activities recorded locally (monitoring, vulnerability triage, incidents, R156 updates), multi-framework coverage (ASPICE-for-Cybersecurity, ISO 27001) — while never compromising the promise: your data never leaves your machine.

Horizons 2–3 describe our roadmap and may evolve. What we'll deliberately never build: cloud monitoring / vSOC / telemetry ingestion, or anything that requires your design data to leave your control.

Questions

Frequently asked about TARAexl

Does TARAexl work fully offline, including on an air-gapped network?

Yes. TARAexl ships as a portable Windows x64 zip — unzip and run, with no installer, no account and no auto-update. There is no cloud service behind it and no telemetry, so it is designed to run on air-gapped and restricted engineering networks. Your work stays in a local project file you own.

Can TARAexl replace a spreadsheet-based TARA?

That is why most teams move to it. A spreadsheet can hold the data, but it can't maintain traceability between damage scenarios, threat scenarios, attack paths and requirements, show coverage status, or produce a consistent auditor-ready export. TARAexl keeps the ISO/SAE 21434 method, the links and the evidence in one place — and still exports to Excel and Word.

Which standards and regulations does TARAexl support?

ISO/SAE 21434 (the full TARA method and cybersecurity concept), UN R155 including Annex 5 coverage and gap analysis, the EU Cyber Resilience Act (Art. 13(2)–(3) mapping for the Annex VII technical documentation), and ISO/DIS 24882 as a real profile. TARAexl supports your work towards these standards; audit and type-approval outcomes remain the responsibility of your assessors and approval authorities.

How can there be an AI assistant if the tool is offline?

The model runs on your own machine, on-device. It drafts threat scenarios, controls and rationale from your project data, and nothing is uploaded — there is no call to an external AI service. You choose the compute backend.

Does any of my design data leave my machine?

No. There is no cloud sync, no telemetry and no per-analysis fees. Everything is stored locally in a project file you control, proprietary catalogs are encrypted at rest, and exports are produced locally.

What does TARAexl produce for an audit?

An Excel risk report, a Word cybersecurity concept, and a one-click Evidence Binder zip containing the report, the concept, the project file and a manifest.json with a SHA-256 per artifact, so every item can be verified independently. ReqIF import/export is available for OEM↔supplier requirement exchange.

Do I need a subscription or a cloud account?

No. Licensing is per-seat and offline (Ed25519-signed) — there is no account to create and no subscription. Request a trial or book a walkthrough to try it on your own machine.

Who is TARAexl for?

Tier-N suppliers, smaller OEMs, and engineering or consulting teams who must produce the same ISO/SAE 21434 and UN R155 evidence as a large OEM — on a realistic budget, and often on networks where a cloud platform is not an option. See the guide to choosing an offline TARA tool for how to compare the options.

Can a whole team work on the same TARA?

Yes — that is what TARAexl Hub is for. Hub runs on your own server behind your firewall and the team reaches it from a browser, with six server-enforced roles, projects grouped into spaces, approval sign-off and a full audit log. To be precise about how it works: one person edits a given project at a time under a four-hour lock that releases on its own, and every save is version-checked, while the review discussion is shared live. It is not simultaneous co-editing of the analysis itself.

Is TARAexl Hub a cloud service?

No. Hub is deployed on your own infrastructure as a Docker stack (application server, PostgreSQL database and a nightly backup) and is designed to run fully air-gapped — loaded once from an offline image bundle, with no telemetry and no licence call-home. There is no hosted or SaaS option, by design.

Build your auditor-ready TARA on your own machine.

Request a trial or book a 20-minute walkthrough — and see a full ISO 21434 + R155 TARA produced offline, end to end.

TARAexl supports your ISO/SAE 21434, UN R155 and EU CRA work. Audit and type-approval outcomes remain the responsibility of your assessors and approval authorities.