Secure by Design
Most teams discover security gaps right before production, or worse, right after. Alvor is security architecture software that runs the design through a governed workflow: impact scoring, security design reviews, threat modeling, control mapping, and evidence-backed sign-off, before a line of code ships.
Who it is for
Design the system once, in a tool that keeps the decision.
Know whose ball it is, and never meet a finding at go-live.
Design decisions land in the same system as the audit.
The process
A governed path from assessment to sign-off. Every step has defined inputs, role-based gates, and an immutable event trail. Nothing skips a step.
Phase 01
Know what you're building
Every project starts with one question: how much security does this actually need? The Business Impact Assessment scores risk across five dimensions (operational, financial, reputational, legal, and health & safety) on a configurable 100-point scale, then classifies the project Low, Medium, or High. That score sets everything downstream: control depth, assurance requirements, and who has to sign off.
Phase 02
Security on the canvas
Don't invent your security architecture from scratch. Drop proven patterns onto an interactive canvas (microservices, serverless, data pipelines) and inherit the controls and threat models that took the industry years to codify. Every component, every data flow, every connection is visible and accounted for.
Phase 03
See the attack surface
Every component in your architecture has an attack surface. Alvor anchors threats directly to the components, data flows, and trust boundaries they target using STRIDE, MITRE ATT&CK techniques, and kill-chain phases, with each mitigation linked to the control that addresses it. Coverage, including every unmitigated threat, stays visible. Threats live on the architecture, not buried in a document nobody opens.
Phase 04
Map once, comply everywhere
NIST CSF 2.0, NIST 800-53, ISO 27001:2022, SOC 2, PCI-DSS 4.0, CIS v8: stop mapping the same control into four different spreadsheets. Controls attach to architecture components by classification, then cross-map across the framework library as equivalent, subset, or superset. Satisfy one control, and every standard it touches updates with it.
Phase 05
Evidence, not assumptions
Run pen tests, SAST, DAST, vulnerability scans, and compliance audits, then link every finding to the control it validates. Evidence flows into an auditable chain (requirement to test to result to sign-off) with versioned artifacts and integrity hashes. When the auditor asks how you verified a control, the answer is already there, timestamped and traceable.
Phase 06
The right people say yes
Four independent approvers (Architect, Assurance, Business Owner, Technical Owner) each review from their own lens. Approve, reject, or request changes with conditions that route the design back a phase. Risk acceptances are documented, and nothing reaches production without every stakeholder's timestamped sign-off. This is where governance becomes permanent record.
The product
01 · The project list
One row per system or change being reviewed. Each shows the architect responsible, the stage it has reached, and how much the business would lose if it went wrong. Nothing sits waiting on someone who does not know it is theirs.

02 · The threat model
Elements promoted straight off the architecture diagram, the threats recorded against them, and a running count of what is mitigated, open and still unaddressed. Try to mark a threat handled without naming a control that deals with it and the system refuses.

03 · The build
Every control chosen while threat modelling lands here on its own, carrying implementation status, an assignee, a due date and somewhere to attach the evidence. Nobody reconstructs the security requirements after the design is finished.

Risk intelligence
Not every project needs a fortress. The Business Impact Assessment scores risk across five dimensions, then automatically determines classification, control depth, and assurance requirements. The right security for the right risk, every time.
Business Impact Assessment
Payment Gateway Upgrade
Composite Score
0
Tier 3 · Full review required
Architecture canvas
Drag components onto an interactive canvas and watch security materialize. Every connection shows its protocol. Every node maps to its controls. Every data flow is visible, typed, and accounted for. This isn't a diagram, it's a living security model.
Agentic studios
The AI assistant docks beside the work and builds the artefact with you: the diagram, the threat model, the design explanation. Every proposal waits for your approval, and everything it touches is audit-logged.
Real, editable shapes on this canvas: zones, nodes, numbered flows, and a legend, laid out like a cloud reference architecture diagram. Paste a whiteboard photo and a vision model recreates it.
AI architecture diagramsIt reads the diagram, registers STRIDE elements, proposes threats from your library, and maps mitigating controls. One approval card per batch; nothing lands without you.
AI threat modelingIt describes what it sees, asks the team a few focused questions at a time, and writes the structured design explanation into the live editor for you to apply and save.
AI design documentsWhen the work is done, one click exports the full design document: project, people, business impact analysis, each diagram with its explanation, the threat model, and the sign-off matrix.
Meet the AI assistantApproval gates
Four independent approvers, each with their own lens, their own decision, their own timestamp. This is where governance becomes permanent record.
Architecture reviewed. Controls verified.
Signed Feb 14, 2026 at 09:42
Pen tested. Scanned. Clean.
Signed Feb 18, 2026 at 14:15
Risk R-2847 accepted. Rationale documented.
Signed Feb 20, 2026 at 11:33
Load test results outstanding.
Awaiting since Feb 20, 2026
Secure by Design, answered
Best for
Teams that review designs before they ship and want the review, the threat model, the controls and the sign-off to be one record.
It runs the security architecture workflow as a governed program. A project starts with classification and a business impact analysis, moves through architecture design on a canvas, threat modeling on that diagram, control mapping, testing and evidence, and ends with named sign-offs before go-live. Every step has defined inputs and role-based gates, and every change is recorded in the event trail.
Threats are anchored to elements on the design's own diagram. Each mapped control becomes a required, threat-driven build control on the project, so engineers see what to build and why. The controls are the same ones the Compliance module tracks, so their implementation and test evidence count toward the frameworks the organisation answers to. A threat that cannot be mitigated is accepted as a risk with an owner and a rationale, on the register rather than in a comment thread.
Sign-off is by named people in the roles the project requires, recorded in the audit trail, and it stays human. The AI Design Studio draws the architecture as editable shapes from a description or a whiteboard photo, the AI Threat Modeling Studio proposes threats and controls in batches, and the design explanation is written by interview. Each of these pauses on an approval card before anything is written.
Yes. The module runs in every deployment model: a dedicated cloud instance in your region, on-premise, or air-gapped, with the AI pointed at a self-hosted model if the network requires it.
What it replaces
The category sells design review as its own product, priced on its own. In Alvor it is a module of the platform you already run the program on.
Instead of
A standalone threat-modelling tool
Deep threat generation against a large component library. The output is a report.
In Alvor
The output is the project's control set, sitting in the build plan with an owner and a due date.
Instead of
A design review in a slide deck
Security sees the architecture two weeks before go-live, when every choice is already built.
In Alvor
A governed record from the first phase, with four named sign-offs and every post-baseline change classified.
Instead of
A diagram in a drawing tool
The picture and the decision drift apart the moment either one changes.
In Alvor
Versioned diagrams on a canvas whose shapes become the threat model, which becomes the controls.
How it connects
Named precisely, because “everything connects to everything” is not a claim anyone can check.
Secure by Design
Fixing a vulnerability in production costs 30× more than catching it at design time. Alvor gives your architects, engineers, and security team a shared workspace to review designs, model threats, and map controls before anything ships.