Introducing CASM
Security architecture that stays current — because it's connected to what's actually running.
Most security tools tell you what's misconfigured. VigilArch tells you why it matters, tied to the real architecture of your environment, updated as that environment changes.
architecture.live
// the problem
Threat models get built once, usually before an audit, as a static diagram in Visio or draw.io. Six months later the environment has drifted — new services, new cloud accounts, decommissioned firewalls, changed trust boundaries — and the diagram is fiction.
Meanwhile, CSPM and vulnerability scanners produce long lists of findings with no architectural context: is this exposed database actually reachable from the internet through three hops, or is it sitting behind a segmented boundary that makes the CVSS score academic?
Architecture review and vulnerability management have historically lived in separate tools, updated on separate schedules, owned by separate teams. The gap between them is where real risk hides.
definition
Continuous Architecture Security Management (CASM)
/kaz-əm/ · noun
The practice of keeping your security architecture — asset inventory, trust boundaries, threat models, and exposure data — as a single, living model instead of a periodic exercise.
instead of
- a threat model done once per year and forgotten
- an asset inventory that's stale the day after it's exported
- vulnerability findings with no architectural context
CASM treats architecture like
infrastructure-as-code treats infrastructure: something discovered continuously, modeled explicitly, and kept in sync with what's actually deployed — across cloud and on-prem alike.
static diagram
synced 8mo ago
live diagram
synced 2s ago
how it works
One pipeline, always running — not four tools stitched together once a year.
01
Discover
VigilArch connects to your cloud accounts (AWS, Azure, GCP) and on-prem network infrastructure (including Cisco ASA and Check Point firewalls) to build a live, continuously refreshed asset inventory — no manual spreadsheets, no stale CMDB exports.
02
Model
Assets get mapped into architecture diagrams with real trust boundaries. STRIDE threat modeling happens directly against this live view — either manually, node by node, or through a guided bulk pass that proposes findings across the whole diagram for review.
03
Correlate
Vulnerability and exposure data is layered onto the architecture itself. A CVE isn't just a severity score in a list — it's tied to a specific asset, its position in the diagram, and the trust boundaries around it, so you see actual reachability and blast radius.
04
Review
CoPilot sits alongside the work, contextual to whatever asset, diagram node, or finding you're looking at, with cited sources behind its suggestions. Findings it proposes go directly into the STRIDE workbench for your team to accept, adjust, or discard.
platform
Everything a continuous review discipline actually needs.
Multi-cloud & on-prem discovery
Continuous asset discovery across AWS, Azure, and GCP, plus on-prem network and firewall connectors (Cisco ASA, Check Point, and others), unified into a single inventory.
STRIDE threat modeling workbench
Structured threat modeling against your real architecture — manual node-level modeling and guided bulk passes across an entire diagram, with bulk apply/discard so a reviewer stays in control.
Vulnerability–exposure correlation
Findings correlated against diagram signals — trust boundaries, connectivity, asset role — so severity reflects actual architectural exposure, not just a standalone CVSS score.
Architecture diagramming
Diagrams generated from and linked to live discovered assets, with node-level detail and drill-down, instead of a disconnected drawing tool bolted on the side.
CoPilot AI assistant
A persistent, docked assistant with context across assets, vulnerabilities, controls, and diagram links — streaming responses, cited provenance, findings written directly into the workbench.
Built for teams, not just individuals
Multi-tenant by design, with role-appropriate views for architects doing the modeling work and stakeholders who just need visibility into current state.
who it's for
Built for the people who own the architecture, not just the findings list.
Security architects
who need threat models that don't go stale the moment they're finished.
Cloud & AppSec teams
managing multi-cloud environments who are tired of fragmented, cloud-only tooling.
Teams preparing for audits
SOC 2, internal security review, customer security questionnaires — who need an accurate, current picture rather than a scramble to rebuild one.
Hybrid infrastructure orgs
where cloud-only posture tools leave the on-prem estate as a blind spot.