VigilArch

Introducing CASM

Security architecture that stays current — because it's connected to what's actually running.

Most security tools tell you what's misconfigured. VigilArch tells you why it matters, tied to the real architecture of your environment, updated as that environment changes.

architecture.live

LIVE
ON-PREMVPC · us-east-1FWfirewall-01LBedge-albAPPapp-svc-01APPapp-svc-02 · newDBprimary-rdsexposed path · CVE-2026-4471
5 assets · 2 trust boundariessynced 2s ago

// the problem

Threat models get built once, usually before an audit, as a static diagram in Visio or draw.io. Six months later the environment has drifted — new services, new cloud accounts, decommissioned firewalls, changed trust boundaries — and the diagram is fiction.

Meanwhile, CSPM and vulnerability scanners produce long lists of findings with no architectural context: is this exposed database actually reachable from the internet through three hops, or is it sitting behind a segmented boundary that makes the CVSS score academic?

Architecture review and vulnerability management have historically lived in separate tools, updated on separate schedules, owned by separate teams. The gap between them is where real risk hides.

definition

Continuous Architecture Security Management (CASM)

/kaz-əm/ · noun

The practice of keeping your security architecture — asset inventory, trust boundaries, threat models, and exposure data — as a single, living model instead of a periodic exercise.

instead of

  • a threat model done once per year and forgotten
  • an asset inventory that's stale the day after it's exported
  • vulnerability findings with no architectural context

CASM treats architecture like

infrastructure-as-code treats infrastructure: something discovered continuously, modeled explicitly, and kept in sync with what's actually deployed — across cloud and on-prem alike.

static diagram

synced 8mo ago

live diagram

synced 2s ago

how it works

One pipeline, always running — not four tools stitched together once a year.

01

Discover

VigilArch connects to your cloud accounts (AWS, Azure, GCP) and on-prem network infrastructure (including Cisco ASA and Check Point firewalls) to build a live, continuously refreshed asset inventory — no manual spreadsheets, no stale CMDB exports.

02

Model

Assets get mapped into architecture diagrams with real trust boundaries. STRIDE threat modeling happens directly against this live view — either manually, node by node, or through a guided bulk pass that proposes findings across the whole diagram for review.

03

Correlate

Vulnerability and exposure data is layered onto the architecture itself. A CVE isn't just a severity score in a list — it's tied to a specific asset, its position in the diagram, and the trust boundaries around it, so you see actual reachability and blast radius.

04

Review

CoPilot sits alongside the work, contextual to whatever asset, diagram node, or finding you're looking at, with cited sources behind its suggestions. Findings it proposes go directly into the STRIDE workbench for your team to accept, adjust, or discard.

platform

Everything a continuous review discipline actually needs.

Multi-cloud & on-prem discovery

Continuous asset discovery across AWS, Azure, and GCP, plus on-prem network and firewall connectors (Cisco ASA, Check Point, and others), unified into a single inventory.

STRIDE threat modeling workbench

Structured threat modeling against your real architecture — manual node-level modeling and guided bulk passes across an entire diagram, with bulk apply/discard so a reviewer stays in control.

Vulnerability–exposure correlation

Findings correlated against diagram signals — trust boundaries, connectivity, asset role — so severity reflects actual architectural exposure, not just a standalone CVSS score.

Architecture diagramming

Diagrams generated from and linked to live discovered assets, with node-level detail and drill-down, instead of a disconnected drawing tool bolted on the side.

CoPilot AI assistant

A persistent, docked assistant with context across assets, vulnerabilities, controls, and diagram links — streaming responses, cited provenance, findings written directly into the workbench.

Built for teams, not just individuals

Multi-tenant by design, with role-appropriate views for architects doing the modeling work and stakeholders who just need visibility into current state.

who it's for

Built for the people who own the architecture, not just the findings list.

Security architects

who need threat models that don't go stale the moment they're finished.

Cloud & AppSec teams

managing multi-cloud environments who are tired of fragmented, cloud-only tooling.

Teams preparing for audits

SOC 2, internal security review, customer security questionnaires — who need an accurate, current picture rather than a scramble to rebuild one.

Hybrid infrastructure orgs

where cloud-only posture tools leave the on-prem estate as a blind spot.

Your architecture already changes constantly.
Your security model should keep up.