The CAIRIS homepage
Score7.3
Rank#1 of 22
PriceFree
Free planYes
Runs onAPI, Linux, macOS, Self-hosted, Web, Windows

Summary

CAIRIS is a free, open-source platform for eliciting, specifying, and validating systems with security and usability in view. It brings together assets, countermeasures, factoids, personas, requirements, and architectural components. As a design develops, it can generate 12 views spanning people, risks, requirements, architecture, and physical locations, as well as threat models such as Data Flow Diagrams. Security analysis uses attack and architectural patterns to assess attack surface and check for known security problems and potential GDPR compliance issues. CAIRIS can produce Volere-compliant requirement specifications and GDPR DPIA documents. Its API supports custom design apps and integration into an existing toolchain. It is available for Linux, macOS, and Windows, with web, API, and self-hosted access; installation options include Docker, Vagrant, and source builds. The web application supports modern browsers except Internet Explorer. A Chrome extension can turn highlighted webpage text into document references connected to a CAIRIS server.

Who it is for

CAIRIS suits teams developing systems that need security, usability, and requirements modeling together. Its API and deployment options also fit users integrating design work into a toolchain or self-hosted environment.

What is good

  • Generates 12 design views automatically.
  • Creates threat models as designs evolve.
  • Produces requirement specifications and GDPR DPIA documents.
  • Free under the Apache Software License.
  • Provides an API for integrations and design apps.

What to know first

  • Internet Explorer is not supported.
  • Live demo databases are visible to everyone.
  • Demo accounts and work can be removed during rebuilds.

Everything Xiaomi review

CAIRIS: the full review

CAIRIS combines requirements modeling, threat analysis, and documentation generation in one platform. Its demo has important data-visibility and persistence limits, so users should export models to avoid losing work.

CAIRIS is an open-source design and analysis platform for teams working on secure, usable systems. It is best suited to people who need requirements, user perspectives, and security analysis tied together; its free availability is appealing, but the public demo is unsuitable for confidential or durable work.

Overview

CAIRIS brings security, usability, and requirements information into one model, including assets, countermeasures, personas, requirements, and architectural components. That breadth helps teams consider how design choices affect people and security together, rather than treating threat modeling as a detached checklist. It also means the platform is aimed at structured design work, not just quick diagramming.

As a design evolves, CAIRIS can generate 12 views across people, risks, requirements, architecture, and physical location, as well as threat models such as Data Flow Diagrams. Automated views can make changing designs easier to inspect, but their value depends on the underlying model representing the system accurately.

Key features

Threat and security analysis

Multiple modeling methods, attack-path analysis, and risk prioritization support a more connected security review. Attack and architectural patterns help assess attack surface and validate designs against known security problems and potential GDPR compliance issues. This is a strong fit for teams that want security considerations to shape architecture early; it is not a substitute for judging whether identified risks apply to their system.

Documentation and integration

CAIRIS generates Volere-compliant requirement specifications and GDPR DPIA documents, reducing the gap between design analysis and formal deliverables. Its API can support custom design apps or integration into an existing toolchain. The Persona Helper Chrome Extension can turn highlighted webpage text into document references linked to a CAIRIS server, which may help teams capture evidence while gathering requirements.

Deployment and demo

Teams can install CAIRIS with Docker or Vagrant, or build it from source on platforms supported by its open-source dependencies; Ubuntu is the most tested platform. The web app works in modern browsers other than Internet Explorer, with Edge supported. The live demo has important safeguards to consider: its databases are visible to everyone, the container is rebuilt nightly, and accounts beyond the recreated test account are deleted Sunday morning. Export models rather than treating the demo as persistent or private storage.

Pricing

CAIRIS is free: the Free plan costs 0.00 USD per free and is available under the Apache Software License. The plan includes the platform's modeling, attack-path analysis, risk prioritization, collaborative review, and templates and frameworks; no seat, quota, or trial limit is stated. This makes it a practical option for teams comfortable deploying and managing open-source software. For help, the maker asks users to report bugs or feature requests through GitHub issues or get in touch.

Platforms

CAIRIS supports API access, Linux, macOS, Windows, self-hosting, and web access. That range supports both locally managed deployments and browser-based use, while the deployment guidance favors Ubuntu as the most tested base. Browser users should note the Internet Explorer exception.

Who it's for

CAIRIS fits security, product, and architecture teams that need to connect requirements, people, design structure, and threat analysis, especially when generated specifications or DPIA documents are part of the workflow. It is less suitable for teams seeking a private, persistent hosted workspace through the public demo, or for anyone who only needs a lightweight standalone threat diagram.

Pros and cons

Pros

  • Combines requirements, usability, and security data, so teams can reason across design concerns in one model.
  • Generates 12 design views, threat models, and formal documents, giving teams several ways to review and communicate evolving work.
  • Free under the Apache Software License, with API access and self-hosting for teams that want to integrate or control deployment.

Cons

  • The public demo exposes all databases and is rebuilt nightly, so sensitive or important work belongs in an exported model or a separately managed deployment.
  • Ubuntu is the most tested platform, which may matter to teams planning other source-based installations.
  • Its range of model types and analysis is more than a team needs if the goal is only to produce a simple threat diagram.

Alternatives

Threat Modeling Software is the broader category to browse when comparing tools across this workflow.

  • OWASP Threat Dragon is another free, open-source option for Linux, macOS, Windows, web, and self-hosted use, with no paid plans or usage limits stated; choose it if that platform coverage and simpler stated pricing arrangement suit your needs better.
  • ThreatOpus is worth considering when a team wants a web/API option with a defined paid Starter tier: 129.99 GBP per month for 15 users, 10 team workspaces, 50 threat-model generations per month, and 10 repositories.
  • IriusRisk offers a free Community Edition capped at three active threat models and one user with limited collaboration; choose it if those limits and its templates, libraries, and XML diagram export meet the need.
  • ThreatModeler Nexus has a free Community Edition for practitioners, students, developers, architects, and security teams to experience threat modeling before scaling; it may suit readers seeking that entry point.
  • ThreatTree has a free tier capped at three forests, three DFDs per forest, and five attack trees per DFD, plus a Pro plan at 29.00 USD per month per user; choose it if those explicit diagram and tree limits fit the project.
  • AWS Threat Composer is another free option across a broad range of platforms.
  • CYMETRIS starts with CYMETRIS Lite at 99.00 EUR per month, including one full TARA project; consider it if a paid project-based option is preferable.
  • itemis SECURE is a paid alternative for web and Windows.

Verdict

Choose CAIRIS if your team wants a free, open-source environment that joins requirements, user considerations, threat analysis, and formal documentation. Its main advantage is that breadth; look elsewhere if you need a private, persistent hosted demo or a narrowly focused diagramming tool.

CAIRIS plans and pricing

All plans
Free Free Freely available under Apache Software License cairis.org · 28 Sept 2026

Compared on threat modeling software

Free plan
Yescairis.org
Attack-path analysis
Yescairis.org
Risk prioritization
Yescairis.org
Collaborative review
Yescairis.org
Templates and frameworks
Yescairis.org
Modeling methods
multiplecairis.org
Deployment
bothcairis.org

Facts

Purpose
CAIRIS is an open source platform for eliciting, specifying, and validating secure and usable systems.cairis.org · 28 Sept 2026
Design data
It supports security, usability, and requirements data including assets, countermeasures, factoids, personas, requirements, and architectural components.cairis.org · 28 Sept 2026
Visualizations
It can automatically generate 12 views of an emerging design from perspectives including people, risks, requirements, architecture, and physical location.cairis.org · 28 Sept 2026
Threat modeling
It can automatically generate threat models such as Data Flow Diagrams as an early stage design evolves.cairis.org · 28 Sept 2026
Security analysis
It uses attack and architectural patterns to help measure attack surface and validate designs for known security problems and potential GDPR compliance issues.cairis.org · 28 Sept 2026
Documentation
It generates documentation including Volere compliant requirement specifications and GDPR DPIA documents.cairis.org · 28 Sept 2026
API
The CAIRIS API can be used to build design apps or integrate CAIRIS into an existing toolchain.cairis.org · 28 Sept 2026
Client access
The web application works in modern browsers except Microsoft Internet Explorer; Microsoft Edge is supported.docs.cairis.org · 28 Sept 2026
Integrations
The Persona Helper Chrome Extension can create document references from highlighted text on a web page and connect to a CAIRIS server.docs.cairis.org · 28 Sept 2026
Demo limits
The live demo is rebuilt nightly, and accounts other than its recreated test account are deleted on Sunday morning each week.docs.cairis.org · 28 Sept 2026
Demo data visibility
The live demo guidance says all databases are visible to everyone and advises exporting models to avoid losing work when the container is rebuilt nightly.cairis.org · 28 Sept 2026
Support
The maker asks users to report problems or feature requests by raising an issue on GitHub or getting in touch.cairis.org · 28 Sept 2026

Best CAIRIS alternatives

See all 12

Where it ranks on Everything Xiaomi

Is CAIRIS yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources