CAIRIS

Web · Windows · Mac · Linux · Self-hosted · API

Freedom report

Three barsScore 6.6

  • Free tierA free tier is on its own pricing page
  • Open codeNo open-source code on record
  • Runs widely4 of 6 device platforms
  • DocumentedPlans, terms and facts published

CAIRIS is an open-source platform for eliciting, specifying and validating systems with security and usability in view. It supports design information including assets, countermeasures, factoids, personas, requirements and architectural components. As a design evolves, it can generate 12 views covering people, risks, requirements, architecture and physical locations, as well as threat models such as Data Flow Diagrams. Security analysis uses attack and architectural patterns to examine attack surface and check for known security problems and potential GDPR compliance issues. CAIRIS can generate Volere-compliant requirement specifications and GDPR DPIA documents. Its API can support design apps or connect CAIRIS with an existing toolchain. Installation options include Docker, Vagrant or source on platforms supported by its dependencies; Ubuntu is the most tested platform. The web application supports modern browsers except Internet Explorer, including Microsoft Edge. The live demo is rebuilt nightly, its databases are visible to everyone, and other accounts are deleted weekly.

Who it is for

CAIRIS suits people developing systems who need to connect requirements, architecture, usability and security analysis. It can also suit teams integrating design apps through an API.

What is good

  • Generates 12 design views and threat models.
  • Produces requirement specifications and GDPR DPIA documents.
  • API supports toolchain integration.
  • Free under the Apache Software License.

What to know first

  • Internet Explorer is not supported by the web application.
  • Live demo databases are visible to everyone.
  • The live demo is rebuilt nightly.

Freedom251 review

CAIRIS: the full review

CAIRIS links system design information with generated views, threat models and security analysis. For demo use, account for public database visibility and nightly rebuilds; Ubuntu is the most tested platform.

CAIRIS is an open-source environment for developing and assessing secure, usable systems. It suits teams that want requirements, user perspectives and threat analysis in one design model. Its strongest case is structured security work from early design through documentation, rather than quick, isolated diagramming.

Overview

CAIRIS brings security, usability and requirements information together, including assets, countermeasures, personas, factoids, requirements and architectural components. This joined-up model is useful when a team needs to consider how a design affects both people and security; it is a more involved choice than a tool focused only on drawing a threat diagram.

From an evolving design, CAIRIS can produce 12 views spanning people, risks, requirements, architecture and physical location, and generate threat models such as Data Flow Diagrams. That can keep different ways of examining a system connected to the same design. The outputs are only as useful as the model behind them, so teams still need to represent the system carefully.

Key features

Threat and security analysis

Multiple modeling methods, attack-path analysis and risk prioritization support more than a static inventory of threats. Attack and architectural patterns help assess attack surface and validate designs against known security problems and potential GDPR compliance issues. This is a good fit for teams bringing security into architecture decisions; it should not be mistaken for a guarantee of security or compliance.

Documentation and integration

CAIRIS generates Volere-compliant requirement specifications and GDPR DPIA documents, giving teams a way to carry design work into formal documentation. Its API can support custom design applications or integration into an existing toolchain. The Persona Helper Chrome Extension can turn highlighted web-page text into document references and connect them to a CAIRIS server.

Pricing

CAIRIS is free: its Free plan costs 0.00 USD per free and is available under the Apache Software License. That makes it an accessible option for teams willing to deploy and manage open-source software rather than buy a priced hosted plan. No paid plan is part of this offer.

The live demo is useful for trying the application, but not for keeping sensitive or durable work. All demo databases are visible to everyone, the container is rebuilt nightly, and accounts other than the recreated test account are deleted on Sunday morning each week. Export models if using the demo, and use a deployment you control for private work.

Platforms

CAIRIS supports Linux, macOS, Windows, web access and self-hosted deployment, as well as an API. It can be installed with Docker or Vagrant, or built from source on platforms supported by its open-source dependencies; Ubuntu is the most tested platform. The web app works in modern browsers, including Microsoft Edge, but not Internet Explorer.

For problems or feature requests, users can raise an issue on GitHub or contact the maker. This is a direct route to report problems, rather than a stated commercial support arrangement.

Who it's for

CAIRIS is best for security, requirements and architecture teams that want to develop a shared system model, generate multiple views and threat models, and carry the work into specifications or DPIA documents. API access and self-hosting also suit teams that want to connect the platform to their own tools or control where models reside. It is less suited to someone who only needs a lightweight diagramming tool or expects a private, persistent public demo.

Pros and cons

  • Pros: Security, usability and requirements data sit in one model, helping teams assess design choices across disciplines.
  • Pros: Generated views, threat models and formal documents can keep analysis and documentation tied to an evolving design.
  • Pros: Free open-source access, self-hosting and an API allow teams to deploy and integrate CAIRIS on their own terms.
  • Cons: The public demo exposes all databases and is rebuilt nightly, making it inappropriate for confidential or lasting work.
  • Cons: Ubuntu is the most tested platform, so teams choosing another deployment platform should account for less testing emphasis.
  • Cons: The platform's broad modeling and analysis focus is more than needed for teams seeking only quick standalone diagrams.

Alternatives

Threat Modeling Software is the broader category to browse when you want to compare tools for this kind of work.

  • OWASP Threat Dragon is a free, open-source option with no paid plans or stated usage limits, suited to readers seeking a simpler free alternative across desktop, web and self-hosted platforms.
  • IriusRisk is worth considering if a freemium service is preferable to CAIRIS's free open-source model; its Community Edition is free and limited to three active threat models and one user with limited collaboration.
  • ThreatModeler Nexus offers a free Community Edition for practitioners, students, developers, architects and security teams who want to experience threat modeling before scaling.
  • ThreatOpus may fit a team seeking a paid, usage-based service: its Starter plan is 129.99 GBP per month and includes 15 users and 50 threat-modelling generations per month.
  • ThreatTree is a more bounded free option for small models, capped at three forests, three DFDs per forest and five Attack Trees per DFD; its Pro plan is 29.00 USD per month, billed per user monthly.
  • AWS Threat Composer is another free alternative.
  • ThreatForge is another free alternative for web, Windows, macOS and Linux.
  • itemis SECURE is a paid alternative for web and Windows.

Verdict

Choose CAIRIS if your team wants a free, extensible way to connect requirements, user perspectives, threat analysis and generated documentation in a system design. Its central advantage is that breadth; look elsewhere if you need a simple diagramming workflow or expect the public demo to keep models private and persistent.

CAIRIS plans and pricing

All plans
Free Free Freely available under Apache Software License cairis.org · 28 Sept 2026

Compared on threat modeling software

Free plan
Yes
Attack-path analysis
Yes
Risk prioritization
Yes
Collaborative review
Yes
Templates and frameworks
Yes
Modeling methods
multiple
Deployment
both

Best CAIRIS alternatives

See all 20