
A2O Architect
Security Architect Workbench
About
What's New in A2O Architect
1.2
July 22, 2026
A2O gives security architects a complete, on-device workspace for keeping assurance current as systems evolve. Turn existing artifacts—including diagrams, infrastructure code, API specifications, database schemas, agent manifests, SBOMs, policies, change tickets, pull requests, release plans, and OSCAL files—into a live assurance graph. A2O identifies affected components, data flows, trust boundaries, threats, requirements, controls, verification activities, and approvals. Every analysis is presented as a proposal for your review before it changes the graph. Explore architecture on an interactive canvas, with evidence, threat, and policy indicators attached to each node. Reuse common architecture patterns across engagements, track revisions, and understand the impact of every change. New assessment capabilities include: Zero-Trust Segmentation Matrix for identifying unsegmented paths, cross-boundary reachability, and excessive blast radius. Cryptographic Agility and PQC Readiness for finding legacy or quantum-vulnerable algorithms and planning migrations. Fault Tolerance and Chaos Security for evaluating whether systems fail securely during outages, failovers, certificate expiration, and other disruptions. Agentic and MCP Boundary Review for detecting prompt-injection channels, unconstrained tools, excessive capabilities, and embedded secrets. Infrastructure, API, database, and dependency analysis for identifying public exposure, wildcard permissions, sensitive-data handling, insecure transport, provenance gaps, and architectural weaknesses. Create focused revalidation plans, coordinate reviews across Governance and Portfolio, and prevent sign-off while material changes remain unresolved. Expired risk acceptances automatically reopen their associated findings. Each engagement has a single, searchable timeline combining audit events, architecture revisions, posture snapshots, change assessments, approvals, and other recorded activity. Workspace-wide search helps you quickly find engagements, threats, requirements, controls, evidence, and change reviews. Produce client-ready deliverables, including Attack Tree Analyses, Agentic and MCP Boundary Reviews, PQC migration plans, and Chaos Security Reviews. Self-contained review bundles include the rendered deliverable, findings register, and a digital signature that binds the content to your device’s P-256 audit identity. Bundles open in any browser without scripts, network access, or external assets. A2O protects sensitive engagement information by hiding content from the app switcher and warning you when the screen is recorded, mirrored, or shared. Restricted engagements are fully obscured during capture, while other classifications remain visible for authorized demonstrations. Face ID, Touch ID, or the device passcode is required before exporting complete workspace archives or client-review bundles. The release also includes Siri and Shortcuts navigation, full Dynamic Type support, workbench undo, system sharing and printing, improved iPhone and iPad layouts, faster imports and exports, and more efficient encrypted storage for large workspaces. All analysis runs entirely on your device.
MoreSubscription plans
A2O Architect Pro Monthly
Every Pro workflow
In-App Purchases
$999.99
A2O Architect Pro Lifetime
Every Pro workflow, forever. No subscription.









