# A2O Architect — Security Architect Workbench

> Security Architect Workbench (iPhone/iPad app by JAMSoft Inc.)

- Source: https://appshunter.io/ios/app/a2o-architect/id6785740531 (this page in markdown: same URL + `.md`)
- Developer: [JAMSoft Inc](https://appshunter.io/developer/1834230814)
- Category: Productivity, Business
- Price: Free with in-app purchases
- Age rating: 4+
- Requires: iOS 26.0 · 11 MB
- Languages: American English
- Released: 2026-07-09
- Data updated: 2026-08-10
- User reviews in markdown: https://appshunter.io/ios/app/a2o-architect/id6785740531/reviews.md

## What is A2O Architect?

A2O Architect is a native security architecture workbench for professionals who need to move from first project context to defensible sign-off.
Frame the engagement, import evidence, model architecture, generate security work products, verify claims, track findings, manage risk acceptance, and export approval-ready deliverables from one focused workspace.
Built for security architects, consultants, CISOs, GRC teams, platform security teams, and product security teams, A2O Architect helps turn messy project context into structured, evidence-backed security output.
Key features:
Alpha to Omega workflow: Frame, Model, Decide, and Sign-off
Engagement profiles, stakeholders, classifications, scope, and compliance drivers
Evidence center with provenance, freshness, disposition, and chain of custody
Work-product catalog for threat models, design reviews, AI risk, cloud controls, questionnaires, audit evidence, risk acceptances, executive briefings, and more
Governed AI generation with local drafts, Apple Intelligence on-device generation, and optional cloud provider egress review
Redaction, provider approval, Restricted-data blocking, and exact payload preview before cloud generation
Assurance graph linking controls, claims, evidence, findings, approvals, and gaps
Immutable sign-off snapshots with hashes, evidence digests, expiry, revocation, and audit trail
Exports for Markdown, branded PDF, Word-compatible RTF, JSON, CSV, SARIF, OSCAL-style packages, and Open Threat Model JSON
Local encrypted workspace storage and passphrase-encrypted archive transfer
A2O Architect does not require a Jamsoft account. Your workspace stays on your device unless you explicitly choose to send selected context to an AI provider you configure.

https://www.apple.com/legal/internet-services/itunes/dev/stdeula/
https://jamsoftinc.com/privacy-policy-a2o-architect

## Pricing and in-app purchases

Base price: Free.

**Subscriptions**

| Subscription | Price | Period |
| --- | --- | --- |
| A2O Architect Pro Monthly | $29.99 | per month |
| A2O Architect Pro Yearly | $299.99 | per year |

**One-time purchases**

| Purchase | Price | Type |
| --- | --- | --- |
| A2O Architect Pro Lifetime | $999.99 | one-time |



## Version history (last 4 releases)

### 1.3 — 2026-08-09

The app is reorganised. The Guided Path shell moves the engagement journey into the title bar as primary navigation, deletes the left rail, and turns the Advisor into a panel beside your work. Alongside it, the new Toolbox mode lets someone run a threat model or gap assessment without creating an engagement at all — that's the single biggest change in how the app feels day to day. Text is also ~16% larger everywhere, from today's change.

Four industry packs are the commercial headline — Healthcare/HIPAA and Payments/PCI DSS, plus FedRAMP and AI Security added this week. What makes them worth $79.99 is that they bundle ~475 real control entries (the full HIPAA Security Rule with CFR citations, all twelve PCI DSS 4.0 requirements at sub-requirement level, the 800-53 Rev 5 Moderate baseline with enhancements, ISO 42001 Annex A, the complete NIST AI RMF core, OWASP LLM Top 10, and 40 EU AI Act obligations) with assessor guidance and cross-framework crosswalks. Generating from a pack blueprint now attaches those catalogs automatically and ends the deliverable with an evidence-derived determination table that has no AI in it.

Growth features round it out: three complimentary cloud AI runs on the free tier (Keychain-counted, so reinstalling doesn't reset them), user-initiated end-to-end-encrypted iCloud sync, findings handoff to Jira/GitHub/Linear, engagement playbooks, white-label export branding, and Quick Start.

### 1.2 — 2026-07-22

A2O gives security architects a complete, on-device workspace for keeping assurance current as systems evolve.
Turn existing artifacts—including diagrams, infrastructure code, API specifications, database schemas, agent manifests, SBOMs, policies, change tickets, pull requests, release plans, and OSCAL files—into a live assurance graph. A2O identifies affected components, data flows, trust boundaries, threats, requirements, controls, verification activities, and approvals. Every analysis is presented as a proposal for your review before it changes the graph.
Explore architecture on an interactive canvas, with evidence, threat, and policy indicators attached to each node. Reuse common architecture patterns across engagements, track revisions, and understand the impact of every change.
New assessment capabilities include:
Zero-Trust Segmentation Matrix for identifying unsegmented paths, cross-boundary reachability, and excessive blast radius.
Cryptographic Agility and PQC Readiness for finding legacy or quantum-vulnerable algorithms and planning migrations.
Fault Tolerance and Chaos Security for evaluating whether systems fail securely during outages, failovers, certificate expiration, and other disruptions.
Agentic and MCP Boundary Review for detecting prompt-injection channels, unconstrained tools, excessive capabilities, and embedded secrets.
Infrastructure, API, database, and dependency analysis for identifying public exposure, wildcard permissions, sensitive-data handling, insecure transport, provenance gaps, and architectural weaknesses.
Create focused revalidation plans, coordinate reviews across Governance and Portfolio, and prevent sign-off while material changes remain unresolved. Expired risk acceptances automatically reopen their associated findings.
Each engagement has a single, searchable timeline combining audit events, architecture revisions, posture snapshots, change assessments, approvals, and other recorded activity. Workspace-wide search helps you quickly find engagements, threats, requirements, controls, evidence, and change reviews.
Produce client-ready deliverables, including Attack Tree Analyses, Agentic and MCP Boundary Reviews, PQC migration plans, and Chaos Security Reviews. Self-contained review bundles include the rendered deliverable, findings register, and a digital signature that binds the content to your device’s P-256 audit identity. Bundles open in any browser without scripts, network access, or external assets.
A2O protects sensitive engagement information by hiding content from the app switcher and warning you when the screen is recorded, mirrored, or shared. Restricted engagements are fully obscured during capture, while other classifications remain visible for authorized demonstrations. Face ID, Touch ID, or the device passcode is required before exporting complete workspace archives or client-review bundles.
The release also includes Siri and Shortcuts navigation, full Dynamic Type support, workbench undo, system sharing and printing, improved iPhone and iPad layouts, faster imports and exports, and more efficient encrypted storage for large workspaces. All analysis runs entirely on your device.

### 1.1 — 2026-07-13

A2O Architect now gives you a stronger, clearer path from evidence to defensible sign-off.
• Compare current evidence with saved baselines to identify changes in risks, controls, and readiness.
• Assess all 93 ISO/IEC 27001:2022 Annex A controls and create a working Statement of Applicability.
• Turn architecture diagrams into reviewable components and data flows using on-device analysis.
• Import SARIF and CSV findings, validate MITRE ATT&CK and CWE references, and export ATT&CK Navigator layers.
• Use Apple Intelligence or your own OpenAI, Claude, or Gemini key with clearer privacy and governance controls.
• Review revisions, document rejected work, and verify portable audit trails across devices.
• Enjoy improved performance, stability, security, and responsive layouts.

### 1.0 — 2026-07-09

No release notes.

## More apps by JAMSoft Inc

- [a-do](https://appshunter.io/ios/app/a-do/id6751292466)
- [TicTacXplode](https://appshunter.io/ios/app/tictacxplode/id6751343654)
- [Smoke 1 with your ...](https://appshunter.io/ios/app/smoke-1-with-your/id6751505060)
- [Playlist-Me](https://appshunter.io/ios/app/playlist-me/id6751526462)
- [Scribely-AI](https://appshunter.io/ios/app/scribely-ai/id6751562073)
- [Spades Night](https://appshunter.io/ios/app/spades-night/id6751740116)

All apps by JAMSoft Inc: https://appshunter.io/developer/1834230814

---

*Data collected daily from the US App Store and indexed by [AppsHunter](https://appshunter.io/). User reviews are verbatim App Store reviews. Ratings, prices and chart positions refresh continuously; this snapshot is from 2026-08-10.*
