In an era where cybersecurity skill shortages plague organizations of all sizes, a new AI-native platform is fundamentally transforming one of the most time-consuming and expertise-dependent processes in application security: threat modeling and security architecture reviews. SecurityReview.AI, co-founded by AppSecEngineer CEO Abhay Bhargav, promises to compress what traditionally takes weeks or months into mere minutes�not through simple automation, but through what the company calls “recursive questioning” that mimics how experienced security engineers interrogate system designs. The platform tackles three core problems that have long plagued security reviews: the sheer number of people required for comprehensive assessments, the extensive data gathering needed across documentation and infrastructure, and perhaps most critically, the scarcity of senior security professionals who possess the breadth of knowledge to conduct thorough threat modeling.
Unlike the flood of AI tools hastily bolted onto existing security products, SecurityReview.AI was built from the ground up with artificial intelligence as its foundation, integrating advanced reasoning models with established threat modeling methodologies like STRIDE and the company’s own PWNISMS framework (Products, Workload, Network, IAM, Secrets Management, Monitoring, and Supply Chain). By connecting directly to document repositories, cloud architecture diagrams, and source code, then mapping findings to compliance frameworks like SOC 2, PCI DSS, and GDPR, the platform aims to democratize security design reviews beyond the typical two-person team who knows how to do them properly. In this exclusive VMblog Q&A, Bhargav explains how his company is addressing hallucination problems that plague other AI security tools, why continuous threat modeling integrated into DevSecOps pipelines represents the future of secure-by-design software, and whether AI will eventually replace human security architects entirely.
++
VMblog: You claim to reduce security architecture reviews from 3 months to 30 minutes. That’s a dramatic reduction – what’s broken about the current process that makes it take so long, and how does your ‘recursive questioning’ technology actually work to solve this?
Abhay Bhargav: There are several large challenges with doing security design reviews and architecture reviews:
- The number of people required to do this in terms of a large organization or even a small organization. The number of people you need to pull into meetings to get this done and to get their inputs on things is quite a lot.
- There is also a lot of data to be gathered. You need to have documentation related to the product, the application interfaces, the network, the components, and all of that stuff. This takes a very long time when a human being does it.
- There’s also a skill issue. Some people who are very experienced security professionals will be able to do this very fast, whereas some who are not so experienced or don’t have that kind of skill will take a very long time to do this.
This is why it takes time, and this is why security design reviews and architecture reviews (threat models) take up very long times. Now, the idea of security review.ai is that we leverage AI to do most of the heavy lifting for us. I would say 95% of the heavy lifting is done by security review.ai, which means that connecting to document sources is done by security review.ai, ensuring that you have multiple sources of input being processed as actionable output is handled by security review.ai. Since it’s AI-native, the AI is able to leverage a very strong pipeline to do all of this stuff quickly. This is why what usually takes a few weeks or sometimes even a couple of months or even more sometimes now takes very little time because you can start connecting this to multiple sources for input which is the most time-consuming thing, and since the AI-native experience is there, it behaves like an experienced security engineer and solves the skill shortage that comes from not having experienced security folks on your team.
VMblog: Your materials mention that typically only two people on a team know how to do threat modeling properly. How big is this skills shortage in the cybersecurity industry, and how does SecurityReview.ai democratize threat modeling for teams that lack deep security expertise?
Bhargav: Skill shortage is a very real thing, especially when it comes to doing intellectually intense work like security design reviews and threat models. This requires a great deal of experience, knowledge about systems, and understanding of the components. This is where the skill shortage comes in because there are very few people who have the breadth and depth of understanding to be able to do this correctly. AI can help with that because AI, when targeted properly towards this problem and has a structured approach to doing this, will provide the same experience as a senior security engineer. While AI does not replace the whole security engineering team, it will help augment their skills to be able to identify the most key things, and they can just sit and focus on a few edits and modifications as necessary. This is where security review democratizes this. This can be done by anybody. Doesn’t have to be a security engineer. It can be done by a developer, a project manager who is part of that project. It can be done by any of those folks who have access to inputs or access to documentation. Or access to source code related to that particular application or product.
VMblog: The security space is flooded with AI-powered tools right now. What makes your approach different from competitors, and how do you avoid the ‘hallucination’ problems you mention that other AI security tools suffer from?
Bhargav: That’s true, the security space is flooded with AI-powered tools. A lot of them have bolted on AI on top of existing tools that were not meant to be AI in the first place. However, Security Review.ai has been created with AI as a first-class citizen.
Security Review uses something called Recursive Questioning that will basically interrogate the input documentation like a human security reviewer would, and that ensures that the hallucinations are kept to the least possible extent. In fact, in most of our customer engagements and our test cases, which have been a quite large number based on the number of applications that we work with, we have seen so far about one or two cases where one or two instances have hallucinated and even that has been in earlier versions of the product. The newer versions of the product, our approach to doing RAG along with the newer reasoning models have essentially ensured that hallucinations do not happen.
VMblog: Walk us through a concrete example – if a fintech company uploads their existing AWS architecture diagrams and API documentation, what specific threats and countermeasures would SecurityReview.ai identify that they might have missed in a traditional review?
Bhargav: In this case, if a FinTech company uploads their diagrams and documentation, what will happen is that the security review will go through this in a structured process of:
- Identifying security objectives
- Breaking down the components and the sensitive information that are likely to be stored, transmitted, or processed by the system
- Identifying very specific threat scenarios based on the system that it has as well as the countermeasures for those threat scenarios
The way this process is set up is that it interrogates the existing documents that they have connected or the existing inputs that they have connected to securityreview.ai. So the idea here is that this would be using the reasoning capabilities of the LLM which has been trained on a massive corpus of data related to these products. The other thing that we’ve done is we’ve added additional corpus on things like popular products, popular components and so on so that we have more of the latest security notifications or advisories from these products. We also have connections to multiple security taxonomies like CAPEC or CWE. Or MITRE attack and so on which also ensures that what threat scenarios and countermeasures have been identified don’t get missed because they relate to all of these things being, all of these things converging at certain points in time.
In addition, we also use existing threat modeling methodologies like STRIDE, and we also use enhanced threat modeling approaches which we have created called PWNISMS (Products Workload Network IAM Secrets Management Monitoring and Supply Chain). This means that it essentially covers all possible cases across these domains to be able to identify threats and countermeasures.
VMblog: You emphasize built-in compliance mappings. With regulations like SOC 2, PCI DSS, and emerging AI governance frameworks, how does SecurityReview.ai help companies stay ahead of the compliance curve rather than just checking boxes after the fact?
Bhargav: One of the key aspects of succeeding at any compliance requirement is to base your security program on a clear understanding of risk. Doing threat modeling or security design reviews are a first step towards doing that, especially for applications. Security review solves that fundamental issue that comes with not just achieving compliance mandates but also surpassing compliance mandates because it aligns itself with risk. Those risks are directly mapped against compliance requirements like PCI DSS or SOC 2 or GDPR or EU NIS 2 and so on and so forth. This is how we ensure that the checkbox thing is very much just the baseline but security review bases its entire analysis on risk, and that’s what these compliance standards require as well. In fact, a lot of these compliance mandates require you to do threat models and security design reviews aside from achieving the compliance mandates that they have. So this is also something security review helps you do.
VMblog: You mention pushing findings directly into existing tools. In practice, how does this work with popular DevSecOps pipelines, and what does the handoff look like between your AI analysis and human security teams?
Bhargav: One of the things that security review.ai allows you to do is to do continuous threat modeling which is very much aligned with integrating it into DevSecOps pipelines or DevSecOps feedback loops.
For instance, one of the things you can do with security review.ai is as soon as product requirement documentation is created, it will trigger a job to analyze that for security requirements and then come up with security design requirements. requirements for that particular product requirement doc. As soon as a Git repository has a pull request created, it could analyze risky code and come up with suggestions on how to address those risky code elements that are there for that particular pull request.
All of these are written back to the source of the trigger, which means that comments are written back as GitHub pull request comments, Confluence comments, or Jira comments and so on. This helps because it directly integrates with their DevSecOps feedback loop, which is very very important.
VMblog: What types of companies are seeing the biggest impact from this approach? Are you primarily serving startups that lack security expertise, or are enterprise security teams also finding value in automating their review processes?
Bhargav: I think the people who are going to be most benefited from SecurityReview.ai are teams that are shipping applications either fast or teams that are shipping applications at scale. These could be enterprise teams, these could be start-up teams, it could be anywhere in the middle. But I think these two sets of teams are going to be greatly benefited by using security review.ai. In addition, teams that have compliance mandates or regulatory mandates will also benefit extensively from SecurityReview because it addresses a lot of the heavy lifting when it comes to compliance earlier on in the cycle which is what you want.
VMblog: Looking ahead, do you see AI eventually replacing human security architects entirely, or is this more about augmenting human expertise? Where do you think security architecture reviews will be in five years?
Bhargav: We have built SecurityReview.ai to augment human expertise. The idea is that while it democratizes security design reviews and threat models across teams, it is not meant to be a zero-human-in-the-loop process. Humans are going to be required to validate some of the findings and amend some of the outputs that have come in. Also, leverage some of these outputs for better engagement with teams so that this secure-by-design vision for the future of software is actually met rather than a theoretical concept which it is in most places currently.
##





