The authors propose a model-based approach to address safety and security assessment of system architecture. They present an integrated process where system engineers design the model of the system architecture, safety and security engineers specify the propagation of failures and attacks inside each component of the architecture using their dedicated tool. They also define the failure modes that have to be merged from both disciplines. The underlying analyses are then performed using Alloy. They instantiate this approach with the system engineering tool melody from Thales, and the risk analysis supporting tool safety architect from All4Tec.