All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
ReversingLabs sells software supply chain security and threat intelligence to software producers and enterprise buyers. Its Spectra Assure product scans software without source code for malware, tampering, and exposed secrets. It also lists AI models it detects in software. For a listed set of Hugging Face models, it reports safety assessments that another company, Splx, develops. Founded in 2009, it had raised $81 million as of its Series B, led by Crosspoint Capital Partners. Its customer SolarWinds added Spectra Assure to its development and deployment pipeline as a final check. Customers of its Spectra Intelligence service query a private database of over 422 billion benign and malicious files. That database, built over more than 15 years, is what a rival would take longest to match.
| Description | Spectra Assure analyzes software packages for supply chain risks such as malware, tampering, and exposed secrets, giving software producers and buyers feedback before software is released or deployed. | [f1] |
|---|---|---|
| Founded | 2009 | [f2] |
| HQ | Cambridge, Massachusetts, United States | [f3] |
| Funding | $81M total | [f2] |
| Latest funding | Series B (56 million dollars, 2021) | [f4] |
| Deployment | SaaS | [f5] |
| Product | What it does |
|---|---|
| Spectra Assure | Spectra Assure: Scans AI and ML model files for malicious code as part of software supply chain analysis and lists detected models in an ML-BOM. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Spectra Assure scans AI and ML model files for malicious code as part of software supply chain analysis and lists detected models in an ML-BOM. It is mapped to the AI Defense Matrix. [f6]
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
ReversingLabs provides binary analysis and software supply chain security. This conventional security is mapped to the Cyber Defense Matrix. [f7]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 4/5 | ReversingLabs names the buyer, the software producer and the enterprise software buyer who must trust binaries they ship or purchase, and ties the pain to concrete incidents. SecurityWeek connects the company to the SolarWinds, Codecov, and Kaseya supply-chain attacks by name, non-vendor corroboration that the problem exists at scale. [s2, s7, s1] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Spectra Assure performs static binary analysis without source code, builds an xBOM and SAFE risk report, and detects AI and ML model files by signature for an ML-BOM, all documented in a public technical portal at docs.secure.software rather than only on marketing pages. SecurityWeek independently describes the binary-integrity and component analysis. [s2, s3, s7] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Software supply chain security is a live buyer-side category driven by the SolarWinds-era incidents that SecurityWeek names, Codecov, Kaseya, and SolarWinds. That places it at a solid buyer-demand level, with a vendor-displayed Visionary spot in the 2026 Gartner Magic Quadrant for the category, not an independently cited Leader placement that would lift it further. [s7, s14, s1] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Co-founders Mario Vuksan and Tomislav Pericin have led ReversingLabs since 2009 with long standing in the malware-analysis field, but the fetched record shows no verifiable prior exit and no independently confirmed publication record beyond the company's own output. That supports a middle score, short of what multiple-exit founders would earn. [s5, s7] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | SolarWinds is featured by name in a published Spectra Assure customer story after rebuilding its program post-Sunburst, ReversingLabs publishes several named and sectoral customer case studies, and Spectra Intelligence supplies file reputation through APIs and direct integrations at scale. Named references across multiple sources support a strong score, below the Gartner-Leader proof that would lift it to the top. [s6, s4, s7] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | ReversingLabs has raised capital across rounds since 2009, with an independent aggregator putting the total near 120 million dollars, more than the 81 million disclosed at the 2021 Series B, and a further SEC Form D exempt offering filed in 2024, and it built two product lines over a long arc. Like the entire private cluster, margins cannot be confirmed publicly, so it holds at adequate rather than 4. [s7, s8, s12, s10] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Software supply chain security and file threat intelligence are recognized categories buyers slot without vendor coaching, and Gartner Peer Insights maintains a ReversingLabs vendor page in the software composition analysis and software supply chain security markets while CB Insights tracks it among cybersecurity vendors. That independent category recognition supports a strong score, short of the category-shaping placement that would earn the top. [s1, s13, s12] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 4/5 | ReversingLabs holds the proprietary data flywheel the venture-backed cluster lacks: a file-reputation repository it says exceeds 422 billion files built since 2009 and a binary-analysis engine that would be expensive to replicate. SecurityWeek independently dates the company to 2009, and it is named in the academic SOREL-20M malware-detection benchmark, whose labels derive from multiple sources, corroborating research-grade file intelligence. That structural moat supports a strong score, above the reproducible catalogs a platform could bundle faster. [s4, s2, s7, s11] |
ReversingLabs sells to the organization that must decide whether a software binary is safe to ship or to buy. The company frames two buyers, the software producer securing its own release pipeline and the enterprise software buyer assessing third-party and commercial packages, and ties both to the risk that a binary hides malicious code, tampering, or unknown components. Spectra Assure analyzes complete software packages without source code to surface those risks.
The pain is grounded in named incidents rather than vendor abstraction. SecurityWeek connects ReversingLabs directly to the SolarWinds, Codecov, and Kaseya supply-chain attacks, naming all three as the high-profile incidents that underlined the need for software-integrity management, which is non-vendor evidence that the problem exists at the scale claimed.
The AI angle extends the same problem to machine learning components. Spectra Assure detects AI and ML model files inside analyzed software by signature and lists them in an ML-BOM, so a buyer can see which models a package pulls in and assess whether they are safe to use before the software ships. [s2, s7, s3]
The ReversingLabs platform runs two product lines on a shared binary-analysis core. Spectra Assure performs static analysis of large software packages without source code, produces an xBOM inventory and a SAFE risk report, and flags malicious code, tampering, and hidden components that signature scanners miss. Spectra Intelligence is the file and network reputation service, which the company says draws on a repository of over 422 billion files with millions added daily.
The capability depth is documented for engineers, not only marketed. ReversingLabs publishes a technical portal at docs.secure.software whose fetched page covers how Spectra Assure detects AI models by signature, lists them in an ML-BOM, and assesses their risk in the SAFE report, the kind of public documentation that separates this cluster's stronger entries from thin marketing pages.
The AI and ML model coverage is real but layered. Spectra Assure identifies models by format signature and records them in the ML-BOM, while the deeper behavioral and safety verdicts come from a partner, Splx, whose red-teaming data the SAFE report displays as an AI security card for a fixed set of Hugging Face models. The native ReversingLabs contribution is model discovery and malicious-code detection, and the safety testing is the partner's. [s4, s3, s9]
ReversingLabs is the established binary-analysis vendor among a cluster of younger code-security companies. Where Cycode, Semgrep, Snyk, and Checkmarx grew up scanning source code and dependencies for application security teams, ReversingLabs came from malware analysis and file reputation and works on compiled binaries, which lets it inspect commercial and closed-source packages those scanners cannot read. That different starting point is its main positioning claim.
Its stated differentiator is depth on binaries without source code. ReversingLabs argues that analyzing the shipped artifact, rather than the source, catches tampering and malicious code introduced after the build, which is the failure mode the SolarWinds Sunburst attack exploited. That claim rests on the company's own description plus the published SolarWinds customer story rather than an independent benchmark.
The structural pressure comes from both sides. Rival code-security vendors contest the same application-security budget with source and dependency scanners of their own, and platform vendors could bundle supply-chain scanning into suites enterprises already own, so the company defends a standalone position on the strength of its data moat and incumbency. [s2, s6, s7]
ReversingLabs shows named-customer proof that many peers in this cluster cannot. SolarWinds is featured in a published Spectra Assure customer story that presents the product as central to the supply-chain security program it built after the Sunburst incident, and the company publishes additional case studies spanning government, energy, insurance, and biotech accounts.
The data business carries an embedded-usage footprint. Spectra Intelligence supplies file reputation through an extensive API and direct integrations, and the company says it processes hundreds of millions of reputation lookups per day, an integration motion that signals usage beyond the marketed customer list.
Independent traction proof is thinner than the named references suggest. The SolarWinds customer story and the Fortune 500 reach are vendor-curated or vendor-claimed, the company displays a Visionary spot in the 2026 Gartner Magic Quadrant for software supply chain security rather than an independently cited Leader placement, and no current revenue or customer total is disclosed in the public record beyond third-party estimates. [s6, s4, s7]
The founding team has run ReversingLabs for the company's full history. Mario Vuksan is chief executive and co-founder and Tomislav Pericin is co-founder, and the pair have led the company since 2009 with long-standing presence in the malware-analysis and reverse-engineering field.
The public credibility signal is tenure and domain depth rather than a track record of exits. The fetched record shows sustained operation of a binary-analysis business over more than fifteen years, but it does not show a verifiable prior exit or an independently confirmed publication record of the kind that lifts the strongest teams in this category.
Investor backing reinforces the operating signal. Crosspoint Capital Partners led the 2021 Series B with existing investor ForgePoint Capital, institutional backing from firms that fund and operate security companies, which supports credibility without substituting for a founder exit. [s5, s7, s8]
ReversingLabs presents the operating maturity expected of a company that has sold to regulated enterprises for over a decade. Its products sit inside customer build pipelines and security operations, and the customer stories name energy, city government, Fortune 500 insurance, biotech, AI, and global banking accounts that carry their own audit expectations, which suggests enterprise procurement exposure. The pricing page states SOC2 Type II compliance for the Spectra Assure Platform, a self-stated line, and no inspectable report or trust portal appears on the fetched pages.
The newer AI surface is where assurance questions concentrate. Because the deeper AI model safety verdicts in the SAFE report come from a partner rather than from ReversingLabs directly, a security review of the AI capability will likely ask how that partner data is sourced, how current it is across the fixed model list, and what happens to coverage outside that list. For a buyer adopting the product specifically for AI model security, the partner dependency is the readiness item most likely to surface in evaluation. [s9, s6, s15]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Cycode | competes with | Application security and software supply chain platform in the same cluster, scanning source and dependencies where ReversingLabs scans compiled binaries. | |
| Checkmarx | competes with | Enterprise application security testing platform with Gartner Leader placement, contesting the same supply-chain security budget. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Snyk | competes with | Developer-first application and supply chain security vendor whose dependency and code scanning overlaps the software supply chain buyer. | |
| Semgrep | competes with | Code-scanning vendor moving into supply chain and AI-generated-code review, competing for the application security team's attention. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Splx | adjacent | AI red-teaming specialist whose testing data ReversingLabs displays in the SAFE report, a partner on AI model security and a potential substitute for it. |
Add analyzed competitors to compare them side by side with ReversingLabs.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
press the advantage
ReversingLabs is durable where it owns an asset rivals cannot quickly rebuild and exposed on what the customer ultimately buys. A private goodware and malware reputation database of over 422 billion files accumulated over more than 15 years is a genuine non-public data asset, and reading compiled software without source code is years of reverse-engineering and machine-learning work. Against that, the customer buys software that produces a risk report rather than a service that underwrites the verdict, no rule mandates the product, and the AI model safety scores come from a partner, Splx. So the lock is the data corpus and pipeline embedding, not a contract a replacement cannot satisfy.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | ReversingLabs sells software the customer runs in its pipeline, with the SAFE report and reputation verdicts as algorithmic output rather than a service that accepts accountability, and the deeper AI safety scoring is a partner's. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Spectra Assure wires into the build and release pipeline and Spectra Intelligence embeds through APIs and direct integrations, real friction to replace, but no data residency lock or network effect appears. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | The pricing page states SOC2 Type II compliance for the Spectra Assure Platform, a self-stated table-stakes line with no inspectable report, trust portal, or regulatory mandate behind it, so nothing here gates procurement, holding it at 1. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Static binary analysis that reads compiled software without source code, plus multi-factor classification across a repository of over 422 billion files, is reverse-engineering and machine-learning work that takes years to build. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | The named buyers are regulated and high-assurance enterprises in financial services, defense, and energy, and the company posts no enterprise price, so procurement-gated replacement is an inference from the buyer type rather than a documented review process. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | ReversingLabs is a platform with application features that scan, inventory, and score software and AI components rather than infrastructure customer traffic is forced through inline. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 3/3 | The company quotes a named non-public corpus, a private goodware and malware database with over 422 billion files accumulated over more than 15 years. Reproducing an accumulation at this scale would take a new entrant comparable years of collection plus the software-vendor and malware-source relationships behind it, which places the corpus above rebuildable public catalogs and crowdsourced corpora and earns the top score. |
ReversingLabs sells to the organization that must decide whether a software binary is safe to ship or to buy. The company frames two buyers, the software producer securing its own release pipeline and the enterprise that assesses third-party and commercial packages, and ties both to the risk that a binary hides malicious code, tampering, or unknown components. SecurityWeek relays the company's claim of working with large enterprises in financial services, defense, and software.
The named demand sits in regulated and high-assurance sectors. The customer stories present SolarWinds and a global energy leader, and the SecurityWeek funding coverage adds financial services and defense. Those buyers likely favor a vendor that can inspect compiled artifacts the producer did not write, an inference the SolarWinds story supports when its CISO describes wanting to run the product on commercial software before purchase. That buyer set fits the deep-pocket enterprise more than the lean self-serve team.
The AI and ML angle extends the same buyer rather than opening a new one. Spectra Assure detects AI models inside analyzed software by signature and lists them in an ML-BOM, so the existing supply-chain buyer can see which models a package pulls in. The open question is whether AI model security pulls a distinct buyer or mainly enriches the report the supply-chain buyer already purchases.
The claimed advantage is reading the shipped artifact rather than the source. Spectra Assure performs static binary analysis that processes large software packages without the source code, and the company says that analysis finds malicious code, tampering, and hidden risks in open-source and commercial packages that legacy scanners miss. SolarWinds itself adopted the product after the Sunburst incident, per its published customer story.
The engine rests on a data asset, not only an algorithm. Spectra Intelligence supplies file and network reputation from a private goodware and malware database of over 422 billion files with millions added daily, and the same binary-analysis and multi-factor classification feeds both the reputation verdicts and the package scan. That corpus is the part a funded rival cannot rebuild by writing software alone.
The AI and ML model coverage is real but layered, and the deepest verdict is a partner's. Spectra Assure identifies models by format signature and records them in the ML-BOM, while the safety and red-teaming assessment in the SAFE report is the SPLX report, which the documentation states is developed by Splx. The native ReversingLabs contribution is model discovery and malicious-code detection, and the behavioral safety scoring comes from outside.
ReversingLabs publishes named-customer proof for its supply-chain line. SolarWinds is featured in a published Spectra Assure customer story in which its CISO, Tim Brown, says the company added the product to its development and deployment pipeline as a final check after the Sunburst incident, alongside the legacy application security testing tools it kept running. The company also publishes a global energy leader and additional sectoral accounts.
The data business carries an embedded-usage footprint beyond the marketed logos. Spectra Intelligence delivers reputation through an extensive API and direct integrations, and the company says its high-volume processing supports hundreds of millions of reputation lookups per day, an integration motion that signals usage the customer page does not enumerate.
Independent traction proof is thinner than the named references suggest. The customer stories are vendor-curated, and the public record discloses no current revenue or customer total beyond third-party estimates. The company raised about 81 million dollars and last took a 2021 Series B, so its go-to-market scale runs on capital that is several years old.
ReversingLabs posts public pricing for the small end of its supply-chain line and reserves the larger plans for a sales conversation. The pricing page lists a free Community tier with 100k lookups a month, a Community+ tier at 500 dollars a month with 1M lookups, and Essentials and Enterprise tiers the page labels "Inquire for pricing". A 14-day free trial of Spectra Assure lowers the entry barrier for a producer evaluating the scanner.
The posted plans show what the company meters at the low end. The Community tiers charge by monthly lookup volume and the page describes both as plans for individual developers, while the Essentials and Enterprise descriptions shift to scanning proprietary, commercial, and open-source software, larger files, and enterprise-wide usage without a posted rate. The company sells the data-intelligence line separately as reputation lookups delivered through the API.
The unposted enterprise price fits the regulated, high-assurance buyer the customer stories name. A free-tier and trial-led entry plus negotiated Essentials and Enterprise terms is the posture of a vendor selling large deals into financial services, defense, and energy accounts, where procurement expects a contract rather than a published rate card.
ReversingLabs delivers software the customer operates, not a managed service. The SolarWinds story confirms the customer added Spectra Assure to its own development and deployment pipeline to scan packages and produce the SAFE report, and Spectra Intelligence delivers reputation data through an API and direct integrations the customer wires into its own tools. The product produces findings the customer's team then acts on.
The operating maturity matches a vendor that has sold to regulated enterprises for over a decade. Products sit inside customer build pipelines and security operations, and the named accounts in financial services, defense, and energy carry their own audit expectations, which suggests experience with enterprise procurement even though the fetched pages publish no formal attestation set.
The AI surface adds an operational dependency on a partner. Because the deeper AI model safety verdicts come from the SPLX report developed by Splx, coverage of AI model testing depends on that partnership and, by the documentation, on a fixed set of Hugging Face models. A buyer adopting the product for AI model security inherits that partner's update cadence and model coverage.
ReversingLabs presents the assurance of an established vendor rather than a posted attestation wall. The pricing page lists SOC2 Type II compliance as a Spectra Assure Platform feature, a self-stated line rather than an inspectable report, and no ISO 27001 or other certification badge or trust portal surfaced on the fetched pages, so the trust case pairs that statement with a fifteen-year operating record selling to regulated buyers.
The proof the company foregrounds is verifiable supply-chain outcomes. In the published SolarWinds story, CISO Tim Brown attests by name that the company added Spectra Assure to its pipeline as a final check on every release, comparing new builds against known-good ones to make sure nothing nefarious got in, and the SAFE report produces a shareable SBOM and risk assessment that buyers can hand to their own auditors. That evidence-on-demand model substitutes for a published certification list when a customer runs a security review.
The newer AI surface is where assurance questions concentrate. Because the deeper AI model safety verdicts come from a partner, a security review of the AI capability will likely ask how that partner data is sourced, how current it stays across the fixed model list, and what happens to coverage outside it. For a buyer adopting the product specifically for AI model security, that partner dependency is the readiness item most likely to surface in evaluation.
ReversingLabs runs two product lines on one binary-analysis core, and the core is the platform claim. Spectra Assure scans software packages and Spectra Intelligence serves file and network reputation, and both draw on the same engine that deconstructs compiled artifacts and classifies them against the company's repository. Owning that shared analysis layer, rather than a single point tool, is the structural position.
The reputation corpus is the asset that compounds over time. The private goodware and malware database of over 422 billion files grows by millions of samples daily, and the company describes that corpus as built on file and network IOCs harvested from more than fifteen years of its own development and research, from software vendors, and from diverse malware and network sources rather than from crowdsourced collection. The fetched pages do not state that customer-submitted files feed the shared classification, so any cross-customer enrichment is at most vendor-implied. The accumulation itself is the ecosystem advantage a rival cannot reproduce by shipping comparable features.
The exposure is that the company's own sales and API are the distribution the record evidences, rather than a channel an incumbent cannot buy. Spectra Intelligence integrates into existing security infrastructure, and while the site navigation advertises marketplaces, OEM partners, and alliances, the cited record does not quantify what those channels contribute, so the evidenced distribution rests on the data and the direct relationship.
Mario Vuksan is chief executive and co-founder and Tomislav Pericin is co-founder, both still in leadership at the company founded in 2009. The credibility signal is tenure in one domain.
The public record shows operation rather than a prior exit. The fetched pages document a binary-analysis business sustained over more than fifteen years, but they do not show a verifiable prior exit or an independently confirmed publication record of the kind that lifts the strongest founding teams in this category. The strength is durability in one domain, not a serial track record.
Investor backing reinforces the operating signal. Crosspoint Capital Partners led the 2021 Series B with existing investor ForgePoint Capital, institutional firms that fund and operate security companies, which supports credibility without substituting for a founder exit. The cited funding record identifies none newer.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | ReversingLabs: Spectra Assure Software Supply Chain Security | official | 2026-07-09 |
| f2 | SecurityWeek on ReversingLabs (founded 2009) | press | 2026-06-14 |
| f3 | SEC EDGAR full-text search result for ReversingLabs Form D filings (business location Cambridge, MA) | regulatory | 2026-07-02 |
| f4 | Venture Capital Journal on Crosspoint leading the 56 million Series B | press | 2026-06-14 |
| f5 | AI Defense Matrix Catalog entry | other | 2026-06-10 |
| f6 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| f7 | ReversingLabs platform | official | 2026-06-14 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | ReversingLabs homepage (Software Supply Chain Security and Threat Intelligence) “See deeper into software packages with advanced static binary analysis that quickly processes large and complex software packages - without the need for source code.” | official | 2026-06-14 |
| s2 | ReversingLabs Spectra Assure product page (software supply chain security) “Spectra Assure goes beyond just vulnerability detection to find malicious code, software components, and hidden risks in open-source, and commercial software packages that legacy scanners miss.” | official | 2026-06-14 |
| s3 | How Spectra Assure scans AI models (ReversingLabs documentation) “Spectra Assure detects AI models in a variety of data formats - both standard and solution-specific - by their signature ... Once identified, these models are listed as components in the ML-BOM.” | official | 2026-06-14 |
| s4 | ReversingLabs Spectra Intelligence (file and network threat intelligence) “Customers have access to over 422 billion files in our threat repository, with millions of samples added daily.” | official | 2026-06-14 |
| s5 | ReversingLabs leadership page (Mario Vuksan CEO and co-founder, Tomislav Pericin co-founder) “Mario Vuksan CEO & Co-founder” | official | 2026-06-14 |
| s6 | ReversingLabs customer stories (SolarWinds and other named accounts) “SolarWinds: Building a Path to Excellence in Software Supply Chain Security with Spectra Assure” | official | 2026-06-14 |
| s7 | SecurityWeek on ReversingLabs raising 56 million dollars in Series B “Threat detection startup ReversingLabs has raised $56 million in a Series B funding round. To date, the company has raised $81 million. ... Founded in 2009, the company claims to be working with large enterprises in sectors such as financial services, defense, software, retail, and insurance.” | press | 2026-06-14 |
| s8 | Venture Capital Journal on Crosspoint leading the 56 million Series B round “Crosspoint leads $56m Series B round for ReversingLabs” | press | 2026-06-14 |
| s9 | Spectra Assure ML-BOM and SPLX (Splx) red-teaming integration for Hugging Face models “Enhancing the ML-BOM within the SAFE report with SPLX testing data ... incorporates assessments based on safety evaluations and red-teaming testing on models used in the analyzed software. ... Currently, this information is displayed only for the following models from Hugging Face” | official | 2026-06-14 |
| s10 | SEC EDGAR full-text search: ReversingLabs Inc Form D exempt-offering filings (CIK 0001724209, Delaware, Cambridge MA, filed 2017, 2021, and 2024) “"display_names":["ReversingLabs, Inc. (CIK 0001724209)"] ... "display_names":["ReversingLabs LLC (CIK 0001724209)"] ... "form":"D" ... "file_date":"2017-12-01" ... "file_date":"2021-08-03" ... "file_date":"2024-05-15" ... "biz_locations":["Cambridge, MA"] ... "inc_states":["DE"]” | regulatory | 2026-06-30 |
| s11 | SOREL-20M malware-detection benchmark co-produced with ReversingLabs (arXiv preprint 2012.07634, Harang and Rudd) “In this paper we describe the SOREL-20M (Sophos/ReversingLabs-20 Million) dataset: a large-scale dataset consisting of nearly 20 million files with pre-extracted features and metadata, high-quality labels derived from multiple sources” | research | 2026-06-30 |
| s12 | CB Insights company profile for ReversingLabs (founded 2009, Cambridge MA, total raised, Regtech and Cybersecurity expert collections) “ReversingLabs raised a total of $120.15M.” | other | 2026-06-30 |
| s13 | Gartner Peer Insights vendor page for ReversingLabs in the software composition analysis and software supply chain security markets “ReversingLabs Reviews, Ratings & Features 2026 | Gartner Peer Insights” | other | 2026-06-30 |
| s14 | ReversingLabs homepage banner naming it a Visionary in the inaugural 2026 Gartner Magic Quadrant for Software Supply Chain Security (vendor-displayed) “ReversingLabs named a Visionary” | official | 2026-06-30 |
| s15 | ReversingLabs plans and pricing page stating SOC2 Type II compliance for the Spectra Assure Platform “SOC2 Type II compliant” | official | 2026-07-02 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | ReversingLabs homepage: Software Supply Chain Security and Threat Intelligence “Software Supply Chain Security & Threat Intelligence” | official | 2026-06-17 |
| s2 | ReversingLabs Spectra Assure product page (binary analysis without source code) “See deeper into software packages with advanced static binary analysis that quickly processes large and complex software packages - without the need for source code. Spectra Assure goes beyond just vulnerability detection to find malicious code, software components, and hidden risks.” | official | 2026-06-18 |
| s3 | ReversingLabs Spectra Intelligence (private goodware and malware reputation database) “Customers have access to over 422 billion files in our threat repository, with millions of samples added daily. ... the industry's largest private goodware and malware database.” | official | 2026-06-17 |
| s4 | How Spectra Assure scans AI models, the SPLX report, and the Hugging Face model list “Spectra Assure detects AI models ... by their signature ... listed as components in the ML-BOM. ... The SPLX report is developed by Splx. ... Currently, this information is displayed only for the following models from Hugging Face” | official | 2026-06-17 |
| s5 | ReversingLabs customer stories (SolarWinds and a global energy leader) “SolarWinds: Building a Path to Excellence in Software Supply Chain Security with Spectra Assure” | official | 2026-06-18 |
| s6 | SecurityWeek on ReversingLabs Series B (founding, funding, supply-chain incidents) “ReversingLabs has raised $56 million in a Series B ... To date, the company has raised $81 million. The round was led by Crosspoint Capital Partners. Existing investor ForgePoint Capital also participated. ... Founded in 2009 ... in financial services, defense, software” | press | 2026-06-17 |
| s9 | Venture Capital Journal: Crosspoint leads 56m Series B round for ReversingLabs “Crosspoint leads $56m Series B round for ReversingLabs” | press | 2026-06-17 |
| s7 | ReversingLabs leadership page (Mario Vuksan CEO and co-founder, Tomislav Pericin co-founder) “Mario Vuksan CEO & Co-founder” | official | 2026-06-17 |
| s8 | Spectra Assure SAFE report and named customer testimonials (SolarWinds, Forescout, ExtraHop) “Spectra Assure offers the SAFE report, which delivers the most comprehensive SBOM/xBOM and risk assessment of an application to identify malware, tampering, suspicious behaviors and more.” | official | 2026-06-18 |
| s10 | ReversingLabs customer story: SolarWinds adds Spectra Assure as a final check in its pipeline “That's when SolarWinds added Spectra Assure to its development and deployment pipeline. Spectra Assure provides 'a final check,' CISO Tim Brown said. ... While SolarWinds continued to leverage legacy application security testing tools” | official | 2026-06-18 |
| s12 | SOREL-20M malware-detection benchmark co-produced with ReversingLabs (arXiv preprint 2012.07634, Harang and Rudd) “In this paper we describe the SOREL-20M (Sophos/ReversingLabs-20 Million) dataset: a large-scale dataset consisting of nearly 20 million files with pre-extracted features and metadata, high-quality labels derived from multiple sources” | research | 2026-06-30 |
| s13 | The Hacker News: Lazarus graphalgo npm and PyPI campaign discovered by ReversingLabs research “"Developers are approached via social platforms like LinkedIn and Facebook, or through job offerings on forums like Reddit," ReversingLabs researcher Karlo Zanki said in a report.” | press | 2026-06-30 |
| s14 | ReversingLabs plans and pricing page, trust probe 2026-07-02 also covered trust subdomain and paths with nothing further served “Community 100k lookups $0 per month ... Community+ 1M lookups $500 per month ... Essentials Inquire for pricing ... Enterprise Inquire for pricing For enterprises to comprehensively secure their software supply chain end-to-end.” | official | 2026-07-02 |
| s15 | ReversingLabs Spectra Intelligence corpus sourcing (in-house research, software vendors, diverse malware and network sources) “Our trusted data corpus is built on continually harvested and constantly curated file and network IOCs from RL’s 15+ years of in-house development and research, along with leading software vendors, and diverse malware and network sources. ... RL doesn't depend on crowdsourced collection.” | official | 2026-07-02 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.