All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
ReversingLabs wears an AI-security label, but the asset a buyer cannot cheaply reproduce is older than the label: a private goodware and malware reputation database holding over 422 billion files, growing by millions a day, and built over more than 15 years. That corpus, plus a binary-analysis engine that inspects compiled software without source code, is a replication barrier a rival would need years of comparable collection to match. The AI and ML model scanning that earns the label is a thinner, recent layer, and the deeper model safety verdicts in its report come from a partner, Splx, for a fixed set of Hugging Face models. A buyer adopting ReversingLabs for AI model security is partly underwriting that partner's coverage.
| Description | Spectra Assure analyzes software packages for supply chain risks such as malware, tampering, and exposed secrets, giving software producers and buyers feedback before software is released or deployed. | [f1] |
|---|---|---|
| Founded | 2009 | [f2] |
| HQ | Cambridge, Massachusetts, United States | [f3] |
| Funding | $81M total | [f2] |
| Latest funding | Series B (56 million dollars, 2021) | [f4] |
| Deployment | SaaS | [f5] |
| Product | What it does |
|---|---|
| Spectra Assure | Spectra Assure: Scans AI and ML model files for malicious code as part of software supply chain analysis and lists detected models in an ML-BOM. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Spectra Assure scans AI and ML model files for malicious code as part of software supply chain analysis and lists detected models in an ML-BOM. It is mapped to the AI Defense Matrix. [f6]
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
ReversingLabs provides binary analysis and software supply chain security. This conventional security is mapped to the Cyber Defense Matrix. [f7]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score |
|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 4/5 |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs, demos, and third-party validation. | 4/5 |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 4/5 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
press the advantage
| Dimension | Score |
|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 3/3 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | ReversingLabs: Spectra Assure Software Supply Chain Security | official | 2026-07-09 |
| f2 | SecurityWeek on ReversingLabs (founded 2009) | press | 2026-06-14 |
| f3 | SEC EDGAR full-text search result for ReversingLabs Form D filings (business location Cambridge, MA) | regulatory | 2026-07-02 |
| f4 | Venture Capital Journal on Crosspoint leading the 56 million Series B | press | 2026-06-14 |
| f5 | AI Defense Matrix Catalog entry | other | 2026-06-10 |
| f6 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| f7 | ReversingLabs platform | official | 2026-06-14 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | ReversingLabs homepage (Software Supply Chain Security and Threat Intelligence) “See deeper into software packages with advanced static binary analysis that quickly processes large and complex software packages - without the need for source code.” | official | 2026-06-14 |
| s2 | ReversingLabs Spectra Assure product page (software supply chain security) “Spectra Assure goes beyond just vulnerability detection to find malicious code, software components, and hidden risks in open-source, and commercial software packages that legacy scanners miss.” | official | 2026-06-14 |
| s3 | How Spectra Assure scans AI models (ReversingLabs documentation) “Spectra Assure detects AI models in a variety of data formats - both standard and solution-specific - by their signature ... Once identified, these models are listed as components in the ML-BOM.” | official | 2026-06-14 |
| s4 | ReversingLabs Spectra Intelligence (file and network threat intelligence) “Customers have access to over 422 billion files in our threat repository, with millions of samples added daily.” | official | 2026-06-14 |
| s5 | ReversingLabs leadership page (Mario Vuksan CEO and co-founder, Tomislav Pericin co-founder) “Mario Vuksan CEO & Co-founder” | official | 2026-06-14 |
| s6 | ReversingLabs customer stories (SolarWinds and other named accounts) “SolarWinds: Building a Path to Excellence in Software Supply Chain Security with Spectra Assure” | official | 2026-06-14 |
| s7 | SecurityWeek on ReversingLabs raising 56 million dollars in Series B “Threat detection startup ReversingLabs has raised $56 million in a Series B funding round. To date, the company has raised $81 million. ... Founded in 2009, the company claims to be working with large enterprises in sectors such as financial services, defense, software, retail, and insurance.” | press | 2026-06-14 |
| s8 | Venture Capital Journal on Crosspoint leading the 56 million Series B round “Crosspoint leads $56m Series B round for ReversingLabs” | press | 2026-06-14 |
| s9 | Spectra Assure ML-BOM and SPLX (Splx) red-teaming integration for Hugging Face models “Enhancing the ML-BOM within the SAFE report with SPLX testing data ... incorporates assessments based on safety evaluations and red-teaming testing on models used in the analyzed software. ... Currently, this information is displayed only for the following models from Hugging Face” | official | 2026-06-14 |
| s10 | SEC EDGAR full-text search: ReversingLabs Inc Form D exempt-offering filings (CIK 0001724209, Delaware, Cambridge MA, filed 2017, 2021, and 2024) “"display_names":["ReversingLabs, Inc. (CIK 0001724209)"] ... "display_names":["ReversingLabs LLC (CIK 0001724209)"] ... "form":"D" ... "file_date":"2017-12-01" ... "file_date":"2021-08-03" ... "file_date":"2024-05-15" ... "biz_locations":["Cambridge, MA"] ... "inc_states":["DE"]” | regulatory | 2026-06-30 |
| s11 | SOREL-20M malware-detection benchmark co-produced with ReversingLabs (arXiv preprint 2012.07634, Harang and Rudd) “In this paper we describe the SOREL-20M (Sophos/ReversingLabs-20 Million) dataset: a large-scale dataset consisting of nearly 20 million files with pre-extracted features and metadata, high-quality labels derived from multiple sources” | research | 2026-06-30 |
| s12 | CB Insights company profile for ReversingLabs (founded 2009, Cambridge MA, total raised, Regtech and Cybersecurity expert collections) “ReversingLabs raised a total of $120.15M.” | other | 2026-06-30 |
| s13 | Gartner Peer Insights vendor page for ReversingLabs in the software composition analysis and software supply chain security markets “ReversingLabs Reviews, Ratings & Features 2026 | Gartner Peer Insights” | other | 2026-06-30 |
| s14 | ReversingLabs homepage banner naming it a Visionary in the inaugural 2026 Gartner Magic Quadrant for Software Supply Chain Security (vendor-displayed) “ReversingLabs named a Visionary” | official | 2026-06-30 |
| s15 | ReversingLabs plans and pricing page stating SOC2 Type II compliance for the Spectra Assure Platform “SOC2 Type II compliant” | official | 2026-07-02 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | ReversingLabs homepage: Software Supply Chain Security and Threat Intelligence “Software Supply Chain Security & Threat Intelligence” | official | 2026-06-17 |
| s2 | ReversingLabs Spectra Assure product page (binary analysis without source code) “See deeper into software packages with advanced static binary analysis that quickly processes large and complex software packages - without the need for source code. Spectra Assure goes beyond just vulnerability detection to find malicious code, software components, and hidden risks.” | official | 2026-06-18 |
| s3 | ReversingLabs Spectra Intelligence (private goodware and malware reputation database) “Customers have access to over 422 billion files in our threat repository, with millions of samples added daily. ... the industry's largest private goodware and malware database.” | official | 2026-06-17 |
| s4 | How Spectra Assure scans AI models, the SPLX report, and the Hugging Face model list “Spectra Assure detects AI models ... by their signature ... listed as components in the ML-BOM. ... The SPLX report is developed by Splx. ... Currently, this information is displayed only for the following models from Hugging Face” | official | 2026-06-17 |
| s5 | ReversingLabs customer stories (SolarWinds and a global energy leader) “SolarWinds: Building a Path to Excellence in Software Supply Chain Security with Spectra Assure” | official | 2026-06-18 |
| s6 | SecurityWeek on ReversingLabs Series B (founding, funding, supply-chain incidents) “ReversingLabs has raised $56 million in a Series B ... To date, the company has raised $81 million. The round was led by Crosspoint Capital Partners. Existing investor ForgePoint Capital also participated. ... Founded in 2009 ... in financial services, defense, software” | press | 2026-06-17 |
| s9 | Venture Capital Journal: Crosspoint leads 56m Series B round for ReversingLabs “Crosspoint leads $56m Series B round for ReversingLabs” | press | 2026-06-17 |
| s7 | ReversingLabs leadership page (Mario Vuksan CEO and co-founder, Tomislav Pericin co-founder) “Mario Vuksan CEO & Co-founder” | official | 2026-06-17 |
| s8 | Spectra Assure SAFE report and named customer testimonials (SolarWinds, Forescout, ExtraHop) “Spectra Assure offers the SAFE report, which delivers the most comprehensive SBOM/xBOM and risk assessment of an application to identify malware, tampering, suspicious behaviors and more.” | official | 2026-06-18 |
| s10 | ReversingLabs customer story: SolarWinds adds Spectra Assure as a final check in its pipeline “That's when SolarWinds added Spectra Assure to its development and deployment pipeline. Spectra Assure provides 'a final check,' CISO Tim Brown said. ... While SolarWinds continued to leverage legacy application security testing tools” | official | 2026-06-18 |
| s12 | SOREL-20M malware-detection benchmark co-produced with ReversingLabs (arXiv preprint 2012.07634, Harang and Rudd) “In this paper we describe the SOREL-20M (Sophos/ReversingLabs-20 Million) dataset: a large-scale dataset consisting of nearly 20 million files with pre-extracted features and metadata, high-quality labels derived from multiple sources” | research | 2026-06-30 |
| s13 | The Hacker News: Lazarus graphalgo npm and PyPI campaign discovered by ReversingLabs research “"Developers are approached via social platforms like LinkedIn and Facebook, or through job offerings on forums like Reddit," ReversingLabs researcher Karlo Zanki said in a report.” | press | 2026-06-30 |
| s14 | ReversingLabs plans and pricing page, trust probe 2026-07-02 also covered trust subdomain and paths with nothing further served “Community 100k lookups $0 per month ... Community+ 1M lookups $500 per month ... Essentials Inquire for pricing ... Enterprise Inquire for pricing For enterprises to comprehensively secure their software supply chain end-to-end.” | official | 2026-07-02 |
| s15 | ReversingLabs Spectra Intelligence corpus sourcing (in-house research, software vendors, diverse malware and network sources) “Our trusted data corpus is built on continually harvested and constantly curated file and network IOCs from RL’s 15+ years of in-house development and research, along with leading software vendors, and diverse malware and network sources. ... RL doesn't depend on crowdsourced collection.” | official | 2026-07-02 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Do not republish its content or share access without the operator's permission.