ReversingLabs Spectra Assure is a software supply chain security platform that scans thousands of file formats to identify embedded threats and secrets leakage. Spectra Assure integrates with CI/CD, cloud, and ITSM tools to automate testing, enforce politics, and establish security guardrails. Spectra Assure supports continuous, customized, extensive coverage for third-party software and open-source components.
Security teams must adapt to new and expansive attack vectors and surfaces. They commonly need to go further than SCA tools to be protected from highly targeted, sophisticated supply chain attacks rather than just vulnerabilities.
ReversingLabs Spectra Assure is a supply chain security platform that scans hundreds of file formats to identify embedded threats and integrates with CI/CD, cloud, and ITSM tools to automate testing, enforce policies, and establish security guardrails. It supports continuous, customized, and extensive coverage for third-party software and open source components.
Assess Your Risk
Continuously collect software bills of material (SBOMs) and risk reports, which follow the CycloneDX and SPDX format, and review each component's supplier, version, relationship with other dependencies, and embedded threats and vulnerabilities.
Find Your Threats
Review executables, components, and dependencies to monitor behaviors and detect suspicious changes in build systems, workflows, and large packages. Discover threats with scanning from the world's largest private repository of goodware and malware.
Consistently Remediate Threats
Automatically enforce risk-based policy controls, verify that severe issues are remediated, track your security posture, and support custom scanning where you can specify what to scan for, how alerts are prioritized, and review recommended steps for remediation with every alert.
For custom pricing, EULA, or a private contract, please contact sales@reversinglabs.com, for a private offer.
Highlights
Software Bill of Materials: Visualize your attack surface by seeing the open source and third-party software components in your environment
Malicious behavior detection: Discover abnormal behaviors and determine if they should be investigated
Secrets Leakage Prevention: Reduce exposed secrets and sensitive information by prioritizing and suppressing alerts to reduce noise and improve response times
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay for the RL Software Supply Chain Security Platform based on how much data you scan each month, measured in gigabytes. The seven dimensions form usage bands, from 0-10 GB up to 500-1000 GB per month. You pick the band that matches your expected monthly scanning volume. As your volume grows, you move into a higher band. All bands cover the same platform for detecting malware, tampering, and risks in software packages. Billing runs on a contract term, so you commit to a band for the contract period.
Top-of-mind questions for buyers
What counts as a gigabyte for billing — file size, unique data, or total scanned volume?
Billing tracks the volume of software data the platform scans each month, measured in gigabytes. You scan software packages such as open-source, proprietary, and commercial builds. The band you choose should reflect the total monthly scan volume across all packages you submit for analysis.
What happens if my monthly scanning volume rises above my current band?
Each band covers a defined monthly gigabyte range. If your volume outgrows your band, you move into a higher band that fits the new range. Because billing runs on a contract term, contact the vendor to adjust your band; they can pro-rate changes during the contract period.
Does the price differ by software type, or only by monthly data volume?
Only monthly scan volume drives which band you pay for. The platform scans open-source packages, proprietary code, and commercial software the same way, without requiring source code. Software type does not change the band; only the total gigabytes scanned per month determines your placement.
www.reversinglabs.com+1
Helpful?
Vendor refund policy
No refunds are available.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
If you are an existing customer requiring support with ReversingLabs products and services we can be reached via phone at: +1.617.250.7518-2
via email at: support@reversinglabs.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Spectra Assure detects malware, tampering, and exposed secrets in the software you build and buy. It analyzes the final software package, whether a binary, container, or AI model, with no source code required, so you can vet third-party and commercial software before deployment. Integrations with CI/CD, cloud, and ITSM tools automate testing and enforce policies across your software supply chain.
A dataset intended to support research on machine learning
techniques for detecting malware. It includes metadata and EMBER-v2
features for approximately 10 million benign and 10 million malicious
Portable Executable files, with disarmed but otherwise complete
files for all malware samples. All samples are labeled using Sophos
in-house labeling methods, have features extracted using the
EMBER-v2 feature set, well as metadata obtained via the pefile
python library, detection counts obtained via ReversingLabs
telemetry, and additional behavioral tags that indicate the rough
behavior of the samples.