Overview
Security teams must adapt to new and expansive attack vectors and surfaces. They commonly need to go further than SCA tools to be protected from highly targeted, sophisticated supply chain attacks rather than just vulnerabilities.
ReversingLabs Spectra Assure is a supply chain security platform that scans hundreds of file formats to identify embedded threats and integrates with CI/CD, cloud, and ITSM tools to automate testing, enforce policies, and establish security guardrails. It supports continuous, customized, and extensive coverage for third-party software and open source components.
Assess Your Risk Continuously collect software bills of material (SBOMs) and risk reports, which follow the CycloneDX and SPDX format, and review each component's supplier, version, relationship with other dependencies, and embedded threats and vulnerabilities.
Find Your Threats Review executables, components, and dependencies to monitor behaviors and detect suspicious changes in build systems, workflows, and large packages. Discover threats with scanning from the world's largest private repository of goodware and malware.
Consistently Remediate Threats Automatically enforce risk-based policy controls, verify that severe issues are remediated, track your security posture, and support custom scanning where you can specify what to scan for, how alerts are prioritized, and review recommended steps for remediation with every alert.
For custom pricing, EULA, or a private contract, please contact sales@reversinglabs.com , for a private offer.
Highlights
- Software Bill of Materials: Visualize your attack surface by seeing the open source and third-party software components in your environment
- Malicious behavior detection: Discover abnormal behaviors and determine if they should be investigated
- Secrets Leakage Prevention: Reduce exposed secrets and sensitive information by prioritizing and suppressing alerts to reduce noise and improve response times
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
RL SSCS 0-10GB/month | RL Software Supply Chain Security Platform - 0-10 GB per month | $75,000.00 |
RL SSCS 10-25GB/month | RL Software Supply Chain Security Platform - 10-25 GB per month | $135,000.00 |
RL SSCS 25-50GB/month | RL Software Supply Chain Security Platform - 25-50 GB per month | $216,000.00 |
RL SSCS 50-100GB/month | RL Software Supply Chain Security Platform - 50-100 GB per month | $324,000.00 |
RL SSCS 100-250GB/month | RL Software Supply Chain Security Platform - 100-250 GB per month | $450,000.00 |
RL SSCS 250-500GB/month | RL Software Supply Chain Security Platform -250-500 GB per month | $600,000.00 |
RL SSCS 500-1000GB/month | RL Software Supply Chain Security Platform - 500-1000 GB per month | $700,000.00 |
Vendor refund policy
No refunds are available
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
ReversingLabs provides technical support 24/7/365 for Software Supply Chain Security products.
Developer Portal https://secure.software
Learning Lab https://www.reversinglabs.com/learning-with-reversinglabs If you are an existing customer requiring support with ReversingLabs products and services we can be reached via phone at: +1.617.250.7518-2 via email at: support@reversinglabs.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Standard contract
Customer reviews
Very good, with small drawbacks in the interface
Disclaimer: I received access as part of my role as a Security Researcher.
I have been using Spectra Analyze for about 1 year now for ~6 hours a week.
Let's start with the interface. There are exactly 2 things that personally bother me.
1. There is no dark mode or I haven't found it.
2. The main dashboard is sometimes overloaded - this also applies to other areas - more on that later.
Otherwise, I must say I find the interface successful. It looks clean, in most cases you immediately see what the status is, and it is thematically well sorted. There are other providers where you feel like you have 10 popups before you find the information. That is not the case here. For some things, like contacted URLs, I would wish for a copy button. That would simplify things a bit more. Otherwise, you have to click 2x more and still get the information - please understand this more as "complaining at a high level."
File Upload
You can upload the data via the GUI or via API. Personally, I have used the GUI now and then, but relatively quickly built an upload script based on the available SDK and now upload 99.9% via API to ReversingLabs.
File Report
On the overview page of the individual file, you immediately see what exactly is going on. Classification, which part (static analysis, dynamic analysis, etc.) rated the file, a graph, network information if available, and much more can be seen at first glance. If you want, you can also get lost in the respective sub-items. Personally, the overview page is usually enough for me.
YARA
What I find pretty good is that I can store my own YARA rules. A "matching" also takes place for files that were uploaded in the past. It is immediately apparent which ones match, you can adjust your rule, etc. - in short, pretty solid.
Support & Feedback
This is the point that surprised me the most. Whether general inquiries or hints about what I didn't like - it was always answered promptly. I was particularly surprised that some requests for possible interface improvements were added within a very short time. I know it differently from other large companies. If I had to give stars, it would be 4.5.
-Interface partially (due to the amount of data) confusing