About Us

Our Expertise

Lab 191 assessments go beyond what automated tools can produce. We understand binary hardening, supply chain risks, and the formal methods required to verify that code is actually safe — and how to document that for regulators.

Every assertion is reviewed and signed by a qualified expert, providing the professional judgment that distinguishes our reports from raw tool output.

Why We Started This

The EU Cyber Resilience Act requires manufacturers to document security due diligence for every third-party component they ship. Most products depend on thousands of open-source packages, and few organizations have a process to assess them at that scale.

Existing options don't fit: raw scanner output won't satisfy an auditor, and full-service consulting engagements aren't practical at the component level. We built Lab 191 to deliver expert-signed, audit-ready reports at a predictable per-component price.

Standards & Methodology Alignment

EU CRA

Regulation 2024/2847

OpenSSF

Scorecard & Best Practices

NIST SSDF

Secure Software Framework

SLSA

Supply Chain Levels for Software Artifacts

Proprietary Tooling

In addition to industry-standard data sources (OpenSSF Scorecard, OSV.dev, NVD), we use proprietary tooling including:

  • ✓
    Binary Hardening Analysis
    Verifies ASLR, DEP, Stack Canaries, and Control Flow Guard in compiled binaries
  • ✓
    AI-Driven Anomaly Detection
    Identifies obfuscated logic, anomalous API calls, and supply chain compromise indicators
  • ✓
    Static Analysis (SAST)
    Rule-based and AI-augmented source code scanning for security vulnerabilities and code quality issues
  • ✓
    CRA Mapping Templates
    Report templates with direct citation language for Annex I requirements