Last updated: February 2026
Lab 191 provides security due diligence reports for open-source software components, delivered as PDF documents. Reports are designed to support compliance with the EU Cyber Resilience Act (CRA) and related regulatory requirements.
Reports represent the professional opinion of our assessors based on evidence available at the time of assessment. They are not guarantees of security, certifications, or legal compliance advice. Reports provide evidence to support your compliance efforts but do not constitute legal advice.
Upon purchase, you receive a non-exclusive, non-transferable license to:
Reports may not be resold, publicly distributed, or used for marketing purposes without prior written permission.
Our total liability arising out of or related to the purchase or use of any report is limited to the purchase price of that report. We are not liable for indirect, consequential, incidental, or punitive damages. We are not liable for regulatory decisions made by market surveillance authorities or any other regulatory body.
We are not liable for security incidents, vulnerabilities, or failures involving any component we have assessed. Our reports reflect the state of a component at the time of assessment and do not warrant its ongoing security or fitness for any particular deployment.
Report content is copyrighted by Lab 191. The underlying open-source component code remains under its original license. Our assessment methodology, tooling, and report templates are proprietary.
This report represents the professional assessment of the undersigned as of the date of issue. It is based on information available at the time of analysis and does not constitute a guarantee of security, a certification, or legal advice. The assessment covers the specific version indicated and does not extend to future versions, patches, or configurations not evaluated. Users of this report should conduct their own evaluation of the component's suitability for their specific use case and regulatory context.
In the course of providing our services, you may share dependency lists, SBOMs, or other technical information about your software stack. We treat all customer-submitted data as confidential and:
For details on personal data processing, see our Privacy Policy.
These terms are governed by and construed in accordance with the laws of Ireland. Any disputes arising from these terms that cannot be resolved amicably shall be submitted to the exclusive jurisdiction of the courts of Ireland.
We may update these terms from time to time. Material changes will be communicated via email to active customers. Continued use of our services after changes constitutes acceptance of the updated terms.
Questions about these terms? Contact us.