Spice Labs
Spice Labs is a post-quantum cryptography readiness company whose Topographer SaaS platform scans JVM artifacts in Artifactory and Docker Hub registries to produce Cryptographic Bills of Materials and color-coded PQC compliance reports for CISOs, DevSecOps teams, and system integrators.
- Company typePrivate
- Founded2024
- HeadquartersSomerville, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Spice Labs does
Spice Labs, Inc. is a cryptographic visibility and post-quantum readiness company founded in 2024 and headquartered in Somerville, Massachusetts. Its product, Topographer, is a cloud-hosted SaaS platform that surveys JVM applications (Java, Scala, Kotlin) by pointing at customer Artifactory or Docker Hub registries and, without source-code access, agents, or SBOMs, generates a Cryptographic Bill of Materials (CBOM) at the artifact-hash level and a color-coded PQC Security Report measured against NSA CNSA 2.0, PCI DSS v4.0, and NIST IR 8547. The underlying Artifact Dependency Graph (ADG) technology uses git-inspired Merkle Trees on the CISA-endorsed OmniBOR specification, with a hyperscale read-only graph database (BigTent) supporting 2+ billion nodes across 25+ million open-source artifacts. Java Flight Recorder instrumentation enables CI/CD-level dynamic analysis that catches quantum-vulnerable cryptography invocations static analysis misses, including dynamically loaded providers and reflection-based algorithm selection.
The company monetizes through subscription SaaS (Topographer), a free tier (Amuse Bouche) launched in March 2026 as a product-led growth entry point, and enterprise contracts including organization-level team management, API access, and configurable retention periods sold via direct enterprise field sales augmented by a system-integrator channel. A full open-source portfolio (Surveyor CLI, GoatRodeo, BigTent, Ginger-j, GitHub Action) is distributed under Apache 2.0 via GitHub and Docker Hub to seed developer adoption. The company has raised $3 million in seed funding (BasisTech, Speedinvest, OakSeed) and explicitly positions itself as a profitable, sustainable-growth operator rather than a growth-at-all-costs startup.
Spice Labs targets three primary personas: CISOs and security leadership needing portfolio-wide PQC posture and board-ready compliance evidence; engineering and DevSecOps teams needing certainty of complete remediation across build artifacts; and system integrators / PQC consultancies seeking differentiation in a market where Gartner has placed PQC among the top six cybersecurity priorities for 2026. Federal agencies subject to CNSA 2.0 and OMB M-23-02, along with regulated finance and healthcare buyers facing PQC transition deadlines, constitute the primary vertical expansion targets.
Spice Labs firmographics
Firmographics- Name
- Spice Labs
- Legal name
- Spice Labs, Inc.
- Website
- https://spicelabs.io
- Company type
- Private
- Founded year
- 2024
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Spice Labs is a post-quantum cryptography readiness company whose Topographer SaaS platform scans JVM artifacts in Artifactory and Docker Hub registries to produce Cryptographic Bills of Materials and color-coded PQC compliance reports for CISOs, DevSecOps teams, and system integrators.
- Ownership category
- akta.pro rank
Spice Labs industry classification
Industry- Product category
- Cryptographic Compliance & Software Supply Chain Security
- NAICS
- Testing Laboratories and Services (54138), Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Security Testing Tooling (SAST/DAST for smart contracts, fuzzing) (FSAPAJAK)
Keywords
Where Spice Labs is headquartered
LocationHeadquarters
- HQ city
- Somerville
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Spice Labs business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Infrastructure, Marketing or Sales, Operations
Revenue model
- SaaS Platform Subscription: Spice Labs Topographer platform provided as cloud-hosted SaaS. Customers pay subscription fees for access to the platform, CBOM generation, PQC reporting, and ADG analysis. 30-day free trial available. Revenue model emphasizes sustainable open source with paid SaaS service on top.
- Free Tier (Amuse Bouche): Free PQC assessment tool providing single-artifact analysis. Generates CBOM reports, PQC Static Analysis with Crypto-agility ratings, and Java Flight Recorder analysis at no cost. Serves as product-led growth entry point.
- Enterprise/Custom Deployments: Organization-level deployments with team management, project administration, API access, and configurable retention periods. Likely sold as enterprise subscriptions with volume pricing.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Amuse Bouche - Free PQC Assessment Tool |
| Subscription | Monthly | Full Platform - 30-Day Free Trial |
| Subscription | Annual | Enterprise Subscription |
Go-to-market motion4 records
Distribution channels6 records
Marketing channels8 records
Spice Labs product offering
Product offeringCore offering
Spice Labs surveys built software artifacts (JARs, Docker images, VM images) in customer Artifactory or Docker Hub registries using cryptographic hashing to generate Cryptographic Bills of Materials (CBOMs) and color-coded Post-Quantum Cryptography (PQC) Security Reports. The Topographer SaaS platform measures compliance against CNSA 2.0, PCI DSS v4.0, and NIST IR 8547, and aggregates results across hundreds to thousands of JVM (Java, Scala, Kotlin) projects into a single trended view.
Product overview
Spice Labs is a cryptographic visibility and post-quantum readiness company offering a unified platform centered on its Topographer SaaS product. Topographer generates Cryptographic Bills of Materials (CBOMs) and color-coded PQC Security Reports by scanning JVM artifacts from Artifactory or Docker Hub registries, measuring compliance against CNSA 2.0, PCI DSS v4.0, and NIST IR 8547. Users can access the platform via the Spice Labs Surveyor CLI (open-source, Apache 2.0), GitHub Actions integration, or the free Amuse Bouche tier for initial PQC assessments. The open-source portfolio includes GoatRodeo (artifact surveyor/ADG extractor), BigTent (read-only graph database), Ginger-j (Java encryption SDK), and a GitHub Action for CI/CD integration. The company also maintains a 2-billion-node database of open-source artifact dependency graphs spanning Java, Debian, Ubuntu, and .NET packages.
Differentiator
Problem solved
Functional benefit
Products and services
- Spice Labs Topographer Cloud-hosted SaaS platform that surveys JVM applications using cryptographic hashes to generate Cryptographic Bills of Materials (CBOMs) and color-coded PQC Security Reports (red/yellow/green) against CNSA 2.0, PCI DSS v4.0, and NIST IR 8547. Aggregates results across hundreds or thousands of projects into a single trended view with CBOM diffing between surveys to track remediation progress. Targets CISOs, security leadership, and DevSecOps teams in regulated enterprises.
- Amuse Bouche Free tier PQC assessment platform providing single-artifact CBOM reports, PQC Static Analysis with Crypto-agility ratings, and Java Flight Recorder analysis. Designed as a no-signup, product-led growth entry point for security teams to evaluate Spice Labs before committing to a paid Topographer subscription.
- Spice Labs Surveyor CLI Open-source Apache 2.0 command-line tool that surveys software artifacts, generates encrypted Artifact Dependency Graphs (ADGs), and uploads them to the Spice Labs platform. Runs locally via JVM or as a Docker container, supports multi-threaded processing, additional metadata tagging, and CI/CD pipeline integration. Used by engineering and DevSecOps teams to drive Topographer surveys.
- BigTent Graph Database Open-source, read-only graph database for software artifacts and their relationships. A high-performance, append-safe graph built for provenance, lineage, and Artifact Dependency Graph exploration, capable of handling 2+ billion node graphs on commodity hardware. Available on GitHub under Apache 2.0.
- GoatRodeo ADG Extractor Open-source artifact surveyor and Artifact Dependency Graph extractor that turns container images, packages, and repositories into verifiable dependency graphs. Used internally by Spice Labs and made available on GitHub for community adoption.
- Ginger-j Java Encryption SDK Open-source Java encryption and uploader SDK for packaging, encrypting, and shipping deployment bundles securely. Provides the encryption layer for Artifact Dependency Graph uploads to the Spice Labs platform.
- Spice Labs Surveyor GitHub Action Official GitHub Action (spice-labs-inc/action-spice-labs-surveyor) enabling automated ADG surveys and uploads as part of GitHub Actions CI/CD workflows. Allows engineering teams to run Spice Labs Surveyor directly in build pipelines for continuous PQC compliance verification.
- PQC Inventory Builder Tool announced in December 2025 aimed at helping organizations transition to post-quantum cryptography by identifying vulnerable encryption algorithms across their systems. Supports compliance efforts ahead of Q-Day for regulated industries such as finance and healthcare.
Quantifiable outcome
- CBOM generation in hours from Artifactory or Docker Hub registry without source code access or engineering burden
- +3 more outcomes
Companies that use Spice Labs
Customer profileSegments5 records
Ideal customer profiles4 records
Spice Labs technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
Feature9 records
Spice Labs partnerships and signals
Strategic signalScale indicators6 records
Recent moves6 records
Expansion highlights6 records
Spice Labs competitors and assessment
Company assessmentDirect peers
- QuSecure: QuSecure is a post-quantum cryptography company offering PQC remediation and crypto-agility tooling. Spice Labs positions itself as the 'measurement layer' complementing QuSecure's 'fix', and both compete for the same CISO PQC budget at regulated enterprises.
- SandboxAQ: SandboxAQ is a well-capitalized cryptography and quantum-AI company offering PQC inventory, crypto-agility, and post-quantum security tooling. It is the most direct, well-funded competitor in the cryptographic visibility and PQC compliance category Spice Labs targets.
- PQShield: PQShield is a UK-based post-quantum cryptography company providing PQC hardware IP, software libraries, and migration tooling. It overlaps with Spice Labs in the PQC migration and crypto-agility space and targets similar regulated customers in finance, government, and defense.
Broad incumbents
- IBM Quantum Safe: IBM Quantum Safe is IBM's enterprise-grade PQC remediation and cryptography management suite, part of IBM's broader security portfolio. Spice Labs complements it on the inventory/measurement side, but IBM's reach into regulated enterprises makes it a credible long-term competitor if it adds native CBOM-generation capabilities.
- Keyfactor: Keyfactor is an established PKI and certificate lifecycle management platform that has expanded into post-quantum readiness. It is cited as a Spice Labs 'measurement-layer complement', but its installed enterprise base and adjacent crypto-management capabilities make it a relevant incumbent peer.
- Sonatype: Sonatype operates Nexus Repository and Lifecycle for artifact management and software composition analysis, and is a leading SBOM provider. While not PQC-focused today, Sonatype is a logical adjacency competitor if it extends its SBOM platform into CBOM and PQC compliance.
- Snyk: Snyk is a leading developer security platform with SCA, SAST, container, and IaC scanning. It is relevant as a peer because its SCA capabilities cover dependency visibility across Java ecosystems that overlap with Spice Labs' artifact-scanning approach, and it serves similar engineering and DevSecOps buyers.
- JFrog: JFrog provides artifact repository (Artifactory) and security scanning (Xray) used by large enterprises to manage Java and other artifacts. Because Spice Labs integrates directly with Artifactory, JFrog is a logical platform competitor if it adds native CBOM/PQC scanning inside its own security stack.
Emerging players
- Chainguard: Chainguard focuses on software supply chain security with hardened container images and signature verification. It overlaps with Spice Labs in the broader software supply chain security and provenance category and competes for similar CISO buyers prioritizing SBOM and artifact integrity.
- Anchore: Anchore provides SBOM generation, container security, and software supply chain compliance for regulated industries. It is comparable as a vendor addressing CBOM/SBOM and compliance-driven buyers in federal, finance, and healthcare — Spice Labs' target verticals.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks3 records
Key highlights7 records
Customer concentration
Spice Labs social profiles
Digital presenceSpice Labs financial estimates
Financial estimateRevenue estimate
Valuation estimate
Spice Labs leadership team
Management profileNumber of profiles
Profiles14 records
Spice Labs funding detail
Funding detailFunding overview
Funding rounds1 record
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Spice Labs M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Spice Labs
What does Spice Labs do?
Spice Labs surveys built software artifacts (JARs, Docker images, VM images) in customer Artifactory or Docker Hub registries using cryptographic hashing to generate Cryptographic Bills of Materials (CBOMs) and color-coded Post-Quantum Cryptography (PQC) Security Reports. The Topographer SaaS platform measures compliance against CNSA 2.0, PCI DSS v4.0, and NIST IR 8547, and aggregates results across hundreds to thousands of JVM (Java, Scala, Kotlin) projects into a single trended view.
Is Spice Labs a public or private company?
Spice Labs is a private company. It is classified as venture growth investor backed and is currently operating.
When was Spice Labs founded?
Spice Labs was founded in 2024. It employs 1 to 10 people.
Where is Spice Labs based?
Spice Labs is headquartered in Somerville, United States, in the North America region.
How does Spice Labs make money?
Three revenue lines are on record. SaaS Platform Subscription is the primary driver. The others are free Tier (Amuse Bouche) and enterprise/Custom Deployments.
Who are Spice Labs's main competitors?
Direct peers on record are QuSecure, SandboxAQ and PQShield. Broad incumbents are IBM Quantum Safe, Keyfactor, Sonatype, Snyk and JFrog. Emerging players are Chainguard and Anchore.
Does Spice Labs have an API?
No public API is recorded for Spice Labs.
What industry is Spice Labs in?
Spice Labs's product category is Cryptographic Compliance & Software Supply Chain Security. Its primary akta.pro industry code is FSAPAJAK, Security Testing Tooling (SAST/DAST for smart contracts, fuzzing). Its NAICS code is 54138 and its SIC code is 7370.