CyLab Usable Privacy and Security Laboratory
CUPS is an academic research laboratory at Carnegie Mellon University that develops tools, labels, and frameworks to improve the usability of privacy and security systems. It serves graduate students, the usable privacy research community, and policymakers through open research, publications, and policy artifacts.
- Company typePrivate
- Founded2005
- HeadquartersPittsburgh, United States
- Headcount5,001–10,000
- GTM typeB2B
- OfferingServices
What CyLab Usable Privacy and Security Laboratory does
CyLab Usable Privacy and Security Laboratory (CUPS) is an academic research laboratory at Carnegie Mellon University, affiliated with the university's broader Carnegie Mellon CyLab. Founded alongside the inaugural Symposium on Usable Privacy and Security (SOUPS) in 2005 and led by Director Lorrie Cranor, CUPS brings together faculty and PhD students from multiple CMU programs—Societal Computing, Human-Computer Interaction, Computer Science, Electrical and Computer Engineering, Engineering and Public Policy, and Public Policy and Management—to conduct interdisciplinary research at the intersection of usable privacy, security, and human-computer interaction. The lab's research is organized around three strategies: building security systems that "just work" without human intervention, making secure systems intuitive, and teaching humans to perform security-critical tasks.
CUPS's core outputs are research artifacts rather than commercial products. The lab has developed more than ten notable tools and frameworks, including the Privacy Nutrition Label, the IoT Security and Privacy Label (presented at the White House Cyber Trust Mark launch), the CCPA Online Privacy Choice Icon (adopted by the California Attorney General), the Personalized Privacy Assistant, the Usable Privacy Policy Project, the Matcha IDE Plugin for privacy label creation, the Data-Driven Password Meter, the Broadband Internet Consumer Label (submitted to the FCC), and the FoxTor anonymous browsing Firefox extension. Research is disseminated through open-access publications at venues including USENIX Security, CHI, SOUPS, CCS, and PoPETs.
CUPS does not sell commercial products and does not disclose revenue. Its funding model consists of competitive federal research grants (notably the NSF IGERT doctoral training program) and philanthropic gifts (including a 2023 gift from Craig Newmark Philanthropies for IoT label research). Selected research has been commercialized through licensing arrangements, most notably anti-phishing training tools developed by CUPS researchers that were commercialized by Wombat Security Technologies (later acquired by Proofpoint). The lab's "customers" in a stakeholder sense are graduate students, the SOUPS research community, and policymakers at the FCC, California AG, and White House.
CyLab Usable Privacy and Security Laboratory firmographics
Firmographics- Name
- CyLab Usable Privacy and Security Laboratory
- Legal name
- CyLab Usable Privacy and Security Laboratory
- Website
- https://cups.cs.cmu.edu
- Company type
- Private
- Founded year
- 2005
- Operating status
- Operating
- Headcount range
- 5,001–10,000 employees
- Short description
- CUPS is an academic research laboratory at Carnegie Mellon University that develops tools, labels, and frameworks to improve the usability of privacy and security systems. It serves graduate students, the usable privacy research community, and policymakers through open research, publications, and policy artifacts.
- Ownership category
- akta.pro rank
Where CyLab Usable Privacy and Security Laboratory is headquartered
LocationHeadquarters
- HQ city
- Pittsburgh
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
CyLab Usable Privacy and Security Laboratory business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Infrastructure
Revenue model
- Research Grants: CUPS operates primarily as an academic research laboratory funded through competitive research grants from government agencies including NSF (IGERT program, NSF grants) and other federal research funding sources.
- Philanthropic Donations: The lab receives charitable donations to support specific research initiatives, such as Craig Newmark Philanthropies gift supporting IoT security and privacy labels research.
- Technology Commercialization: Research outputs are commercialized through licensing, such as anti-phishing training tools developed by CUPS being commercialized by Wombat Security.
- Student Fellowships: NSF IGERT program provides two-year doctoral training fellowships to U.S. citizens and permanent residents participating in the CUPS program.
Go-to-market motion1 record
Distribution channels4 records
Marketing channels7 records
CyLab Usable Privacy and Security Laboratory product offering
Product offeringCore offering
CUPS is an academic research laboratory at Carnegie Mellon University that conducts interdisciplinary research on usable privacy and security. It develops open-source research tools and prototypes (such as the FoxTor anonymous browsing extension, Privacy Nutrition Labels, IoT Security Labels, the Personalized Privacy Assistant, and the Matcha IDE plugin) and trains graduate students in usable privacy and security research through programs affiliated with multiple CMU PhD programs.
Product overview
CyLab Usable Privacy and Security Laboratory (CUPS) is a research laboratory at Carnegie Mellon University focused on understanding and improving the usability of privacy and security software and systems. Rather than a commercial product company, CUPS produces research tools and prototypes including FoxTor (an anonymous Firefox browsing extension), various privacy labeling systems (nutrition labels for privacy, IoT security labels, broadband consumer labels), and privacy policy analysis tools (Usable Privacy Policy Project, Bank Privacy Policy Search Engine, Privacy Finder). The lab also developed the Matcha IDE plugin and the CCPA-compliant Online Privacy Choice Icon. These tools are primarily research outputs designed to make privacy and security more accessible to end users.
Differentiator
Problem solved
Functional benefit
Brands
- SOUPS - Symposium On Usable Privacy and Security: An annual academic conference organized by CUPS that brings together researchers in human computer interaction, security, and privacy.
Products and services
- FoxTor FoxTor is a Firefox browser extension that enables anonymous web browsing by automatically configuring the browser to use Tor and Privoxy networks, using 'Masked' and 'Unmasked' metaphors to help users control when websites can track them. It is intended for end users seeking accessible anonymous web browsing and is freely distributed as open-source software.
- Privacy Nutrition Label A standardized privacy 'nutrition label' designed to present privacy information in a consumer-friendly format similar to food nutrition labels, enabling users to quickly understand data practices. Designed for website operators, app developers, and consumers; freely available as a research artifact.
- IoT Security and Privacy Label A standardized labeling system for Internet of Things devices that communicates security and privacy information to consumers. Presented at the White House's Cyber Trust Mark launch in July 2023 and supported by Craig Newmark Philanthropies funding.
- Personalized Privacy Assistant An intelligent agent project aimed at developing systems capable of learning users' privacy preferences over time, semi-automatically configuring privacy settings, and making privacy decisions on their behalf. Targeted at mobile app users.
- Usable Privacy Policy Project A research project developing approaches to extract information from natural-language privacy policies and display that information in useful ways for users. Targets researchers, policymakers, and consumers.
- Bank Privacy Policy Search Engine A search engine that allows users to find and compare bank privacy policies, helping consumers understand how financial institutions handle their personal information.
- Matcha IDE Plugin An IDE plugin for creating accurate privacy nutrition labels, developed to help developers easily generate and implement privacy labels for their applications.
- Privacy Finder A search engine for privacy policies that helps users find and analyze website privacy practices using P3P standards.
- Online Privacy Choice Icon A stylized blue toggle icon designed and tested by the lab for online privacy choices, adopted by the California Attorney General for CCPA compliance and now appearing across the internet.
- Broadband Internet Consumer Label A consumer label for broadband internet services designed by the lab, submitted to the FCC in October 2022 to help consumers understand broadband service privacy practices.
- CUPS Doctoral Training Program (NSF IGERT) An interdisciplinary doctoral training program funded by NSF IGERT, offering two-year fellowships to U.S. citizens and permanent residents pursuing PhD research in usable privacy and security across multiple CMU departments.
- Symposium On Usable Privacy and Security (SOUPS) An annual academic conference organized by CUPS and now managed by USENIX Association that brings together researchers in human computer interaction, security, and privacy. The premier venue for usable privacy and security research with peer-reviewed proceedings published in the ACM Digital Library.
Quantifiable outcome
- CCPA privacy choice icon designed by CUPS was officially recommended by California Attorney General
- +4 more outcomes
Companies that use CyLab Usable Privacy and Security Laboratory
Customer profileNamed customers3 records
Segments1 record
Ideal customer profiles3 records
CyLab Usable Privacy and Security Laboratory technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
Feature11 records
CyLab Usable Privacy and Security Laboratory partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core.
- Carnegie Mellon CyLabcoreCUPS is affiliated with Carnegie Mellon CyLab, the university's broader security and privacy research center. This affiliation provides shared resources, collaboration opportunities, and institutional support across security and privacy research initiatives.
- USENIX AssociationcoreSOUPS (Symposium on Usable Privacy and Security) is now managed by USENIX Association. USENIX publishes the conference proceedings and provides organizational infrastructure for the annual symposium.
- ACM (Association for Computing Machinery)coreACM Digital Library hosts SOUPS conference proceedings. CUPS faculty serve on ACM program committees and the conference follows ACM formatting and publication standards.
Scale indicators4 records
Recent moves6 records
Expansion highlights6 records
CyLab Usable Privacy and Security Laboratory competitors and assessment
Company assessmentDirect peers
- Princeton CITP (Center for Information Technology Policy): Princeton's CITP conducts interdisciplinary academic research at the intersection of technology, privacy, security, and policy — including usable security and digital identity. It is the closest peer to CUPS in scope, prestige, and policy-influence posture.
- NYU Center for Cyber Security: NYU CCS is an interdisciplinary academic center producing research on usable security, privacy, and the human factors of cyber defense. Its multidisciplinary faculty and policy engagement mirror CUPS's model.
- Max Planck Institute for Security and Privacy (CISPA): CISPA is a leading European academic research center focused on security and privacy, with substantial work on usable security and human factors. It is a peer in scale, output volume, and field-defining status.
- Georgia Tech Institute for Information Security & Privacy: Georgia Tech IISP coordinates usable security and privacy research across multiple schools and runs active programs on human-centered security — directly comparable to CUPS in faculty breadth and policy engagement.
- Indiana University Center for Applied Cybersecurity Research: IU CACR is an interdisciplinary academic center producing peer-reviewed research on usable privacy and security, with strong ties to the SOUPS community and NSF-funded usable security programs.
- UC Berkeley Center for Long-Term Cybersecurity (CLTC): CLTC funds and publishes academic research on usable security, privacy decision-making, and human factors of cybersecurity. It is a peer in policy-facing research output and field-building activities.
- University of Michigan Safe Computing / Security & Privacy Research: UMich hosts active usable security and privacy research groups contributing regularly to SOUPS, USENIX Security, and CHI. It is a peer in faculty strength, student pipeline, and publication footprint.
- Cornell Tech (Security, Privacy, and HCI groups): Cornell Tech conducts academic research spanning usable privacy, security UX, and policy. Its NYC-based interdisciplinary model and faculty overlap with the SOUPS community make it a strong comparable.
- UC Berkeley CITRIS / Center for Information Technology Research in the Interest of Society: CITRIS funds and disseminates academic research on privacy, security, and policy at UC Berkeley and beyond. It is a peer in operating multi-campus usable-privacy programs and producing policy-relevant outputs.
Broad incumbents
- Carnegie Mellon CyLab: CMU CyLab is CUPS's parent organization and a broader university security and privacy research center encompassing many more groups than usable privacy/security alone. It is comparable as the institutional umbrella hosting CUPS.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
CyLab Usable Privacy and Security Laboratory social profiles
Digital presenceCyLab Usable Privacy and Security Laboratory financial estimates
Financial estimateRevenue estimate
Valuation estimate
CyLab Usable Privacy and Security Laboratory leadership team
Management profileNumber of profiles
Profiles2 records
CyLab Usable Privacy and Security Laboratory funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CyLab Usable Privacy and Security Laboratory M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CyLab Usable Privacy and Security Laboratory
What does CyLab Usable Privacy and Security Laboratory do?
CUPS is an academic research laboratory at Carnegie Mellon University that conducts interdisciplinary research on usable privacy and security. It develops open-source research tools and prototypes (such as the FoxTor anonymous browsing extension, Privacy Nutrition Labels, IoT Security Labels, the Personalized Privacy Assistant, and the Matcha IDE plugin) and trains graduate students in usable privacy and security research through programs affiliated with multiple CMU PhD programs.
Is CyLab Usable Privacy and Security Laboratory a public or private company?
CyLab Usable Privacy and Security Laboratory is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was CyLab Usable Privacy and Security Laboratory founded?
CyLab Usable Privacy and Security Laboratory was founded in 2005. It employs 5,001 to 10,000 people.
Where is CyLab Usable Privacy and Security Laboratory based?
CyLab Usable Privacy and Security Laboratory is headquartered in Pittsburgh, United States, in the North America region.
How does CyLab Usable Privacy and Security Laboratory make money?
Four revenue lines are on record. Research Grants are the primary driver. The others are philanthropic Donations, technology Commercialization and student Fellowships.
Who are CyLab Usable Privacy and Security Laboratory's main competitors?
Direct peers on record are Princeton CITP (Center for Information Technology Policy), NYU Center for Cyber Security, Max Planck Institute for Security and Privacy (CISPA), Georgia Tech Institute for Information Security & Privacy, Indiana University Center for Applied Cybersecurity Research, UC Berkeley Center for Long-Term Cybersecurity (CLTC), University of Michigan Safe Computing / Security & Privacy Research, Cornell Tech (Security, Privacy, and HCI groups) and UC Berkeley CITRIS / Center for Information Technology Research in the Interest of Society. Carnegie Mellon CyLab is listed as a broad incumbent.
Does CyLab Usable Privacy and Security Laboratory have an API?
No public API is recorded for CyLab Usable Privacy and Security Laboratory.