Rescale Project Horizon EU
RESCALE is a Horizon Europe research consortium of 15 European partners building a Trusted Bill of Materials platform for automated software and hardware supply chain cybersecurity, funded by the EU under Grant Agreement 101120962.
- Company typePrivate
- Founded2023
- HeadquartersBrussels, Belgium
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Rescale Project Horizon EU does
RESCALE (Revolutionised Enhanced Supply Chain Automation with Limited Threats Exposure) is a Horizon Europe Research and Innovation Action coordinated by ATHINA – Industrial Systems Institute (ISI) in Athens, Greece, and executed by a 15-partner consortium spanning 13 European countries. The project is developing a holistic cybersecurity assessment framework for software and hardware supply chains, anchored on the Trusted Bill of Materials (TBOM) — a machine-readable, cryptographically verifiable artifact that consolidates component inventories with evidence from automated security testing. The integrated platform comprises four testing modules (Static Code Analysis, Dynamic Testing, Low-Level Security Testing, Dynamic Hardware Analyzer), an orchestration layer (Trust Orchestrator), and a blockchain-backed Trust Storage Platform for tamper-evident evidence retention, with outputs in CycloneDX and SPDX-compatible formats aligned to IETF SCITT.
The technical stack combines rule-based static analyzers (Bandit, Semgrep), ML-based vulnerability classifiers (SAVE-ME using CodeBERT for Erlang), symbolic execution (IVEE), fault injection (FATex), ML-enhanced API fuzzing (RAISE on RESTler), evolutionary test generation (EvoMaster), low-level binary and speculative-execution analysis (InSpectre Gadget, SafeFetch), and FPGA-based side-channel capture (FlexLECO, ChipWhisperer). Two pilot use cases validate the framework: privacy-by-design distributed cloud storage (Chocolate Cloud ApS) and security-aware data-flow infrastructure for Erlang-based embedded/distributed systems (Peer Stritzinger GmbH).
Commercially, RESCALE is not a revenue-generating enterprise. The project is funded by the European Commission under Horizon Europe Grant Agreement No. 101120962 with €10.12 million over 36 months (1 October 2023 – 30 September 2026). It has no commercial pricing model, no paying customers, and no disclosed post-grant commercialization vehicle. Go-to-market is community- and standards-led: open-access publications in IEEE, ACM, USENIX, Elsevier, Springer; conference presence at HiPEAC, IETF, Hardwear.io, DFRWS EU; synergies with SYNAPSE and CyberSecDome; and engagement with EU regulatory frameworks (Cyber Resilience Act, NIS2).
Rescale Project Horizon EU firmographics
Firmographics- Name
- Rescale Project Horizon EU
- Legal name
- RESCALE – Revolutionised Enhanced Supply Chain Automation with Limited Threats Exposure
- Website
- https://rescale-project.eu
- Company type
- Private
- Founded year
- 2023
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- RESCALE is a Horizon Europe research consortium of 15 European partners building a Trusted Bill of Materials platform for automated software and hardware supply chain cybersecurity, funded by the EU under Grant Agreement 101120962.
- Ownership category
- akta.pro rank
Rescale Project Horizon EU industry classification
Industry- Product category
- Supply Chain Security Software
- NAICS
- Custom Computer Programming Services (541511), Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Testing Laboratories (8734)
- akta.pro primary industry
- Regulatory Taxonomy, Rules Mapping & Controls Testing (FSAFAOAN)
- akta.pro secondary industry
- Data Quality, Lineage & Regulatory Data Management (FSAFAOAM)
Keywords
Where Rescale Project Horizon EU is headquartered
LocationHeadquarters
- HQ city
- Brussels
- HQ country
- Belgium
- HQ region
- Europe
Offices7 records
Markets served
Rescale Project Horizon EU business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure, Others
Revenue model
- EU Research Funding: RESCALE is funded by Horizon Europe, the EU's key funding programme for research and innovation, under grant agreement No 101120962. This is a non-revenue-generating research project.
Go-to-market motion1 record
Distribution channels1 record
Marketing channels6 records
Rescale Project Horizon EU product offering
Product offeringCore offering
RESCALE is a Horizon Europe research project developing a holistic cybersecurity assessment framework for software and hardware supply chains. The framework is built around the Trusted Bill of Materials (TBOM), a structured assurance artifact that consolidates evidence from four integrated security testing modules: Static Code Analysis, Dynamic Testing, Low-Level Security Testing, and Dynamic Hardware Analyzer. Outputs are cryptographically recorded on a blockchain-based Trust Storage Platform and orchestrated through the Trust Orchestrator, enabling continuous, verifiable supply chain security validation.
Product overview
RESCALE is a Horizon Europe research project developing a holistic cybersecurity platform for software and hardware supply chain security. The platform is built around the Trusted Bill of Materials (TBOM) as the central artifact, which consolidates security evidence across multiple analysis modules. The Static Code Analysis Module provides automated source code vulnerability detection using SAVE-ME (ML-based Erlang analysis), SASTer (multi-language Python/C/C++ analysis), and IVEE (symbolic execution). The Dynamic Testing Module evaluates runtime behavior using FATex (fault tolerance), RAISE (API security with ML-enhanced fuzzing), and EvoMaster (evolutionary algorithm-based testing). The Low-Level Security Testing Module analyzes firmware and kernel components using InSpectre Gadget and SafeFetch. The Dynamic Hardware Analyzer detects side-channel vulnerabilities using FlexLECO and ChipWhisperer. All modules generate standardized SSCG/DSCG security guarantees that feed into the TBOM, with cryptographic verification via the Trust Storage Platform. The platform is orchestrated through the Trust Orchestrator and validated through two pilot use cases (PST automotive/industrial IoT infrastructure and CC cloud storage).
Differentiator
Problem solved
Functional benefit
Products and services
- RESCALE Continuous Security Assurance Platform The integrated platform combining all RESCALE modules (Static Code Analysis, Dynamic Testing, Low-Level Security Testing, Dynamic Hardware Analyzer) with the Trust Orchestrator, enabling continuous security validation and TBOM generation across the software and hardware supply chain. Designed for software/hardware manufacturers, system integrators, and auditors requiring verifiable security assurance.
- Trusted Bill of Materials (TBOM) The central artifact of the RESCALE framework — a structured, traceable, and reproducible assurance record that combines hardware and software component inventory with evidence from static/dynamic security testing, vulnerability information, and cryptographic verification. Built on CycloneDX and SPDX formats with blockchain-based trust storage.
- Static Code Analysis Module Automates detection of security flaws at the source code level using multiple integrated analyzers (SAVE-ME for ML-based Erlang analysis, SASTer for multi-language Python/C/C++ analysis, and IVEE for symbolic execution). Generates Static Supply Chain Component Guarantees (SSCG) for each analyzed component.
- Dynamic Testing Module Analyzes compiled software artifacts under runtime conditions using orchestrator-managed tools (FATex for fault tolerance, RAISE for API security with ML-enhanced fuzzing, EvoMaster for AI-driven automated test case generation). Generates Dynamic Supply Chain Component Guarantees (DSCG).
- Low-Level Security Testing Module Identifies vulnerabilities in firmware, kernel modules, and embedded systems using specialized tools (InSpectre Gadget for ROP gadget detection, SafeFetch for speculative execution vulnerability mitigation, FATex for firmware/kernel fault injection testing). Performs memory safety analysis, execution tracing, microarchitectural analysis, and firmware fuzzing.
- Dynamic Hardware Analyzer Detects and analyzes hardware vulnerabilities and side-channel attack (SCA) risks using trace collection tools (FlexLECO for FPGA-based leakage assessment, ChipWhisperer for power analysis), preprocessing software, and attack simulation techniques (TVLA, correlation power analysis, machine-learning template attacks).
- Trust Storage Platform Records cryptographic hashes of TBOMs and assessment reports on a public blockchain rather than publishing complete reports, enabling verifiable integrity, traceability, and immutability while protecting confidential security information from public disclosure. Connects with X.509 certificates, PKCS#7, and IETF SCITT mechanisms.
- Trust Orchestrator Central orchestrator that manages security testing workflows across all RESCALE modules, coordinates execution of multiple security testing tools, and aggregates findings into unified security assessments for TBOM generation.
Quantifiable outcome
- Automated vulnerability detection reduces manual security assessment effort by standardizing evaluation processes across software and hardware layers.
- +1 more outcomes
Companies that use Rescale Project Horizon EU
Customer profileNamed customers2 records
Segments3 records
Ideal customer profiles3 records
Rescale Project Horizon EU technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability7 records
Feature6 records
Rescale Project Horizon EU partnerships and signals
Strategic signalPartnerships
Eleven partnerships are on record, tiered core and flagship.
- CyberSecDome ProjectcoreExploring collaboration opportunities with CyberSecDome for joint communication activities and knowledge-sharing. Early discussions positive with interest in coordinated outreach and joint events.
- IETF SCITT Working GroupcoreRESCALE presented at IETF 123 in Madrid to the SCITT Working Group. Established synergy for aligning RESCALE concepts with emerging international standards for supply chain integrity, transparency, and trust.
- SYNAPSE ProjectflagshipJoint activities with SYNAPSE for constructing robust systems, providing secure-by-design supply chains, automating evaluations, and facilitating cybersecurity audits. Active synergy collaboration.
- ATHENA Research Centre / Industrial Systems Institute (ISI)coreProject Coordinator Dr. Apostolos Fournaris leads RESCALE from ISI in Athens, Greece. ISI coordinates all 15 consortium partners and manages project execution under HORIZON-CL3-2022-CS-01.
- Stichting VU (VUA)coreVUA hosts the 3rd plenary meeting and contributes to low-level security testing module development (D3.7 Solutions for Security Testing of Low-Level System Components).
- Chocolate Cloud ApS (CC)corePilot partner for privacy-by-design distributed cloud and edge storage use case. CC contributes D2.2 Use Case Specification and D5.3/D5.4 Pilot Deployment, Test and Demonstration.
- AEGIS IT Research GmbHcoreHosted 4th plenary meeting in Braunschweig, Germany. Contributed D1.2 Data Management Plan and develops the RESCALE platform tools and submodules.
- Peer Stritzinger GmbH (PST)corePilot partner for auto-placement security aware augmented data-flow and infrastructure use case. Contributes to static code analysis tools (D3.1/D3.2).
- Sphynx Technology Solutions AG (STS)coreHosted 5th plenary meeting in Krakow, Poland. Contributes to RESCALE Continuous Security Assurance Platform (D4.2/D4.3) and security assurance presentations.
- Binare Ltd (BNR)coreHosted 6th plenary meeting and 2nd Info Day in Helsinki, Finland. Contributes to dynamic testing components (D3.3/D3.4).
- Intrasoft International (INT)coreContributes to High Level Architecture (D2.5/D2.6) and Trust Orchestrator (D5.1/D5.2), key components of the RESCALE platform.
Scale indicators4 records
Recent moves6 records
Expansion highlights5 records
Rescale Project Horizon EU competitors and assessment
Company assessmentDirect peers
- Sonatype: Sonatype provides commercial software supply chain security tools including SBOM management (Sonatype SBOM Manager) and vulnerability intelligence. Directly comparable to RESCALE's TBOM and supply chain security testing mission, though Sonatype is a commercial incumbent while RESCALE is a research consortium.
- Anchore: Anchore offers SBOM generation, container security scanning, and software supply chain compliance tools (including Syft and Grype). Overlaps directly with RESCALE's static analysis modules and TBOM framework focused on software component transparency.
Broad incumbents
- JFrog: JFrog provides an end-to-end software supply chain platform spanning artifact management, security scanning, and compliance. Broader portfolio than RESCALE but overlapping capability in software component analysis and SBOM lifecycle management.
- Snyk: Snyk is a developer security platform spanning SAST (Snyk Code), SCA (Snyk Open Source), and container security. Comparable to RESCALE's Static Code Analysis and Dynamic Testing modules, with a much broader commercial developer footprint.
- Veracode: Veracode is an established application security testing platform offering SAST, DAST, and software composition analysis. Directly comparable to RESCALE's Static Code Analysis Module and broader testing portfolio.
- Checkmarx: Checkmarx provides application security testing including SAST (CxSAST), SCA (CxSCA), and API security. Comparable to RESCALE's Static Code Analysis Module (SASTer, IVEE) and Dynamic Testing Module (RAISE) capabilities.
Emerging players
- Endor Labs: Endor Labs provides software dependency management and SBOM-based supply chain security, including reachability analysis. Directly comparable to RESCALE's TBOM framework and dependency/component analysis focus.
- Ox Security: Ox Security offers software supply chain security with SBOM management and pipeline security posture. Comparable to RESCALE's TBOM and Continuous Security Assurance Platform mission.
- Chainguard: Chainguard focuses on software supply chain security with hardened container images and SBOM-based attestation. Comparable to RESCALE's TBOM trust storage approach and continuous security assurance framing.
Others
- OpenSSF: Open Source Security Foundation (Linux Foundation) develops open source security best practices, SBOM tooling, and supply chain frameworks like Sigstore and GUAC. Adjacent to RESCALE's open TBOM approach and supply chain integrity mission, serving as a potential ecosystem collaborator.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
Rescale Project Horizon EU social profiles
Digital presenceRescale Project Horizon EU financial estimates
Financial estimateRevenue estimate
Valuation estimate
Rescale Project Horizon EU leadership team
Management profileNumber of profiles
Profiles1 record
Rescale Project Horizon EU funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Rescale Project Horizon EU M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Rescale Project Horizon EU
What does Rescale Project Horizon EU do?
RESCALE is a Horizon Europe research project developing a holistic cybersecurity assessment framework for software and hardware supply chains. The framework is built around the Trusted Bill of Materials (TBOM), a structured assurance artifact that consolidates evidence from four integrated security testing modules: Static Code Analysis, Dynamic Testing, Low-Level Security Testing, and Dynamic Hardware Analyzer. Outputs are cryptographically recorded on a blockchain-based Trust Storage Platform and orchestrated through the Trust Orchestrator, enabling continuous, verifiable supply chain security validation.
Is Rescale Project Horizon EU a public or private company?
Rescale Project Horizon EU is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Rescale Project Horizon EU founded?
Rescale Project Horizon EU was founded in 2023. It employs 1 to 10 people.
Where is Rescale Project Horizon EU based?
Rescale Project Horizon EU is headquartered in Brussels, Belgium, in the Europe region.
How does Rescale Project Horizon EU make money?
One revenue line is on record: EU Research Funding.
Who are Rescale Project Horizon EU's main competitors?
Direct peers on record are Sonatype and Anchore. Broad incumbents are JFrog, Snyk, Veracode and Checkmarx. Emerging players are Endor Labs, Ox Security and Chainguard. OpenSSF is listed as an others.
Does Rescale Project Horizon EU have an API?
No public API is recorded for Rescale Project Horizon EU.
What industry is Rescale Project Horizon EU in?
Rescale Project Horizon EU's product category is Supply Chain Security Software. Its primary akta.pro industry code is FSAFAOAN, Regulatory Taxonomy, Rules Mapping & Controls Testing, with a secondary code of FSAFAOAM, Data Quality, Lineage & Regulatory Data Management. Its NAICS code is 541511 and its SIC code is 7370.