NinjaLab
NinjaLab is a Montpellier-based cryptographic security consultancy, founded in 2017 by ex-ANSSI researchers, that performs side-channel, fault-injection, and white-box penetration testing for hardware manufacturers (smartcards, secure elements, FIDO tokens) and supports Common Criteria certification schemes.
- Company typePrivate
- Founded2017
- HeadquartersMontpellier, France
- Headcount1–10
- GTM typeB2B
- OfferingServices
What NinjaLab does
NinjaLab is a Montpellier, France-based cryptographic security consultancy founded in 2017 by Victor Lomne and Thomas Roche, both former members of ANSSI's hardware security team (Roche additionally spent time on Apple's Fairplay DRM and ApplePay Security teams). The firm specializes in the security analysis of cryptographic implementations, offering penetration testing for side-channel attacks (power and electromagnetic), fault injection attacks (laser and electromagnetic), and white-box cryptography attacks. It also develops custom side-channel and fault-injection platforms, delivers countermeasure consulting for secure implementations at hardware co-processor, embedded software, and white-box levels, and supports ITSEFs and Common Criteria certification schemes with pre-evaluation tests, custom challenges, and reports aligned to certification requirements.
The company's revenue is generated entirely through professional services engagements on a quote basis, typically structured as multi-year contracts, with reports formatted for direct reuse in Common Criteria certification. Its primary customers are hardware manufacturers and security-product companies (smartcards, microcontrollers, secure elements, FPGAs, IoT devices, hardware security tokens), with named engagements involving Ledger (cryptocurrency wallets), Yubico and Google (FIDO hardware tokens), and major semiconductor vendors including NXP, STMicroelectronics, Thales, and Infineon. Beyond services, NinjaLab has released one open-source product — Inspector Gadget (July 2024), a Python tool for assessing masking gadget complexity published in IACR Communications in Cryptology — and lists turnkey test platforms, white-box execution tracers, a statistical analysis library, and a portfolio of protected implementations as offerings under consideration.
The firm is intentionally small (approximately five people: two co-founders, an engineer/PhD student, a hosted INRIA PhD student, and an intern). It has no disclosed external funding, parent company, or acquisitions, and relies on research-driven credibility rather than paid marketing: over 40 publications in venues including CHES, CRYPTO, ASIACRYPT, IEEE S&P, USENIX Security, and IACR; high-profile vulnerability disclosures (EUCLEAK/CVE-2024-45678 in Infineon chips, CVE-2021-3011 in Google Titan); competition wins (Ledger Challenge 2018, CHES 2023); and participation in French collaborative research projects VERISICC and SCATTER alongside ANSSI, CNRS, INRIA, CryptoExperts, and eShard.
NinjaLab firmographics
Firmographics- Name
- NinjaLab
- Legal name
- NinjaLab
- Website
- https://ninjalab.io
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- NinjaLab is a Montpellier-based cryptographic security consultancy, founded in 2017 by ex-ANSSI researchers, that performs side-channel, fault-injection, and white-box penetration testing for hardware manufacturers (smartcards, secure elements, FIDO tokens) and supports Common Criteria certification schemes.
- Ownership category
- akta.pro rank
NinjaLab industry classification
Industry- Product category
- Cybersecurity Consulting
- NAICS
- Other Computer Related Services (541519)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKADAE)
Keywords
Where NinjaLab is headquartered
LocationHeadquarters
- HQ city
- Montpellier
- HQ country
- France
- HQ region
- Europe
Offices1 record
Markets served
NinjaLab business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Infrastructure
Revenue model
- Penetration Testing Services: Penetration testing on cryptographic implementations including side-channel analysis, fault injection, and white-box cryptography attacks using in-house platforms and tools. Targets products such as smartcards, microcontrollers, SoCs, FPGAs, IoT devices, and smartphones. Report formats are aligned with Common Criteria for easy reuse in certification.
- Custom Platform Development: On-demand consulting and development for custom side-channel and fault attack platforms and software analysis tools to meet specific client needs in security measurement and fault injection analysis.
- Countermeasure Consulting: On-demand consulting and development for secure cryptographic implementations at any level including hardware co-processor, embedded software, and white-box cryptography implementation for market stand-out or certification purposes.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom professional services engagement |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels4 records
NinjaLab product offering
Product offeringCore offering
NinjaLab provides specialized cryptographic implementation security consulting, performing side-channel, fault injection, and white-box cryptography penetration tests on products such as smartcards, microcontrollers, SoCs, FPGAs, IoT devices, and smartphones using its in-house laboratory and proprietary tools. The company also delivers custom attack platform development and countermeasure consulting for secure cryptographic implementations, with reports formatted to align with Common Criteria certification requirements.
Product overview
NinjaLab is a cryptographic security consulting firm founded in 2017 by two researchers with over 20 years of combined experience. The company operates as a single unified service offering organized around three core pillars: Penetration Tests (side-channel, fault, and white-box cryptography analysis using in-house lab and tools), Platforms and Tools (on-demand consulting for custom testing platforms and software), and Countermeasures (secure implementation development at any level). The product portfolio also includes Inspector Gadget, an open-source Python tool for assessing masking gadget complexity released in 2024, and a Certification Support service aligned with Common Criteria. Several additional products — turnkey test platforms, white-box execution tracers, a statistical analysis library, and a protected implementations portfolio — are listed as under consideration. NinjaLab's work on vulnerability discoveries (EUCLEAK, A Side Journey to Titan) and participation in challenges (CHES 2023, Ledger Challenge 2018) serves as public research demonstrations of its capabilities.
Differentiator
Problem solved
Functional benefit
Products and services
- Penetration Tests Side-channel, fault, and white-box cryptography analysis services performed using NinjaLab's in-house laboratory and proprietary tools. Covers power and electromagnetic side-channel measurement, laser and electromagnetic fault injection, higher-order attacks, machine learning-based attacks, and combined attacks. Conducted on smartcards, microcontrollers, SoCs, FPGAs, IoT devices, and smartphones for hardware manufacturers and security product companies.
- Platforms and Tools On-demand consulting and development services for custom side-channel measurement platforms, fault injection platforms, and software analysis tools tailored to specific penetration testing needs. Targeted at clients requiring bespoke security testing infrastructure.
- Countermeasures On-demand consulting and development services for secure cryptographic implementations at any level, including hardware co-processors, embedded software, and white-box cryptography implementations, aimed at strengthening products for market differentiation or certification purposes.
- Inspector Gadget Open-source Python-based software tool for assessing and comparing the complexity of masking gadgets, used for fair comparison of masked cryptographic implementations such as Kyber compression function. Distributed freely under GPL v.3 license.
- Certification Support Support services for ITSEFs (Information Technology Security Evaluation Facilities) and certification schemes, including R&D and pre-evaluation tests, custom challenge development for assessing ITSEF technical level, and ITSEF audits. Penetration test reports are formatted to match Common Criteria requirements.
Quantifiable outcome
- Extraction of full long-term ECDSA secret keys from YubiKey 5Ci and all YubiKey 5 Series in few minutes using local electromagnetic side-channel acquisitions
- +3 more outcomes
Companies that use NinjaLab
Customer profileNamed customers3 records
Segments3 records
Ideal customer profiles3 records
NinjaLab technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
NinjaLab partnerships and signals
Strategic signalPartnerships
22 partnerships are on record, tiered core and minor.
- ANSSIcoreFrench Cybersecurity Agency partner. NinjaLab co-founders previously worked in the hardware security team of ANSSI's scientific division. ANSSI is part of VERISICC collaborative research project for automated verification and generation of masked cryptographic implementations.
- CNRScoreFrench National Centre for Scientific Research. Active research collaboration including joint publications with LIRMM (CNRS laboratory) on cryptology and side-channel security.
- INRIAcoreFrench National Institute for Research in Digital Science and Technology. Partner in VERISICC collaborative research project and hosts PhD students including Lucas Tabary-Maujean at Inria Sophia Antipolis.
- LedgercoreFrench cryptocurrency hardware wallet manufacturer. Won Ledger Challenge 2018 by discovering side-channel vulnerability in Ledger Nano S. Continued collaboration on security research.
- NXP SemiconductorscoreMajor secure microcontroller manufacturer. Research discovered vulnerabilities in NXP secure elements (Google Titan Security Key research) but also collaborates on security evaluation methodologies.
- STMicroelectronicscoreMajor semiconductor manufacturer. Listed as partner demonstrating industry collaboration for security evaluation and research.
- ThalescoreMajor French technology company in digital security. Listed as partner demonstrating collaboration in security ecosystem.
- CryptoExpertscoreCryptography research company and project leader of VERISICC collaborative research project. Joint work on automated verification and generation of masked cryptographic implementations.
- eShardcoreSecurity research company and project leader of SCATTER collaborative research project studying practical effectiveness of SCATTER side-channel attack method.
- YubicocoreMajor FIDO hardware token manufacturer. Research discovered EUCLEAK vulnerability in YubiKey 5 Series affecting Infineon-based products. Collaboration through responsible disclosure process.
- University of Montpellier / LIRMMcoreAcademic research laboratory. Hosts NinjaLab co-founders' academic affiliations, PhD student supervision (Malek Sfaxi), and joint research publications. Co-founder Victor Lomne returned to work as researcher at LIRMM before founding NinjaLab.
- University Grenoble-Alpes / LCISminorAcademic research laboratory collaboration in cryptography and embedded systems security.
- University of Bretagne Sud / Lab-STICCminorAcademic research laboratory collaboration in cryptography and embedded systems security.
- University of Rennes / IETRminorAcademic research laboratory collaboration in signal processing and electronics.
- University Catholic of Louvain / Crypto GroupcoreAcademic cryptography research group. Hosts former NinjaLab intern Paco Poilbout for PhD studies on post-quantum cryptography.
- ZamaminorCryptography technology company focused on fully homomorphic encryption. Listed as partner demonstrating industry collaboration.
- TropicSquareminorSecurity technology company. Listed as partner demonstrating industry collaboration.
- IPcoresminorIP core technology company. Listed as partner demonstrating industry collaboration.
- GIE CBminorGroupement d'Intérêt Économique des Cartes Bancaires (French banking card consortium). Listed as partner demonstrating financial sector collaboration.
- CNFMminorCoordination Nationale des Formations en Microélectronique. Listed as partner demonstrating academic collaboration.
- CRoCSminorCentre for Research on Cryptography and Security at Masaryk University. Listed as partner demonstrating international academic collaboration.
- GooglecoreMajor technology company. NinjaLab research discovered vulnerability in Google Titan Security Key (CVE-2021-3011). Collaboration through responsible disclosure process.
Scale indicators3 records
Recent moves6 records
Expansion highlights5 records
NinjaLab competitors and assessment
Company assessmentBroad incumbents
- Kudelski Security: Cryptography and hardware security division of the Kudelski Group; provides side-channel and cryptographic implementation services to media, IoT, and semiconductor clients. Larger incumbent with adjacent capabilities in the same vendor ecosystem.
- IOActive: Global security consultancy with a strong hardware and embedded systems security practice, including side-channel and fault injection testing for chip and payment vendors. Broader portfolio than NinjaLab but comparable delivery model.
- Cryptography Research (Rambus): Original commercial cryptography and side-channel research firm, now part of Rambus; licenses DPA countermeasures broadly across the smartcard/secure-element industry. Larger incumbent with broader IP licensing model but less boutique consulting focus.
- NCC Group: Global cybersecurity consultancy with hardware and embedded security capabilities; competes for enterprise penetration testing RFPs but at much larger scale and broader scope than NinjaLab's cryptographic specialization.
Emerging players
- PQShield: Post-quantum cryptography company providing IP and implementation consulting for PQC migrations; emerging player in an adjacent niche where NinjaLab's masking expertise (Inspector Gadget for Kyber) provides a complementary capability.
Direct peers
- Riscure: Leading independent lab for side-channel and fault injection security evaluation of chips and embedded devices; offers Inspector toolchain and similar penetration testing services to smartcard, secure element, and IoT vendors. Closest direct competitor in NinjaLab's exact niche.
- eShard: French side-channel attack research and tooling company (SCATTER project partner with NinjaLab); provides penetration testing, custom platforms, and the ChipWhisperer-style tools ecosystem for hardware security evaluation. Directly comparable offering and geography.
- Secure-IC: French security company providing side-channel analysis, fault injection testing, and certified IP for embedded systems. Competes in the same French hardware-security ecosystem with overlapping customer base (NXP, STMicroelectronics tier).
- CryptoExperts: French cryptography research firm partnering with NinjaLab on VERISICC; provides cryptographic implementation consulting, formal verification, and masked implementation development. Overlapping customer base and French research ecosystem positioning.
Regional players
- Quarkslab: French security R&D consultancy known for deep binary and cryptographic analysis; shares the French cybersecurity research ecosystem and overlapping customers in finance and government, though with broader software focus.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
NinjaLab social profiles
Digital presenceNinjaLab financial estimates
Financial estimateRevenue estimate
Valuation estimate
NinjaLab leadership team
Management profileNumber of profiles
Profiles5 records
NinjaLab funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
NinjaLab M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about NinjaLab
What does NinjaLab do?
NinjaLab provides specialized cryptographic implementation security consulting, performing side-channel, fault injection, and white-box cryptography penetration tests on products such as smartcards, microcontrollers, SoCs, FPGAs, IoT devices, and smartphones using its in-house laboratory and proprietary tools. The company also delivers custom attack platform development and countermeasure consulting for secure cryptographic implementations, with reports formatted to align with Common Criteria certification requirements.
Is NinjaLab a public or private company?
NinjaLab is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was NinjaLab founded?
NinjaLab was founded in 2017. It employs 1 to 10 people.
Where is NinjaLab based?
NinjaLab is headquartered in Montpellier, France, in the Europe region.
How does NinjaLab make money?
Three revenue lines are on record. Penetration Testing Services are the primary driver. The others are custom Platform Development and countermeasure Consulting.
Who are NinjaLab's main competitors?
Broad incumbents on record are Kudelski Security, IOActive, Cryptography Research (Rambus) and NCC Group. PQShield is listed as an emerging player. Direct peers are Riscure, eShard, Secure-IC and CryptoExperts. Quarkslab is listed as a regional player.
Does NinjaLab have an API?
No public API is recorded for NinjaLab.
What industry is NinjaLab in?
NinjaLab's product category is Cybersecurity Consulting. Its primary akta.pro industry code is BPAKADAE, Penetration Testing & Red Teaming. Its NAICS code is 541519.