VxLabs

Automotive TARA, SBOM and compliance platform plus security engineering services

CompanyAutomotive CybersecurityCloud

Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below · Last reviewed August 2026 · How we review listings

What is VxLabs?

VxLabs is an automotive cybersecurity and embedded software company founded in January 2022, registered in Regensburg, Germany (HRB 19099) with a US entity in Delaware. Its platform, ThreatZ, is an AWS-hosted SaaS launched in October 2025 that links system modelling, TARA, SBOM, vulnerability management, incident handling and compliance evidence in a single knowledge graph for ISO/SAE 21434 and UNECE R155. The company also sells engineering services covering AUTOSAR Classic and Adaptive ECU development, penetration testing, CSMS consulting and R155 type approval support. Uraeus was the earlier platform brand and uraeus.io now redirects to vxlabs.ai.

Best for: OEM and Tier 1 teams wanting an integrated TARA, SBOM and compliance evidence workspace, or project-based automotive security engineering.
Pros
  • Registered operating company with a German commercial register entry (HRB 19099, Regensburg) and a separate US entity
  • The ThreatZ launch in October 2025 was covered by independent automotive trade press including Telematics Wire
  • Scope is automotive specific throughout, built around ISO/SAE 21434 and UNECE R155 rather than repackaged general IT security
  • Publishes concrete engagement models (time and materials, fixed price, managed-service retainer) and a defined delivery process
Things to check
  • The Uraeus brand was retired and uraeus.io redirects to vxlabs.ai, so older references and links point at the previous name
  • Customer logos shown on the site are vendor claims, with no published case detail or contactable references
  • Compliance posture is stated as ISO/SAE 21434 aligned and SOC 2 Type II aligned rather than certified, so request certificates directly
  • Founded 2022 and small relative to others in this category, so delivery capacity and references are worth checking

Reported in public reviews and vendor documentation. See sources below.

Key Features

ThreatZ TARA module using STRIDE threat modelling aligned to ISO/SAE 21434 Clause 15
SBOM management supporting CycloneDX and SPDX with CVE matching
Vulnerability management workflow from CVE assessment through to vehicle SOC decision
Incident command with auto-correlation and fleet map visualisation
Compliance evidence generation for ISO/SAE 21434, UNECE R155, GB 44495 and the EU Cyber Resilience Act
Vehicle and system modelling including COVESA VSS signals
Security testing support covering fuzzing and ODX, ARXML and XMI formats
Engineering services: AUTOSAR ECU development, vehicle network penetration testing, CSMS consulting and R155 type approval support

Are you VxLabs? Improve this listing with screenshots, case studies and more.

Sources & references

Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.

Spot an error, or do you represent VxLabs? Request a correction.