VxLabs vs PCA Cyber Security

VxLabs

VxLabs is an automotive cybersecurity and embedded software company founded in January 2022, registered in Regensburg, Germany (HRB 19099) with a US entity in Delaware. Its platform, ThreatZ, is an AWS-hosted SaaS launched in October 2025 that links system modelling, TARA, SBOM, vulnerability management, incident handling and compliance evidence in a single knowledge graph for ISO/SAE 21434 and UNECE R155. The company also sells engineering services covering AUTOSAR Classic and Adaptive ECU development, penetration testing, CSMS consulting and R155 type approval support. Uraeus was the earlier platform brand and uraeus.io now redirects to vxlabs.ai.

Pros
  • Registered operating company with a German commercial register entry (HRB 19099, Regensburg) and a separate US entity
  • The ThreatZ launch in October 2025 was covered by independent automotive trade press including Telematics Wire
  • Scope is automotive specific throughout, built around ISO/SAE 21434 and UNECE R155 rather than repackaged general IT security
  • Publishes concrete engagement models (time and materials, fixed price, managed-service retainer) and a defined delivery process
Things to check
  • The Uraeus brand was retired and uraeus.io redirects to vxlabs.ai, so older references and links point at the previous name
  • Customer logos shown on the site are vendor claims, with no published case detail or contactable references
  • Compliance posture is stated as ISO/SAE 21434 aligned and SOC 2 Type II aligned rather than certified, so request certificates directly
  • Founded 2022 and small relative to others in this category, so delivery capacity and references are worth checking

Pricing:

PCA Cyber Security

PCA Cyber Security (formerly PCAutomotive) is a Budapest-based specialist in offensive security and threat intelligence for vehicles and embedded systems. The firm runs dedicated CyberLab and CyberGarage research facilities and has built a strong public reputation through repeated Pwn2Own Automotive participation and disclosed vehicle vulnerability research, including 21 vulnerabilities across Skoda and Volkswagen vehicles and their cloud backend. While rooted in automotive, PCA has expanded into fintech, manufacturing, consumer electronics, and energy. It is a services-led firm focused on penetration testing, TARA, verification and validation, and managed product SOC monitoring rather than off-the-shelf software.

Pros
  • Elite offensive research talent. Repeat Pwn2Own Automotive contestants in 2024 and 2025
  • Proven track record of high-impact disclosed vehicle research (Skoda/VW, Nissan Leaf)
  • Deep hands-on embedded and hardware expertise via dedicated lab facilities
  • TISAX Assessment Level 3 accredited; regular presence at Black Hat, Hexacon, and escar
Things to check
  • Services and consulting model rather than a licensed product. Value scales with engagements
  • Smaller team than the large platform vendors; project-based delivery with no public pricing
  • Less suited to buyers seeking an off-the-shelf, deployable security product

Pricing: Custom (contact sales)