Spectra Assure Free Trial
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free TrialMonzy Merza, Co-Founder and CEO, CroglWe use a number of different products for product security, but Spectra Assure is the only one that will actually stop a release if something doesn't pass.
Crogl integrated Spectra Assure with its build and release processes to ensure every release is analyzed and security requirements are met before release. The Spectra Assure SAFE Report identifies malware, tampering, new threats, suspicious behaviors, or indicators of novel software supply chain attacks. After updates are made, the new build is assessed to ensure that remediation efforts have actually resolved issues before the product is released.
Spectra Assure is integrated directly into Crogl’s CI/CD build pipeline, assessing software builds before release. While Crogl operates in both customer on‑premises and private cloud environments, the architectural design could be deployed on AWS for scalability and resilience. In such a configuration, AWS compute (e.g., EC2 or container services) would host the Spectra Assure scanning engine, with S3 for artifact storage and Amazon RDS or DynamoDB for SBOM and SAFE report data. Integration points include build servers (e.g., Jenkins, GitHub Actions) that feed binaries into S3 and trigger scans via AWS Lambda or Step Functions.
Spectra Assure is powered by the world’s largest threat repository, with 40+ billion searchable malware and goodware files and up-to-date intelligence to stay ahead of emerging threats and increasingly advanced malware attacks.
“We know that when we're using Spectra Assure, we're not just running a vulnerability check underneath that vulnerability check. There is a lot of understanding of malware analysis, supply chain problems, and the relatedness of one library to another. We're getting the benefit of that,” said Merza.



Learn about complex binary analysis and how it tackles supply chain threats like malware, tampering, exposed secrets and more — all without source code.