Security by Design · Proven by Test
Is your company
and are your products secure?
Being 99% secure is 100% insecure!
SQ-Software GmbH protects your innovations, products, data and processes. As the key sales partner of Primary Target, we deliver CodeX, the patented, AI-powered platform for automated threat analysis and risk assessment, together with hands-on penetration testing by TestArmy and turnkey secure-development solutions.
CodeX Performance — Radar System TARA
FIG. 01 — Real project data, OEM & Tier-1
The Challenge
It is only a question of time before you are attacked and your business is disrupted or destroyed.
IT systems automate mission-critical processes. Complexity is rising, regulation is tightening, and AI is making cyber attacks easier every day. Manual, spreadsheet-driven security processes can no longer keep up.
Complexity is exploding
IT systems control critical automated workflows, and their complexity keeps growing a modern vehicle alone runs 50M+ lines of code across 60+ processors.
Legislation threatens company survival
Since July 2024, vehicles without a completed threat analysis cannot be registered in Germany. The EU CRA mandates full compliance for new products by September 2026 with fines up to €15M or 2.5% of global turnover.
AI makes attacks easier
Cyber attacks are becoming simpler and cheaper to launch, also thanks to AI. The threat level is growing across every industrial vertical.
Security specialists are scarce
Experts are expensive and hard to find. Leading Tier-1 suppliers employ entire teams just to review Excel-based TARAs and still can't keep pace.
Isolated point solutions
Security tools are often used as disconnected island solutions with decentralised data, no access control, no versioning and error-prone manual work.
Insecure, unscalable processes
The current state of manual security engineering is a liability, not a process. It cannot scale to meet today's regulatory and threat landscape.
At SQ-Software GmbH we categorise your data into security classes, integrate the most effective security gateways and workflows, and evaluate, automate and optimise your processes. This ensures that your innovations, products, data and processes are protected and compliant.
Get Advice NowSolutions · One Partner, Full Lifecycle
Secure by design. Proven by test.
Regulators now expect security to be designed in and demonstrated. SQ-Software delivers both disciplines from a single source: CodeX automates the analysis, TestArmy exercises the result.
CodeX — Threat Analysis Detection developed by Hackers
Patented, AI-powered SaaS platform for automated Threat Analysis and Risk Assessment (TARA). It replaces manual Excel processes with an auditable workflow backed by 10,000+ threats, 90% faster and 80% cheaper.
Explore the platform → Services · Verification PhaseTestArmy — QA & Cyber Testing
100+ certified testers and pentesters deliver AI-driven penetration testing, auditing, performance and quality testing. We simulate attacks on your products before anyone else intrudes. ISTQB Platinum · ISO 9001 & 27001.
Explore TestArmy → Platform · Production PlanningManufacturing Optimization — Powered by Circonomit
An AI decision-intelligence platform that calculates the optimal production plan under your real constraints — order sequencing, capacity, inventory and workforce — recalculated automatically as conditions change.
Explore Manufacturing Optimization →Model the threats
CodeX automates threat analysis and risk assessment (TARA) while your product is still on the drawing board, auditable, versioned and reusable.
CodeX · by Primary Target — sold & delivered via SQ-SoftwareDevelop securely
We set up verifiable security standards and quality rules for your software development process, for you and your suppliers checked automatically.
SQ-Software · secure development solutionsExercise the threats
TestArmy's certified engineers attack, load and probe what you build with AI-driven penetration testing, auditing and QA before anyone else does.
TestArmy · QA & cybersecurity testingFlagship Offering · Design Phase
CodeX — Automated Cybersecurity for Industrial Products
A patented, AI-powered, browser-based platform that replaces insecure, manual Excel processes with cutting time-to-market by 90% and costs by 80%. Delivered on a secure blade server with HSM, or on a sovereign cloud such as Stackit or Telekom.
SQ-Software — the Key Sales Partner of Primary Target
Automated Threat Analysis
Identifies attack vectors across all software and hardware components using a database of 10,000+ threats, There are no scarce experts needed for routine assessments.
Risk Assessment & Visualisation
Calculates residual risk and visualises the security impact of vulnerabilities across the entire system architecture and creates a clear, fact-based picture for decision-makers.
Automated Countermeasures
Recommends targeted countermeasures tailored to your system's configuration and risk profile with no guesswork required.
Secure Development Workflow
Enforces access rights, encrypted data storage, change management and process tracking. Your development process becomes a security asset.
Tool Chain Integration
Browser-based and API-ready. Integrates with your engineering, PLM and security tooling. Import architecture diagrams and electronic signal maps directly.
TARA Reuse & Scaling
Component-level TARAs are reusable across projects and customers. This is up to 10× cheaper than creating new ones. Ideal for supplier networks and platform architectures.
| Capability | CodeX | Others |
|---|---|---|
| ISO/SAE 21434 coverage | 80% | 10–15% |
| Threat database (10,000+ entries) | ✔ | 120 max |
| Full automation | ✔ | Partial |
| Workflow management, versioning & change tracking | ✔ | ✗ |
| Combat field simulation | ✔ | ✗ |
| Security by Design + encrypted storage with HSM | ✔ | ✗ |
⚖ European Patent PT4483EP — automated threat identification & countermeasure selection. A legally protected competitive advantage.
Verification Phase · Offered through SQ-Software
TestArmy — Penetration Testing & Quality Assurance
Threats modeled are only half the story, they must also be exercised. TestArmy's Wrocław-based specialists deliver AI-driven penetration testing, auditing and quality testing of digital products, so you bring functional, secure solutions to market.
- AI-driven penetration testing — auditing and vulnerability assessment for web, mobile and infrastructure.
- Test automation — Cypress, Selenium, Appium and modern stacks.
- Performance & functional testing — for web and mobile products under real-world load.
- UX, accessibility & QA consulting — plus developer staff augmentation for your teams.
- Certified credentials — ISTQB Platinum Partner · ISO 9001 & ISO 27001 certified · customers in critical infrastructure, machinery, ships, arms, medical and household devices.
TestArmy Group at a glance
100+ certified testers and pentesters, putting years of experience to work for companies that ship regulated, security-critical products.
TRITON — Generative Automation of Security Penetration Tests
A collaborative EDF project co-developed by TestArmy: fully automated penetration testing for high-security defence applications using Generative AI, GAN-based ethical hacking, and the Human-as-a-Security-Sensor (HaaSS) concept for military SOCs, telecom networks and critical infrastructure.
New Offering · Production Planning
Manufacturing Optimization — Turn Complexity Into the Best Decision
Delivered with our partner Circonomit, this AI decision-intelligence platform helps manufacturing companies with high product variety find the optimal balance between operating capacity and financial outcome — automatically, in seconds, without modelling experts and without a complete data set.
Delivered by Jürgen Vollmer — Manufacturing & Security Specialist — Juergen.Vollmer@ext.circonomit.com
Order Prioritisation & Sequencing
Recalculates which order runs where and when, every day, across multiple production areas — a concrete recommendation for the planner, not another spreadsheet.
Bottleneck Simulation
Simulates supply chain constraints before they hit the shop floor, so you can react to a shortage before it becomes a delay.
Inventory Optimisation
Balances stock levels against service level and cost, based on your actual dependencies rather than static reorder points.
Production Planning
Optimises on-time delivery, machine utilisation and contribution margin together, instead of trading one off against the others.
Variant & Changeover Planning
Accounts for setup times, tool changes and material availability when sequencing high-variant production.
Workforce & Shift Planning
Plans headcount, shifts and downtime scenarios alongside the production plan, not as an afterthought.
🏭 Proof of concept: a causal model with ~30–50 variables and rules, built in days. Pilot projects run €12,000–€45,000 depending on complexity; ongoing operation from €2,500/month.
SQ-Software Solutions & Services
Turnkey solutions for secure software development
Beyond CodeX and TestArmy, SQ-Software markets and delivers turnkey solutions and services for software development departments, finding defects automatically and embedding security and quality rules directly into your development process.
Verifiable security & quality standards
We help you establish auditable security standards and quality rules for your software development process, your company and your suppliers to verify the delivered code automatically.
Obfuscation, signing & attack resistance
We obfuscate your executables, sign them securely and harden them against attacks to protect your intellectual property in the field.
Biometric identification & authorisation
For the voice channel, we integrate passive and active biometric controls for identification and authorisation to secure your customer-facing processes.
Regulation built into the process
We integrate security and quality rules, norms and regulations like ISO 21434, ISO 27001, DORA, NIS2, EU CRA into your development process, and optimise your workflows to run compliantly by default. Add security requirements as early as product planning and design.
Regulatory Landscape
Compliance deadlines are approaching fast
Regulations are tightening across all industrial sectors. Our solutions make sure you're ready for today, and for future updates to the regulatory framework.
EU Cyber Resilience Act (CRA)
Applies to all products with digital elements sold in the EU. Mandatory vulnerability reporting from September 2026; full compliance by December 2027. Fines up to €15M or 2.5% of global annual turnover.
⏰ Sept 2026 → Dec 2027ISO/SAE 21434 & UN R155
The automotive cybersecurity standard, now enforced by law in Germany and across the EU. OEMs mandate compliance throughout their supply chain; vehicle registration requires a completed TARA.
⏰ In effect — July 2024NIS2 Directive
Expanded critical-infrastructure cybersecurity across the EU for automotive, energy, health, transport and manufacturing. Requires risk-management measures and incident reporting.
⏰ In effect — Oct 2024DORA
The EU's Digital Operational Resilience Act imposes strict ICT risk-management, testing and reporting obligations on the financial sector and its technology suppliers.
⏰ In effect — Jan 2025IEC 62443 & EU MDR / FDA
The core standards for industrial automation and control-system security, plus medical-device cybersecurity requirements throughout the device lifecycle.
⏰ Industry standard / in effectDO-326A & EASA
Aviation cybersecurity airworthiness process standard is required for new type certifications and major modifications to aircraft and avionics.
⏰ Certification requirementAbout Us
Security & Quality Software GmbH
SQ-Software GmbH is a German IT-security company based in Ismaning near Munich. We support companies in protecting their key innovations, products, data and processes by evaluating workflows and integrating the best security tools into daily operations.
We market and distribute turnkey solutions and services for software development departments integrated directly into the development process: automated defect detection, secure development processes, application hardening, voice biometrics and compliance with ISO 21434, ISO 27001, DORA, NIS2 and the EU CRA.
Strategic Partnership
Key Sales Partner of Primary Target GmbH
SQ-Software is sales partner of CS Angress and Primary Target GmbH, the Munich-based developer of the patented, award-winning CodeX platform for automated threat assessment and risk analysis.
Through this partnership and our cooperation with the TestArmy Group our customers get security across the full product lifecycle from a single, local point of contact: consulting, licensing, implementation, integration and testing.
🏆 CodeX: Best Cybersecurity Technology 2023 (Handelsblatt Group, Fraunhofer ISI & Capgemini)
🥈 E-Mobility Startup Award 2023 (Porsche & Baden-Württemberg)
🏅 German Startup Pokal 2024, 2nd place
Information
News, Events & Background
Stay up to date with the latest developments at SQ-Software and our partners from company background and news to upcoming events and official press releases.
About SQ-Software & the Partnership
SQ-Software GmbH (Security & Quality Software GmbH) is an IT-security company based in Ismaning near Munich. We help companies establish verifiable security standards and quality rules for their software development process for themselves and along their software supply chain (SBOM) to verify them automatically.
As the key sales partner of Primary Target GmbH, we market CodeX: a patented, AI-powered platform for automated threat assessment and risk analysis (TARA) of industrial products. Following the principle of Security by Design, CodeX replaces insecure, manual Excel-based processes with a fully automated, auditable workflow, serving markets like IoT, Manufacturing, Automotive, Defense, Medical, Aviation or Marine, and supporting compliance like ISO/SAE 21434, the EU CRA, NIS2, DORA, NIST and OWASP.
Primary Target Joins the Defense Management Network Platform
Our partner Primary Target has joined the Defense Management Network Platform (defence.management) to systematically promote and accelerate collaboration between industry, research and defense organizations. The European defense landscape is undergoing a profound transformation:
- Hybrid threats and cyberattacks on critical infrastructure are increasing in frequency and complexity.
- Interoperability between national systems and multinational task forces remains one of the greatest technical hurdles.
- Innovation cycles in AI, sensor technology, software-defined capabilities and unmanned systems are shortening dramatically.
- Supply chains and industrial capacities are under pressure from geopolitical tensions and a shortage of skilled workers.
- Regulatory requirements such as certifications, norms and safety standards are becoming more extensive and complex.
TRITON — European Defence Fund Project
TestArmy co-develops TRITON, an EDF-funded project automating penetration testing for high-security defence applications with Generative AI. See the official TRITON website.
it-sa 2026
Meet us at it-sa in Nürnberg: our partner Primary Target GmbH will be represented at the Defence Management Network booth from 27 to 29 October 2026. Talk about how to stay and become secure — and how to use AI to automate your business processes. Get a live CodeX demo and discuss your TARA and compliance roadmap with us on site.
Press Releases
Official press releases from SQ-Software GmbH and our partners will be published here. For press enquiries, please contact us at contact@sq-software.com.
Get Started
Request a demo or a consultation
See CodeX in action, scope a security test with TestArmy, or get advice on your secure development process. Select your topic and we'll tailor the conversation to your specific use case usually within one business day.
SQ-Software GmbH
Freimanner Str. 14
85737 Ismaning, Germany
- Request the White Paper on TARA automation
- Schedule a 30-minute discovery call
- Proof of concept with your real TARA data
- Scoped test plan from TestArmy's engineers