RunSafe Targets Operational Software Assurance Market as U.S. Cyber Strategy Shifts to Deployed Systems
- 5 hours ago
- 2 min read
RunSafe Security is positioning itself at the center of an emerging cybersecurity category designed to protect the software already running inside weapons platforms, energy systems, industrial equipment, vehicles, and medical devices.
The company calls the category Operational Software Assurance, or OSA. Unlike application security programs focused primarily on development and software supply chains, OSA addresses compiled software and firmware throughout their years-long operational lives.
The strategy arrives as artificial intelligence accelerates vulnerability discovery and raises concerns that attackers may develop exploits faster than operators can test, certify, and deploy patches.
“Cybersecurity has spent decades getting better at finding vulnerabilities, but finding more vulnerabilities doesn't protect the software already operating our aircraft, weapons platforms, energy systems, factories, and other critical infrastructure,” said Joseph M. Saunders, founder and CEO of RunSafe Security. “AI is making that gap impossible to ignore. Operational Software Assurance is about knowing what's actually in your software, protecting it while it runs, and continuously proving that protection.”
Research from Lionfish Tech Advisors analysts Brad LaPorte and Rob Smith defines OSA through three functions: identifying software components and reachable vulnerabilities, protecting deployed code from exploitation, and generating evidence that systems meet regulatory and mission requirements.
RunSafe says its platform performs those tasks by analyzing compiled software and firmware, applying runtime protections without source-code modifications, and continuously producing assurance documentation.
That model targets a stubborn problem in operational technology and national security. Mission-critical systems can remain deployed for decades, while patches may require extensive testing, recertification, or scheduled downtime. Some legacy software cannot be quickly rewritten in memory-safe programming languages or replaced with newer systems.
“While AI didn't create the problem of vulnerable legacy software, it did change the economics of attacking it,” said Shane Fry, CTO of RunSafe Security. “We cannot assume defenders will find, patch, test, and recertify every vulnerability before an adversary can exploit it.”
RunSafe’s announcement also aligns OSA with the White House’s National Security Science and Technology Strategy, which treats cybersecurity as a foundation for missile defense, autonomous systems, battlefield operations, critical infrastructure, and other strategic priorities.
Lionfish calls runtime protection a “Digital Golden Dome” for software. The comparison reflects a defensive model in which organizations assume some threats will penetrate earlier security layers, then prevent those threats from successfully exploiting deployed code.
The researchers identified more than 140 funded U.S. defense programs potentially exposed to runtime software risk. Those programs account for roughly $87 billion in fiscal 2026 procurement and $159.5 billion in the fiscal 2027 request, although the figures measure software exposure rather than RunSafe’s addressable revenue.
RunSafe’s underlying technology originated in DARPA-funded research. The company says its binary and firmware protections are now used across defense, aerospace, and critical infrastructure environments, with technology also available through the military’s Iron Bank software repository.


