
Binary-Level Firmware and Software Supply Chain Security
Founded in 2021 by a group of program analysts and firmware security researchers, the Santa Monica-based company sells binary-level product security to device manufacturers, OEMs and ODMs, firmware suppliers, and enterprise product security and procurement teams. Its focus is the layer beneath the operating system, where shipped firmware, embedded stacks and third-party binaries arrive without source code and conventional scanners have little visibility. Founder Alex Matrosov, previously chief offensive security researcher at NVIDIA, has moved to the board of directors, with Gwenyth Castro appointed chief executive.
The Binarly Transparency Platform inspects compiled artifacts directly rather than source, reconstructing what a build actually contains. It generates and validates SBOMs and CBOMs against the binary itself, identifies reused, modified or backported code that version-number matching misses, and flags tampering, hardcoded secrets, malicious code, unsafe functions and secure-by-design failures. Patented reachability analysis for binary executables establishes whether a flaw is genuinely callable at runtime, while an Exploitation Maturity Score weights findings against live exploit signals and CISA KEV tracking. Results can enforce CI/CD release gates and feed continuous post-deployment monitoring.
Positioning rests on ground truth taken from the artifact instead of declared inventories, letting buyers verify supplier claims and vendors ship defensible evidence rather than spreadsheets. The research arm has led coordinated disclosure of LogoFAIL, PKfail and firmware flaws affecting HP, Lenovo, Qualcomm and U-Boot, and publishes free tooling including FwHunt and an xz backdoor detector. Stated use cases span automotive ECUs and OTA pipelines, medical device submissions, telco equipment, aerospace and drones, and post-quantum cryptography migration. Investors include Two Bear Capital, Westwave Capital and Cisco Investments.



