Skip to content

aDolus

aDolus's FACT Platform reverse-analyzes software binaries and firmware to generate SBOMs and flag vulnerabilities and malware in OT, ICS, and IoT devices; acquired by Exiger in 2024.

Visit Website ↗ + Add to Compare
60/100Incremental Innovator

Overview

aDolus builds the FACT Platform, a software supply chain security tool that generates enriched Software Bills of Materials (SBOMs) for industrial control systems, operational technology, and IoT devices, including devices whose vendors don’t natively supply one. Rather than depending on a vendor-provided SBOM, FACT analyzes software binaries and device firmware directly to reconstruct a component inventory, then screens it for known vulnerabilities, embedded malware, counterfeit components, and certificate or provenance issues, producing a risk score aimed at procurement, product security, and vulnerability management teams in regulated and critical-infrastructure industries.

Founded in 2017 and headquartered in Victoria, British Columbia, aDolus built its business partly around the SBOM mandate created by U.S. Executive Order 14028, which directs federal agencies to require SBOMs from software suppliers, a requirement that is especially hard to satisfy for legacy industrial and OT equipment. In July 2024, third-party and supply chain risk management firm Exiger acquired aDolus’s assets, folding its binary-level SBOM and firmware analysis capability into Exiger’s broader supply chain risk platform.

aDolus continues to operate its FACT Platform under its own brand post-acquisition, addressing a real and still largely unsolved gap: most SBOM tooling assumes a cooperative vendor, while aDolus’s binary-analysis approach works even when one isn’t available. The Exiger acquisition should extend its distribution into a larger enterprise risk customer base, though it also means aDolus’s future roadmap is now set within Exiger’s broader strategy rather than as an independent company.

Innovation Matrix Assessment

Innovation Velocity 6/10

aDolus moved from a standalone SBOM/firmware analysis tool to a component embedded within Exiger's broader third-party risk platform following the 2024 acquisition, extending its capability into wider supply chain risk workflows.

Operational Value 5/10

aDolus operated with roughly 11-50 employees pre-acquisition around a single specialized platform (FACT); it now has access to acquirer Exiger's larger operational base, but the aDolus-specific team and product remain a focused, narrow capability.

Market Momentum 6/10

Being acquired by Exiger, an established and well-capitalized supply chain risk management firm, in July 2024 is a strong external validation and momentum signal, even though pre-acquisition funding amounts were not publicly disclosed.

Category Disruption 6/10

Most SBOM tooling assumes a cooperative vendor supplying a bill of materials; aDolus instead reverse-analyzes binaries and firmware directly, which is a meaningfully different technical approach that works even when no vendor SBOM exists, a common situation in legacy OT and IoT equipment.

Real-World Efficacy 5/10

The regulatory driver behind SBOM adoption (Executive Order 14028) is independently verifiable, but the accuracy and coverage of FACT's binary-level vulnerability, malware, and counterfeit-component detection are described only in vendor materials, with no independent test results found.

Enduring Relevance 8/10

SBOM requirements for federal and critical-infrastructure software suppliers are an active, regulation-driven need, and the gap aDolus addresses (generating SBOMs for devices without vendor-supplied ones) is a persistent, unresolved problem in OT and ICS security.

Why CISOs Should Care

For security and OT teams responsible for software supply chain risk in industrial, IoT, and critical infrastructure environments, aDolus's FACT Platform can generate a usable SBOM and vulnerability/malware risk score even for devices whose vendors don't natively supply one.

What Makes It Different

Most SBOM tools depend on a vendor supplying a bill of materials; aDolus's FACT Platform reverse-analyzes binaries and firmware directly to construct an SBOM and flag vulnerabilities, malware, and counterfeit components without needing vendor cooperation.

The Matrix Verdict

60/100 — INCREMENTAL INNOVATOR

A focused, technically credible software-supply-chain security tool addressing a genuine SBOM completeness gap in OT, ICS, and IoT environments, now folded into Exiger's larger third-party risk platform following a 2024 acquisition.

Editorial Note: Claims vs. Verified Findings

The specific accuracy and coverage claims for FACT's vulnerability, malware, and counterfeit-component detection are vendor-described; no independent test results were found. The 2024 Exiger acquisition, Executive Order 14028's SBOM mandate, 2017 founding, and Victoria, BC headquarters are independently confirmed via press releases and public regulation text.

Sources