Skip to content

Binarly

Firmware and software supply chain security company whose Transparency Platform has uncovered dozens of high-severity UEFI vulnerabilities, including the widely covered LogoFAIL flaw, across major device vendors.

Visit Website ↗ + Add to Compare
73/100Meaningful Innovator

Overview

Binarly builds the Binarly Transparency Platform, which scans firmware, bootloaders, and compiled binaries to find known and unknown vulnerabilities, exposed cryptographic material, and evidence of malicious implants at a layer traditional software composition analysis and endpoint tools generally do not reach. The pitch is that firmware is both a persistent, hard-to-detect place for attackers to hide and a routinely under-inventoried part of the software supply chain, and Binarly’s static and machine-learning-based analysis is built specifically to close that visibility gap at scale, across binaries from many different vendors and toolchains.

The company has backed that positioning with a steady stream of original vulnerability research: it disclosed 23 high-severity flaws in AMI/Insyde-derived UEFI firmware used by Lenovo, Dell, HP, Intel, AMD, Acer, and other major OEMs; it discovered and coordinated disclosure of LogoFAIL, a widely covered Secure Boot bypass affecting the image-parsing libraries used by most UEFI implementations; and it separately found 16 additional high-impact firmware vulnerabilities specific to HP enterprise devices. These findings were confirmed through CERT/CC coordinated disclosure and resulted in vendor patches, giving Binarly a track record that is independently checkable rather than self-reported.

Founded in 2021, Binarly raised a $3.6 million pre-seed round in 2022 and closed a $10.5 million seed round in March 2024 led by Two Bear Capital, with participation from Cisco Investments among others. For CISOs, Binarly is relevant less as a general vulnerability management tool and more as a specialist answer to a specific, high-consequence blind spot: firmware and boot-chain integrity across a heterogeneous device fleet.

Innovation Matrix Assessment

Innovation Velocity 8/10

In roughly three years the company has published multiple major original vulnerability disclosures (the 23-flaw InsydeH2O findings, LogoFAIL, and 16 HP-specific vulnerabilities), a research output pace well above typical firmware-security vendors of similar size.

Operational Value 6/10

As a roughly 30-50 person company, Binarly runs a specialized research and analysis platform used in coordinated disclosure workflows with major OEMs, but public evidence of large-scale enterprise deployment and support operations is limited.

Market Momentum 7/10

A $10.5M seed round in March 2024 with Cisco Investments as a strategic participant, following extensive media coverage of LogoFAIL in late 2023, indicates real commercial and reputational momentum.

Category Disruption 8/10

Firmware and UEFI security is a chronically under-tooled layer of the supply chain; Binarly's platform-based approach to scanning binaries for known and unknown firmware vulnerabilities at scale is a meaningfully different approach than manual reverse-engineering or vendor self-attestation.

Real-World Efficacy 8/10

Binarly's core efficacy claim is independently verifiable: the vulnerabilities it found were assigned CVEs, coordinated through CERT/CC, and patched by affected OEMs (Lenovo, Dell, HP, Intel, AMD, Acer and others), which is a stronger evidence bar than vendor-reported detection statistics.

Enduring Relevance 7/10

Firmware supply chain integrity is rising in priority alongside SBOM mandates and nation-state interest in persistent, below-the-OS implants, making Binarly's niche increasingly relevant to enterprise and government risk programs.

Why CISOs Should Care

Binarly gives security teams visibility into a part of the supply chain, device firmware, that most vulnerability management programs do not scan at all, backed by a public track record of finding real, patched CVEs.

What Makes It Different

Unlike general vulnerability scanners or software composition analysis tools, Binarly's platform is purpose-built to analyze compiled firmware and boot-chain binaries across OEMs, using its own research output as proof of capability rather than only marketing claims.

The Matrix Verdict

73/100 — MEANINGFUL INNOVATOR

A young but credible specialist vendor whose independently confirmed vulnerability research (LogoFAIL and the InsydeH2O disclosures in particular) substantiates its platform claims better than most early-stage security startups can demonstrate at this stage.

Editorial Note: Claims vs. Verified Findings

The vulnerability counts, CVE assignments, and affected-vendor lists (Lenovo, Dell, HP, Intel, AMD, Acer, etc.) are independently corroborated through CERT/CC advisories and security press coverage (BleepingComputer, SecurityWeek). Funding amounts and investor names come from company press releases and are not independently audited, though they are consistent with SecurityWeek and Business Wire reporting.

Sources