Binarly
Firmware and software supply chain security company whose Transparency Platform has uncovered dozens of high-severity UEFI vulnerabilities, including the widely covered LogoFAIL flaw, across major device vendors.
Visit Website ↗ + Add to CompareOverview
Binarly builds the Binarly Transparency Platform, which scans firmware, bootloaders, and compiled binaries to find known and unknown vulnerabilities, exposed cryptographic material, and evidence of malicious implants at a layer traditional software composition analysis and endpoint tools generally do not reach. The pitch is that firmware is both a persistent, hard-to-detect place for attackers to hide and a routinely under-inventoried part of the software supply chain, and Binarly’s static and machine-learning-based analysis is built specifically to close that visibility gap at scale, across binaries from many different vendors and toolchains.
The company has backed that positioning with a steady stream of original vulnerability research: it disclosed 23 high-severity flaws in AMI/Insyde-derived UEFI firmware used by Lenovo, Dell, HP, Intel, AMD, Acer, and other major OEMs; it discovered and coordinated disclosure of LogoFAIL, a widely covered Secure Boot bypass affecting the image-parsing libraries used by most UEFI implementations; and it separately found 16 additional high-impact firmware vulnerabilities specific to HP enterprise devices. These findings were confirmed through CERT/CC coordinated disclosure and resulted in vendor patches, giving Binarly a track record that is independently checkable rather than self-reported.
Founded in 2021, Binarly raised a $3.6 million pre-seed round in 2022 and closed a $10.5 million seed round in March 2024 led by Two Bear Capital, with participation from Cisco Investments among others. For CISOs, Binarly is relevant less as a general vulnerability management tool and more as a specialist answer to a specific, high-consequence blind spot: firmware and boot-chain integrity across a heterogeneous device fleet.
Innovation Matrix Assessment
In roughly three years the company has published multiple major original vulnerability disclosures (the 23-flaw InsydeH2O findings, LogoFAIL, and 16 HP-specific vulnerabilities), a research output pace well above typical firmware-security vendors of similar size.
As a roughly 30-50 person company, Binarly runs a specialized research and analysis platform used in coordinated disclosure workflows with major OEMs, but public evidence of large-scale enterprise deployment and support operations is limited.
A $10.5M seed round in March 2024 with Cisco Investments as a strategic participant, following extensive media coverage of LogoFAIL in late 2023, indicates real commercial and reputational momentum.
Firmware and UEFI security is a chronically under-tooled layer of the supply chain; Binarly's platform-based approach to scanning binaries for known and unknown firmware vulnerabilities at scale is a meaningfully different approach than manual reverse-engineering or vendor self-attestation.
Binarly's core efficacy claim is independently verifiable: the vulnerabilities it found were assigned CVEs, coordinated through CERT/CC, and patched by affected OEMs (Lenovo, Dell, HP, Intel, AMD, Acer and others), which is a stronger evidence bar than vendor-reported detection statistics.
Firmware supply chain integrity is rising in priority alongside SBOM mandates and nation-state interest in persistent, below-the-OS implants, making Binarly's niche increasingly relevant to enterprise and government risk programs.
Why CISOs Should Care
Binarly gives security teams visibility into a part of the supply chain, device firmware, that most vulnerability management programs do not scan at all, backed by a public track record of finding real, patched CVEs.
What Makes It Different
Unlike general vulnerability scanners or software composition analysis tools, Binarly's platform is purpose-built to analyze compiled firmware and boot-chain binaries across OEMs, using its own research output as proof of capability rather than only marketing claims.
The Matrix Verdict
73/100 — MEANINGFUL INNOVATOR
A young but credible specialist vendor whose independently confirmed vulnerability research (LogoFAIL and the InsydeH2O disclosures in particular) substantiates its platform claims better than most early-stage security startups can demonstrate at this stage.
Editorial Note: Claims vs. Verified Findings
The vulnerability counts, CVE assignments, and affected-vendor lists (Lenovo, Dell, HP, Intel, AMD, Acer, etc.) are independently corroborated through CERT/CC advisories and security press coverage (BleepingComputer, SecurityWeek). Funding amounts and investor names come from company press releases and are not independently audited, though they are consistent with SecurityWeek and Business Wire reporting.
Sources
Alternatives to Binarly
Unknown Cyber Inc.
Malware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Synack Inc
A penetration-testing-as-a-service platform pairing a vetted researcher community with AI-driven attack surface discovery for continuous security validation.
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Cogent Security
Agentic AI platform that autonomously triages, investigates, and remediates vulnerabilities as a force multiplier for security teams.
Airlock Digital
Application allowlisting (deny-by-default) platform that blocks unapproved executables, scripts, and processes to prevent ransomware and malware execution.
ReversingLabs
Software supply chain security and binary analysis vendor that inspects compiled software and packages for malware and unauthorized…