Emproof
Emproof protects embedded software at the binary level against reverse engineering and exploitation, without requiring source code access or hardware changes.
Visit Website ↗ + Add to CompareOverview
Emproof is a European deep-tech spinout — originating out of Ruhr University Bochum, the Max Planck Institute, and the Horst Görtz Institute for IT Security — that applies binary-level analysis and hardening to embedded software. The core pitch is narrow and technical: most embedded and legacy devices in the field can’t be re-audited or re-compiled by their original vendor, so traditional application security tooling (which typically needs source access) doesn’t reach them. Emproof’s platform, Emproof Nyx, works directly on compiled binaries to identify exploitable weaknesses and apply hardening — control-flow protections, anti-tamper measures, obfuscation against reverse engineering — without requiring the source code or a hardware redesign.
The company targets three distinct buyer groups: automotive and medical-device manufacturers building new embedded products, operators of legacy industrial and IoT devices that can no longer be patched conventionally, and defence/aerospace programs where source code for third-party or older components is often unavailable. This legacy-device angle is one of the more genuinely differentiated parts of the pitch, since most embedded security vendors focus on securing new development rather than hardening what’s already deployed and unpatchable.
Emproof is early-stage: founded in 2019, it raised a €2M seed round in 2022 from TIIN Capital, High-Tech Gründerfonds and Cyber Impact, and closed a follow-on round in early 2026 with new investor Auriga Cyber Ventures and SecFund joining alongside expanded commitments from existing backers. That same round brought in Marc Schieder as CEO specifically to move the company from a research-driven academic spinout toward a repeatable enterprise SaaS business — a transition still in progress rather than complete. No named enterprise customers or independent third-party evaluations of Nyx’s protection claims are publicly available yet.
Innovation Matrix Assessment
Emproof has moved from academic research (Ruhr University Bochum / Max Planck / Horst Görtz Institute) to a productized platform, Emproof Nyx, addressing automotive, medtech, legacy/IoT and defence use cases -- a genuine but still-narrow product footprint for a company this young.
The January 2026 hire of a dedicated CEO (Marc Schieder) explicitly to lead the shift 'from a research-driven startup to a scalable enterprise SaaS organization' indicates the company itself acknowledges its go-to-market and operational maturity are still developing.
Emproof closed a new funding round in early 2026 led by new investor Auriga Cyber Ventures with SecFund joining and existing backers (High-Tech Gründerfonds, TIIN Capital) expanding commitments, following a €2M seed in 2022 -- consistent, if modest, funding progression.
Binary-level hardening that requires neither source code nor hardware changes addresses a real blind spot: legacy and third-party embedded components that can never be re-audited conventionally. This is a meaningfully different approach than source-based SAST/SCA tooling used for new embedded development.
No named enterprise customers, deployment case studies, or independent third-party security evaluations of Nyx's protection claims are publicly available; the company's credibility currently rests on its academic research pedigree rather than field-verified outcomes.
Firmware and embedded-device attack surface is a growing concern across automotive, medical device, and critical-infrastructure IoT, and the specific problem of hardening already-deployed, unpatchable legacy binaries is under-served by mainstream AppSec vendors, giving Emproof real strategic relevance despite its small size.
Why CISOs Should Care
For organizations running large fleets of embedded or legacy devices they can't recompile or physically retrofit, Emproof offers a way to harden those binaries against tampering and exploitation post-deployment, closing a gap most AppSec and IoT security tools don't address.
What Makes It Different
Unlike source-code-dependent AppSec tools, Emproof works purely on compiled binaries, letting it protect legacy and third-party embedded components where source access is impossible.
The Matrix Verdict
53/100 — INCREMENTAL INNOVATOR
Emproof has a technically credible and genuinely differentiated approach to an under-served problem, backed by strong academic research roots and fresh funding, but it is still an early-stage company transitioning from research project to commercial vendor with no independently verified customer outcomes yet.
Editorial Note: Claims vs. Verified Findings
Vendor-sourced and unverified: the effectiveness of Nyx's binary hardening against real-world exploitation attempts, and any implied customer traction in automotive/medtech/defence. Independently verifiable: the company's academic origins, its 2022 seed round and 2026 follow-on funding and investors, and the January 2026 CEO appointment.
Sources
Alternatives to Emproof
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…