Binarly

Binarly is a software and firmware supply-chain security company focused on validating compiled code when source code is unavailable, incomplete, or unreliable. Its technology analyzes firmware images, executables, libraries, containers, and other shipped artifacts to uncover vulnerabilities, secrets, cryptographic weaknesses, malicious code, and supply-chain tampering.

Binarly combines an enterprise platform with free and community tools for vulnerability hunting, firmware scanning, and reverse-engineering workflows. Its positioning is strongest in firmware, embedded, and third-party software environments where manifest-based, version-based, or source-only approaches leave major blind spots. The company helps customers generate trustworthy software inventories, understand real exposure in delivered binaries, and reduce risk before products are shipped or approved for deployment.

Offerings, Capabilities, and Integrations

Binarly’s offerings center on binary-level inspection and risk analysis for firmware and software supply chains. Its capabilities span known and unknown vulnerability detection, dependency discovery, secrets exposure, cryptographic asset visibility, malicious and suspicious code detection, mitigation weakness analysis, and validation of what is actually present in compiled artifacts. The company also supports exploit-aware prioritization through reachability analysis and threat-intelligence-driven scoring, helping teams focus on issues that are actionable in production.

Binarly supports product security, procurement, vendor-risk, and incident-response workflows with exports such as SBOM, CBOM, VEX, and advisory-style reporting. The platform can be used as a cloud-hosted service, deployed on-prem, or provisioned as an isolated instance, and it supports operational integration through APIs, Jira connectivity, notifications, and custom rule workflows that incorporate technologies such as FwHunt and YARA.

Products and Services

  • Binarly Transparency Platform: Binarly’s flagship enterprise platform for analyzing compiled software and firmware without source-code access. It delivers vulnerability discovery, dependency and secrets analysis, cryptographic visibility, malicious code detection, SBOM and CBOM generation, VEX export, and exploit-aware prioritization.
  • Binary Risk Hunt: A free scanning service that helps teams inspect firmware and software binaries, detect known vulnerabilities and implants, identify leaked cryptographic material, map dependencies including transitive components, and generate SBOMs.
  • VulHunt: A binary vulnerability hunting framework that uses Lua rules, dataflow analysis, code-pattern matching, and decompilation to detect known and unknown vulnerabilities in POSIX binaries and UEFI firmware.
  • FwHunt: A rule format designed to scan for known vulnerabilities in UEFI firmware.
  • FwHunt Community Scanner: Open tools for analyzing UEFI firmware and checking UEFI modules against FwHunt rules.
  • efiXplorer: An IDA plugin and loader for UEFI firmware analysis and reverse-engineering automation.
  • Idalib: Idiomatic Rust bindings for the IDA SDK that enable developers to build standalone binary analysis tools using IDA’s idalib.
  • PKfail Free Scanner: A free detection tool that allows users to upload firmware binaries and check for exposure to the PKfail Secure Boot key issue.
  • XZ Utils: A free scanner for detecting signs of the XZ backdoor in affected binaries.

Target Customers

Binarly targets software producers, hardware OEMs, ODMs, firmware suppliers, and product security teams that need to validate compiled artifacts before release. Its products fit organizations that want binary-level assurance inside build, QA, and release processes, especially when third-party components and embedded software are part of the final deliverable.

Binarly also serves enterprise security, procurement, third-party risk, and incident-response teams that need independent validation of vendor software and firmware. Its use cases align particularly well with industries that depend on embedded systems, regulated products, or critical infrastructure, including automotive, aerospace, healthcare, finance, and telecom environments.

Key People

  • Gwenyth Castro: CEO
  • Alex Matrosov: Founder and Board Member
  • Sam Thomas: Chief Scientist
  • Philipp Deppenwiese: Head of Product
  • Grigory Glushko: Head of Engineering
  • Yegor Vasilenko: Sr. Principal Security Researcher – Head of Research
  • Barrett Elkins: Director of Global Sales
  • Dave Alfaro: Head of Customer Success
  • Curtis Yanko: Director of Solutions Engineering

Key Facts

  • Headquarters: Santa Monica, California, United States
  • Employees: Approximately 45
  • Annual Revenue: $6M-$7M
  • Parent Company: None
  • Subsidiaries: None
  • Publicly Listed: Private
Binarly

Enter a search