Know what’s inside every firmware you ship.
FDIE extracts, analyzes, and scores firmware automatically - CVEs, SBOMs, compliance grades, and version-over-version intelligence, with zero manual reverse engineering.
Built for compliance against EU CRA, ETSI EN 303 645, OWASP FSTM, NIST, and IEC 62443-4-2
Deterministic analysis. Every result is reproducible.
FDIE uses static binary analysis, pattern matching, and CVE database lookups. No machine learning, no probabilistic scoring, no hallucinations. Run the same firmware twice and you get identical output. Every finding traces back to a specific binary, line, or configuration value you can verify yourself. The two biggest noise generators in firmware scanning, context-free high-entropy “secrets” and universal crypto-constant signatures, are suppressed by design.
Low false positives aren’t a setting you toggle - they’re an engineering discipline we test on every commit.
Deterministic
Reachability-gated suppression
Gated every release
Firmware formats
Security test cases
Compliance frameworks
Deterministic
Measured & CI-gated - every release
Most firmware ships with unknown risk.
No visibility
Most teams don’t know what’s actually inside their own firmware images - which libraries, which versions, which known vulnerabilities ship in every release.
Manual & slow
Manual reverse engineering takes days per image - too slow to run on every release, so most firmware ships unanalyzed.
Compliance deadline
Article 14 reporting becomes binding September 2026, and the EU Cyber Resilience Act becomes fully mandatory in December 2027, covering nearly every connected product sold in the EU.
The EU Cyber Resilience Act requires SBOMs, vulnerability handling, and conformity documentation for virtually every product with digital elements sold in the EU.
Learn about EU CRA compliance →From upload to audit-ready report - automatically.
Upload
Drop any firmware image - 15+ formats supported (squashfs, UBI, JFFS2, cramfs, ext, FAT, cpio, raw NAND dumps, and vendor-specific wrappers).
Extract
Automatic filesystem extraction, path-traversal safe, with full provenance tracking.
Analyze
Hardening flags, hardcoded secrets, weak crypto, and dangerous functions, matched against the full NVD CVE database with EPSS and CISA KEV.
Score
40+ deterministic test cases across 7 categories produce a 0-10 risk score and A-F grades across 6 compliance frameworks.
Report
CycloneDX/SPDX SBOMs, VEX documents, and audit-ready PDF reports - generated automatically.
Everything you need to ship firmware with confidence.
Automated Extraction
15+ formats, unpacked & filesystem-mapped in minutes.
CVE & Vulnerability Matching
Full NVD correlation, CPE version-range filtering, EPSS scoring, and CISA KEV flagging.
40+ Point Security Test Suite
Credentials, cryptography, binary hardening, attack surface, known vulnerabilities, firmware update, and secure boot.
SBOM & VEX Generation
CycloneDX + SPDX export, per-component license detection, dependency graphs, and function-hash fingerprinting that identifies statically-linked components with no version string left in the binary.
Compliance Scoring
A-F grades across EU CRA, ETSI EN 303 645, OWASP FSTM, NIST SP 800-193, NIST IR 8259A, and IEC 62443-4-2.
Delta Intelligence
Cross-version CVE tracking, component lineage, blast-radius analysis, and deterministic narrative summaries.
Open about our engine. Every result is traceable and reproducible.
Extraction Engine
Carves and unpacks 15+ firmware formats including SquashFS, UBI, JFFS2, cramfs, ext, FAT, raw NAND, and vendor-specific wrappers.
Binary Analysis Engine
Disassembles ELF, PE, and raw firmware images across 15+ CPU architectures - x86, ARM, ARM64, MIPS, RISC-V, PowerPC, SPARC, S390, MSP430, TriCore, PIC/dsPIC, MicroBlaze, Nios II, and more - via our own in-house disassembler, checks compiler hardening flags, maps linked libraries, and detects dangerous function usage.
CFG and Reachability
Control-flow graph analysis determines whether vulnerable code paths are actually reachable, powering accurate VEX assessments.
Intelligence Layer
CVE matching against the full NVD database, EPSS and CISA KEV correlation, malware signature scanning, and hardcoded secret detection.
The disassembler and control-flow engine - FirmBin - is built entirely in-house from published ISA manuals, not wrapped around Ghidra, Capstone, or radare2. Every engine ships as a self-contained image with no third-party black boxes and no external tool dependencies at runtime.
Firmware security isn’t a snapshot. It’s a history.
Component lineage - track a library across every firmware version you’ve shipped: when it was upgraded, what CVEs opened or closed, and how its license changed.
Blast radius - when a shared component changes, see every affected binary across your product line instantly.
Triage carry-forward - findings triaged in v1.2 automatically surface their disposition when the same finding reappears in v1.3.
Patch-presence verification - when a vendor backports a CVE fix without bumping the version string, FDIE checks the actual function code against real before/after patches proven elsewhere in your firmware history, instead of trusting the version string alone.
All narratives are generated by deterministic, rule-based templates - not generative AI - so every statement in your compliance evidence is traceable and audit-safe. No hallucination risk.
Miss the EU CRA deadline and you can’t sell into the EU. The clock is already running.
Article 14 vulnerability-reporting obligations become legally binding on September 11, 2026. Full CE-marking and conformity-assessment obligations follow on December 11, 2027, after which products that don’t comply cannot legally be sold in the EU market. Manufacturers must produce an SBOM, run a vulnerability handling process, complete a conformity assessment, and report actively exploited vulnerabilities to ENISA within 24 hours.
Non-compliance carries real financial exposure too: infringement penalties run up to EUR 10 million or 2% of global annual turnover, whichever is higher. Waiting until the deadline is close isn’t a neutral choice, it’s a decision to carry both risks at once.
Article 14-ready alert tracking
Actively exploited vulnerabilities are flagged the moment they’re detected, with the timeline data CRA incident reporting requires.
Auto-generated SBOM & VEX
CycloneDX and SPDX SBOMs plus VEX documents are produced for every firmware image - no separate tooling required.
Compliance grade mapped to CRA annexes
FDIE’s A-F compliance grade maps directly to CRA essential requirements, so you know exactly where you stand.
Plans that scale with your firmware program.
Pro
$99/seat/mo
- Unlimited firmware uploads, 500 MB max storage size
- Invite-only team members
- EU CRA framework + Article 14 alerts
- SBOM (CycloneDX + SPDX) + VEX
- Threat intel (CISA KEV + EPSS)
- Delta Intelligence + full REST API
Growth
$199/seat/mo
- Unlimited uploads, 5 GB max storage size
- All 6 compliance frameworks
- MalwareBazaar + VirusTotal threat intel
- FunctionDiff + patch verification
- Threat modeling (TARA / EMB3D)
- Dedicated account manager + SLA
Enterprise
Custom
From $399/seat/mo · scoped to your deployment and team size
- All Growth features
- SaaS (shared) or on-premise deployment
- Custom team members & highest storage tier
- SSO / SAML
- Air-gap & custom infrastructure
- Custom SLA & update cadence
Frequently asked questions
FDIE (Firmware Delta Intelligence Engine) is an automated firmware security analysis platform for hardware and IoT manufacturers, PSIRTs, and compliance teams. Upload a firmware image and FDIE extracts the filesystem, analyzes every binary, matches findings against 355,000+ CVEs, runs a 40+ point security test suite across 7 categories, generates CycloneDX and SPDX SBOMs and VEX documents, and grades the firmware against six global compliance frameworks - all without manual reverse engineering.
No. FDIE performs filesystem extraction, binary analysis, CVE matching, SBOM generation, and compliance scoring automatically. There are zero manual steps between uploading a firmware image and receiving an audit-ready report.
FDIE grades firmware against six global compliance frameworks: the EU Cyber Resilience Act (CRA), ETSI EN 303 645, OWASP Firmware Security Testing Methodology (FSTM), NIST SP 800-193, NIST IR 8259A, and IEC 62443-4-2 - each mapped to FDIE's 40+ point test suite with A-F grading.
The EU Cyber Resilience Act (CRA) is an EU regulation that sets cybersecurity requirements - including SBOMs, vulnerability handling processes, conformity assessment, and incident reporting - for virtually every product with digital elements sold in the EU. Article 14 vulnerability-reporting obligations become legally binding on September 11, 2026. Full conformity-assessment and CE-marking obligations follow on December 11, 2027. FDIE maps directly to CRA requirements, including Article 14 vulnerability-reporting alerts.
An SBOM (Software Bill of Materials) is a structured inventory of every software component, library, and dependency inside a piece of software or firmware. FDIE automatically generates SBOMs in both CycloneDX and SPDX formats for every analyzed firmware image, along with VEX (Vulnerability Exploitability eXchange) documents describing which vulnerabilities are exploitable.
No. FDIE's vulnerability matching, security scoring, SBOM/VEX generation, and Delta Intelligence narratives are produced by deterministic, rule-based engines and templates - not large language models. Every finding and every statement in your compliance evidence is reproducible, traceable, and free of AI hallucination risk.
FDIE is deterministic, not probabilistic. The same firmware always produces the same output. Two of the biggest noise sources in firmware scanners, context-free high-entropy secrets and crypto-constant signatures, are suppressed by design. Every finding traces back to a specific binary, line, or configuration value you can verify yourself.
Every component of FDIE's analysis pipeline is built in-house: the extraction engine (30+ firmware formats), control-flow and reachability analysis, firmware decryption, and binary parsing. There are no third-party analysis frameworks. FDIE publishes its full engine stack and provides an SBOM of its own software on request.
FDIE extracts the filesystem and binaries from an uploaded firmware image, identifies every software component and library version, and matches each one against 355,000+ CVEs with CVSS scoring. It then runs a 40+ point security test suite across 7 categories - credential security, firmware update, cryptography, binary hardening, attack surface, known vulnerabilities, and secure boot - to surface misconfigurations that CVE matching alone would miss.
FDIE extracts and analyzes 30+ firmware and filesystem formats, including common embedded Linux images, filesystem archives, and bootloader/update package formats. The extraction engine handles nested archives and encrypted partitions automatically, so a single upload is enough to reach the binaries inside.
A standard SBOM/SCA tool tells you what's in a single firmware build. Delta Intelligence is FDIE's engine for comparing two firmware versions: it tracks component lineage across versions, computes the blast radius of a change, and carries forward triage decisions (suppressions, false-positive markings) so they don't need to be redone on every release. See the Delta Intelligence page for details.
No. FDIE is entirely self-contained. All engines including extraction, decryption, binary parsing, and CVE matching are built in-house and ship as part of the platform. Nothing needs to be installed separately.
See your firmware’s security score in minutes.
Book a 30-minute walkthrough with our team - bring your own firmware image or use one of ours.