Skip to main content
FDIE
Firmware Delta Intelligence Engine

Keep release decisions connected to the evidence.

Analyse supported firmware images, compare identified components and review vulnerability decisions across releases. FDIE brings component history, bounded runtime observations and SBOM/VEX exports into one workflow for connected-device teams.

See the plan
35

Firmware formats

60

Security test cases

385,000+

CVE records in FDIE's NVD mirror

11

Compliance frameworks

How FDIE works

From a supported image pair to a reviewable decision.

Start with two releases of one product. Agree compatibility and coverage, then use the analysis to focus your team’s next review.

Step 1

Scope

Confirm image access, product and hardware variant, supported format and hosting requirements.

Step 2

Analyse

Extract supported content, identify components and collect static and available runtime evidence. Review coverage gaps.

Step 3

Compare

Inspect component, finding and function changes alongside engine and vulnerability-feed context.

Step 4

Review

Decide which earlier assessments remain applicable and investigate changes that need fresh triage.

Step 5

Export

Share SBOM, VEX and review evidence with stated limitations as part of your release documentation.

Firmware portfolio

Keep firmware and coverage in view.

Find a release, review its processing state and check how much of the image was assessed before opening the results. Partial and unassessed images remain visible in the same library.

FDIE firmware library showing six older firmware samples with partial and unassessed binary-analysis coverage. Enlarge firmware library
Example library of older firmware releases. “Complete” refers to processing, while partial and unassessed coverage warnings remain visible. Grades and count semantics await reconciliation; zero recovered binaries or missing findings do not establish that a device is secure.

Example library of older firmware releases. “Complete” refers to processing, while partial and unassessed coverage warnings remain visible. Grades and count semantics await reconciliation; zero recovered binaries or missing findings do not establish that a device is secure.

View the original capture for context
Core capabilities

What is actually running under the hood.

All capabilities are included in the Enterprise plan. Analysis coverage depends on the image; hosting, usage and support are scoped in your contract.

CVE and vulnerability matching

NVD correlation with CPE version-range filtering for fewer false matches, plus EPSS scoring and CISA KEV flagging. Matching runs on identifiers recovered from the binary: dynamic-linking metadata, version banners, strings and component signatures.

Binary intelligence

Inspect available decompiled functions, call graphs and extracted strings alongside a finding. Coverage depends on the binary format, architecture and analysis outcome; missing decompilation remains visible.

Delta Intelligence

Component lineage, known dependency relationships and reviewable triage suggestions across analysed releases of your product.

Dynamic analysis

Emulates supported binaries and attempts supported Linux boots in an isolated sandbox. Observations are bounded by the paths and environments exercised.

Automated extraction

Recover supported filesystems and wrappers, including SquashFS, UBI, JFFS2, CramFS, ext, FAT, raw NAND and common vendor wrappers.

Continuous monitoring and alerts

Once analysed, every image is re-matched against the NVD mirror daily and checked against the CISA KEV catalogue every six hours; EPSS scores refresh daily. A new match raises a notification after that check, so the lag is the sync interval plus the feed's own publication delay, not real time. You can also re-match on demand.

Reporting and integrations

Export reviewable PDF evidence and configure webhooks, Slack or Microsoft Teams notifications for findings raised by analysis or scheduled rechecks.

60-point security test suite

Credentials, cryptography, binary hardening, attack surface, known vulnerabilities, update mechanisms and secure boot, in one pass.

SBOM, CBOM and VEX

CycloneDX and SPDX inventories of identified components and licences, plus VEX documents recording vulnerability assessments, uncertainty and reviewed decisions.

Threat modeling

TARA and MITRE EMB3D built automatically from what FDIE found: components, exposed services, the boot chain and observed runtime behaviour.

Malware and threat intelligence

YARA content rules surface matching indicators in extracted files for investigation alongside CVE candidates. A match needs review; absence of a match does not establish that an image is malware-free.

Compliance scoring

Assessed-control grades across eleven frameworks: ETSI EN 303 645, EN 18031-1, EN 18031-2, EN 18031-3, OWASP FSTM, NIST SP 800-193, NIST IR 8259A, IEC 62443-4-2, IEC 81001-5-1, FDA 524B and TEC 31318, with explicit coverage gaps. CRA disclosure review is available separately.

Security and trust

Your firmware deserves careful handling.

Firmware images and everything extracted from them are encrypted at rest and in transit, access is scoped per organisation, and nothing you upload is sold, used to train a model, or disclosed beyond the hosting and service providers named in our DPA.

Full security and trust details

Encryption

Encrypted at rest and in transit

Isolation

Per-organisation isolation on every query

Sandboxing

Sandboxes destroyed after every run

Data region

India, or on-premises in your own environment

Evidence browser

Move from a finding to the file behind it.

Inspect source locations and recorded results in context. Recovery and analysis coverage remain part of the review.

BusyBox selected in the FDIE filesystem browser for an older DAP2360 release, with source location and associated findings. Enlarge product capture
Example analysis of an older firmware release. BusyBox is selected with its source location and associated findings. This capture illustrates the evidence browser; displayed findings are not independent vulnerability validation or a statement about current vendor products.

Example analysis of an older firmware release. BusyBox is selected with its source location and associated findings. This capture illustrates the evidence browser; displayed findings are not independent vulnerability validation or a statement about current vendor products.

See more product captures
Next step

Start with one product and two releases.

Review a sample comparison with us. Then scope a supported image pair, hosting requirements and the evidence your team needs to evaluate.

or explore pricing

21-day free trial on the full platform. No card, no automatic conversion.

Schedule a call

Start with the evidence your team needs.

Choose a time that suits you. We will cover your product, your release workflow and whether a scoped evaluation makes sense. Calls are held on Zoom.

Loading the booking calendar

Calendar unavailable? Open scheduling in a new tab.