All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Eclypsium sells a platform that inspects firmware and hardware inside enterprise endpoints, servers, network devices and AI hardware. Its named references are a cloud provider, a credit union and a defense contractor. The company announced in 2022 that CISA had added its platform to the Continuous Diagnostics and Mitigation Approved Products List. CISA publishes that list as a download, not a page naming vendors. The listing rests on the company's own word. CISA calls the catalog authoritative, and now accepts no new submissions for the indefinite future. No rival can apply while it stays closed. Eclypsium has raised $110 million since 2017, and no reviewed source outside the company names a customer. A buyer checking references works from the company’s own pages.
| Description | Infrastructure security company whose platform builds a component inventory for enterprise devices, hardens their firmware, and detects implants and tampering across endpoints, servers, network gear and AI data center hardware. | [f1] |
|---|---|---|
| Founded | 2017 | [f2] |
| HQ | Portland, Oregon, United States | [f3] |
| Funding | $110M total | [f2] |
| Latest funding | $25M strategic round, March 2026, led by PEAK6 Strategic Capital | [f2] |
| Product | What it does |
|---|---|
| Eclypsium Platform | Inventories the components inside enterprise devices, monitors firmware integrity and configuration drift, and detects implants that endpoint agents cannot see. |
| InfraTrust | Free knowledge base of hardware and firmware security advisories from enterprise device manufacturers, published with a monthly digest called InfraTrust Pulse. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
The Eclypsium Platform inventories the components inside endpoints, servers and network devices, hardens their firmware, and detects threats in that hardware. These capabilities are mapped to the Cyber Defense Matrix. [f1]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Eclypsium names a specific buyer and a specific blind spot, the firmware and hardware layer that endpoint tools cannot read. One non-vendor record documents an instance of it, a Hacker News account of known firmware flaws and misconfigured security features across three Palo Alto Networks firewall models. The reviewed sources carry no independent quantification of the pain at scale. [s2, s13, s1] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Eclypsium's own pages set out the mechanism, covering component inventory, firmware integrity and configuration drift monitoring, automated patching, and detection of implants that disable endpoint agents. A Hacker News article shows that analysis applied to three named appliance models, and Palo Alto Networks answered the published findings. [s2, s13, s1] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The enabler is credible and the buyer-side proof is indirect. Eclypsium argues that attacker tactics have moved to endpoint firmware and network edge devices, and a January 2025 Hacker News article documents flaws in that layer, but no reviewed source records dated buyer demand of more than one kind in the past year. [s2, s13, s12] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | TechCrunch records that Yuriy Bulygin spent nearly a decade at Intel leading security threat analysis, became senior director of advanced threat research at McAfee, and founded the open source CHIPSEC assessment framework. Both founders still hold the top jobs, and a Hacker News article covers the firmware research the company publishes. [s11, s4, s7, s13] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Executives at DigitalOcean, First Financial Credit Union and Lockheed Martin give attributed statements on Eclypsium's homepage, and the same page presents American Express, Motorola, KDDI and IPG under a trusted-by heading without attributing a statement to any of them. SecurityWeek separately states that the company joined the NVIDIA Inception Program. Every customer statement is vendor-published, which holds the score below the top rung. [s1, s12, s18] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | SecurityWeek puts total capital at $110 million since 2017, which is proportional to an enterprise and government motion, and shipping is visible in the 2026 platform expansion and the InfraTrust launch. No reviewed source discloses revenue, margin or a growth-efficiency measure. [s12, s9, s17] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Independent outlets place Eclypsium the same way without vendor help, calling it a firmware security company in 2022, an Oregon startup focused on firmware and device security in 2025, and a device supply chain security firm in 2026. TechCrunch describes the same ground. [s10, s9, s12, s11] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Coverage spanning many manufacturers is friction rather than a structural moat. SecurityWeek states that the platform covers dozens of hardware vendors, and Eclypsium sets manufacturer names including HP, Lenovo, Dell, Intel and Microsoft beside its platform description, each of them controlling its own firmware. The federal listing and the analyzed binary corpus both rest on the company's own statements. [s12, s1, s15, s18] |
The problem sits below the layer that endpoint security tools read. Eclypsium's platform page states that attacker tactics have shifted toward endpoint firmware and network edge devices, where traditional endpoint detection and vulnerability management cannot see. A Hacker News article records an evaluation of three Palo Alto Networks firewall models that turned up known firmware flaws and misconfigured security features. Palo Alto Networks answered that it was aware of the published research.
The evidenced buyers sit in regulated industries. Eclypsium's homepage carries attributed statements from executives at DigitalOcean, First Financial Credit Union and Lockheed Martin. The same page presents American Express, Motorola, KDDI and IPG under a trusted-by heading with no statement attached, and KDDI's open innovation fund also appears in the record as a Series B investor, so those four names are marketing references rather than evidenced customers.
A federal purchasing channel runs through CISA and it is closed to newcomers. CISA describes its Continuous Diagnostics and Mitigation Approved Products List as the authoritative catalog for approved products meeting the program's technical requirements, reviewed submission by submission against established criteria. The same page states the list is not accepting new submissions for the indefinite future. Eclypsium announced in July 2022 that its platform had been added to that list. [s2, s13, s1, s10, s18, s14, s15]
The platform does three jobs across one device fleet. Eclypsium's platform page describes inventorying components, hardening devices, and detecting threats in hardware infrastructure. The hardening work covers firmware integrity and configuration drift monitoring plus automated patching, and the detection work targets indicators of compromise in hardware, firmware and software. Findings leave through configurable alerts, REST APIs and integrations with security operations tooling.
Coverage breadth is the claim that carries the product, and only the company puts a number on it. SecurityWeek states that Eclypsium covers dozens of hardware vendors and monitors thousands of devices, servers, networking products and GPU clusters. The company's own release puts the same coverage at hundreds of thousands of end-user devices and over 30 million device binaries analyzed. A buyer sizing the deployed base works from the seller's figure.
A second offering is free and public. Eclypsium launched InfraTrust in July 2026 as a knowledge base of hardware and firmware risk, with a monthly digest called InfraTrust Pulse, and describes it as a free resource. The site groups advisories by manufacturer, naming Dell, Cisco, Lenovo, HPE, HP, Fortinet, AMD and NVIDIA. [s2, s12, s18, s17, s16]
Eclypsium sells coverage across manufacturers that each control their own firmware. SecurityWeek states that the platform covers dozens of hardware vendors, and the homepage sets HP, Lenovo, Dell, Apple, Intel, Hewlett Packard Enterprise, Microsoft and AMD beside a sentence about protecting enterprise hardware. The reviewed sources do not establish what those manufacturers cover on each other's hardware, so the breadth claim rests on Eclypsium's own description of its coverage.
One named peer appears in the independent record. A TechCrunch article naming the Series B describes Finite State as a startup providing firmware-based supply chain security for connected devices, and quotes Bulygin arguing that most cybersecurity vendors treat this layer of protection as an afterthought.
The research work shows the position from the other side. A Hacker News article records that Eclypsium evaluated three Palo Alto Networks firewall models and that Palo Alto Networks responded to the findings. Palo Alto Networks appears on Eclypsium's homepage as covered technology and in the research as a subject. That research doubles as a public demonstration of the firmware inspection the platform sells. [s1, s2, s11, s13]
Named customers all appear on Eclypsium's own pages. Executives at DigitalOcean, First Financial Credit Union and Lockheed Martin give attributed statements on the homepage, which is stronger evidence than the customer names the same page carries without comment. No reviewed source outside the company names a customer or sizes the customer base.
Partner motion is documented and mostly vendor-stated. The company names SHI, WWT, GuidePoint Security and Myriad360 as expanded channel partnerships. A SecurityWeek article states that Eclypsium joined the NVIDIA Inception Program, which is the one partnership signal an outside publication carries.
Revenue evidence is absent from the reviewed record. SecurityWeek noted in 2022 that the company claimed significant growth in annual recurring revenue and customer base, and attributed that claim to the company. No reviewed source states a revenue figure, a customer count or a retention measure, so a buyer comparing Eclypsium with a rival works from the company's own account of its scale. [s1, s18, s12, s10]
The founders still hold the top jobs nine years on. Eclypsium's team page lists Yuriy Bulygin as chief executive and founder and Alex Bazhaniuk as chief technology officer and founder. The 2024 Form D names Yury Bulygin as an executive officer and director and Oleksandr Bazhaniuk as a director, and lists the company as a Delaware corporation in Portland, Oregon.
The founding record is in firmware specifically. TechCrunch states that Bulygin spent nearly a decade at Intel leading security threat analysis and directing research on software and hardware vulnerabilities, then became senior director of advanced threat research at McAfee before founding CHIPSEC, an open source platform security assessment framework. Eclypsium's company page dates the founding to 2017 and names Bazhaniuk as the Intel colleague who joined him.
The research output continues and outside publications cover it. A Hacker News article of January 2025 records the Palo Alto Networks firewall evaluation, and the homepage lists later research posts on a Cisco firewall crash, a Fortinet flaw and a Windows recovery bypass. That is a publication habit rather than a single event. [s4, s7, s11, s3, s13, s1]
The attestation on record is four years old and self-announced. Eclypsium stated in June 2022 that Armanino LLP had completed a SOC 2 Type II report against the AICPA Trust Services Criteria. No reviewed source dates a more recent report, so a regulated buyer would have to ask for a current one.
The probed trust surfaces carry a disclosure policy and no attestation listing. The Security and Trust page heads a Trust Center section and then presents a vulnerability disclosure policy inviting researchers to report issues. The trust and security subdomains did not resolve when probed on 2026-09-04.
The compliance material addresses the buyer's obligations. Eclypsium's compliance page states that supply chain security, firmware security and device integrity have become priorities across industry standards and regulations, and maps NIST SP 800-161 and SP 800-193 to what the platform does. Those are the customer's requirements rather than certificates the company holds. [s19, s5, s6]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| NetRise | competes with | Competes for the same buyer of binary and firmware analysis across enterprise device fleets. | |
| Finite State | competes with | A TechCrunch article on Eclypsium's Series B names Finite State as a startup providing firmware-based supply chain security for connected devices. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
Add analyzed competitors to compare them side by side with Eclypsium.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
press the advantage
Eclypsium sells software that its customers run, and the accumulated asset behind it is a corpus of device firmware. The company states that the platform is powered by a database of over 30 million device binaries, and that size is its own figure. Firmware and boot-chain analysis takes years of specialized skill, which the founder acquired over nearly a decade at Intel. A funded rival can hire that skill, so it slows a newcomer without blocking one. The company announced a place on a federal catalog in 2022, and CISA publishes that list as a download rather than naming vendors. CISA takes no new submissions, so that placement is a head start on the company’s own word rather than a lasting lock. The reviewed record does not size what leaving would cost a customer.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Eclypsium delivers software the customer configures and operates against its own fleet. The cloud platform identifies, verifies and fortifies firmware in laptops, servers, network gear and connected devices, and the reviewed record evidences no paid layer that accepts accountability for the outcome. InfraTrust is published free, so it adds reach rather than a paid expertise blend. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | The mechanism is documented and the exit is not sized. Component inventory, firmware baselines and integrations into a customer's alerting and security operations tooling create real friction to revert. The cited record documents no non-portable state, no network effect and no residency constraint, and nothing in it states what a migration would take. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 2/3 | SOC 2 Type II, which Eclypsium announced in 2022, is a commercial bar a determined rival can clear. The company also announced in July 2022 that CISA had added the platform to the Continuous Diagnostics and Mitigation Approved Products List, a catalog CISA reviews against established program criteria and now states is closed to new submissions and publishes as a downloadable document rather than a page naming vendors. That government-mediated placement costs a replacement time and sponsorship, short of the retained liability the top rung describes. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Reading firmware and boot-chain integrity across many manufacturers takes years of specialized expertise. Eclypsium describes verifying the authenticity of every device and component and detecting implants that evade endpoint agents, and TechCrunch records that its founder built the CHIPSEC assessment framework after nearly a decade of hardware security research at Intel. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | The buyers are regulated enterprises and government agencies. The named references include a defense contractor and a credit union, SecurityWeek describes the customers as critical infrastructure organizations and enterprises, and the company announced a placement on a federal purchasing catalog. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Eclypsium is a platform beside the infrastructure rather than infrastructure other applications run on. It monitors devices and feeds findings into a customer's alerting and security operations tooling through configurable alerts and REST APIs. Removing it costs coverage rather than breaking the systems it watches. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 2/3 | The cited record names a retained asset rather than a technique in use. Eclypsium states that the platform is powered by a database of over 30 million device binaries, an accumulated corpus the reviewed record neither publishes nor shows duplicated by a public catalog. The size is the company's own figure, and an advantage of this shape is replicable with time and effort. |
Eclypsium segments by device class first and by industry second. Its platform page groups coverage into user endpoints, servers, network devices and AI hardware, and the site organizes solutions by energy and utilities, financial services, government and telecommunications. The named customers match those segments.
The evidenced buyers sit at the regulated end. Executives at DigitalOcean, First Financial Credit Union and Lockheed Martin appear with attributed statements, and SecurityWeek describes the customers as critical infrastructure organizations and enterprises. American Express, Motorola, KDDI and IPG appear on the same page under a trusted-by heading with no statement attached, and KDDI's open innovation fund also appears in the record as a Series B investor, so those four are marketing references rather than evidenced customers.
The federal segment has its own gate. Eclypsium announced in July 2022 that CISA had added its platform to the Continuous Diagnostics and Mitigation Approved Products List, and CISA describes that list as the authoritative catalog for approved products meeting the program's technical requirements. CISA states that its acquisition office gives federal agencies several ways to purchase approved products.
The engineering claim is about seeing below the operating system. Eclypsium's platform page describes verifying the integrity and authenticity of every device and component, monitoring firmware integrity and configuration drift, and detecting indicators of compromise in hardware, firmware and software. The homepage names the targets as rootkits, bootkits, implants and backdoors that evade endpoint detection.
Breadth across manufacturers is the second claim. SecurityWeek states that the platform covers dozens of hardware vendors, and the homepage sets HP, Lenovo, Dell, Apple, Intel, Hewlett Packard Enterprise, Microsoft and AMD beside a sentence about protecting enterprise hardware. Each of those manufacturers controls the firmware Eclypsium inspects.
AI hardware is the newest surface. The homepage already lists AI hardware among what the platform protects, and SecurityWeek describes further coverage of GPU-based AI servers, network edge systems and enterprise connected devices as planned investment. The same article states that the company joined the NVIDIA Inception Program.
Selling runs through partners as well as direct. Eclypsium names SHI, WWT, GuidePoint Security and Myriad360 as expanded channel partnerships, and a SecurityWeek article states that it joined the NVIDIA Inception Program. The federal path runs through the purchasing catalog the company announced joining in 2022.
Free research is the top of the funnel. A Hacker News article of January 2025 covers Eclypsium's evaluation of three Palo Alto Networks firewall models, which is trade coverage the company earned by publishing. It also launched InfraTrust in July 2026 as a free hardware risk knowledge base with a monthly digest.
The demand proof stays inside the company's own pages. No reviewed source outside Eclypsium names a customer, states a revenue figure or sizes the customer base. SecurityWeek recorded in 2022 that the company claimed significant growth in annual recurring revenue and attributed that claim to the company.
Nothing paid is priced in public. No price, package or tier appears on any Eclypsium page in the reviewed record, and the calls to action lead to a demo request or a guided product tour. That pattern fits a negotiated enterprise sale.
The charging unit is not published either. The company describes its coverage in devices monitored and binaries analyzed, which suggests a per-device or per-fleet basis, and no reviewed source states the unit. A buyer cannot compare cost against a rival from the public material.
One offering is explicitly free. Eclypsium describes InfraTrust as a free resource and publishes it on a separate site, so the paid platform and the free knowledge base are presented to buyers separately.
Delivery is software the customer runs against its own fleet. Eclypsium describes a cloud-based platform that identifies, verifies and fortifies firmware in laptops, servers, network gear and connected devices, and SecurityWeek calls it a SaaS platform. The customer's team configures it and owns the outcomes.
Findings leave through the customer's existing tooling. The platform page describes configurable alerts, REST APIs and integration with security operations tooling, and the homepage describes enriching a customer's existing systems with component-level inventory, vulnerability and threat data. That places Eclypsium beside the security stack rather than inside the network traffic it watches.
Operations span the device lifecycle. The site organizes use cases as onboarding, production and decommissioning, and the company describes operationalizing security throughout the fleet and lifecycle of enterprise devices.
The one attestation on record is four years old and announced by the company. Eclypsium stated in June 2022 that Armanino LLP had completed a SOC 2 Type II report against the AICPA Trust Services Criteria. No reviewed source dates a later report.
The probed trust surfaces carry a disclosure policy and no certificate listing. The Security and Trust page heads a Trust Center section and then presents a vulnerability disclosure policy inviting researchers to report issues. The trust and security subdomains did not resolve when probed on 2026-09-04.
The compliance page speaks to the buyer's obligations. It maps NIST SP 800-161 and SP 800-193 to what the platform does, and states that supply chain security, firmware security and device integrity have become priorities across industry standards and regulations. Those are the customer's requirements rather than certificates Eclypsium holds.
Eclypsium's business sits downstream of hardware it does not build. The homepage sets HP, Lenovo, Dell, Apple, Intel, Hewlett Packard Enterprise, Microsoft and AMD beside a sentence about protecting enterprise hardware, and each of them publishes the firmware the platform inspects. A manufacturer changing its firmware format or attestation would land on Eclypsium first.
The integration surface points at the customer's security stack. The platform page describes REST APIs and integration with security operations tooling, and the homepage describes enriching existing security information and IT service management systems. Those are the systems a buyer would keep after a switch.
One ecosystem relationship runs through research. A Hacker News article records that Eclypsium evaluated three Palo Alto Networks firewall models and that Palo Alto Networks responded to the published findings, and the homepage lists Palo Alto Networks among covered technology. Eclypsium inspects vendors whose products it also covers.
Both founders still hold the top jobs nine years on. Eclypsium's team page lists Yuriy Bulygin as chief executive and founder and Alex Bazhaniuk as chief technology officer and founder. The 2024 Form D names Yury Bulygin as an executive officer and director and Oleksandr Bazhaniuk as a director.
The founding expertise is in firmware specifically. TechCrunch states that Bulygin spent nearly a decade at Intel leading security threat analysis and directing research on software and hardware vulnerabilities, then became senior director of advanced threat research at McAfee before founding CHIPSEC, an open source platform security assessment framework. Eclypsium's company page names Bazhaniuk as the Intel colleague who joined him in 2017.
The board carries an investor director. The 2024 Form D lists Timothy Porter and Alex Doll as directors and John Ewert as an executive officer, and SecurityWeek quotes Alex Doll of Ten Eleven Ventures and notes that he joined the board with the Series B round.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Eclypsium: Platform overview page | official | 2026-09-04 |
| f2 | SecurityWeek: Eclypsium Raises $25 Million for Device Supply Chain Security | press | 2026-09-04 |
| f3 | SEC EDGAR: Eclypsium, Inc. Form D/A primary document | regulatory | 2026-09-04 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.