All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Finite State sells firmware and software analysis to regulated device makers in medical, automotive, and industrial markets that must prove each release is secure to US and EU regulators. Its research record is publicly visible. A CISA advisory credits a Finite State researcher with reporting hard-coded-password flaws in Philips patient monitors, its 2019 Huawei firmware assessment drew press coverage and a Huawei rebuttal, and Omdia profiled the firm in 2024. Commercial proof is thinner. The homepage shows named logos, but the newest named customer reference in the reviewed pages dates to 2021, and the latest disclosed raise is a 2024 growth round. Finite State is most convincing for buyers facing EU Cyber Resilience Act and FDA deadlines, and weakest on recent referenceable wins.
| Description | Product security platform for connected-device manufacturers that builds SBOMs from firmware, binaries, and source code, ranks vulnerabilities by reachability, and assembles audit-ready evidence for regulations such as the EU CRA and FDA premarket cybersecurity requirements. | [f1] |
|---|---|---|
| Founded | 2017 | [f2] |
| HQ | Columbus, Ohio, US | [f3] |
| Subsidiaries | MergeBase (Software composition analysis vendor acquired in June 2024. Its source-code SCA folded into the Finite State Platform, and the MergeBase site remains live.) | |
| Latest funding | Growth round, $20M (March 2024) | [f3] |
| Product | What it does |
|---|---|
| Finite State Platform | Generates SBOMs from firmware, binaries, and source code, runs reachability-based vulnerability analysis, and produces audit-ready compliance evidence through AI-agent workflows. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
The platform inventories software shipped in device firmware and applications, surfaces exploitable vulnerabilities, and gates releases through CI/CD policy checks. Finite State uses AI to defend conventional device software and is mapped to the Cyber Defense Matrix. [f1]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 4/5 | Named buyer (product security teams at device manufacturers) and a regulatory driver corroborated outside vendor copy. SecurityWeek and Industrial Cyber tie demand to supply-chain risk and regulatory pressure on connected devices, and a CISA medical-device advisory shows the firmware-vulnerability problem is real. [s3, s14, s20] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Detailed platform pages and an interactive product tour back the claims, Help Net Security reports the platform ingests 120-plus external data sources, and the firmware engine is independently validated by a CISA-credited vulnerability discovery in Philips devices and the Iotasphere tooling behind the Huawei assessment. No independent head-to-head benchmark exists, which caps the score. [s2, s16, s17, s20] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | FDA premarket cybersecurity requirements and the EU Cyber Resilience Act give device makers compliance deadlines, Industrial Cyber ties the company's growth to that regulatory pressure, and Omdia covers the firmware security category. The enabler is regulatory, and the vendor's February 2026 relaunch frames FDA 524B and the EU CRA as demanding audit-ready traceability for every release. [s6, s14, s19] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Founder Matt Wyckhouse came from Battelle, and the team's firmware research record is now independently corroborated across multiple sources. A CISA medical-device advisory credits a Finite State researcher with Philips vulnerabilities, BankInfoSecurity covered its Huawei firmware assessment, and Omdia profiled the firm in 2024, evidencing sustained in-domain standing beyond a single signal. [s15, s17, s19, s20] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | Johnson Controls, Google, and Hitachi Energy logos and a Schneider Electric executive endorsement exist, but the newest named-customer reference dates to 2021 and the homepage testimonials are anonymous role titles. [s1, s11, s24] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | Funding is verifiable round by round, a $12.5 million Series A in 2020 and a $30 million Series B in 2021 that brought the 2021 total to $49.5 million, followed by a $20 million growth round in 2024, with visible shipping and an acquisition. The 2024 round came in smaller than the Series B and no revenue is disclosed, so efficiency is unconfirmed. [s12, s13, s15] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Product security for connected devices is an established buyer category with a recognizable competitive set and a regulatory budget line, and Omdia places Finite State in firmware security, even as the vendor layers new Product Security OS language on top. [s2, s14, s19] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Binary analysis across many architectures is hard to copy quickly, but application security platforms that already own the SCA budget could bundle binary scanning, and the compliance-evidence moat is asserted mostly in vendor materials. [s1, s2] |
Finite State targets product security teams at connected-device manufacturers in medical, automotive, industrial, and energy markets. These teams must prove to regulators that the software inside shipped devices is secure. The company names FDA Section 524B premarket requirements and the EU Cyber Resilience Act as the rules forcing manufacturers to produce audit-ready evidence for every release.
Independent coverage corroborates the problem at the buyer level. SecurityWeek describes the platform as addressing supply-chain risk and vulnerability visibility for connected devices and embedded systems, and Industrial Cyber attributes the company's growth to escalating regulatory pressure on software supply chains. The 2024 growth round was led by Energy Impact Partners, an investor focused on the energy and industrial markets Finite State sells into.
Finite State quantifies the operational pain as vulnerability noise. The company reports that 40.5% of findings analyzed for reachability since 2024 were confirmed unreachable, a vendor-supplied figure that frames the triage burden its buyers carry. [s3, s6, s13, s14, s1]
Finite State Platform turns shipped software into a system of record. It generates SBOMs from firmware, binaries, and source code, runs reachability analysis to separate exploitable findings from noise, and the June 2024 MergeBase acquisition added source-code software composition analysis to the binary side.
Independent records corroborate the engine's depth more than vendor pages alone could. BankInfoSecurity described the firmware analysis tool, Iotasphere, breaking firmware images into components for static, dynamic, and symbolic analysis, Help Net Security reported the platform ingests 120-plus external data sources, and a CISA medical-device advisory credits a Finite State researcher with vulnerabilities in Philips patient monitors.
The February 2026 release recast the platform as an autonomous Product Security OS powered by AgentOS, with Finite State Copilot and Assurance Studio as named components. The launch language is broad, and the visible release notes from the same period describe incremental triage and policy improvements rather than new autonomous behavior, so a buyer can verify the agent claims only through a demo. [s2, s7, s17, s16, s20, s6, s22]
Finite State competes in product security for connected devices against NetRise, ONEKEY, and Cybellum, which also sell firmware and device software analysis to manufacturers. Its stated differentiation is unifying source, binary, and compliance evidence in one system, a contrast the platform page draws against source-only application security tools and firmware-only scanners. Omdia covered the company in its firmware-security analyst research in 2024, placing it inside that named category.
Application security incumbents are the adjacent threat. Black Duck, Snyk, and other SCA vendors own the source-code side of the same budget and could extend toward binaries. Finite State's counter is depth, because firmware unpacking and reachability analysis across many architectures take longer to replicate than feature-list parity. [s2, s19]
The motion is enterprise sales into regulated industries. The pricing page publishes no prices and routes every path to a demo request or a self-serve product tour, the profile of negotiated deals.
Customer proof is logo-heavy and reference-light. The homepage displays Johnson Controls, Google, Aptiv, Hitachi Energy, Quectel, and Hubbell logos alongside anonymous role-titled testimonials. The most recent named customer reference is Schneider Electric, whose Global Chief Product Security Officer Klaus Jaeckle said in the 2021 Series B announcement that the platform was transforming the company's product security. Schneider also invested through Schneider Electric Ventures in the same round.
Services thicken the motion. A practitioner-led services arm sells compliance and security work alongside the platform, supporting connected-product teams on regulatory pressure, release risk, and exploitability questions. [s4, s1, s11, s5, s24]
Founder and CEO Matt Wyckhouse came from Battelle and has run Finite State since 2017. The team's firmware reverse-engineering skill set traces to its reported backgrounds in the U.S. Intelligence Community, the same expertise the product's binary analysis requires.
That standing is independently corroborated rather than self-asserted. A CISA medical-device advisory credits Finite State researcher Shawn Loveric with vulnerabilities in Philips patient monitors, the company's 2019 Huawei firmware assessment drew coverage from outlets including BankInfoSecurity, and Omdia profiled the firm in 2024. Finite State also hired a head of policy and compliance in early 2026, deepening the regulatory bench its thesis depends on. [s9, s10, s17, s20, s19]
Finite State earns buyer trust through regulatory fluency and the nature of its product. The company hired a head of policy and compliance in February 2026, publishes FDA Section 524B and EU Cyber Resilience Act guidance across its industry pages, and frames its core output as evidence a regulator can audit.
The company's public security materials explain the SOC 2 framework and how the platform helps customers reach SOC 2 and similar compliance, rather than foregrounding the company's own attestation. For a vendor whose product is audit evidence, buyers will weigh its published security posture alongside the regulatory expertise it sells. [s6, s3, s10, s5, s23]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| NetRise | competes with | Sells software supply chain and firmware risk visibility to device makers, overlapping Finite State's binary-analysis core. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| ONEKEY | competes with | European product cybersecurity and compliance platform targeting the same EU CRA-driven device-manufacturer buyer. | |
| Cybellum | competes with | Product security platform for automotive, medical, and industrial manufacturers, matching Finite State's regulated verticals. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Black Duck | adjacent | SCA incumbent that owns the source-code side of the software supply chain budget and could extend into binaries. | |
| Snyk | adjacent | Developer-security platform whose SCA and container scanning cover the application layer Finite State entered through MergeBase. |
Add analyzed competitors to compare them side by side with Finite State.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Firmware unpacking and reachability analysis across many processor architectures took Finite State years to build. A CISA advisory credits a Finite State researcher with reporting real flaws in Philips patient monitors. Its regulated buyers also switch slowly, because their compliance workflows reference its evidence. That depth and that friction are a head start, not a structural lock. Switching costs come from accumulated SBOM history, not network effects. The record shows no federal authorization, and application security incumbents that own the source-code side of the same budget could extend into binaries. Finite State is most defensible while EU and FDA deadlines push buyers toward auditable evidence, and weakest if those incumbents close the firmware gap.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Finite State delivers a platform the customer's team operates through command-line, API, and CI-CD checks, owning the outcomes, and the practitioner-led services arm is purchased separately as an optional attachment rather than an accountability layer built into the delivered product. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Accumulated SBOM history, carried-forward triage judgments, and CI-CD embedding create real friction, but migration cost comes from rebuildable history rather than network effects or data-residency lock-in. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Finite State's product feeds audit-ready evidence into customers' FDA and EU Cyber Resilience Act workflows, a product capability that serves the buyer's own regulatory mandate. The cited pages establish that customer-facing compliance capability, which a determined rival could match. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Firmware unpacking and reachability analysis across many binary architectures require years of program-analysis expertise, publicly traceable through a CISA-credited Philips vulnerability report and the contested 2019 Huawei firmware assessment, that a fast copy cannot replicate. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | Buyers are regulated device manufacturers in medical, automotive, industrial, and energy markets, whose procurement and regulatory review processes slow any replacement. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | The product is a platform with application features, a system of record for product security rather than infrastructure other applications depend on. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The record names no non-public corpus behind the analysis. The MergeBase acquisition and vendor-reported scan activity document capability and usage rather than a proprietary dataset, so the asset is replicable by a funded rival with time. |
Finite State segments by regulation rather than by company size. The site carries industry pages for medical devices, industrial systems, automotive, and government, and each leads with the rule that binds that buyer, FDA Section 524B for medical devices and the EU Cyber Resilience Act for connected products. The persona is the product security engineer who owes regulators and downstream customers evidence about shipped software, not the enterprise CISO.
The newest public proof of demand is named logos rather than named references. The homepage shows Johnson Controls, Google, Aptiv, Hitachi Energy, Quectel, and Hubbell, but the testimonials are anonymous role titles and no customer case study appears among the public pages reviewed, where Schneider Electric figures as both a Series B investor and, through its product security officer, a 2021 customer reference. The company repositioned for the current AI generation in February 2026 and ships continuously, so the pitch is current even where the named-reference proof is thin.
Deal-size signals point at large negotiated contracts. The pricing page publishes no numbers and routes every path to a demo request or a self-serve product tour, the profile of global manufacturers rather than mid-market teams.
The durable capability is binary analysis at unusual breadth. Finite State Platform decomposes firmware and binaries across a wide range of instruction set architectures, merges source and binary SBOMs, and runs reachability analysis that the vendor says confirmed 40.5% of analyzed findings unreachable since 2024. Source-code analysis arrived with the June 2024 MergeBase acquisition.
Independent records support the engine's reach beyond vendor pages. A CISA medical-device advisory credits a Finite State researcher with firmware vulnerabilities in Philips patient monitors, BankInfoSecurity described the Iotasphere tool decomposing firmware images for static, dynamic, and symbolic analysis, and Help Net Security reported the platform ingests 120-plus external data sources.
The AI layer is newly announced, with no independent validation in the reviewed record. AgentOS, Finite State Copilot, and Assurance Studio were announced as named components of the February 2026 autonomous Product Security OS launch, described as in private preview with early-access participation open. Release notes from the same period describe VEX carry-forward fixes, policy accuracy, and API behavior rather than autonomous behavior, so the public materials support the analysis engine more strongly than the agent claims.
The motion is enterprise and sales-assisted, with demo requests gating every path and a practitioner-led services arm selling compliance work alongside the platform. The public pages reviewed show no marketplace listing or reseller program, so the vendor reaches buyers through its own pipeline.
Founder visibility is high for a company of this age. Matt Wyckhouse fronts conference panels on connected-device security, and announced executive hires built out security, engineering, and compliance leadership through early 2026, including a head of policy and compliance. At this stage the hired team is appropriate and the founder acting as technical evangelist is a strength. The missing piece is referenceable customers speaking alongside him.
A self-serve product tour lowers the evaluation barrier. The walkthrough on the homepage lets a prospect handle the product before sales contact, and the documentation site is public rather than gated.
Finite State publishes no prices, the standard posture for negotiated enterprise deals. The pricing page exists mainly to route prospects to a demo request or a self-serve product tour rather than to quote a number.
The charging unit is not disclosed publicly, but a per-product and per-scan structure would match how a device maker counts the problem, per product line shipped. The vendor publishes no comparative price framing, leaving the value defense implicit in the binary-analysis depth.
Delivery centers on programmatic integration. Release notes document command-line behavior, public API endpoints for scans and findings, and SBOM export fixes, so integration into customer pipelines is real rather than aspirational. Policy checks gate releases inside those pipelines, which embeds the product where the buyer's release decisions happen.
Operational maturity shows in the changelog cadence. Recent entries cover VEX triage reliability across rescans, license policy accuracy, scanner auto-update, and upload-experience fixes, the texture of a product running in production at customers rather than a demo platform.
Finite State earns buyer trust through regulatory fluency backed by its own attestation. A head of policy and compliance joined in February 2026, the industry pages walk through FDA Section 524B and EU Cyber Resilience Act obligations, and the product's core output is evidence built for regulator review.
The company's SOC 2 explainer states that Finite State has achieved SOC 2 Type 2 certification, though the public materials spend more space on how the platform helps customers reach SOC 2 than on the company's own posture. For a vendor whose product is audit evidence, buyers will weigh that attestation alongside the regulatory expertise it sells.
Finite State positions as a platform and now as an operating system, but the visible ecosystem leans on its own pipeline. The platform page emphasizes unified internal workflows, from design review to shipped binary to evidence pack, and notes out-of-the-box integrations, though no browsable third-party marketplace or partner directory appeared on the public pages.
Channel reach is the structural weakness. If an incumbent copied the feature list, Finite State would keep its binary-analysis depth and accumulated unpacking knowledge, but buyers encounter the product through the vendor's own marketing and a self-serve tour rather than through channels an incumbent could not buy.
The system-of-record strategy is the platform play that could work. SBOM history, carried-forward triage judgments, and compliance evidence accumulate inside the platform, and every release a customer ships deepens the archive a regulator may later audit. That accumulation raises switching costs more than integration breadth does.
The founder's background is the team's core asset. Matt Wyckhouse founded the company in 2017 after a cyber research career at Battelle, where he was founding CTO of its Cyber Innovations Unit, applied-research pedigree that supplies the program-analysis skills firmware reverse engineering requires.
The research record is externally documented rather than self-asserted. A CISA medical-device advisory credits Finite State researcher Shawn Loveric with reporting vulnerabilities in Philips patient monitors, the 2019 Huawei firmware assessment drew coverage from outlets including BankInfoSecurity, and Omdia profiled the firm in 2024. The hiring pattern through early 2026 added security, engineering, and compliance leadership, including a head of policy and compliance that matches the regulatory thesis.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Finite State platform page | official | 2026-06-11 |
| f2 | Finite State Raises $30M Series B (Business Wire) | press | 2026-06-11 |
| f3 | Finite State Raises $20 Million to Grow Software Supply Chain Security Business (SecurityWeek) | press | 2026-06-11 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Finite State homepage “Since 2024, 40.5% of findings analyzed for reachability were confirmed unreachable.” | official | 2026-06-29 |
| s2 | Finite State platform page “Finite State unifies firmware, binaries, source code, and compliance evidence into autonomous, review-gated workflows that help engineering teams move at the speed of AI.” | official | 2026-06-29 |
| s3 | Finite State medical devices industry page “Finite State is the Product Security Automation Platform for medical devices, uniting firmware, binaries, and source code into a single, ground-truth system of record.” | official | 2026-06-29 |
| s4 | Finite State pricing page “Flexible Plans for Every Stage of Product Security” | official | 2026-06-29 |
| s5 | Finite State services page “Practitioner-led support for connected product teams facing regulatory pressure, release risk, customer assurance requests, and exploitability questions.” | official | 2026-06-29 |
| s6 | Finite State autonomous Product Security OS launch announcement “As regulations like FDA 524B and the EU Cyber Resilience Act (CRA) demand audit-ready traceability for every release” | official | 2026-06-29 |
| s7 | Finite State MergeBase acquisition announcement “announced today the acquisition of MergeBase, a leading provider of software supply chain security solutions.” | official | 2026-06-29 |
| s8 | Finite State $20M growth round announcement “today announced that it raised a $20 million growth round led by Energy Impact Partners (EIP).” | official | 2026-06-29 |
| s9 | The Present and Future of Finite State (company blog) “we've secured $30 million in our Series B funding round, allowing us to grow our team and continue to fulfill our mission of protecting the devices that power our modern lives.” | official | 2026-06-29 |
| s10 | Finite State press and news index “Finite State Appoints Doc McConnell as Head of Policy and Compliance to Strengthen Regulatory Leadership” | official | 2026-06-29 |
| s11 | Finite State Raises $30M Series B (Business Wire) “Finite State's platform is transforming our product security, said Klaus Jaeckle, Global Chief Product Security Officer at Schneider Electric.” | press | 2026-06-29 |
| s12 | Finite State Raises $30 Million in Series B Funding (SecurityWeek) “Connected device security provider Finite State on Monday announced that it has raised $30 million in Series B funding. To date, the company has raised $49.5 million.” | press | 2026-06-29 |
| s13 | Finite State Raises $20 Million to Grow Software Supply Chain Security Business (SecurityWeek) “Software risk management firm Finite State announced on Friday that it has raised $20 million in growth funding in a round led by Energy Impact Partners (EIP).” | press | 2026-06-29 |
| s14 | Finite State raises $20 million growth round (Industrial Cyber) “Finite State's robust growth trajectory comes amid escalating cyber threats and regulatory pressures driving organizations to prioritize software supply chain security.” | press | 2026-06-29 |
| s15 | Finite State lands $30M Series B to help uncover security flaws in device firmware (TechCrunch) “comes a year after Finite State raised a $12.5 million Series A round. It brings the total amount of funds raised by the firm to just shy of $50 million.” | press | 2026-06-29 |
| s16 | Finite State releases Next Gen Platform for software supply chain security (Help Net Security) “Finite State has released its Next Generation Platform featuring extended SBOM management with the ability to ingest and aggregate 120+ external data sources.” | press | 2026-06-29 |
| s17 | Report: Huawei's Firmware Riddled With Problems (BankInfoSecurity) “For its analysis, Finite State used a tool it developed called Iotasphere. The company says the tool contains dozens of unpackers, which can break down monolithic binary firmware images into components for analysis.” | press | 2026-06-29 |
| s18 | Huawei PSIRT: Technical Analysis Report Regarding Finite State Supply Chain Assessment “Binary vulnerability scanning tools are generally used for auxiliary analysis because their error rate can reach up to over 90%. Thus, Finite State's conclusions are drawn in a hasty manner and are inaccurate.” | other | 2026-06-29 |
| s19 | Omdia On the Radar: Finite State tackles firmware security and risks (Rik Turner, Nov 2024) “Finite State's technology is designed to automate product security for internet-connected devices across the software supply chain lifecycle.” | research | 2026-06-29 |
| s20 | CISA ICS Medical Advisory ICSMA-19-255-01: Philips IntelliVue WLAN “Shawn Loveric of Finite State, Inc., reported these vulnerabilities to Philips.” | regulatory | 2026-06-29 |
| s21 | Finite State Acquires MergeBase to Form a Powerhouse in Application Security (PRWeb) “Leveraging the combined power of Finite State's advanced binary analysis and MergeBase's deep source code analysis, it delivers unmatched software supply chain visibility and risk protection throughout the SDLC.” | press | 2026-06-29 |
| s22 | Finite State documentation changelog “This release focuses on vulnerability triage reliability and policy accuracy. VEX carry-forward now preserves user judgements across component name casing differences and patch-version bumps.” | official | 2026-06-29 |
| s23 | Finite State SOC 2 compliance explainer “Finite State offers a comprehensive solution to support companies trying to gain SOC2 certifications by helping to improve their software supply chain security and monitor for vulnerabilities.” | official | 2026-06-29 |
| s24 | Finite State homepage customer logo wall “Johnson Controls logo. Google logo. Aptiv logo. Hitachi Energy logo. Quectel logo. Hubbell logo.” | official | 2026-06-29 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Finite State homepage “Since 2024, 40.5% of findings analyzed for reachability were confirmed unreachable.” | official | 2026-06-29 |
| s2 | Finite State platform page “Finite State unifies firmware, binaries, source code, and compliance evidence into autonomous, review-gated workflows that help engineering teams move at the speed of AI.” | official | 2026-06-29 |
| s3 | Finite State medical devices industry page “Finite State is the Product Security Automation Platform for medical devices, uniting firmware, binaries, and source code into a single, ground-truth system of record.” | official | 2026-06-29 |
| s4 | Finite State pricing page “Flexible Plans for Every Stage of Product Security” | official | 2026-06-29 |
| s5 | Finite State services page “Practitioner-led support for connected product teams facing regulatory pressure, release risk, customer assurance requests, and exploitability questions.” | official | 2026-06-29 |
| s6 | Finite State autonomous Product Security OS launch announcement “As regulations like FDA 524B and the EU Cyber Resilience Act (CRA) demand audit-ready traceability for every release” | official | 2026-06-29 |
| s7 | Finite State MergeBase acquisition announcement “announced today the acquisition of MergeBase, a leading provider of software supply chain security solutions.” | official | 2026-06-29 |
| s8 | Finite State $20M growth round announcement “today announced that it raised a $20 million growth round led by Energy Impact Partners (EIP).” | official | 2026-06-29 |
| s9 | The Present and Future of Finite State (company blog) “we've secured $30 million in our Series B funding round, allowing us to grow our team and continue to fulfill our mission of protecting the devices that power our modern lives.” | official | 2026-06-29 |
| s10 | Finite State press and news index “Finite State Appoints Doc McConnell as Head of Policy and Compliance to Strengthen Regulatory Leadership” | official | 2026-06-29 |
| s11 | Finite State Raises $30M Series B (Business Wire) “Finite State's platform is transforming our product security, said Klaus Jaeckle, Global Chief Product Security Officer at Schneider Electric.” | press | 2026-06-29 |
| s12 | Finite State Raises $30 Million in Series B Funding (SecurityWeek) “Connected device security provider Finite State on Monday announced that it has raised $30 million in Series B funding. To date, the company has raised $49.5 million.” | press | 2026-06-29 |
| s13 | Finite State Raises $20 Million to Grow Software Supply Chain Security Business (SecurityWeek) “Software risk management firm Finite State announced on Friday that it has raised $20 million in growth funding in a round led by Energy Impact Partners (EIP).” | press | 2026-06-29 |
| s14 | Finite State raises $20 million growth round (Industrial Cyber) “Finite State's robust growth trajectory comes amid escalating cyber threats and regulatory pressures driving organizations to prioritize software supply chain security.” | press | 2026-06-29 |
| s15 | Finite State lands $30M Series B to help uncover security flaws in device firmware (TechCrunch) “comes a year after Finite State raised a $12.5 million Series A round. It brings the total amount of funds raised by the firm to just shy of $50 million.” | press | 2026-06-29 |
| s16 | Finite State releases Next Gen Platform for software supply chain security (Help Net Security) “Finite State has released its Next Generation Platform featuring extended SBOM management with the ability to ingest and aggregate 120+ external data sources.” | press | 2026-06-29 |
| s17 | Report: Huawei's Firmware Riddled With Problems (BankInfoSecurity) “For its analysis, Finite State used a tool it developed called Iotasphere. The company says the tool contains dozens of unpackers, which can break down monolithic binary firmware images into components for analysis.” | press | 2026-06-29 |
| s18 | Huawei PSIRT: Technical Analysis Report Regarding Finite State Supply Chain Assessment “Binary vulnerability scanning tools are generally used for auxiliary analysis because their error rate can reach up to over 90%. Thus, Finite State's conclusions are drawn in a hasty manner and are inaccurate.” | other | 2026-06-29 |
| s19 | Omdia On the Radar: Finite State tackles firmware security and risks (Rik Turner, Nov 2024) “Finite State's technology is designed to automate product security for internet-connected devices across the software supply chain lifecycle.” | research | 2026-06-29 |
| s20 | CISA ICS Medical Advisory ICSMA-19-255-01: Philips IntelliVue WLAN “Shawn Loveric of Finite State, Inc., reported these vulnerabilities to Philips.” | regulatory | 2026-06-29 |
| s21 | Finite State Acquires MergeBase to Form a Powerhouse in Application Security (PRWeb) “Leveraging the combined power of Finite State's advanced binary analysis and MergeBase's deep source code analysis, it delivers unmatched software supply chain visibility and risk protection throughout the SDLC.” | press | 2026-06-29 |
| s22 | Finite State documentation changelog “This release focuses on vulnerability triage reliability and policy accuracy. VEX carry-forward now preserves user judgements across component name casing differences and patch-version bumps.” | official | 2026-06-29 |
| s23 | Finite State homepage customer logo wall “Johnson Controls logo. Google logo. Aptiv logo. Hitachi Energy logo. Quectel logo. Hubbell logo.” | official | 2026-06-29 |
| s24 | Finite State SOC 2 compliance explainer “Finite State offers a comprehensive solution to support companies trying to gain SOC2 certifications by helping to improve their software supply chain security and monitor for vulnerabilities.” | official | 2026-06-29 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.