All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Finite State sells firmware and software analysis to regulated device makers in medical, automotive, and industrial markets that must prove each release is secure to US and EU regulators. Its research record is publicly visible. A CISA advisory credits a Finite State researcher with reporting hard-coded-password flaws in Philips patient monitors, its 2019 Huawei firmware assessment drew press coverage and a Huawei rebuttal, and Omdia profiled the firm in 2024. Commercial proof is thinner. The homepage shows named logos, but the newest named customer reference in the reviewed pages dates to 2021, and the latest disclosed raise is a 2024 growth round. Finite State is most convincing for buyers facing EU Cyber Resilience Act and FDA deadlines, and weakest on recent referenceable wins.
| Description | Product security platform for connected-device manufacturers that builds SBOMs from firmware, binaries, and source code, ranks vulnerabilities by reachability, and assembles audit-ready evidence for regulations such as the EU CRA and FDA premarket cybersecurity requirements. | [f1] |
|---|---|---|
| Founded | 2017 | [f2] |
| HQ | Columbus, Ohio, US | [f3] |
| Subsidiaries | MergeBase (Software composition analysis vendor acquired in June 2024. Its source-code SCA folded into the Finite State Platform, and the MergeBase site remains live.) | |
| Latest funding | Growth round, $20M (March 2024) | [f3] |
| Product | What it does |
|---|---|
| Finite State Platform | Generates SBOMs from firmware, binaries, and source code, runs reachability-based vulnerability analysis, and produces audit-ready compliance evidence through AI-agent workflows. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
The platform inventories software shipped in device firmware and applications, surfaces exploitable vulnerabilities, and gates releases through CI/CD policy checks. Finite State uses AI to defend conventional device software and is mapped to the Cyber Defense Matrix. [f1]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score |
|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 4/5 |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs, demos, and third-party validation. | 4/5 |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
| Dimension | Score |
|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Finite State platform page | official | 2026-06-11 |
| f2 | Finite State Raises $30M Series B (Business Wire) | press | 2026-06-11 |
| f3 | Finite State Raises $20 Million to Grow Software Supply Chain Security Business (SecurityWeek) | press | 2026-06-11 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Finite State homepage “Since 2024, 40.5% of findings analyzed for reachability were confirmed unreachable.” | official | 2026-06-29 |
| s2 | Finite State platform page “Finite State unifies firmware, binaries, source code, and compliance evidence into autonomous, review-gated workflows that help engineering teams move at the speed of AI.” | official | 2026-06-29 |
| s3 | Finite State medical devices industry page “Finite State is the Product Security Automation Platform for medical devices, uniting firmware, binaries, and source code into a single, ground-truth system of record.” | official | 2026-06-29 |
| s4 | Finite State pricing page “Flexible Plans for Every Stage of Product Security” | official | 2026-06-29 |
| s5 | Finite State services page “Practitioner-led support for connected product teams facing regulatory pressure, release risk, customer assurance requests, and exploitability questions.” | official | 2026-06-29 |
| s6 | Finite State autonomous Product Security OS launch announcement “As regulations like FDA 524B and the EU Cyber Resilience Act (CRA) demand audit-ready traceability for every release” | official | 2026-06-29 |
| s7 | Finite State MergeBase acquisition announcement “announced today the acquisition of MergeBase, a leading provider of software supply chain security solutions.” | official | 2026-06-29 |
| s8 | Finite State $20M growth round announcement “today announced that it raised a $20 million growth round led by Energy Impact Partners (EIP).” | official | 2026-06-29 |
| s9 | The Present and Future of Finite State (company blog) “we've secured $30 million in our Series B funding round, allowing us to grow our team and continue to fulfill our mission of protecting the devices that power our modern lives.” | official | 2026-06-29 |
| s10 | Finite State press and news index “Finite State Appoints Doc McConnell as Head of Policy and Compliance to Strengthen Regulatory Leadership” | official | 2026-06-29 |
| s11 | Finite State Raises $30M Series B (Business Wire) “Finite State's platform is transforming our product security, said Klaus Jaeckle, Global Chief Product Security Officer at Schneider Electric.” | press | 2026-06-29 |
| s12 | Finite State Raises $30 Million in Series B Funding (SecurityWeek) “Connected device security provider Finite State on Monday announced that it has raised $30 million in Series B funding. To date, the company has raised $49.5 million.” | press | 2026-06-29 |
| s13 | Finite State Raises $20 Million to Grow Software Supply Chain Security Business (SecurityWeek) “Software risk management firm Finite State announced on Friday that it has raised $20 million in growth funding in a round led by Energy Impact Partners (EIP).” | press | 2026-06-29 |
| s14 | Finite State raises $20 million growth round (Industrial Cyber) “Finite State's robust growth trajectory comes amid escalating cyber threats and regulatory pressures driving organizations to prioritize software supply chain security.” | press | 2026-06-29 |
| s15 | Finite State lands $30M Series B to help uncover security flaws in device firmware (TechCrunch) “comes a year after Finite State raised a $12.5 million Series A round. It brings the total amount of funds raised by the firm to just shy of $50 million.” | press | 2026-06-29 |
| s16 | Finite State releases Next Gen Platform for software supply chain security (Help Net Security) “Finite State has released its Next Generation Platform featuring extended SBOM management with the ability to ingest and aggregate 120+ external data sources.” | press | 2026-06-29 |
| s17 | Report: Huawei's Firmware Riddled With Problems (BankInfoSecurity) “For its analysis, Finite State used a tool it developed called Iotasphere. The company says the tool contains dozens of unpackers, which can break down monolithic binary firmware images into components for analysis.” | press | 2026-06-29 |
| s18 | Huawei PSIRT: Technical Analysis Report Regarding Finite State Supply Chain Assessment “Binary vulnerability scanning tools are generally used for auxiliary analysis because their error rate can reach up to over 90%. Thus, Finite State's conclusions are drawn in a hasty manner and are inaccurate.” | other | 2026-06-29 |
| s19 | Omdia On the Radar: Finite State tackles firmware security and risks (Rik Turner, Nov 2024) “Finite State's technology is designed to automate product security for internet-connected devices across the software supply chain lifecycle.” | research | 2026-06-29 |
| s20 | CISA ICS Medical Advisory ICSMA-19-255-01: Philips IntelliVue WLAN “Shawn Loveric of Finite State, Inc., reported these vulnerabilities to Philips.” | regulatory | 2026-06-29 |
| s21 | Finite State Acquires MergeBase to Form a Powerhouse in Application Security (PRWeb) “Leveraging the combined power of Finite State's advanced binary analysis and MergeBase's deep source code analysis, it delivers unmatched software supply chain visibility and risk protection throughout the SDLC.” | press | 2026-06-29 |
| s22 | Finite State documentation changelog “This release focuses on vulnerability triage reliability and policy accuracy. VEX carry-forward now preserves user judgements across component name casing differences and patch-version bumps.” | official | 2026-06-29 |
| s23 | Finite State SOC 2 compliance explainer “Finite State offers a comprehensive solution to support companies trying to gain SOC2 certifications by helping to improve their software supply chain security and monitor for vulnerabilities.” | official | 2026-06-29 |
| s24 | Finite State homepage customer logo wall “Johnson Controls logo. Google logo. Aptiv logo. Hitachi Energy logo. Quectel logo. Hubbell logo.” | official | 2026-06-29 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Finite State homepage “Since 2024, 40.5% of findings analyzed for reachability were confirmed unreachable.” | official | 2026-06-29 |
| s2 | Finite State platform page “Finite State unifies firmware, binaries, source code, and compliance evidence into autonomous, review-gated workflows that help engineering teams move at the speed of AI.” | official | 2026-06-29 |
| s3 | Finite State medical devices industry page “Finite State is the Product Security Automation Platform for medical devices, uniting firmware, binaries, and source code into a single, ground-truth system of record.” | official | 2026-06-29 |
| s4 | Finite State pricing page “Flexible Plans for Every Stage of Product Security” | official | 2026-06-29 |
| s5 | Finite State services page “Practitioner-led support for connected product teams facing regulatory pressure, release risk, customer assurance requests, and exploitability questions.” | official | 2026-06-29 |
| s6 | Finite State autonomous Product Security OS launch announcement “As regulations like FDA 524B and the EU Cyber Resilience Act (CRA) demand audit-ready traceability for every release” | official | 2026-06-29 |
| s7 | Finite State MergeBase acquisition announcement “announced today the acquisition of MergeBase, a leading provider of software supply chain security solutions.” | official | 2026-06-29 |
| s8 | Finite State $20M growth round announcement “today announced that it raised a $20 million growth round led by Energy Impact Partners (EIP).” | official | 2026-06-29 |
| s9 | The Present and Future of Finite State (company blog) “we've secured $30 million in our Series B funding round, allowing us to grow our team and continue to fulfill our mission of protecting the devices that power our modern lives.” | official | 2026-06-29 |
| s10 | Finite State press and news index “Finite State Appoints Doc McConnell as Head of Policy and Compliance to Strengthen Regulatory Leadership” | official | 2026-06-29 |
| s11 | Finite State Raises $30M Series B (Business Wire) “Finite State's platform is transforming our product security, said Klaus Jaeckle, Global Chief Product Security Officer at Schneider Electric.” | press | 2026-06-29 |
| s12 | Finite State Raises $30 Million in Series B Funding (SecurityWeek) “Connected device security provider Finite State on Monday announced that it has raised $30 million in Series B funding. To date, the company has raised $49.5 million.” | press | 2026-06-29 |
| s13 | Finite State Raises $20 Million to Grow Software Supply Chain Security Business (SecurityWeek) “Software risk management firm Finite State announced on Friday that it has raised $20 million in growth funding in a round led by Energy Impact Partners (EIP).” | press | 2026-06-29 |
| s14 | Finite State raises $20 million growth round (Industrial Cyber) “Finite State's robust growth trajectory comes amid escalating cyber threats and regulatory pressures driving organizations to prioritize software supply chain security.” | press | 2026-06-29 |
| s15 | Finite State lands $30M Series B to help uncover security flaws in device firmware (TechCrunch) “comes a year after Finite State raised a $12.5 million Series A round. It brings the total amount of funds raised by the firm to just shy of $50 million.” | press | 2026-06-29 |
| s16 | Finite State releases Next Gen Platform for software supply chain security (Help Net Security) “Finite State has released its Next Generation Platform featuring extended SBOM management with the ability to ingest and aggregate 120+ external data sources.” | press | 2026-06-29 |
| s17 | Report: Huawei's Firmware Riddled With Problems (BankInfoSecurity) “For its analysis, Finite State used a tool it developed called Iotasphere. The company says the tool contains dozens of unpackers, which can break down monolithic binary firmware images into components for analysis.” | press | 2026-06-29 |
| s18 | Huawei PSIRT: Technical Analysis Report Regarding Finite State Supply Chain Assessment “Binary vulnerability scanning tools are generally used for auxiliary analysis because their error rate can reach up to over 90%. Thus, Finite State's conclusions are drawn in a hasty manner and are inaccurate.” | other | 2026-06-29 |
| s19 | Omdia On the Radar: Finite State tackles firmware security and risks (Rik Turner, Nov 2024) “Finite State's technology is designed to automate product security for internet-connected devices across the software supply chain lifecycle.” | research | 2026-06-29 |
| s20 | CISA ICS Medical Advisory ICSMA-19-255-01: Philips IntelliVue WLAN “Shawn Loveric of Finite State, Inc., reported these vulnerabilities to Philips.” | regulatory | 2026-06-29 |
| s21 | Finite State Acquires MergeBase to Form a Powerhouse in Application Security (PRWeb) “Leveraging the combined power of Finite State's advanced binary analysis and MergeBase's deep source code analysis, it delivers unmatched software supply chain visibility and risk protection throughout the SDLC.” | press | 2026-06-29 |
| s22 | Finite State documentation changelog “This release focuses on vulnerability triage reliability and policy accuracy. VEX carry-forward now preserves user judgements across component name casing differences and patch-version bumps.” | official | 2026-06-29 |
| s23 | Finite State homepage customer logo wall “Johnson Controls logo. Google logo. Aptiv logo. Hitachi Energy logo. Quectel logo. Hubbell logo.” | official | 2026-06-29 |
| s24 | Finite State SOC 2 compliance explainer “Finite State offers a comprehensive solution to support companies trying to gain SOC2 certifications by helping to improve their software supply chain security and monitor for vulnerabilities.” | official | 2026-06-29 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Do not republish its content or share access without the operator's permission.