All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Inc. ranked NetRise No. 148 on its 2026 Inc. 5000 and credited 2,118% growth over three years. The company analyzes compiled binaries and firmware to show software buyers and builders what is actually inside the code they ship or purchase. Its published customer proof is thinner than that growth implies, with two named references on NetRise’s own pages and no customer named by an outside source in the reviewed record. CISA added the platform to the Continuous Diagnostics and Mitigation Program’s Approved Product List in 2023 and now states the list is not accepting new submissions for the indefinite future. Accenture announced in June 2026 that it would buy NetRise outright and run it under Dragos, with the deal expected to close in August or September, pending regulatory approvals.
| Description | Software supply chain security company whose platform analyzes compiled code and firmware to build a software asset inventory, validate software bills of materials, and rank the vulnerabilities in components that actually execute. | [f1] |
|---|---|---|
| Founded | 2020 | [f2] |
| HQ | Austin, Texas, United States | [f3] |
| Funding | $24.8M total | [f4] |
| Latest funding | $10M Series A, April 2025, led by DNX Ventures | [f4] |
| Product | What it does |
|---|---|
| NetRise Platform | Analyzes compiled binaries and firmware to produce a software inventory, validate SBOMs, and rank vulnerabilities by whether the affected component runs at startup. |
| NetRise Provenance | Maps open-source components to their source repositories, maintainers and organizations, models downstream blast radius, and enforces package policy at install time. |
| NetRise ZeroLens | Decompiles compiled binaries and maps risky code patterns to CWEs, exporting findings to Binary Ninja and Ghidra for follow-up analysis. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
The NetRise Platform maintains an inventory of the software actually executing across an environment, and NetRise Provenance scopes how far risk reaches when a component is compromised. These products are mapped to the Cyber Defense Matrix. [f5]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 4/5 | NetRise names its audience as software builders and software buyers and addresses federal agencies, and the obligation behind the pain is primary-sourced. CISA's Binding Operational Directive 26-04 of 10 June 2026 compels federal civilian agencies to prioritize high-risk vulnerabilities for timely action, and three non-vendor sources place the same problem, Omdia's market study, a CyberScoop article on scrutiny of embedded vulnerabilities, and a procurement guide advising buyers on the same job. [s1, s8, s20, s11, s14, s19] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Product pages describe binary-derived inventory, startup-reachability ranking, and decompilation to intermediate languages with CWE mapping and Binary Ninja and Ghidra export. A patent office examined and granted a US patent on the component-identification method, and CISA reviews the platform against Approved Products List criteria to validate the vendor's claim, though neither measures detection quality and no independent benchmark appears in the reviewed sources. [s3, s5, s15, s17, s16] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | CISA's Binding Operational Directive 26-04 of 10 June 2026 compels federal civilian agencies to prioritize high-risk vulnerabilities for timely action, Inc.'s 2026 ranking records 2,118% three-year growth, which is money customers actually spent, and a CyberScoop article of June 2026 states that firmware visibility has drawn increased scrutiny, all dated within the last twelve months. Omdia's May 2025 market study frames the category, and the enabler is regulatory, dated to 2026. [s20, s12, s11, s14] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Thomas Pace's Cylance executive tenure and Michael Scott's named inventorship on the company's patent are verifiable in-domain experience, and SecurityWeek adds Pace's Marine background. No founder exit, sustained publication record, or independent recognition of the founding team appears in the reviewed sources, and the CISA and NTIA record plus Stuart McClure's Cylance record named on the company page belong to an adviser and a board member. [s2, s10, s15] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Inc.'s No. 148 ranking with 2,118% three-year growth is independent corroboration of customers spending, and a government-contracting outlet dated the Approved Products List placement to September 2023. Two named references, a Carahsoft channel and an Asc3nd-launched federal managed offering show partners reselling. Both named references are vendor-hosted, which holds the score below the top rung. [s12, s16, s7, s5, s8] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | NetRise raised $24.8 million in total, most recently a $10 million Series A in April 2025, and reached Inc.'s 2,118% three-year growth mark with 40 employees recorded for 2025, which is proportional to a company selling to enterprises and shipping product. Neither the growth base nor any revenue, margin, or per-company acquisition figure is disclosed, so efficiency itself stays unconfirmed. [s13, s12, s2, s10] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | An independent procurement guide lists Netrise in the vendor set a buyer would consider for IoT vulnerability management, alongside Cybellum, Finite State, JFrog, OneKey and Synopsys Black Duck, and Omdia published a Market Radar comparing vendor capabilities in the firmware and software supply chain security market. A third party places NetRise inside that set without the vendor's framing, though the guide states that mentioning a provider is not a recommendation, and no analyst placement is independently confirmed in the reviewed record. [s19, s14] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | The federal Approved Products List placement adds procurement friction, and the binary analysis is specialized engineering rather than a feature toggle. A procurement guide names nine other vendors buyers may consider for the same job, and the reviewed record shows no accumulating data asset that a platform vendor could not eventually match. [s19, s16, s17, s3] |
Purchased software and devices arrive as compiled artifacts, so the parts list a supplier hands over is a claim rather than a measurement. NetRise reads the binary instead. Its platform assesses the results of a software build, identifies the components in the binary image, and finds risk beyond published CVEs and CWEs, which lets a buyer validate a supplier's software bill of materials against the code that was actually shipped.
The nearest federal obligation is dated and compulsory, though it does not name this product class. CISA's Binding Operational Directive 26-04 of 10 June 2026 is a compulsory direction to federal civilian agencies, and it prioritizes high-risk vulnerabilities for timely action while deferring low-risk ones. NetRise's federal announcement of July 2026 ties its offering to that directive and to a post-quantum cryptography executive order it dates to 22 June 2026, arguing that prioritizing by risk depends on knowing what code is already deployed.
The pain is visible outside vendor copy. Omdia published a Market Radar on the firmware and software supply chain security market in May 2025, and a CyberScoop article states that firmware-level visibility and software supply chain security have drawn increased scrutiny since high-profile incidents revealed how deeply embedded vulnerabilities can propagate through industrial device ecosystems. [s3, s20, s8, s11]
NetRise starts from the compiled artifact rather than the source repository. The NetRise Platform validates a software bill of materials with a binary-derived inventory of the code that actually executes, and it ranks vulnerabilities by whether the affected component runs at startup. Its platform page frames that as a way to inspect purchased software and devices without relying on vendor self-attestations or delayed disclosures.
Two further products extend the analysis in opposite directions. NetRise Provenance reveals where open-source components originate, who maintains them and how healthy their repositories are, and it models dependency and reverse-dependency relationships so a team can see how far a compromise reaches across libraries, repositories, products and vendors. NetRise ZeroLens translates compiled binaries into intermediate languages, maps risky code patterns to CWEs, and hands findings to Binary Ninja or Ghidra for a reverse engineer to take further.
A patent office examined one piece of the method. US patent 12,175,241, machine learning-based universal software component identification, was granted in December 2024 to Netrise Inc and names co-founder Michael Scott and Yaroslav Oliinyk as inventors. No independent benchmark of detection quality against competing binary analyzers appears in the reviewed sources, so a buyer weighing NetRise against Cybellum or Finite State has vendor descriptions rather than measured results. [s3, s4, s5, s15, s9, s19]
Buyers can place NetRise without vendor coaching. A procurement guide on purchasing IoT vulnerability management solutions lists Netrise among the vendors that might suit, alongside Aqua Security, aDolus, Cybellum, Finite State, Firmalyzer, JFrog, Moabi, OneKey and Synopsys Black Duck. Omdia published a Market Radar comparing vendor capabilities in the firmware and software supply chain security market in May 2025, so the category has an analyst frame as well as a procurement one.
The claim NetRise makes against that set is about where the analysis starts. Its platform page argues for inspecting purchased software and devices directly rather than trusting a supplier's self-attestation.
NetRise is exposed on that same list. It names JFrog and Synopsys Black Duck among the vendors a buyer might consider for this purchase. A rival that wanted binary analysis would have to build the engineering itself. [s19, s14, s3]
The independent traction signal is a growth ranking. Inc. placed NetRise at No. 148 on its 2026 Inc. 5000 and credited 2,118% growth over three years, at a company size Inc. records as 11 to 50 people.
Named-reference proof is thinner and vendor-hosted. Two references appear on NetRise's own pages, Marcos Marrero, chief information security officer at H.I.G. Capital, and Garrett Schumacher, business unit director for product security at Velentium Medical. No source outside NetRise names a customer in the reviewed record, so a buyer checking references has little independent material to work from.
Outside evidence is strongest in the federal channel. CISA added the platform to the Continuous Diagnostics and Mitigation Program's Approved Product List, which a government-contracting outlet dated to September 2023, NetRise's government page names Carahsoft as its partner for public-sector buyers, and in July 2026 the company launched a partner-led managed offering for the federal market with Asc3nd Technologies Group as launch partner.
Accenture announced on 18 June 2026 that it would acquire NetRise outright, alongside runZero and a majority stake in Dragos, at a combined enterprise value of roughly $4.175 billion, with NetRise to operate under Dragos once the deal closes. The $208 million recurring-revenue figure Accenture projected covers all three companies together, so NetRise's own scale stays undisclosed. [s12, s7, s5, s16, s8, s10, s11]
The founders are in-domain and their public record is short. Thomas Pace, co-founder and chief executive, is listed on NetRise's company page as a former executive at Cylance, and a SecurityWeek article describes him as a former US Marine. Michael Scott, co-founder and chief technology officer, is a named inventor on the company's patent and is quoted on what happens while a compromised package is still published.
NetRise's board and advisers carry records the founders' own history does not. Its company page names Stuart McClure, who founded and led Cylance, as a board member, and Allan Friedman, formerly a senior advisor and strategist at CISA and director of cybersecurity initiatives at NTIA, as an advisor. Those are governance and advisory roles rather than products the founders shipped.
No prior exit, sustained publication record, or independent industry recognition of the founding team appears in the reviewed sources, so a buyer weighing the team has titles and one patent to go on. [s2, s10, s15, s9]
NetRise publishes its security posture on its own site. The security page states that the company maintains compliance with applicable government regulations and appropriate frameworks including SOC 2 Type II, and describes stored customer data as encrypted and segmented using Google Cloud Storage practices.
The trust center at trust.netrise.io lists more. Rendered, it names a SOC 2 Type II report under Resources, carries a Request access control, and enumerates control families covering infrastructure, organizational, product, internal and data privacy security. No federal authorization for NetRise's own cloud service appears on the probed surfaces.
The federal placement is the stronger readiness credential. CISA reviews each Approved Products List submission against established program criteria to validate the vendor's claim. CISA's own page states the list is not accepting new submissions for the indefinite future, and the same page also documents a monthly submission season with a calendar, so how open that route is today is not settled by the record. [s6, s18, s17, s16]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Finite State | competes with | Named in the same procurement guide's vendor set for the same firmware and device software risk job. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| ONEKEY | competes with | Named in the same procurement guide's vendor set as a vendor a buyer might consider instead. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Cybellum | competes with | Named in the same procurement guide's vendor set for IoT vulnerability management. | N/AThese companies operate in different domains, so the scores reflect readiness in different markets. |
| Black Duck | adjacent | Listed by the same procurement guide among vendors a buyer might consider, and tracked here as adjacent rather than a direct substitute. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| JFrog | adjacent | Named in the same procurement guide's vendor list, and recorded as adjacent because the guide does not present it as a direct substitute. | N/AWe scored these companies at different scopes, so the totals measure different things. |
Add analyzed competitors to compare them side by side with NetRise.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
NetRise sells software as the product, received by upload, API or integration. Behind the binary analysis the reviewed record identifies one patented technique, a US patent granted in December 2024 on a method for identifying software components. That record names no proprietary corpus and no cross-customer learning loop. Its buyers slow replacement. Federal agencies buy through integrator partners and program review, and CISA states the Approved Products List carrying its platform is closed to new submissions for the indefinite future. NetRise is most defensible inside federal accounts reached through that placement, and weakest outside that channel, where a procurement guide lists nine other vendors alongside it.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | NetRise sells software as the product, received by upload, API or integration. The managed federal offering is delivered by partners such as Asc3nd Technologies Group rather than by NetRise, so no accountability layer is built into what NetRise itself sells. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Accumulated binary-derived inventory, validated bills of materials, and policy embedded in continuous integration, the editor and the command line create real friction to revert. The cited record documents no non-portable state, no network effect and no residency constraint, and it does not size what leaving would cost, so the mechanism is documented but the migration is not sized by the cited record. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 2/3 | NetRise's trust center lists SOC 2 Type II, a commercial bar a determined rival could clear. NetRise also holds a placement on CISA's Continuous Diagnostics and Mitigation Program's Approved Product List, which CISA reviews against established criteria and states is closed to new submissions for the indefinite future, though the same page documents a monthly submission season. The placement is an incumbent procurement advantage, short of the liability acceptance and audit trails of the top rung. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Unpacking compiled firmware and containers, identifying components without source, determining which of them execute at startup, and decompiling binaries into intermediate languages for weakness mapping is specialized program-analysis work, and a patent office granted a US patent on one part of it in December 2024. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | NetRise targets regulated segments, with industry pages for government, healthcare, power and utilities and device manufacturers, and its documented channel is the federal one, a Carahsoft partnership and a partner-led offering delivered through federal integrators and managed service providers. Procurement and program review in those segments slow any replacement. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | The product is a platform with application features, a system of record for what software an organization runs, rather than infrastructure other applications depend on at runtime. The package firewall enforces policy during installs, and the reviewed record names no application that depends on NetRise to run. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | One US patent granted in December 2024 covers a single component-identification technique, which is protected method rather than the accumulated data advantage the next rung describes. No named non-public dataset and no cross-customer learning loop appears in the cited record, and a rival building from scratch would face the patent rather than a corpus it cannot obtain. |
NetRise segments by who touches the software. Its own material addresses software builders and software buyers as separate audiences, and its site carries industry pages for government organizations, healthcare, power and utilities, consulting firms, enterprise corporations and device manufacturers.
NetRise shows its evidence at the regulated end of that list. The government page pairs the platform with CISA's Continuous Diagnostics and Mitigation program and names Carahsoft as the public-sector partner, the medical reference is a product security lead at Velentium Medical, and the enterprise reference is the chief information security officer at H.I.G. Capital.
NetRise sells through negotiated contracts. Purchase-oriented calls to action lead to a demo request or a conversation with a live expert, and no list price appeared on the reviewed pages, which is the profile of enterprise and federal purchasing rather than self-serve adoption.
The differentiating capability is that NetRise reads the compiled artifact. Its platform validates a software bill of materials with a binary-derived inventory of the code that actually executes and ranks vulnerabilities by whether the affected component runs at startup. NetRise positions that as a way to see code a declared manifest omits.
One identification technique is patented, and the record stops there. US patent 12,175,241, machine learning-based universal software component identification, was granted in December 2024 on an application filed by Netrise Inc, naming Michael Scott and Yaroslav Oliinyk as inventors. That covers one machine-learning method for identifying software components rather than a corpus a rival would need years to gather.
NetRise also applies AI in three named features. NetRise Trace uses semantic and keyword search over the inventory, ZeroLens generates qualitative summaries of weaknesses it maps to CWEs, and Provenance plugins apply the same package policy inside AI coding assistants including Claude Code, Gemini and Codex.
NetRise sells through partners into the federal market. Its government page names Carahsoft as the public-sector partner, and in July 2026 it announced a partner-led managed software supply chain risk management offering delivered through federal integrators and managed service providers, with Asc3nd Technologies Group as strategic launch partner.
Independent evidence of selling comes from a growth ranking. Inc. placed NetRise at No. 148 on its 2026 Inc. 5000 with 2,118% three-year growth, at a company size Inc. records as 11 to 50 people, while the two named references on the company's own pages are the whole of the named-reference record the reviewed sources identify.
The acquisition is not yet closed. Accenture announced on 18 June 2026 that it would acquire NetRise outright as part of a roughly $4.175 billion transaction that also takes a majority stake in Dragos, with the deal expected to close in August or September pending regulatory approvals, and NetRise to operate under Dragos once it does.
No list price appeared on the reviewed pages. Purchase-oriented calls to action lead to a demo request, a live expert, or a work-email form, which is how enterprise and federal buyers negotiate contracts, and no list price is published.
The packaging is clear even where the price is not. NetRise sells the platform as the inventory layer and offers Provenance as a standalone product, so a buyer can start with either the binary-derived inventory or the open-source provenance and policy layer.
The federal route is a third way to buy, because the managed offering announced in July 2026 is delivered by partners rather than by NetRise, so an agency buys the outcome through an integrator and NetRise supplies the analysis.
NetRise delivers a cloud platform its customers operate. The company describes an automated, cloud-based platform giving insight into risks in firmware and software components, and compiled artifacts reach it by upload, API or integration.
Enforcement runs where developers already work. The July 2026 release put package trust decisions into Visual Studio Code, a command-line package firewall that blocks non-compliant packages at install time, and plugins for AI coding assistants, with a shared policy engine applying the same decision in the editor, at the command line and in continuous integration.
The operational promise is speed at incident time. The company frames the work as answering where an organization is exposed when a supply chain incident emerges, which is why the platform ranks findings by whether the affected component executes at startup.
NetRise publishes its own posture and holds one commercial attestation. The security page states that the company maintains compliance with applicable government regulations and appropriate frameworks including SOC 2 Type II, and describes stored customer data as encrypted and segmented using Google Cloud Storage practices.
The trust center at trust.netrise.io lists the detail a buyer can check without a contract. Rendered, it names a SOC 2 Type II report under Resources, carries a Request access control, and enumerates control families across infrastructure, organizational, product, internal and data privacy security. No federal authorization for NetRise's own cloud service appears on the probed surfaces.
The program placement is the credential a rival would have to obtain separately. CISA reviews each Approved Products List submission against established criteria to validate the vendor's claim, and CISA states the list is not accepting new submissions for the indefinite future while the same page documents a monthly submission season.
NetRise positions two products as one platform. The company describes an inventory product that tracks what is actually executing and a provenance product that scopes how far a compromise reaches, and it sells Provenance separately as well.
NetRise integrates with tools practitioners already run. ZeroLens maps findings to Binary Ninja or Ghidra for deeper reverse engineering, Provenance reaches developer registries including PyPI through a single API, and the developer-workflow release added Visual Studio Code and command-line enforcement.
Provenance now treats AI coding assistants as an enforcement point. Its plugins apply the same package policy to AI-initiated dependency installs in Claude Code, Gemini and Codex, which is where the company argues dependencies now enter projects for people who are not developers.
The founding record is in-domain and short on public proof. NetRise's company page lists Thomas Pace, co-founder and chief executive, as a former executive at Cylance, and a SecurityWeek article describes him as a former US Marine. Michael Scott, co-founder and chief technology officer, is a named inventor on the company's patent and speaks for it on supply chain attacks.
The governance around them is better decorated than the founding history. The company page names Stuart McClure, who founded and led Cylance, as a board member, and Allan Friedman, formerly a senior advisor and strategist at CISA and director of cybersecurity initiatives at NTIA, as an advisor. Those records belong to board members and advisers. The team stayed small while the revenue grew. The company page counts 40 employees in 2025 and Inc. records a size of 11 to 50 people against 2,118% three-year growth, which is a lean shipping record rather than a scaled organization.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | NetRise Platform product page | official | 2026-08-18 |
| f2 | Inc.: NetRise company profile, Inc. 5000 2026 | press | 2026-08-18 |
| f3 | CyberScoop: Accenture shells out $4.18B on three companies in big industrial cybersecurity push | press | 2026-08-18 |
| f4 | FinTech Global: Software supply chain security firm NetRise secures $10m Series A round | press | 2026-08-18 |
| f5 | NetRise homepage | official | 2026-08-18 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.