ONEKEY

Application SecurityGovernance Risk Compliance also known as IoT Inspector, ONEKEY GmbH

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2020
Last updated 2026-07-16

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

ONEKEY publishes its firmware extractor, unblob, under the MIT license for any rival to run, while describing the binary analysis it sells as patent-pending rather than granted. That analysis reads device firmware as raw binary, with no source code, and produces the software inventories, vulnerability rankings, and compliance evidence European device makers now need under the EU Cyber Resilience Act. The named customers on ONEKEY's homepage and its PwC Germany investment are credibility a rival could also earn. A competitor can rerun the public tooling. Matching ONEKEY's documented RTOS analysis, architecture detection, load-address recovery, and component identification takes expertise the public tooling alone does not supply. That depth is what a buyer should test.

Sourced Details

Description Product cybersecurity and compliance platform for connected-device manufacturers and operators that analyzes firmware binaries without source code, generates SBOMs, prioritizes vulnerabilities, and produces audit evidence for regulations such as the EU Cyber Resilience Act and IEC 62443. [f1]
Founded 2020 [f2]
Latest funding Minority investment from PwC Germany (December 2023), with eCAPITAL as existing backer [f3]

Products

Product What it does
ONEKEY Product Cybersecurity & Compliance Platform (OCP) Automates SBOM generation, binary firmware analysis, vulnerability detection and prioritization, zero-day discovery, and lifecycle monitoring through Digital Cyber Twins for connected products.
ONEKEY Compliance Wizard Patent-pending assistant that guides manufacturers through regulatory requirements such as the EU Cyber Resilience Act, IEC 62443, and ETSI EN 303 645 and assembles audit-ready compliance bundles.

Matrix Coverage

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

ONEKEY inventories software components in device firmware, surfaces and prioritizes exploitable vulnerabilities, and monitors products across their lifecycle. It applies AI to defend conventional embedded and device software, so its product lines map to the Cyber Defense Matrix. [f1]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 28 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 4/5 ONEKEY names a specific buyer, product security and compliance teams at connected-device manufacturers, and ties the pain to dated regulation. A vendor-independent procurement guide places the same firmware-compliance problem and competitive set, corroborating the pain outside vendor copy. [s1, s6, s4]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 Detailed platform and feature pages describe binary SBOM generation, vulnerability prioritization, and the Compliance Wizard, and a sustained public research program adds external validation through the open-source unblob extractor and dated CVE advisories, and a vendor-independent procurement guide treats the capability set as credible. No independent benchmark of detection quality is published, which caps the score. [s2, s9, s10, s6]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5 EU Cyber Resilience Act deadlines approach, the vendor's own site counts down to the initial CRA phase as of 2026, and the Compliance Wizard maps directly to CRA, IEC 62443, and ETSI EN 303 645 requirements. The EU-funded CRACoWi consortium and an external procurement guide are buyer-side signals that the regulatory window is open now. The enabler is regulatory, the CRA timeline of the past two years. [s8, s6, s4]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 The 2020 spin-off from SEC Consult and the research lab's CVE advisories and open-source unblob tool are a verifiable in-domain origin and sustained output, but no founder prior exit is documented and the advisory record sits below the recognized publication bar, so this is the honest default. [s3, s9, s10, s5]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 Snap One and Swisscom appear only on ONEKEY's own homepage without independent corroboration of scale, and the external signals (a PwC Germany minority investment and the EU CRACoWi consortium) are backer and partnership signals rather than independently confirmed customer references, so reputable PwC backing supports the indirect-signal bump while the score holds at the vendor-displayed level. [s1, s5]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 Funding is verifiable but modest, an initial 2020 round and a December 2023 minority stake from PwC Germany and eCAPITAL, against a global enterprise compliance ambition. Shipping cadence and the research output show visible work per euro. [s11, s5, s9]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 4/5 Product security for connected devices is an established budget line, and a vendor-independent procurement guide names ONEKEY in the recognizable set with NetRise, Cybellum, and Finite State, so buyers place it without vendor coaching. [s6, s4]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Binary analysis across many embedded architectures is hard to copy in a quarter, but application-security and software-composition platforms that already hold the budget could bundle firmware scanning, and ONEKEY's public unblob extractor is open source, so the technology itself is not the barrier. [s2, s10]
Business Risks An application-security or software-composition incumbent that already sells to device makers could bundle binary firmware scanning and absorb the core capability…
  • An application-security or software-composition incumbent that already sells to device makers could bundle binary firmware scanning and absorb the core capability.
  • The unblob extractor is MIT-licensed, so a funded rival can run this public ONEKEY-maintained firmware tool without rebuilding it.
  • A small disclosed raise against a global enterprise compliance ambition could limit go-to-market reach if larger competitors out-spend ONEKEY.
  • CRA enforcement timelines could settle in ways that let incumbents satisfy the same evidence requirements with lighter tooling.
Problem & Market ONEKEY targets product security and compliance teams at connected-device manufacturers and operators. These teams carry a hard burden of proof: that the software inside shipped devices is secure and audit-ready against the wave of regulatory regimes now landing on connected products in Europe and beyond. The platform frames the pain as finding vulnerabilities and compliance gaps in firmware that the team often did not write and cannot see the source for. Vendor-independent sourcing corroborates the problem at the buyer level. A CyberCompare procurement guide places ONEKEY in a named set of IoT vulnerability-management vendors that device makers evaluate. The homepage carries attributed testimonials from Snap One, Swisscom, and Trimble, plus a medical-device manufacturer quoted without a company name…

ONEKEY targets product security and compliance teams at connected-device manufacturers and operators. These teams carry a hard burden of proof: that the software inside shipped devices is secure and audit-ready against the wave of regulatory regimes now landing on connected products in Europe and beyond. The platform frames the pain as finding vulnerabilities and compliance gaps in firmware that the team often did not write and cannot see the source for.

Vendor-independent sourcing corroborates the problem at the buyer level. A CyberCompare procurement guide places ONEKEY in a named set of IoT vulnerability-management vendors that device makers evaluate. The homepage carries attributed testimonials from Snap One, Swisscom, and Trimble, plus a medical-device manufacturer quoted without a company name. [s4, s6, s1, s12]

Product Capabilities The ONEKEY Product Cybersecurity & Compliance Platform analyzes firmware binaries without source code, generates a software bill of materials, detects and prioritizes vulnerabilities, discovers zero-days, and monitors products across their lifecycle. The Compliance Wizard adds a guided path through CRA, IEC 62443, and ETSI EN 303 645 requirements and assembles audit-ready evidence bundles. Public research backs the capability claims more than most vendor sites do. ONEKEY maintains the open-source unblob extractor that parses dozens of firmware and filesystem formats, and its research lab publishes dated vulnerability advisories carrying assigned CVE identifiers, such as remote code execution in a Diviotec IP camera. No independent benchmark of detection quality is published, which limits external validation…

The ONEKEY Product Cybersecurity & Compliance Platform analyzes firmware binaries without source code, generates a software bill of materials, detects and prioritizes vulnerabilities, discovers zero-days, and monitors products across their lifecycle. The Compliance Wizard adds a guided path through CRA, IEC 62443, and ETSI EN 303 645 requirements and assembles audit-ready evidence bundles.

Public research backs the capability claims more than most vendor sites do. ONEKEY maintains the open-source unblob extractor that parses dozens of firmware and filesystem formats, and its research lab publishes dated vulnerability advisories carrying assigned CVE identifiers, such as remote code execution in a Diviotec IP camera. No independent benchmark of detection quality is published, which limits external validation. [s2, s10, s9]

Competitive Positioning ONEKEY sits in the product security and compliance category for connected devices, an established budget line rather than an invented one. A CyberCompare procurement guide places it alongside NetRise, Cybellum, and Finite State, so buyers locate it without vendor coaching. ONEKEY differentiates on binary firmware analysis paired with a guided compliance workflow and European expert services. The exposure is that ONEKEY maintains a public, MIT-licensed extractor, unblob, that any rival can run, so a copycat must clear the accumulated platform and compliance position rather than the public extraction tooling itself…

ONEKEY sits in the product security and compliance category for connected devices, an established budget line rather than an invented one. A CyberCompare procurement guide places it alongside NetRise, Cybellum, and Finite State, so buyers locate it without vendor coaching.

ONEKEY differentiates on binary firmware analysis paired with a guided compliance workflow and European expert services. The exposure is that ONEKEY maintains a public, MIT-licensed extractor, unblob, that any rival can run, so a copycat must clear the accumulated platform and compliance position rather than the public extraction tooling itself. [s6, s4, s10]

Go-to-Market & Traction ONEKEY shows named reference customers on record…

ONEKEY shows named reference customers on record. Snap One, Swisscom, and Trimble give attributed testimonials on the homepage, joined by security service providers that use ONEKEY in their consulting work. This is stronger named-reference evidence than most vendors at its disclosed funding stage carry.

The go-to-market reach is reinforced by a strategic minority investment from PwC Germany and eCAPITAL and by participation in the EU-funded CRACoWi consortium with thirteen European partners building a CRA compliance assistant. The selling motion is European-led, consistent with a Dusseldorf base and a regulated-buyer focus. [s1, s12, s5, s8]

Team & Credibility ONEKEY has a verifiable origin in the same domain…

ONEKEY has a verifiable origin in the same domain. It launched in 2020 as IoT Inspector, a spin-off from penetration-testing firm SEC Consult, and rebranded to ONEKEY in 2022. That lineage is a documented prior build in embedded and firmware security rather than a claimed background.

The team sustains a recognized research function. ONEKEY runs a research lab that publishes named CVE advisories and maintains a widely used open-source extractor, a continuing publication record rather than a single disclosure event. [s3, s9, s10]

Trust Readiness ONEKEY achieved ISO/IEC 27001:2022 certification announced in June 2026, covering the development and operation of its platform and its expert services including penetration testing and CRA readiness assessments. This is a commercial information-security attestation rather than a government authorization. No federal authorization or regulatory mandate specific to ONEKEY appears in the public record as of this analysis. The certification is table-stakes assurance for enterprise procurement, not a barrier a determined rival could not also clear…

ONEKEY achieved ISO/IEC 27001:2022 certification announced in June 2026, covering the development and operation of its platform and its expert services including penetration testing and CRA readiness assessments. This is a commercial information-security attestation rather than a government authorization.

No federal authorization or regulatory mandate specific to ONEKEY appears in the public record as of this analysis. The certification is table-stakes assurance for enterprise procurement, not a barrier a determined rival could not also clear. [s8]

Competitors Finite State, NetRise, Cybellum…
Company Relationship Note Compare
Finite State competes with Both build SBOMs from device firmware and assemble CRA and FDA compliance evidence for connected-device manufacturers.
NetRise competes with Sells firmware and software supply-chain analysis to the same device-manufacturer buyer. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Cybellum competes with Product security and compliance platform strong in automotive contexts, competing for the same regulated-device buyer. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.

Add analyzed competitors to compare them side by side with ONEKEY.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 13 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

ONEKEY sells into regulated device makers in medical, automotive, industrial, and telecommunications, whose procurement and review slow any replacement once firmware history, SBOM exports, and lifecycle monitoring accumulate in the platform. Two differentiators do not lock that in. ONEKEY publishes the unblob extractor under the MIT license for any rival to run and calls its binary breakdown patent-pending rather than granted, and its ISO 27001 certification is a commercial bar a competitor can clear, not a mandate ONEKEY holds. The part that resists quick copying is binary firmware analysis across many embedded architectures, built over years. ONEKEY is most defensible inside entrenched regulated accounts and weakest where a broader application-security vendor could reach the same buyers.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 The platform is software the customer's team operates and remains accountable for, generating reports and compliance packages as product output, while consulting, penetration testing, and CRA readiness assessments are advertised as separate services rather than accountability transferred in the sold offer.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Accumulated SBOM and firmware history, lifecycle monitoring, and pipeline embedding create real friction to revert, and the cited record shows no network effect or residency constraint lifting migration cost beyond rebuildable history.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 ONEKEY holds a commercial ISO/IEC 27001 certification and its product feeds customers' own CRA and IEC 62443 evidence, which is a capability serving the buyer's mandate rather than a federal authorization or regulatory mandate ONEKEY itself holds, so a determined rival could clear the same commercial bar.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Binary firmware extraction with automated architecture detection, load-address recovery, and RTOS analysis is specialized program-analysis work at the hard end of the craft, which a fast copy cannot replicate.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 Buyers are regulated device manufacturers in medical, automotive, industrial, and telecommunications markets, whose procurement and regulatory review processes slow any replacement.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 The product is a platform and system of record for product security and compliance, not infrastructure that other applications depend on at runtime.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 No named non-public data corpus or granted IP appears in the cited record. ONEKEY maintains the MIT-licensed unblob extractor that any rival can run, and its binary analysis is described as patent-pending rather than granted, so the score reflects the absence of a cited proprietary dataset or granted patent moat.
Strategic Market Segmentation ONEKEY segments by regulation rather than by company size…

ONEKEY segments by regulation rather than by company size. Its messaging leads with the EU Cyber Resilience Act, IEC 62443, and ETSI EN 303 645, the rules that bind connected-device makers. The named customer references on its homepage are product makers Snap One and Trimble plus Swisscom, speaking through a senior security consultant, while Kudelski IoT and Atos add attributed testimonials as security service providers, and the served markup associates the medical-device testimonial with Richard Wolf through its logo. The persona is the product security or compliance engineer who owes regulators evidence about shipped software.

A vendor-independent procurement guide treats ONEKEY as a credible option device makers evaluate, naming it among IoT vulnerability-management vendors. ONEKEY is Germany-based and CRA-focused, with the platform sold worldwide and customers cited across Asia, Europe, and America.

Product Capabilities & AI Advantages The durable capability is binary firmware analysis without source code…

The durable capability is binary firmware analysis without source code. ONEKEY decomposes firmware, generates a software bill of materials, prioritizes vulnerabilities, and discovers zero-days, then monitors products across their lifecycle. Real-time operating system support and automated architecture detection extend the reach into embedded targets that resist generic scanners.

The extraction layer is open while the analysis is proprietary. ONEKEY maintains the MIT-licensed unblob extractor, a public firmware-extraction tool any rival can run, while its binary-code analysis is described by its investor announcement as proprietary, patent-pending technology, so the defensible edge is the accumulated platform, the proprietary analysis, and the research output.

Sales Engagement & Go-to-Market ONEKEY sells from its German base with European partnerships, paired with expert services…

ONEKEY sells from its German base with European partnerships, paired with expert services. Named reference customers appear on record. Snap One, Trimble, and Swisscom give attributed customer testimonials on the homepage, joined by Kudelski IoT and Atos speaking as service providers, several attributed references on the public record.

Distribution is reinforced by PwC Germany's December 2023 minority investment, with eCAPITAL an existing backer since its 2020 round, and by the EU-funded CRACoWi consortium with thirteen European partners building a CRA compliance assistant. These relationships give ONEKEY a credibility channel into regulated buyers that pure software marketing would not.

Pricing Model ONEKEY does not publish prices on its site and routes buyers to a demo request, the pattern of a vendor pursuing negotiated enterprise deals rather than self-serve adoption. Pricing is undisclosed and likely sales-negotiated, with no public price ladder to confirm the unit a buyer pays for. No public price ladder or marketplace listing was found in this analysis, so the pricing-as-positioning signal is limited to the hidden-price, sales-led inference. Pricing is quote-based and undisclosed, with consulting advertised separately, and the cited pages do not show whether deals bundle the two…

ONEKEY does not publish prices on its site and routes buyers to a demo request, the pattern of a vendor pursuing negotiated enterprise deals rather than self-serve adoption. Pricing is undisclosed and likely sales-negotiated, with no public price ladder to confirm the unit a buyer pays for.

No public price ladder or marketplace listing was found in this analysis, so the pricing-as-positioning signal is limited to the hidden-price, sales-led inference. Pricing is quote-based and undisclosed, with consulting advertised separately, and the cited pages do not show whether deals bundle the two.

Product Delivery & Operations ONEKEY delivers as a hosted platform available worldwide, with binary analysis that needs no source code, device access, or network access, which lowers the integration burden for a manufacturer protecting third-party firmware. Lifecycle monitoring through Digital Cyber Twins keeps assessing products after release. A Product Security Incident Response Team workflow and automated vulnerability prioritization support the post-release operations buyers run on the platform. The delivery model blends self-service analysis with expert consulting for CRA readiness and integration…

ONEKEY delivers as a hosted platform available worldwide, with binary analysis that needs no source code, device access, or network access, which lowers the integration burden for a manufacturer protecting third-party firmware. Lifecycle monitoring through Digital Cyber Twins keeps assessing products after release.

A Product Security Incident Response Team workflow and automated vulnerability prioritization support the post-release operations buyers run on the platform. The delivery model blends self-service analysis with expert consulting for CRA readiness and integration.

Earning Customers' Trust ONEKEY achieved ISO/IEC 27001:2022 certification announced in June 2026, covering the development and operation of its platform and its expert services including penetration testing and CRA readiness assessments. This is a commercial information-security attestation that supports enterprise procurement. No cited source shows a government authorization or regulatory mandate specific to ONEKEY. The certification is assurance that eases buying, not a barrier a determined competitor could not also clear…

ONEKEY achieved ISO/IEC 27001:2022 certification announced in June 2026, covering the development and operation of its platform and its expert services including penetration testing and CRA readiness assessments. This is a commercial information-security attestation that supports enterprise procurement.

No cited source shows a government authorization or regulatory mandate specific to ONEKEY. The certification is assurance that eases buying, not a barrier a determined competitor could not also clear.

Platform Strategy & Ecosystem Positioning ONEKEY positions itself as a system of record for product security and compliance rather than infrastructure other applications depend on at runtime. The Compliance Wizard, SBOM export in standard formats, and CVE prioritization make it a hub buyers route firmware and evidence through. The ecosystem reach is widened by the open-source unblob project and the CRACoWi consortium, which seed ONEKEY's tooling and standards work into the broader European firmware-security community. That community presence is a distribution and credibility asset more than a lock-in mechanism…

ONEKEY positions itself as a system of record for product security and compliance rather than infrastructure other applications depend on at runtime. The Compliance Wizard, SBOM export in standard formats, and CVE prioritization make it a hub buyers route firmware and evidence through.

The ecosystem reach is widened by the open-source unblob project and the CRACoWi consortium, which seed ONEKEY's tooling and standards work into the broader European firmware-security community. That community presence is a distribution and credibility asset more than a lock-in mechanism.

Team & Execution Capability ONEKEY launched in 2020 as IoT Inspector, a spin-off from penetration-testing firm SEC Consult, and rebranded to ONEKEY in 2022. The lineage is a documented prior build in embedded and firmware security, and Jan Wendenburg leads the company as chief executive. The team sustains a recognized research function that publishes named CVE advisories and maintains the unblob open-source extractor, a continuing publication record rather than a one-time disclosure. That research output is a credibility signal disproportionate to the disclosed funding…

ONEKEY launched in 2020 as IoT Inspector, a spin-off from penetration-testing firm SEC Consult, and rebranded to ONEKEY in 2022. The lineage is a documented prior build in embedded and firmware security, and Jan Wendenburg leads the company as chief executive.

The team sustains a recognized research function that publishes named CVE advisories and maintains the unblob open-source extractor, a continuing publication record rather than a one-time disclosure. That research output is a credibility signal disproportionate to the disclosed funding.

Sources

Company Detail Sources (3)
Id Source Tier Accessed
f1 ONEKEY platform overview official 2026-06-21
f2 ONEKEY about page official 2026-06-21
f3 eCAPITAL: PwC Germany invests in ONEKEY press 2026-07-16
Profile Analysis Sources (12)
Id Source Tier Accessed
s1 ONEKEY homepage
“Keep your connected devices secure and compliant by design. Meet the software designed for manufacturers and operators to avoid risks along the whole lifecycle.”
official 2026-06-21
s2 ONEKEY platform overview
“Discover your centralized solution for SBOM validation, vulnerability detection and prioritization, zero-day discovery, regulatory compliance or product lifetime monitoring.”
official 2026-06-21
s3 ONEKEY about page
“In 2020, we launched under the brand name IoT-Inspector - as a spin-off from SEC-Consult, a global leader in cybersecurity and penetration testing.”
official 2026-06-21
s4 ONEKEY Compliance Wizard feature page
“Navigate standards like EU Cyber Resilience Act, IEC 62443 and ETSI 303 645 effortlessly.”
official 2026-06-21
s5 eCAPITAL: PwC Germany invests in ONEKEY
“PwC Holdings Germany GmbH, PwC Germany's investment company for industrial growth capital, has acquired a minority stake in ONEKEY GmbH, headquartered in Dusseldorf, together with eCAPITAL to finance growth.”
press 2026-06-21
s6 CyberCompare: Considerations for purchasing IoT vulnerability management solutions
“For IoT vulnerability management, suitable vendors include Aqua Security, aDolus, Cybellum, Finite State, Firmalyzer, JFrog, Moabi, Netrise, OneKey (formerly IoT Inspector), and Synopsys Black Duck.”
research 2026-06-21
s7 ONEKEY: Vulnerability Management and SBOM Generation Are Key to CRA Compliance official 2026-06-21
s8 ONEKEY receives ISO/IEC 27001 certification (Presseportal)
“Im Rahmen des EU-gefoerderten Projekts CRACoWi (Cyber Resilience Act Compliance Wizard) entwickelt ONEKEY gemeinsam mit 13 europaeischen Partnern einen KI-gestuetzten Assistenten zur automatisierten Umsetzung des EU Cyber Resilience Act (CRA).”
press 2026-06-21
s9 ONEKEY research blog
“Security Advisory: Remote Code Execution on Diviotec IP Camera (CVE-2025-5113)”
official 2026-06-21
s10 unblob (onekey-sec/unblob) GitHub repository
“unblob is licensed under the MIT License.”
official 2026-06-21
s11 ONEKEY Secures Millions in Funding from eCAPITAL official 2026-06-21
s12 ONEKEY: Why Customers Trust Us homepage testimonials
“As a medical device manufacturer, we use the ONEKEY platform to systematically manage and monitor all cybersecurity aspects of our software-enabled medical devices.”
official 2026-07-02
Deep-Dive Sources (12)
Id Source Tier Accessed
s1 ONEKEY homepage
“Keep your connected devices secure and compliant by design. Meet the software designed for manufacturers and operators to avoid risks along the whole lifecycle.”
official 2026-06-21
s2 ONEKEY platform overview
“Discover your centralized solution for SBOM validation, vulnerability detection and prioritization, zero-day discovery, regulatory compliance or product lifetime monitoring.”
official 2026-06-21
s3 ONEKEY about page
“In 2020, we launched under the brand name IoT-Inspector - as a spin-off from SEC-Consult, a global leader in cybersecurity and penetration testing.”
official 2026-06-21
s4 ONEKEY Compliance Wizard feature page
“Navigate standards like EU Cyber Resilience Act, IEC 62443 and ETSI 303 645 effortlessly.”
official 2026-06-21
s5 eCAPITAL: PwC Germany invests in ONEKEY
“PwC Holdings Germany GmbH, PwC Germany's investment company for industrial growth capital, has acquired a minority stake in ONEKEY GmbH, headquartered in Dusseldorf, together with eCAPITAL to finance growth.”
press 2026-06-21
s6 CyberCompare: Considerations for purchasing IoT vulnerability management solutions
“For IoT vulnerability management, suitable vendors include Aqua Security, aDolus, Cybellum, Finite State, Firmalyzer, JFrog, Moabi, Netrise, OneKey (formerly IoT Inspector), and Synopsys Black Duck.”
research 2026-06-21
s7 ONEKEY: Vulnerability Management and SBOM Generation Are Key to CRA Compliance official 2026-06-21
s8 ONEKEY receives ISO/IEC 27001 certification (Presseportal)
“Im Rahmen des EU-gefoerderten Projekts CRACoWi (Cyber Resilience Act Compliance Wizard) entwickelt ONEKEY gemeinsam mit 13 europaeischen Partnern einen KI-gestuetzten Assistenten zur automatisierten Umsetzung des EU Cyber Resilience Act (CRA).”
press 2026-06-21
s9 ONEKEY research blog
“Security Advisory: Remote Code Execution on Diviotec IP Camera (CVE-2025-5113)”
official 2026-06-21
s10 unblob (onekey-sec/unblob) GitHub repository
“unblob is licensed under the MIT License.”
official 2026-06-21
s11 ONEKEY Secures Millions in Funding from eCAPITAL official 2026-06-21
s12 ONEKEY: Why Customers Trust Us homepage testimonials
“As a medical device manufacturer, we use the ONEKEY platform to systematically manage and monitor all cybersecurity aspects of our software-enabled medical devices.”
official 2026-07-02

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.