Eclypsium
Eclypsium provides a SaaS platform for hardware and firmware supply chain security across endpoints, servers, network devices, and AI infrastructure. It serves enterprise, government, financial services, telecom, and AI data center buyers with component-level visibility and AI-assisted binary analysis.
- Company typePrivate
- Founded2017
- HeadquartersPortland, United States
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What Eclypsium does
Eclypsium, Inc. is a Portland, Oregon-headquartered (Delaware-incorporated) private cybersecurity company founded in 2017 that sells a SaaS-based hardware and firmware supply chain security platform. The platform performs agentless and agent-based inspection of endpoints, servers, network devices, and AI infrastructure at the layer below the operating system where EDR and traditional vulnerability management tools cannot see. Core technical capabilities include component-level inventory generation (SBOM/FBOM/HBOM) covering CPU microcode, BMC firmware, storage controllers, NICs, TPM, and Intel ME; firmware vulnerability scanning validated against a proprietary database of more than 12 million known-good firmware hashes spanning 23+ enterprise hardware vendors; integrity monitoring and tamper detection; and "Eclypsium Automata," an AI-assisted binary analysis engine for detecting backdoors, implants, and stealthy bootkits. The product is delivered as a single platform with four asset-class modules (Endpoint, Server, Network Device, AI Data Center Security) plus a lifecycle management solution covering onboarding, production, and decommissioning, and a regulatory compliance layer mapped to NIST SP 800-53/161/193/1800-34, FFIEC, CJIS, NERC CIP, CMMC, EO 14028, NIS2, DORA, the EU Cyber Resilience Act, and PCI-DSS.
Eclypsium sells exclusively through a quote-based enterprise subscription model with no publicly disclosed pricing. Go-to-market is a high-touch direct field sales motion, supplemented by self-guided interactive product tours (a product-led layer), an active threat-research/content engine (253+ blog posts, 26+ white papers, 75 events/webinars, the "Below the Surface" podcast), and ecosystem embedding through the NVIDIA Inception Program and deep OEM integrations. The company runs dedicated sales teams for financial institutions and the public sector. Named customers include Lockheed Martin, American Express, Motorola, KDDI, Interpublic Group, DigitalOcean, First Financial Credit Union, Centurion Managed Care, and Copperleaf, alongside unnamed major accounts such as a top-three U.S. bank and a global financial institution covering hundreds of thousands of endpoints.
Revenue mechanics are pure recurring SaaS, with multi-year contracts tied to endpoint, server, network device, and AI infrastructure counts, and additional managed-services-style revenue from federal and public-sector engagements. The company is venture-backed, having raised over $100 million cumulatively (Series A $2.3M in 2017, Series B $25M in 2022, a ~$35M SEC-exempt offering in 2024, Series C $45M in 2025, and a $25M Series C+ in March 2026) from Andreessen Horowitz, Intel Capital, Qualcomm Ventures, Ten Eleven Ventures, PEAK6 Strategic Capital, Madrona, Pavilion Capital, Sixty Degree Capital, Singtel Innov8, and Alumni Ventures. CEO and co-founder Yuriy Bulygin leads the company.
Eclypsium firmographics
Firmographics- Name
- Eclypsium
- Legal name
- Eclypsium, Inc.
- Website
- https://eclypsium.com
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Eclypsium provides a SaaS platform for hardware and firmware supply chain security across endpoints, servers, network devices, and AI infrastructure. It serves enterprise, government, financial services, telecom, and AI data center buyers with component-level visibility and AI-assisted binary analysis.
- Ownership category
- akta.pro rank
Eclypsium industry classification
Industry- Product category
- Firmware and Hardware Supply Chain Security
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
- akta.pro secondary industry
- Confidential Computing & Hardware-backed Protection (TEE/HSM) (HDADAFAJ)
Keywords
Where Eclypsium is headquartered
LocationHeadquarters
- HQ city
- Portland
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Eclypsium business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- SaaS Platform Subscription: Recurring SaaS subscription revenue from the Eclypsium digital supply chain security platform delivered as a cloud service. Pricing is quote-based, accessed via 'Request a Demo' / 'Talk supply chain security with an expert' CTAs across the website, indicating enterprise contract-based subscriptions rather than self-serve pricing.
- Enterprise / Financial Services Deployments: Large-scale enterprise contracts (e.g., protecting hundreds of thousands of endpoints for a major financial institution) generating multi-year subscription revenue with land-and-expand dynamics across endpoints, servers, network devices, and AI infrastructure.
- Government / Public Sector Contracts: Subscription and contract revenue from federal, defense, law enforcement (CJIS), utilities (NERC CIP), and public sector customers, supported by dedicated public-sector sales teams and compliance-focused platform editions.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Quote-based enterprise subscription (no public tiers) |
Go-to-market motion4 records
Distribution channels4 records
Marketing channels11 records
Eclypsium product offering
Product offeringCore offering
Eclypsium provides a SaaS-based digital supply chain security platform that performs agentless and agent-based inspection of firmware, hardware components, and device integrity across endpoints, servers, network devices, and AI infrastructure. The platform unifies component inventory (SBOM/FBOM/HBOM), firmware vulnerability management against a database of 12M+ known-good firmware hashes, continuous integrity monitoring, AI-assisted binary analysis (Eclypsium Automata), and integration with SIEM/SOAR systems via REST APIs. It is sold to Fortune-class enterprises and government agencies via direct field sales with quote-based subscription pricing.
Product overview
Eclypsium offers a single unified platform (the Eclypsium Platform) with a platform-plus-modules architecture for hardware supply chain security. The core platform unifies component inventory, device hardening, and threat detection across the device lifecycle and is delivered as a SaaS solution with modules covering four asset classes: Endpoint Security, Server Infrastructure Security, Network Device Security, and AI Data Center Security. These modules are extended by solution-layer offerings including Secure Device Lifecycle Management (with Onboarding, Production, and Decommissioning sub-stages), Firmware Security for Enterprises, Cyber Supply Chain Risk Management (C-SCRM) / Digital Supply Chain Security, Enterprise Ransomware Protection, Zero Trust for Endpoints, and Regulatory Compliance. The underlying AI-assisted binary analysis engine, Eclypsium Automata, powers threat detection across the platform modules.
Differentiator
Problem solved
Functional benefit
Products and services
- Eclypsium Platform Unified hardware supply chain security platform that protects enterprises and government agencies from hidden risks in hardware supply chains by securing critical hardware, firmware, and components across every enterprise device. It unifies component inventory, device hardening, and threat detection across the device lifecycle from onboarding to production to secure disposition, delivered as a single SaaS solution covering endpoints, servers, network devices, and AI hardware.
- Endpoint Security Protects laptops, workstations, and desktops from firmware attacks and ransomware targeting endpoints. Provides continuous firmware-level security monitoring without compromising performance, with automated discovery and inventory, vulnerability and exposure management, integrity monitoring, threat detection, and automated firmware updates across every major endpoint vendor.
- Server Infrastructure Security Provides component-level visibility and security across data center server fleets and AI infrastructure. Delivers component-level inventory, vulnerability and configuration management, and threat detection powered by Eclypsium Automata AI-assisted binary analysis, with the ability to validate update binaries and schedule firmware updates.
- Network Device Security Protects VPNs, firewalls, routers, switches, and other network edge devices from ransomware and nation-state attacks without requiring agents. Provides continuous discovery, vulnerability and risk management, integrity monitoring, and automated firmware updates across every major network vendor, addressing the 8x increase in vulnerability exploitation in network devices per Verizon DBIR 2025.
- AI Data Center Security Continuous monitoring and hardening for AI factories, AI infrastructure, and AI supply chains. Provides AI server and GPU risk analysis including NVIDIA GPUs, AI infrastructure integrity verification, vulnerability management, threat detection, hardware supply chain attack prevention, and secure decommissioning of GPU servers for resale or disposal. Supports NIST SP 800-223 requirements.
- Secure Device Lifecycle Management Comprehensive security across the entire device lifecycle, with stages for Onboarding (acceptance testing, supply chain validation), Production (continuous monitoring of firmware integrity, vulnerabilities, and threats), and Decommissioning (data sanitization and validation before resale or recycling).
- Firmware Security for Enterprises Detects vulnerabilities, misconfigurations, and active attacks that EDR and vulnerability management cannot see. Uses a unique database of over 12 million known-good hashes to provide firmware vulnerability management, active threat detection (bootkits, implants, IOCs targeting firmware), integrity monitoring, automated patching, and stealthy ransomware detection (e.g., HybridPetya).
- Cyber Supply Chain Risk Management (C-SCRM) / Digital Supply Chain Security Verifies and protects IT hardware and component firmware at procurement and runtime. Enables supply chain verification and continuous monitoring of devices across the entire lifecycle (procurement, active operations, asset disposition), with vendor security evaluation, SBOM/FBOM monitoring, patch screening, and data sanitization validation.
- Enterprise Ransomware Protection Defends IT infrastructure against ransomware that exploits security blind spots, including boot-level persistence and network edge compromise. Detects ransomware where EDR cannot, with network appliance threat detection across Cisco, Fortinet, F5, Juniper, NetScaler, Palo Alto, and SonicWall, firmware/UEFI integrity verification, accelerated vulnerability response, and supply chain validation.
- Zero Trust for Endpoints Extends zero trust assurance to the foundational, bare-metal compute levels, covering chipsets, hardware, infrastructure code, and the manufacturing supply chain behind components within each asset. Addresses the 15-20 embedded firmware components per endpoint cited by Gartner.
- Regulatory Compliance Purpose-built automated platform for ensuring security of technology supply chains and integrity of devices and underlying firmware. Supports industry-specific requirements including FFIEC (financial services), CMS ARS (healthcare/insurance), NIST SP 800-171 and CMMC (defense industrial base and law enforcement), NERC CIP and AWIA (utilities), PCI-DSS (retail), and EU regulations NIS2, DORA, and Cyber Resilience Act (CRA).
Quantifiable outcome
- Protects hundreds of thousands of endpoints and AI servers globally
- +4 more outcomes
Companies that use Eclypsium
Customer profileNamed customers12 records
Segments7 records
Ideal customer profiles4 records
Eclypsium technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
AI capability2 records
Feature7 records
Eclypsium partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered flagship ecosystem partner and core technology integration.
- NVIDIAflagship ecosystem partnerEclypsium joined NVIDIA's Inception Program in December 2025 to secure critical AI infrastructure across private and public sectors. Eclypsium's platform is used to protect NVIDIA GPU-based AI servers, validate GPU firmware integrity between tenant transitions, and detect compromised AI infrastructure. The Inception program badge is prominently displayed on the AI Data Center Security product page.
- SIEM / SOAR ecosystem (integrations)core technology integrationEclypsium provides configurable alerts, REST APIs, and native SIEM/SOAR integration to enrich existing security operations with component-level inventory, vulnerability, and threat data for automated response workflows.
- Multi-OEM hardware vendor ecosystemcore technology integrationEclypsium's platform supports firmware-level inspection and supply chain validation across hardware from Cisco, F5, Fortinet, Juniper, Palo Alto Networks, Arista, Aruba, Ivanti/Pulse Secure, Extreme Networks, HP, Lenovo, Dell, Apple, Intel, HPE, Microsoft, AMD, VMware, Supermicro, Quanta, and Fujitsu — these are supported technology integrations rather than commercial partnerships.
Scale indicators11 records
Recent moves8 records
Expansion highlights6 records
Eclypsium competitors and assessment
Company assessmentEmerging players
- Medcrypt: Medcrypt delivers cybersecurity for connected medical devices with a focus on vulnerability management and SBOM workflows, sharing Eclypsium's firmware-level approach in the healthcare vertical.
- Armis: Armis delivers an asset intelligence and security platform for managed, unmanaged, and IoT/OT devices, with overlapping device-discovery, firmware-visibility, and vulnerability management capabilities.
- Claroty: Claroty provides cybersecurity for OT, IoT, and BMS in critical infrastructure, with comparable asset visibility and vulnerability management use cases for industrial and connected environments.
- Nozomi Networks: Nozomi Networks provides OT and IoT security with deep asset visibility, vulnerability management, and threat detection across critical infrastructure — adjacent to Eclypsium's firmware supply chain and network device coverage.
Broad incumbents
- SentinelOne: SentinelOne's Singularity platform is broadening into firmware integrity, AI workload protection, and supply chain security, creating potential overlap with Eclypsium's server and AI infrastructure modules.
- CrowdStrike: CrowdStrike's Falcon platform is extending into firmware security and supply chain risk management, positioning it as a broad incumbent that could compete with Eclypsium's endpoint and server coverage as part of a larger enterprise bundle.
Direct peers
- Phosphorus Cybersecurity: Phosphorus provides xIoT (extended IoT) security including firmware visibility and remediation, acquired by Palo Alto Networks in 2023. Directly overlaps with Eclypsium's device-level firmware monitoring scope.
- RunSafe Security: RunSafe Security specializes in firmware cybersecurity and runtime binary hardening for embedded systems and OT/ICS, offering directly comparable firmware-level protection against memory corruption and supply chain attacks.
- Finite State: Finite State provides firmware supply chain security, SBOM/FBOM analysis, and vulnerability management for connected devices and critical infrastructure — the closest direct competitor to Eclypsium in firmware SBOM and embedded system risk.
- Binarly: Binarly focuses on firmware vulnerability detection and AI-assisted binary analysis at the UEFI/BIOS layer — overlapping directly with Eclypsium's Automata engine and below-OS threat detection capabilities.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Eclypsium social profiles
Digital presenceEclypsium compliance and trust
Trust signalCompliance8 records
Eclypsium financial estimates
Financial estimateRevenue estimate
Valuation estimate
Eclypsium leadership team
Management profileNumber of profiles
Profiles9 records
Eclypsium subsidiaries and ownership
Company hierarchySubsidiaries1 record
Eclypsium funding detail
Funding detailFunding overview
Funding rounds9 records
Investors24 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Eclypsium M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Eclypsium
What does Eclypsium do?
Eclypsium provides a SaaS-based digital supply chain security platform that performs agentless and agent-based inspection of firmware, hardware components, and device integrity across endpoints, servers, network devices, and AI infrastructure. The platform unifies component inventory (SBOM/FBOM/HBOM), firmware vulnerability management against a database of 12M+ known-good firmware hashes, continuous integrity monitoring, AI-assisted binary analysis (Eclypsium Automata), and integration with SIEM/SOAR systems via REST APIs. It is sold to Fortune-class enterprises and government agencies via direct field sales with quote-based subscription pricing.
Is Eclypsium a public or private company?
Eclypsium is a private company. It is classified as venture growth investor backed and is currently operating.
When was Eclypsium founded?
Eclypsium was founded in 2017. It employs 51 to 100 people.
Where is Eclypsium based?
Eclypsium is headquartered in Portland, United States, in the North America region.
How does Eclypsium make money?
Three revenue lines are on record. SaaS Platform Subscription is the primary driver. The others are enterprise / Financial Services Deployments and government / Public Sector Contracts.
Who are Eclypsium's main competitors?
Emerging players on record are Medcrypt, Armis, Claroty and Nozomi Networks. Broad incumbents are SentinelOne and CrowdStrike. Direct peers are Phosphorus Cybersecurity, RunSafe Security, Finite State and Binarly.
Does Eclypsium have an API?
Yes. Eclypsium provides REST APIs that allow developers and security teams to build custom integrations and automate response actions. The platform exposes configurable alerts via REST APIs for integration with downstream security and IT operations systems. It also supports automated threat response workflows as part of its enterprise integration and automation capabilities.
What industry is Eclypsium in?
Eclypsium's product category is Firmware and Hardware Supply Chain Security. Its primary akta.pro industry code is HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing), with a secondary code of HDADAFAJ, Confidential Computing & Hardware-backed Protection (TEE/HSM). Its NAICS code is 54151 and its SIC code is 7370.