Prove & Run
ProvenRun builds formally proven, Common Criteria EAL7-certified secure operating systems and HSMs for automotive, semiconductor, aerospace/defense, and IoT OEMs. It licenses ProvenCore/ProvenCore-M/ProvenVisor/ProvenHSM to chipmakers and tier-1 suppliers worldwide.
- Company typePrivate
- Founded2009
- HeadquartersParis, France
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Prove & Run does
ProvenRun is a Paris-based cybersecurity software company founded in 2009 that builds formally proven secure operating systems, real-time operating systems, hypervisors, hardware security modules, and trusted applications for connected and safety-critical devices. Its core technology uses deductive formal methods to mathematically verify security properties down to generated machine code; ProvenCore is the world's first and only operating system to achieve Common Criteria EAL7 certification, and ProvenCore-M is certified at PSA/SESIP Level 3 for microcontrollers. The product portfolio—ProvenCore, ProvenCore-M, ProvenVisor, ProvenApps, ProvenBox, and the next-generation ProvenHSM—targets automotive (notably Software Defined Vehicles via the Ampere/Renault 'Protocol Breaker' co-development), semiconductors (STMicroelectronics, SiFive, Arm), aerospace and defense, cloud/telecom/Web3, and IoT. ProvenRun monetizes through software licensing and certification kits, complemented by professional services (security consulting, engineering, training) and support/maintenance packages, selling primarily via direct enterprise sales, OEM/embedded distribution, and channel partners such as Atos. In December 2023 the company closed a €15M Series A led by Tikehau Capital with the French Ministry of Defence's Definvest fund to accelerate product development and North American expansion.
Prove & Run firmographics
Firmographics- Name
- Prove & Run
- Legal name
- ProvenRun
- Website
- https://provenrun.com
- Company type
- Private
- Founded year
- 2009
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- ProvenRun builds formally proven, Common Criteria EAL7-certified secure operating systems and HSMs for automotive, semiconductor, aerospace/defense, and IoT OEMs. It licenses ProvenCore/ProvenCore-M/ProvenVisor/ProvenHSM to chipmakers and tier-1 suppliers worldwide.
- Ownership category
- akta.pro rank
Prove & Run industry classification
Industry- Product category
- Embedded Cybersecurity Software
- NAICS
- Computer Systems Design and Related Services (54151), Computer Systems Design and Related Services (5415), Scientific Research and Development Services (5417), Security Systems Services (56162)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Secure Elements & Trusted Execution Processors (TPM/TEE/Crypto MCUs) (HDAHAJAK)
- akta.pro secondary industries
- Security & Trusted Hardware ICs (Secure Element/TPM/Crypto) (HDAHABAF), Cybersecurity for Financial Services Compliance (controls, audits, SOC/ISO mapping) (FSAGAFAK)
Keywords
Where Prove & Run is headquartered
LocationHeadquarters
- HQ city
- Paris
- HQ country
- France
- HQ region
- Europe
Offices3 records
Markets served
Prove & Run business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Software Licensing: ProvenRun licenses its secure OS, RTOS, hypervisor, and HSM products to semiconductor companies, automotive OEMs, and IoT device manufacturers. Licensing includes certification support and is typically structured as multi-year contracts with major customers integrating ProvenCore into their certified platforms.
- Professional Services: Comprehensive services including security consulting (risk analysis, security architecture, certification support), engineering (Secure Boot, TEE development, trusted application development), and support/maintenance. Training led by experts in security and embedded software development. Board support packages for Arm and RISC-V processors.
- Certification Kits: ProvenRun provides certification kits that enable customers to achieve security certifications more efficiently. Includes documentation, test suites, and support for Common Criteria, PSA Certified, and industry-specific certification requirements.
Go-to-market motion3 records
Distribution channels4 records
Marketing channels5 records
Prove & Run product offering
Product offeringCore offering
Prove & Run (ProvenRun) develops and licenses formally proven secure operating systems, real-time operating systems, hypervisors, hardware security modules, and trusted applications for embedded and connected devices. Products including ProvenCore (EAL7-certified OS), ProvenCore-M (PSA/SESIP Level 3 RTOS), ProvenVisor (hypervisor), ProvenHSM, and ProvenApps serve automotive, semiconductor, aerospace/defense, IoT, and cloud/telecom customers with mathematically verified security foundations.
Differentiator
Problem solved
Functional benefit
Brands
- ProvenCore: Secure OS/TEE for microprocessors - formally proven at EAL7 level
- ProvenCore-M
- ProvenApps
- ProvenBox
- ProvenHSM
- ProvenVisor
Products and services
- ProvenCore Ultra-secure OS developed using deductive formal methods and certified at the highest level of security (EAL7 on Common Criteria). Provides the best foundation to develop secure-by-design complex connected devices in a cost-effective way, serving automotive, aerospace/defense, and semiconductor customers.
- ProvenCore-M Secure Real-Time Operating System (RTOS) certified at the highest level of security for IoT (PSA/SESIP level 3). Provides a highly secure foundation at industrial costs for hardware-constrained microcontrollers, with compatibility to standard APIs.
- ProvenVisor Secure hypervisor for ARMv8-A architecture with hardware virtualization extensions, enforcing strong security properties on Virtual Machines with minimal Trusted Computing Base. Supports Common Criteria EAL5 certification.
- ProvenHSM Next-generation Hardware Security Module that combines strong certifications with cloud-ready performance. Built on the formally proven ProvenCore OS with post-quantum cryptography (PQC) support, high throughput, large secure storage, elastic multi-tenant scaling, and easy integration through standard REST and PKCS#11 interfaces. A SDK enables application development without losing certifications.
- ProvenApps Modular trusted applications and secure services that can be integrated into ProvenCore or ProvenCore-M environments. Includes secure storage, cryptography, network, VPN, filters, firmware update, and key provisioning, ensuring flexibility and scalability across different security requirements.
- ProvenBox Secure appliance solution for embedded and cloud environments, leveraging ProvenRun's formally proven secure OS foundation to deliver hardware-isolated security services.
- Protocol Breaker Innovative cybersecurity IP co-developed with Ampere for automotive Software Defined Vehicle (SDV) platforms. Creates secure pathways for in-vehicle Ethernet communications by separating 'Front' and 'Back' segments with formal isolation, reducing vulnerability exposure significantly. Uses Rust for memory-safe development.
- Security Consulting Professional consulting services covering risk analysis, security architecture design, and certification support for customers in embedded security and connected devices.
- Security Engineering and Development Engineering and development services including Secure Boot implementation, Trusted Execution Environment (TEE) development, and trusted application development. Includes training led by experts in security and embedded software development.
- Support and Maintenance Comprehensive support and maintenance offering product documentation, knowledge base, support packages, and technical advice from developers, engineers, and architects. Includes board support packages for Arm and RISC-V microprocessors and microcontrollers.
Quantifiable outcome
- Mathematical proof of correctness eliminates entire classes of errors versus reactive testing approaches
- +2 more outcomes
Companies that use Prove & Run
Customer profileNamed customers4 records
Segments5 records
Ideal customer profiles5 records
Prove & Run technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration7 records
Feature8 records
Prove & Run partnerships and signals
Strategic signalPartnerships
Twelve partnerships are on record, tiered strategic, flagship, core and minor.
- CryptoNext SecuritystrategicIntegration of post-quantum cryptography into ProvenHSM, providing fully integrated high-assurance end-to-end security stack for post-quantum era. Reinforces shared ambition for secure cryptographic infrastructure in demanding environments.
- Ampere (Renault Group)flagshipStrategic collaboration to secure onboard communications on Ampere's future Software Defined Vehicle platforms. ProvenRun co-develops Protocol Breaker cybersecurity IP using Rust and ProvenCore, specifically designed for SDV environments. Includes live demonstration at CES 2024.
- SiFivecoreProvenCore integrated with SiFive WorldGuard technology providing SoC-level mechanism for software isolation on RISC-V platforms. Combines hardware-enhanced WorldGuard isolation with formally proven ProvenCore OS for best-in-class security on RISC-V architectures.
- RISC-V InternationalminorStrategic member supporting free and open RISC-V instruction set architecture. ProvenRun contributes to technical direction emphasizing that security is paramount, already providing ProvenCore TEE for RISC-V platforms.
- CinemostrategicWorld's first DRM implementation of GlobalPlatform Secure Media Path Protection Profile. ProvenCore TEE combined with Cinemo's Widevine L1 Trusted Application for automotive multimedia protection. Demonstrated at CES 2022 for premium video-on-demand streaming in vehicles.
- AtosstrategicSelected to join Atos Scaler accelerator program as supplier of Trusted Products and Services for embedding security in connected device infrastructure. Atos program dedicated to start-ups complementing their industry-centric portfolio.
- GAIA-XminorDay-1 member of European initiative defining next generation data infrastructure aligned with European values. Working with other members to bring higher level of security and trust to cloud services.
- MicrosoftstrategicMain contributor to Microsoft's Edge Compute Node Protection Profile, a Common Criteria (ISO 15408) standard for engineering, evaluating, and consuming security for IoT devices. Leverages ProvenRun's expertise in Common Criteria, certification, and IoT security.
- ArmcoreProvenRun supports Arm's certified Cortex-M33 and Cortex-M35P soft processor IPs (EAL6+ certified) with ProvenCore secure OS. Enables industry to develop cost-effective security solutions trusted at high assurance levels.
- European Processor Initiative (EPI)strategicSecurity technology partner in major European initiative designing low-power processors for extreme scale computing. Dr. Dominique Bolignano serves as Global Security Technical Leader. Project involves 26 participants financed by EU Horizon 2020.
- KalraystrategicStrategic partnership to bring security to Kalray's manycore MPPA architectures for Cyber Physical Systems. ProvenRun provides security architecture expertise and certified OS solutions for high-end security services on high-performance computing platforms.
- ES3CAP ProjectstrategicSecurity technology partner in Kalray-led ES3CAP project building environment for critical applications on MPPA hardware platform. Project supported by automotive, aerospace, and defense manufacturers including Renault-Nissan-Mitsubishi, MBDA, and Safran.
Scale indicators4 records
Recent moves6 records
Expansion highlights5 records
Prove & Run competitors and assessment
Company assessmentDirect peers
- Green Hills Software: Developer of the INTEGRITY RTOS and high-assurance secure operating systems used in automotive, aerospace, defense, and industrial applications. Directly competes with ProvenCore in the certified embedded OS market, particularly for EAL-certified deployments.
- BlackBerry QNX: Provider of QNX Neutrino RTOS, a foundational secure operating system for automotive instrument clusters, ADAS, and infotainment. Directly overlaps with ProvenRun's automotive SDV and secure ECU ambitions.
- Wind River Systems: Vendor of VxWorks RTOS and Helix virtualization, serving aerospace/defense, automotive, and industrial IoT. Competes head-to-head with ProvenCore-M and ProvenVisor in safety- and security-certified embedded environments.
- SYSGO: Developer of PikeOS, a certified RTOS and hypervisor for safety- and security-critical embedded systems in automotive, aerospace, and railway. Directly comparable to ProvenVisor's ARMv8-A secure virtualization value proposition.
- Lynx Software Technologies: Provider of LynxOS and the Mosaik hypervisor for mission-critical and security-focused embedded deployments in defense and industrial markets. Competes with ProvenRun in high-assurance secure OS for sensitive workloads.
- Trustonic: Supplier of the Kinibi TEE for mobile, automotive, and IoT devices. Directly competes with ProvenCore in TEE deployments on ARM TrustZone-enabled chips for transaction isolation and secure services.
- KasperskyOS: Secure-by-design microkernel OS targeting industrial IoT, critical infrastructure, and embedded systems. Comparable secure OS positioning in regulated verticals, particularly in EMEA markets.
Emerging players
- Sequitur Labs: Provides IoT security frameworks and TEE-based solutions for AI/ML workloads at the edge. Overlaps with ProvenRun in securing connected devices but emphasizes different verticals and runtime isolation strategies.
- Hex Five Security: Developer of MultiZone Security for RISC-V, providing hardware-enforced isolation for multiple trusted execution zones. Competes with ProvenRun in the emerging RISC-V TEE market.
- wolfSSL: Embedded TLS/crypto library provider widely used in IoT, automotive, and industrial. Adjacent competitor in the embedded security stack where ProvenApps and ProvenCore-M integrate cryptography.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Prove & Run social profiles
Digital presenceProve & Run financial estimates
Financial estimateRevenue estimate
Valuation estimate
Prove & Run leadership team
Management profileNumber of profiles
Profiles5 records
Prove & Run funding detail
Funding detailFunding overview
Funding rounds1 record
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Prove & Run M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Prove & Run
What does Prove & Run do?
Prove & Run (ProvenRun) develops and licenses formally proven secure operating systems, real-time operating systems, hypervisors, hardware security modules, and trusted applications for embedded and connected devices. Products including ProvenCore (EAL7-certified OS), ProvenCore-M (PSA/SESIP Level 3 RTOS), ProvenVisor (hypervisor), ProvenHSM, and ProvenApps serve automotive, semiconductor, aerospace/defense, IoT, and cloud/telecom customers with mathematically verified security foundations.
Is Prove & Run a public or private company?
Prove & Run is a private company. It is classified as venture growth investor backed and is currently operating.
When was Prove & Run founded?
Prove & Run was founded in 2009. It employs 11 to 50 people.
Where is Prove & Run based?
Prove & Run is headquartered in Paris, France, in the Europe region.
How does Prove & Run make money?
Three revenue lines are on record. Software Licensing is the primary driver. The others are professional Services and certification Kits.
Who are Prove & Run's main competitors?
Direct peers on record are Green Hills Software, BlackBerry QNX, Wind River Systems, SYSGO, Lynx Software Technologies, Trustonic and KasperskyOS. Emerging players are Sequitur Labs, Hex Five Security and wolfSSL.
Does Prove & Run have an API?
No public API is recorded for Prove & Run.
What industry is Prove & Run in?
Prove & Run's product category is Embedded Cybersecurity Software. Its primary akta.pro industry code is HDAHAJAK, Secure Elements & Trusted Execution Processors (TPM/TEE/Crypto MCUs), with a secondary code of HDAHABAF, Security & Trusted Hardware ICs (Secure Element/TPM/Crypto). Its NAICS code is 54151 and its SIC code is 7371.