Moabi
Moabi sells an automated binary-analysis SaaS platform that audits software, firmware and IoT/automotive/telecom products for vulnerabilities, SBOM and regulatory compliance (CRA, NIS2, DORA) without requiring source code, targeting European enterprise customers via direct field sales.
- Company typePrivate
- Founded2020
- HeadquartersParis, France
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Moabi does
Moabi (legal entity MOABI Solutions) is a French cybersecurity company founded in 2020 and headquartered in Sophia Antipolis (Valbonne), with a secondary presence at STATION F in Paris alongside Thales. It sells an automated product-security audit platform that analyzes software, firmware and containers without requiring access to source code. The core technology combines static and dynamic binary analysis, integrates the Witchcraft Compiler Collection (WCC) framework for sub-millisecond CVE confirmation on stripped binaries, and produces Software Bills of Materials (SBOM) and Cryptographic Bills of Materials (CBOM) directly from deployed binaries, including statically linked components invisible to package managers. The platform also enriches CVEs with KEV, EPSS and SVCC data and assesses binary hardening (ASLR, RELRO, NX, FORTIFY, stack canaries) at scale, with stated capacity of up to 10,000 binaries every four hours.
The commercial offering is delivered as a SaaS subscription covering the core MOABI Platform plus vertical modules for Connected Vehicles, IoT/Distributed Sensors, Industry 4.0/IIoT, 5G/Telecom, and Supply Chain Security. Go-to-market is direct enterprise field sales, with pricing not publicly disclosed and demos routed through the company website. Moabi explicitly positions against the EU Cyber Resilience Act, NIS2 and DORA regulatory frameworks, and the company has built an innovation consortium with EURECOM, INRIA and Campus Cyber under the ASCiDy technology transfer programme to add dynamic analysis (fuzzing) to the platform. The only named reference customer is Thales DIS, which provides two separate enterprise testimonials in defense and security.
Operationally, Moabi is an early-stage company with 1-10 employees, a single disclosed $500,000 funding round dated January 2022 with unnamed investors, no public revenue disclosure, and founder-CEO/CTO Jonathan Brossard as the sole identified member of the management team. The company is also affiliated with STATION F and Sophia Antipolis, two of France's most prominent technology hubs, which is relevant to its positioning within the French sovereign cybersecurity ecosystem.
Moabi firmographics
Firmographics- Name
- Moabi
- Legal name
- MOABI Solutions
- Website
- https://moabi.com
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Moabi sells an automated binary-analysis SaaS platform that audits software, firmware and IoT/automotive/telecom products for vulnerabilities, SBOM and regulatory compliance (CRA, NIS2, DORA) without requiring source code, targeting European enterprise customers via direct field sales.
- Ownership category
- akta.pro rank
Moabi industry classification
Industry- Product category
- Application Security Software
- NAICS
- Computer Systems Design and Related Services (5415), Testing Laboratories and Services (541380)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC)
Keywords
Where Moabi is headquartered
LocationHeadquarters
- HQ city
- Paris
- HQ country
- France
- HQ region
- Europe
Offices2 records
Markets served
Moabi business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Infrastructure, Marketing or Sales, Operations
Revenue model
- SaaS Subscription - Automated Security Audits: The MOABI platform offers automated security audits and KPIs as a SaaS subscription service, enabling organizations to continuously assess product security, supplier security levels, and maintain compliance with regulatory frameworks (Cyber Resilience Act, NIS2, DORA). The platform analyzes binaries, firmwares and containers as deployed, generating SBOMs and detailed security reports.
Go-to-market motion1 record
Distribution channels1 record
Marketing channels6 records
Moabi product offering
Product offeringCore offering
The MOABI platform offers automated security audits and key performance indicators to assess product security. It automates the analysis and testing of thousands of software products, binaries, firmware and containers without requiring source code, based on security standards, best practices, and detection of known vulnerabilities and 0-Days. The platform generates Software Bills of Materials (SBOMs) directly from deployed binaries, performs continuous 24/7 vulnerability monitoring, and integrates with CI/CD pipelines to support regulatory compliance (Cyber Resilience Act, NIS2, DORA).
Product overview
MOABI offers a unified automated security audit platform with sector-specific modules. The core MOABI Platform provides binary analysis, SBOM generation, and vulnerability detection without source code access. This is supplemented by industry-specific solutions for Connected Vehicles, IoT/Distributed Sensors, Industry 4.0/IIoT, and 5G/Telecom sectors, plus a Supply Chain Security module. All solutions share the platform's core capabilities including automated audits, 24/7 vulnerability monitoring, and CI/CD integration, while offering tailored analysis approaches for each vertical.
Differentiator
Problem solved
Functional benefit
Products and services
- MOABI Platform Automated binary analysis platform for product security audits that analyzes software, firmware, and containers without requiring source code, generates SBOMs, measures cybersecurity posture, and detects vulnerabilities including 0-days. Includes automated software audits, source code-free analysis, SBOM generation, reports and remediation plans, CI/CD integration, and 24/7 vulnerability monitoring.
- Connected Vehicle Security Audits Vertical-specific security auditing solution for connected vehicles (land, air, sea, rail, defense) that analyzes and improves embedded software security without requiring source code. Covers in-house and third-party software, generates S-BOMs, and produces detailed analysis reports for automotive, aerospace, naval, rail, and defense industries.
- IoT / Distributed Sensors Security Audits Security auditing solution for IoT products, distributed sensors, and actuators that performs in-depth analysis and testing of connected device firmware without source code. Assesses strengths and weaknesses of IoT firmware to enable rapid threat response and device comparison based on cybersecurity criteria.
- Industry 4.0 / IIoT Security Audits Cybersecurity audit solution to evaluate and test new Industry 4.0 systems and equipment including IIoT, 3D printing, robotics, and cyber-physical systems. Enables manufacturers to compare suppliers, demand high security levels during selection, and drive continuous cybersecurity improvement through detailed audits and reports.
- 5G / Telecom Security Audits Automated cybersecurity audit solution for telecom software, operating systems, applications, and firmware without requiring source code. Provides comprehensive assessment across in-house R&D products, third-party vendors, and open-source software for telecom operators and digital service providers rolling out 5G and OSS/BSS platforms.
- Supply Chain Security Audits Supply chain security audit solution that protects products from the design stage through delivery with systematic and consistent cybersecurity criteria for supplier selection and benchmarking. Prevents software bugs and vulnerabilities from propagating from suppliers to end users.
Quantifiable outcome
- Up to 10,000 binaries analyzed every 4 hours
- +2 more outcomes
Companies that use Moabi
Customer profileNamed customers2 records
Segments4 records
Ideal customer profiles4 records
Moabi technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability4 records
Feature10 records
Moabi partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core, supporting and minor.
- EURECOMcoreEURECOM, recognized worldwide for research in cybersecurity and software instrumentation, leads the ASCiDy project alongside MOABI as a Programme de Transfert de Technologie aux Campus Cyber (PTCC). The partnership aims to integrate dynamic analysis (fuzzing) capabilities into the MOABI platform for source-code-free software testing and zero-day vulnerability detection.
- INRIAsupportingINRIA (French National Institute for Research in Digital Science and Technology) supports the ASCiDy project as a catalyst for technology transfer and guarantor of French innovation promotion, working with EURECOM and MOABI on sovereign cybersecurity innovation.
- Campus CybersupportingCampus Cyber serves as a catalyst for technology transfer and guarantor of innovation promotion within the ASCiDy project, contributing to building a sovereign ecosystem of product cybersecurity innovation anchored in Sophia-Antipolis.
- SNCFminorSNCF participated in discussions at Cyber On Board 2026 conference, sharing expertise on transport sector cybersecurity challenges including long lifecycles, multiple suppliers, critical embedded components, and NIS2 obligations on heterogeneous systems.
Scale indicators2 records
Recent moves6 records
Expansion highlights5 records
Moabi competitors and assessment
Company assessmentDirect peers
- ReversingLabs: ReversingLabs provides binary analysis and software supply chain security, including file and binary reputation services, SBOM generation, and malware detection without source code access. Directly comparable to Moabi's core value proposition of source-code-free vulnerability detection for software supply chains.
- Cybellum: Cybellum (acquired by Keysight) provides a product security platform for connected devices and embedded software, performing binary-level vulnerability analysis and SBOM generation without source code. Closely comparable to Moabi's connected vehicle, IoT, and Industry 4.0 verticals with the same source-code-free approach.
- Sonatype: Sonatype's Nexus platform provides software supply chain security, SBOM management, and vulnerability intelligence for development teams. Comparable to Moabi in the SBOM and supply chain security category, though Sonatype relies more on package metadata than Moabi's binary-level analysis.
- Anchore: Anchore provides SBOM generation, container security, and software supply chain compliance platforms used by enterprises for vulnerability management and regulatory alignment. Comparable to Moabi's SBOM and continuous monitoring capabilities, with overlap in CRA/NIS2 compliance use cases.
Broad incumbents
- JFrog Xray: JFrog Xray is part of the broader JFrog DevSecOps platform, providing binary-level vulnerability scanning and software composition analysis alongside artifact management. Comparable capabilities in binary scanning but as part of a wider DevOps suite rather than a focused product security tool.
- Synopsys (Black Duck): Synopsys Black Duck is an established software composition analysis and SBOM platform covering open source vulnerability management and license compliance. Comparable to Moabi in software supply chain security but as part of Synopsys's broader portfolio including SAST and DAST.
- Snyk: Snyk is a developer security platform with capabilities spanning SBOM, software composition analysis, and container security. Comparable to Moabi in supply chain security positioning, but with broader developer tooling focus and significantly larger scale.
- Veracode: Veracode is an established application security testing platform covering SAST, DAST, and software composition analysis. Comparable to Moabi in vulnerability detection for enterprise software but as part of a broader application security suite rather than a source-code-free binary specialist.
Emerging players
- VicOne: VicOne specializes in automotive cybersecurity, providing vulnerability management and SBOM solutions for connected vehicles. Highly comparable to Moabi's connected vehicle vertical focus, though narrower in scope with deeper automotive OEM relationships.
Regional players
- Kudelski Security: Kudelski Security provides cybersecurity services and IoT/connected product security testing, including binary analysis and reverse engineering capabilities. Comparable to Moabi's binary analysis approach for connected products, with stronger presence in Switzerland and the US than France.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
Moabi social profiles
Digital presenceMoabi financial estimates
Financial estimateRevenue estimate
Valuation estimate
Moabi leadership team
Management profileNumber of profiles
Profiles1 record
Moabi funding detail
Funding detailFunding overview
Funding rounds2 records
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Moabi M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Moabi
What does Moabi do?
The MOABI platform offers automated security audits and key performance indicators to assess product security. It automates the analysis and testing of thousands of software products, binaries, firmware and containers without requiring source code, based on security standards, best practices, and detection of known vulnerabilities and 0-Days. The platform generates Software Bills of Materials (SBOMs) directly from deployed binaries, performs continuous 24/7 vulnerability monitoring, and integrates with CI/CD pipelines to support regulatory compliance (Cyber Resilience Act, NIS2, DORA).
Is Moabi a public or private company?
Moabi is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Moabi founded?
Moabi was founded in 2020. It employs 1 to 10 people.
Where is Moabi based?
Moabi is headquartered in Paris, France, in the Europe region.
How does Moabi make money?
One revenue line is on record: saaS Subscription - Automated Security Audits.
Who are Moabi's main competitors?
Direct peers on record are ReversingLabs, Cybellum, Sonatype and Anchore. Broad incumbents are JFrog Xray, Synopsys (Black Duck), Snyk and Veracode. VicOne is listed as an emerging player. Kudelski Security is listed as a regional player.
Does Moabi have an API?
No public API is recorded for Moabi.
What industry is Moabi in?
Moabi's product category is Application Security Software. Its primary akta.pro industry code is HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing), with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 5415 and its SIC code is 7372.