Raelize
Raelize is a Dutch boutique consultancy founded in 2020 that provides embedded device security consultancy, penetration testing, and training, with deep specialization in Fault Injection attacks, TEE exploitation, and AI-assisted hardware vulnerability research.
- Company typePrivate
- Founded2020
- HeadquartersRotterdam, Netherlands
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Raelize does
Raelize B.V. is a Dutch boutique consultancy founded in 2020 in Rotterdam by Cristofaro Mune and Niek Timmers, providing embedded device security consultancy, testing, and training services to organizations developing SoCs, IoT products, and connected devices across mobile, payment, automotive, industrial, and IoT markets. The firm's core technical capability is hardware-level security assessment, with particular depth in Fault Injection attacks (including voltage glitching and ElectroMagnetic Fault Injection), Secure Boot bypass, Trusted Execution Environment exploitation, flash encryption bypass, and OTP memory analysis. Raelize has disclosed multiple CVEs against the Espressif ESP32 family (CVE-2019-15894, CVE-2019-17391, CVE-2020-13629, CVE-2020-15048) and demonstrated a single EM-glitch privilege escalation to root on Google TV Streamer 4K's Mediatek MT8696.
The firm develops and publishes proprietary research artifacts: the FIRM (Fault Injection Reference Model) methodology, a custom TAoFI Target development board exposing separate power-domain headers and SPI flash routing on an ESP32, and Python tooling for orchestrating and visualizing ChipWhisperer glitch campaigns. Most distinctively, Raelize has documented an AI-assisted Fault Injection workflow (AI-FI) in which Claude Code autonomously writes attack scripts, configures lab hardware, debugs issues, and builds live monitoring dashboards, achieving a 57.5% success rate bypassing ESP32 Secure Boot V1 without any human-authored code. The training portfolio includes TAoFI (The Art of Fault Injection) and TEEPwn, a hands-on gamified CTF-style Trusted Execution Environment training offered both privately and through public conference cohorts.
Raelize's business model rests entirely on professional services: time-and-materials consultancy engagements, project-based penetration testing and code or architecture reviews, and training delivered either privately on customer sites or publicly through conferences and institutional hosts. Publicly disclosed training pricing is €3,000 per attendee for remote cohorts and €4,250 for in-person classroom cohorts. Distribution is direct via the firm's website and email, augmented by channel partnerships with Ringzer0 (nullcon, hardwear.io), Payatu (nullcon, hardwear.io), and NFI (Netherlands Forensic Institute). The firm is privately held with no disclosed external funding, headcount in the 1–10 range, and operations anchored in the Netherlands while serving clients globally.
Raelize firmographics
Firmographics- Name
- Raelize
- Legal name
- Raelize B.V.
- Website
- https://raelize.com
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Raelize is a Dutch boutique consultancy founded in 2020 that provides embedded device security consultancy, penetration testing, and training, with deep specialization in Fault Injection attacks, TEE exploitation, and AI-assisted hardware vulnerability research.
- Ownership category
- akta.pro rank
Raelize industry classification
Industry- Product category
- Embedded Device Security Services
- NAICS
- Testing Laboratories and Services (54138), Other Scientific and Technical Consulting Services (54169)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Security Risk Assessment, Auditing & Security Consulting Training (BPAKAOAH)
- akta.pro secondary industry
- Breach & Attack Simulation (BAS) (HDADAHAD)
Keywords
Where Raelize is headquartered
LocationHeadquarters
- HQ city
- Rotterdam
- HQ country
- Netherlands
- HQ region
- Europe
Offices1 record
Markets served
Raelize business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Device Security Consultancy: Expert consulting engagements where Raelize leverages their deep knowledge of device-level security (Secure Boot, TEEs) and advanced testing techniques to improve product security design and implementation.
- Device Security Testing: Security testing engagements evaluating product security and verifying assumptions, including penetration testing of embedded devices, code reviews of secure applications, and architecture reviews of SoCs and TEE operating systems.
- Device Security Training: Hands-on training programs delivered both publicly (at conferences) and privately (on-site at manufacturers/labs), covering Fault Injection, TEE security, and embedded device security concepts. Revenue generated through training fees.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| One time/ perpetual license | Multi-year contract | TEEPwn Online Training - Remote |
| One time/ perpetual license | Multi-year contract | TEEPwn Classroom Training - NFI, Netherlands |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels5 records
Raelize product offering
Product offeringCore offering
Raelize is a boutique embedded device security consultancy that sells three core services: Device Security Consultancy (improving product security design around Secure Boot, TEEs, and SoC architecture), Device Security Testing (penetration testing, secure code/architecture reviews of embedded devices, SoCs and TEE operating systems), and Device Security Training (TAoFI and TEEPwn hands-on courses on Fault Injection and TEE exploitation). The firm delivers services globally via direct engagement, conference partnerships, and private on-site training.
Product overview
Raelize is a device security services consultancy offering three core services: Device Security Consultancy, Device Security Testing, and Device Security Training. Their training portfolio includes TEEPwn (Trusted Execution Environment training) and TAoFI (The Art of Fault Injection training). They publish research including the FIRM (Fault Injection Reference Model) framework and detailed security analyses of embedded devices like ESP32 and Google TV Streamer. The company focuses on hardware security, fault injection attacks, and embedded system vulnerabilities.
Differentiator
Problem solved
Functional benefit
Brands
- TAoFI (The Art of Fault Injection): Advanced Fault Injection training program covering concepts, methodologies, techniques, and real-world fault injection attacks on embedded devices.
- TEEPwn
- FIRM (Raelize Fault Injection Reference Model)
Products and services
- Device Security Consultancy Professional service that helps embedded device manufacturers improve product security design and implementation, leveraging deep knowledge of Secure Boot, Trusted Execution Environments, and advanced testing techniques such as Fault Injection.
- Device Security Testing Security evaluation service that tests, breaks, and secures products at a professional lab level across Mobile, Payment, Automotive, Industrial, and IoT markets; includes penetration testing, secure code reviews of trusted applications, and architecture reviews of SoCs and TEE operating systems.
- Device Security Training Hands-on training programs covering Fault Injection, TEE security, and embedded device security; delivered publicly at conferences and privately at manufacturer/lab sites to develop workforce knowledge and skills.
- TEEPwn (Trusted Execution Environment Training) Hands-on, gamified Capture the Flag training focused on Trusted Execution Environment security, teaching offensive system-level perspective and exploitation of TEE vulnerabilities in ARMv8 TrustZone-based environments for security analysts and researchers.
- TAoFI (The Art of Fault Injection Training) Advanced training program covering Fault Injection concepts, methodologies, techniques, and attacks; students learn to perform real-world Fault Injection attacks on embedded targets such as ESP32 using ChipWhisperer-Husky and other commercial tooling.
Quantifiable outcome
- ESP32 Secure Boot bypassed using EMFI on silicon revision 0 and 1, leading to multiple CVEs (CVE-2019-15894, CVE-2019-17391, CVE-2020-13629, CVE-2020-15048)
- +2 more outcomes
Companies that use Raelize
Customer profileNamed customers4 records
Segments4 records
Ideal customer profiles2 records
Raelize technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability4 records
Feature4 records
Raelize partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered moderate and core.
- NFI (Netherlands Forensic Institute)moderateNFI (Netherlands Forensic Institute) hosts Raelize's TEEPwn classroom training in the Netherlands from April 7-10, 2026. NFI provides the physical training location and institutional backing, while Raelize delivers the training content and expertise.
- RiscuremoderateRiscure CEO Marc Witteman provides a peer endorsement of Raelize's team, recommending them for their high ethical and quality standards. Witteman has worked with both founders (Cristofaro Mune and Niek Timmers) personally, indicating an existing professional relationship and mutual respect between the two embedded security firms.
- Ringzer0 TrainingcoreRaelize founders (Cristofaro Mune and Niek Timmers) have served as trainers at Ringzer0's flagship events nullcon and hardwear.io for multiple years. Their research has consistently attracted technical audience attention and industry recognition. Ringzer0 provides the event platform and audience while Raelize provides expert training content.
- PayatucoreNiek Timmers and Cristofaro Mune have served as trainers at Payatu's flagship events nullcon and hardwear.io for two consecutive years. Payatu is a security research company that organizes high-profile hardware security conferences where Raelize provides training and research presentations.
Scale indicators1 record
Recent moves6 records
Expansion highlights6 records
Raelize competitors and assessment
Company assessmentDirect peers
- Riscure: Riscure is the most established dedicated hardware/embedded security lab, offering device security testing, side-channel and fault injection services, and tooling. Riscure's CEO Marc Witteman personally endorses Raelize's founders, signaling direct overlap in target customers (SoC manufacturers, security labs) and methodology (FI/EMFI attacks on embedded devices).
- IOActive: IOActive is a long-standing security consultancy with a dedicated hardware/embedded security practice covering smart cards, IoT, automotive, and consumer electronics. Directly competes for the same embedded device penetration testing and architecture review engagements as Raelize, with broader service breadth across software and network security.
- Red Balloon Security: Red Balloon Security specializes in embedded system and firmware security research and consulting, with deep expertise in hardware-level attacks and defenses. Targets the same SoC and IoT device manufacturer customers as Raelize, and operates in an overlapping niche of offensive embedded security research.
- Atredis Partners: Atredis Partners is a boutique security consultancy performing penetration testing and security research across hardware, firmware, mobile, and IoT. Closely matches Raelize's boutique research-driven model and embedded device testing focus, serving similar device manufacturer and enterprise clients.
- Payatu: Payatu organizes hardwear.io and nullcon (flagship hardware security conferences) and provides embedded/IoT security testing and research services. Direct channel partner and quasi-peer, sharing the same training conferences and overlapping customer base in embedded device security.
Broad incumbents
- NCC Group: NCC Group is a large global cybersecurity consultancy with a hardware/embedded device security practice alongside broader IT security offerings. Competes for embedded security testing engagements at much larger scale and with broader geographic footprint, but lacks Raelize's depth in advanced fault injection.
- Trail of Bits: Trail of Bits is a well-known security research and consulting firm with strength in software, blockchain, and applied cryptography. While not a direct FI competitor, it competes for premium security consulting engagements with similar research-driven positioning and publications-based marketing.
- Quarkslab: Quarkslab is a security consultancy and software vendor with deep binary analysis and reverse engineering capabilities, including embedded and TEE security work. Competes in the same high-end security research consultancy segment, though with stronger software analysis than hardware FI depth.
Emerging players
- Ringzer0 Training: Ringzer0 Training curates advanced security training content and events (hardwear.io, nullcon) where Raelize founders instruct. Closely aligned in positioning around hands-on, expert-led embedded security training, and serves as both partner and adjacent player in the security training market.
Others
- NewAE Technology: NewAE manufactures ChipWhisperer, the open-source side-channel and fault injection platform used in Raelize's FI tooling and TAoFI training. Indirect ecosystem participant as the tooling vendor that underpins Raelize's fault injection methodology and teaching infrastructure.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat3 records
Key risks5 records
Key highlights6 records
Customer concentration
Raelize social profiles
Digital presenceRaelize financial estimates
Financial estimateRevenue estimate
Valuation estimate
Raelize leadership team
Management profileNumber of profiles
Profiles2 records
Raelize funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Raelize M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Raelize
What does Raelize do?
Raelize is a boutique embedded device security consultancy that sells three core services: Device Security Consultancy (improving product security design around Secure Boot, TEEs, and SoC architecture), Device Security Testing (penetration testing, secure code/architecture reviews of embedded devices, SoCs and TEE operating systems), and Device Security Training (TAoFI and TEEPwn hands-on courses on Fault Injection and TEE exploitation). The firm delivers services globally via direct engagement, conference partnerships, and private on-site training.
Is Raelize a public or private company?
Raelize is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Raelize founded?
Raelize was founded in 2020. It employs 1 to 10 people.
Where is Raelize based?
Raelize is headquartered in Rotterdam, Netherlands, in the Europe region.
How does Raelize make money?
Three revenue lines are on record. Device Security Consultancy is the primary driver. The others are device Security Testing and device Security Training.
Who are Raelize's main competitors?
Direct peers on record are Riscure, IOActive, Red Balloon Security, Atredis Partners and Payatu. Broad incumbents are NCC Group, Trail of Bits and Quarkslab. Ringzer0 Training is listed as an emerging player. NewAE Technology is listed as an others.
Does Raelize have an API?
No public API is recorded for Raelize.
What industry is Raelize in?
Raelize's product category is Embedded Device Security Services. Its primary akta.pro industry code is BPAKAOAH, Security Risk Assessment, Auditing & Security Consulting Training, with a secondary code of HDADAHAD, Breach & Attack Simulation (BAS). Its NAICS code is 54138 and its SIC code is 8734.