ARIANNA
ARIANNA provides a SaaS vulnerability management platform combining SBOM and HBOM generation with continuous monitoring and exploitability-based prioritization for manufacturers of connected devices and embedded products across automotive, industrial, medical, and IoT verticals.
- Company typePrivate
- Founded2026
- HeadquartersVimercate, Italy
- Headcount—
- GTM typeB2B
- OfferingSoftware
What ARIANNA does
ARIANNA provides a SaaS vulnerability management platform purpose-built for manufacturers of connected devices and embedded systems. The platform combines Software Bill of Materials (SBOM) and Hardware Bill of Materials (HBOM) generation through proprietary Software Composition Analysis (SCA) tools that operate on build artifacts without requiring source code disclosure, reverse engineering of binaries, or agents on target devices. SCA coverage spans Yocto, Debian, Ubuntu, Alpine, Red Hat, Gentoo, Buildroot, OpenWRT, Android, Windows, PHP, C/C++, Python, Java, .NET, JavaScript, Go, Maven, Gradle, and multiple RTOS systems and MCU/MPU SDKs (STM32, Espressif, Silicon Labs, Nordic, NXP, Zephyr). Continuous vulnerability monitoring correlates device components against NVD, CVE.org, GitHub Security Advisories, EUVD, CISA KEV, ExploitDB, and Metasploit, with prioritization driven by CVSS severity, KEV catalog evidence, exploit maturity, EPSS scores, and attack-vector relevance. A policy engine maps internal and external requirements to remediation SLAs and audit-ready exports in SPDX, CycloneDX, VEX, and CSV formats. Data is hosted and processed within the European Union.
The company serves enterprise device manufacturers across automotive, industrial automation, medical devices, consumer electronics and IoT (primary verticals), plus defense and aerospace, energy and utilities, and transportation and logistics (secondary verticals). Named customers include ISEO, Flex, Riello, Telsy, Infatron, QSD, and Orthofix. The platform is positioned around regulatory compliance workflows — explicitly the EU Cyber Resilience Act (including 24-hour exploit reporting), RED DA, NIS2, FDA pre-market submissions, ISO/SAE 21434, UNECE WP.29 R155/R156, IEC 62443, NIST SP 800-53/800-161, ETSI EN 303 645, and NERC CIP — making regulatory readiness rather than generic IT vulnerability management the primary value proposition.
ARIANNA was spun out of Security Pattern s.r.l. in March 2026, with the platform itself originating as an internal product of Security Pattern. Jan Jager serves as CEO and Massimo Ratti as CTO, and the company officially launched at the EU Cyber Act Conference in Brussels. Monetization is via enterprise SaaS subscriptions (specific pricing tiers are not publicly disclosed) distributed through a hybrid GTM combining direct enterprise sales (book-a-demo, free trial) and a partner ecosystem: Security Pattern as founding implementation partner, REEKON covering Asia-Pacific (Singapore, Taiwan, India, Hong Kong), Estigiti for European implementation and advisory, and COMPLYD for CRA governance integration. The company is privately held, headquartered in Vimercate, Italy, with a European primary footprint and no disclosed funding, revenue, or headcount figures.
ARIANNA firmographics
Firmographics- Name
- ARIANNA
- Legal name
- Security Pattern s.r.l.
- Website
- https://ariannateam.ai
- Company type
- Private
- Founded year
- 2026
- Operating status
- Operating
- Short description
- ARIANNA provides a SaaS vulnerability management platform combining SBOM and HBOM generation with continuous monitoring and exploitability-based prioritization for manufacturers of connected devices and embedded products across automotive, industrial, medical, and IoT verticals.
- Ownership category
- akta.pro rank
ARIANNA industry classification
Industry- Product category
- Vulnerability Management Software
- NAICS
- Software Publishers (513210), Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Programming Services (7371), Services-Engineering, Accounting, Research, Management (8700)
- akta.pro primary industry
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
- akta.pro secondary industries
- Control System Cybersecurity for OT (ICS Security, Monitoring, Hardening) (IMAGABAL), Threat & Vulnerability Assessments (TVA) (BPAKADAD)
Keywords
Where ARIANNA is headquartered
LocationHeadquarters
- HQ city
- Vimercate
- HQ country
- Italy
- HQ region
- Europe
Offices1 record
Markets served
ARIANNA business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Platform Subscription: SaaS-based vulnerability management platform accessed via subscription model. Customers can book demos and start free trials, indicating a subscription-based go-to-market with potential tiered pricing based on device count, vulnerability monitoring volume, or user seats.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Free Trial |
| Freemium | Pay-as-you-go | Demo |
Go-to-market motion3 records
Distribution channels5 records
Marketing channels6 records
ARIANNA product offering
Product offeringCore offering
ARIANNA provides a SaaS vulnerability management platform for manufacturers of connected and embedded devices that unifies SBOM and HBOM governance with continuous vulnerability monitoring, exploitability-based prioritization, policy-driven remediation, and audit-ready regulatory reporting. Its proprietary SCA tools generate complete software bills of materials from build artifacts without requiring source code access, reverse engineering, or on-device agents.
Product overview
ARIANNA is a unified vulnerability management platform purpose-built for connected devices and embedded systems. The core product consists of the ARIANNA Platform, which provides end-to-end SBOM and HBOM governance, continuous vulnerability monitoring, workflow-driven remediation, and compliance reporting. Supporting the platform are ARIANNA SCA Tools—proprietary Software Composition Analysis scripts that generate component inventories without source code access or reverse engineering. The platform monitors 250,000+ vulnerabilities daily across 100+ global customers, supporting a range of ecosystems including Linux distributions, RTOS systems, MCU/MPU SDKs, and build frameworks. Data is hosted and processed within the European Union.
Differentiator
Problem solved
Functional benefit
Products and services
- ARIANNA Platform A SaaS vulnerability management workspace for enterprise device manufacturers that builds and maintains SBOMs and HBOMs, performs continuous vulnerability monitoring with exploitability-based prioritization, drives workflow-based remediation with SLA tracking, and generates audit-ready reports for regulations including CRA, RED DA, and FDA.
- ARIANNA SCA Tools Proprietary Software Composition Analysis scripts (Python, Bash, or PowerShell) that run in customer build environments to generate complete SBOMs with accurate vulnerability mapping, without requiring source code disclosure, reverse engineering of binaries, or agents installed on target devices. Supports Yocto, Debian, Ubuntu, Alpine, Red Hat, Gentoo, Buildroot, OpenWRT, Android, Windows, PHP, C/C++, Python, Java, .NET, JavaScript, Go, Maven, Gradle, RTOS systems, and MCU/MPU SDKs from STM32, Espressif, Silicon Labs, Nordic, NXP, Keil, and Zephyr.
Quantifiable outcome
- 250K+ vulnerabilities monitored daily across customer portfolios
- +2 more outcomes
Companies that use ARIANNA
Customer profileNamed customers7 records
Segments7 records
Ideal customer profiles1 record
ARIANNA technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Feature8 records
ARIANNA partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered secondary and core.
- COMPLYDsecondaryCOMPLYD partners with ARIANNA to connect Cyber Resilience Act governance with technical SBOM, HBOM, and vulnerability management capabilities. COMPLYD supports organizations navigating CRA compliance requirements while ARIANNA provides the technical visibility into component inventories, vulnerability relevance, triage workflows, and evidence needed for product-security decisions.
- EstigitisecondaryEstigiti joins the ARIANNA partner ecosystem as an implementation and advisory partner, supporting organizations in improving vulnerability management processes and addressing cybersecurity and compliance requirements including the European Cyber Resilience Act. Expertise in cybersecurity governance, risk management, and secure product development.
- REEKONcoreREEKON is an official Implementation Partner for the Asian market, supporting connected device manufacturers across Singapore, Taiwan, India, and Hong Kong. REEKON brings expertise in cybersecurity compliance, payment security, penetration testing, architecture validation, and certification support to help customers with ARIANNA onboarding, deployment, device model creation, vulnerability management processes, and CRA compliance preparation.
- Security PatterncoreSecurity Pattern is the founding organization behind ARIANNA and the first official ARIANNA partner. As the mother company that spun out ARIANNA, Security Pattern offers comprehensive services including SBOM and vulnerability management enablement, threat modeling, penetration testing, compliance readiness (IEC 62443, ISO/SAE 21434, MDR, RED DA, CRA), IoT security architecture, and cybersecurity training.
Scale indicators4 records
Recent moves7 records
Expansion highlights5 records
ARIANNA competitors and assessment
Company assessmentEmerging players
- Nozomi Networks: Nozomi Networks provides OT and IoT cybersecurity, including asset visibility, vulnerability assessment, and threat detection for industrial and critical infrastructure networks. Adjacent to ARIANNA in industrial automation and energy verticals with comparable connected-device vulnerability management use cases.
- Claroty: Claroty focuses on cybersecurity for operational technology (OT) and industrial control systems, with asset discovery and vulnerability management. Adjacent to ARIANNA's industrial automation and energy verticals, with overlapping customer profiles in connected operational environments.
Broad incumbents
- Snyk: Snyk is a large developer security platform with SCA capabilities for open-source vulnerability detection and SBOM generation. Overlaps with ARIANNA's SBOM and vulnerability intelligence but is a broad IT/application security incumbent rather than embedded-systems specialized.
- Mend (formerly WhiteSource): Mend provides application security and SCA tooling, including SBOM generation and open-source vulnerability detection. Comparable to ARIANNA on SCA/SBOM but primarily focused on application development environments rather than connected devices and embedded systems.
- Sonatype: Sonatype operates the Nexus platform for software supply chain security, including SBOM lifecycle management and vulnerability intelligence. Competes with ARIANNA on SBOM generation and continuous monitoring but is positioned as a general software supply chain incumbent rather than a device-specialist.
- JFrog: JFrog provides a software supply chain platform including artifact management, SBOM capabilities, and security scanning. Overlaps with ARIANNA on SBOM and vulnerability management for software components but is a broader DevOps/CI-CD infrastructure vendor rather than a connected-device specialist.
- Synopsys Black Duck: Black Duck (part of Synopsys) is an established SCA platform for open-source license compliance, SBOM generation, and security vulnerability detection. A broad incumbent in software supply chain security, comparable to ARIANNA on SCA/SBOM but with a much broader enterprise footprint and embedded-systems-adjacent coverage.
Direct peers
- VicOne: VicOne provides automotive cybersecurity solutions including SBOM management, vulnerability monitoring, and VSOC capabilities for the automotive supply chain. Direct overlap with ARIANNA's automotive vertical and similar regulatory alignment (ISO/SAE 21434, UNECE WP.29).
- Finite State: Finite State provides SBOM management and vulnerability analysis purpose-built for connected devices and embedded systems, serving device manufacturers in automotive, medical, industrial, and critical infrastructure. Closely comparable to ARIANNA in product scope (SBOM + device-centric vulnerability management) and target verticals.
- Cybellum (Keysight Technologies): Cybellum, now part of Keysight, offers a Product Security Platform that generates SBOMs and assesses vulnerabilities for connected products in automotive, medical, industrial, and IoT. Direct overlap with ARIANNA in device-centric vulnerability management and regulatory compliance support (ISO/SAE 21434, FDA, UNECE WP.29).
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
ARIANNA financial estimates
Financial estimateRevenue estimate
Valuation estimate
ARIANNA leadership team
Management profileNumber of profiles
Profiles2 records
ARIANNA funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ARIANNA M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ARIANNA
What does ARIANNA do?
ARIANNA provides a SaaS vulnerability management platform for manufacturers of connected and embedded devices that unifies SBOM and HBOM governance with continuous vulnerability monitoring, exploitability-based prioritization, policy-driven remediation, and audit-ready regulatory reporting. Its proprietary SCA tools generate complete software bills of materials from build artifacts without requiring source code access, reverse engineering, or on-device agents.
Is ARIANNA a public or private company?
ARIANNA is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was ARIANNA founded?
ARIANNA was founded in 2026.
Where is ARIANNA based?
ARIANNA is headquartered in Vimercate, Italy, in the Europe region.
How does ARIANNA make money?
One revenue line is on record: platform Subscription.
Who are ARIANNA's main competitors?
Emerging players on record are Nozomi Networks and Claroty. Broad incumbents are Snyk, Mend (formerly WhiteSource), Sonatype, JFrog and Synopsys Black Duck. Direct peers are VicOne, Finite State and Cybellum (Keysight Technologies).
Does ARIANNA have an API?
Yes. ARIANNA provides a set of powerful REST APIs that enable security teams to build automation and integrate vulnerability management into development workflows. Through dedicated endpoints, pipelines can automatically create new Device Model versions, upload the information required to generate SBOMs, trigger the creation of new vulnerability reports, retrieve the latest report for a specific Device Model version, and filter/retrieve high-priority vulnerabilities. The API supports CI/CD pipeline integration for automated SCA execution, model uploads, and report generation.
What industry is ARIANNA in?
ARIANNA's product category is Vulnerability Management Software. Its primary akta.pro industry code is HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing), with a secondary code of IMAGABAL, Control System Cybersecurity for OT (ICS Security, Monitoring, Hardening). Its NAICS code is 513210 and its SIC code is 7371.