Independent cybersecurity directory, built from public sources. Featured listings are paid placements and always labelled. How we work

Product Threat Intelligence Providers: 6 companies compared

Companies that provide threat intelligence focused on specific products and devices, rather than general enterprise or network threat intelligence. This covers vulnerability intelligence tailored to a product's own hardware and software composition, software composition analysis and SBOM validation for supply chain visibility, firmware integrity monitoring, and tracking of fraud techniques and attack strategies aimed at a product line. It is bought both by manufacturers of automotive, payment and embedded devices, and by operators such as banks that run large fleets of devices they did not build.

6 companies|Updated July 2026

6 Product Threat Intelligence Providers, side by side

Featured listings are paid placements.

companyFoundedEngagementSpecialismStandards / accreditations
PCA CervusFeatured2019—Manufacturers, importers and operators of embedded and connected products in payment, aut…—
PCA Cyber Security2019Project-based engagementsManufacturers and operators of payment devices, vehicles, industrial systems and other em…TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434
Eclypsium2017Enterprise subscriptionBanks needing firmware-level integrity assurance across a large estate of laptops, server…—
Finite State—Not publicly disclosedManufacturers of connected devices across IoT, automotive, medical, and industrial sector…—
Upstream Security2017Subscription (custom)OEMs and fleet operators that want cloud-scale detection, response, and a managed Vehicle…ISO/SAE 21434, UNECE R155, UNECE R156
VicOne2022Subscription (custom)OEMs and suppliers wanting a broad, lifecycle automotive security portfolio backed by an…ISO/SAE 21434, UNECE R155, Automotive SPICE (ASPICE) Level 2

PCA Cervus

Device-by-device vulnerability monitoring for embedded products, from supplier SBOMs to patch validation

Founded
2019

PCA Cervus is a device-centric vulnerability monitoring and threat intelligence platform for embedded and connected products, made by PCA Cyber Security, the Munich- and Budapest-based embedded cybersecurity firm. PCA describes the workflow in six steps: upload an SBOM, Cervus validates the software components, new vulnerabilities are detected, affected products are identified, risk is prioritised and engineering is notified. It validates supplier SBOMs or generates them, models each device from its components, and correlates vulnerability and threat intelligence with those components, so the picture is built around the product rather than around individual CVEs. Monitoring continues after a product is released or certified, and PCA supports remediation through to patch validation. Compliance reporting covers the Cyber Resilience Act, PCI PTS, PCI DSS, UNECE R155, ISO/SAE 21434, IEC 62443-4-2 and RED / EN 18031. Cervus imports existing SBOMs, integrates with ticketing systems and exports data, and PCA says its AI-assisted analysis uses self-hosted models so product information stays under the customer's control. It is aimed at manufacturers, importers and operators of embedded products in payment, automotive, industrial, energy, medical and consumer IoT markets. PCA says the platform was developed with its offensive security researchers. Pricing and deployment options are not published.

Capabilities

  • Import of existing and supplier SBOMs, with validation of the software components
  • SBOM validation and/or generation for embedded products
  • Device-centric model: each product's components are correlated with vulnerability and threat intelligence
  • Continuous monitoring for new vulnerabilities, exploits and threats after release or certification, identifying the affected products
  • Prioritisation of exploitable vulnerabilities rather than every CVE
  • Remediation support through to patch validation, with engineering notified through ticketing integrations
  • Compliance reports and evidence for the CRA, PCI PTS, PCI DSS, UNECE R155, ISO/SAE 21434, IEC 62443-4-2 and RED / EN 18031
  • AI-assisted analysis using self-hosted models, per PCA
  • Monitoring of threats targeting company secrets, infrastructure and code

Eclypsium

Product Threat Intelligence
Best fit for

Banks needing firmware-level integrity assurance across a large estate of laptops, servers and network devices

Eclypsium monitors firmware and hardware integrity below the operating system, covering laptops, servers, network devices, baseboard management controllers and AI data centre hardware. It verifies the integrity and authenticity of components to establish trust in hardware infrastructure, and detects indicators of compromise in hardware, firmware and software. It publishes a financial services practice aimed at bank device estates, naming First Financial as a customer with an attributed quote from its VP of Information Technology, and maps firmware controls to FFIEC cybersecurity guidelines, SOX internal controls, PCI DSS firmware integrity requirements and NYDFS cybersecurity regulations. The company was founded in 2017 by Yuriy Bulygin and Alex Bazhaniuk, both former Intel security engineers, and is based in Portland, Oregon.

Founded

2017

Engagement

Enterprise subscription

Finite State

Product Threat Intelligence Providers
Best fit for

Manufacturers of connected devices across IoT, automotive, medical, and industrial sectors needing firmware-level vulnerability and exploit intelligence tied to compliance evidence.

Finite State positions itself as the "Product Security OS for Connected Devices," analyzing firmware, binaries, and source code to generate SBOMs, identify vulnerabilities, and produce compliance evidence, embedded directly into release workflows. Its threat intelligence capability centers on exploitability-based prioritization and execution-aware reachability analysis, aimed at cutting through vulnerability noise to surface findings that are actually reachable and exploitable. It covers IoT and embedded systems, automotive and connected vehicles, medical devices, industrial control systems, and energy and utilities infrastructure, and supports EU Cyber Resilience Act, FDA, and NIST compliance frameworks.

Engagement

Not publicly disclosed

PCA Cervus

SBOM Analysis
Best fit for

Manufacturers, importers and operators of embedded and connected products in payment, automotive, industrial and IoT markets that need to track vulnerabilities device by device against supplier SBOMs and produce evidence for regulations such as the Cyber Resilience Act, PCI PTS and UNECE R155

PCA Cervus is a device-centric vulnerability monitoring and threat intelligence platform for embedded and connected products, made by PCA Cyber Security, the Munich- and Budapest-based embedded cybersecurity firm. PCA describes the workflow in six steps: upload an SBOM, Cervus validates the software components, new vulnerabilities are detected, affected products are identified, risk is prioritised and engineering is notified. It validates supplier SBOMs or generates them, models each device from its components, and correlates vulnerability and threat intelligence with those components, so the picture is built around the product rather than around individual CVEs. Monitoring continues after a product is released or certified, and PCA supports remediation through to patch validation. Compliance reporting covers the Cyber Resilience Act, PCI PTS, PCI DSS, UNECE R155, ISO/SAE 21434, IEC 62443-4-2 and RED / EN 18031. Cervus imports existing SBOMs, integrates with ticketing systems and exports data, and PCA says its AI-assisted analysis uses self-hosted models so product information stays under the customer's control. It is aimed at manufacturers, importers and operators of embedded products in payment, automotive, industrial, energy, medical and consumer IoT markets. PCA says the platform was developed with its offensive security researchers. Pricing and deployment options are not published.

PCA Cyber Security

PCI PTS Compliance Testing Companies
Best fit for

Manufacturers and operators of payment devices, vehicles, industrial systems and other embedded products who need hands-on product security testing and monitoring against the CRA, PCI PTS, UN R155 and ISO/SAE 21434

PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.

Founded

2019

Engagement

Project-based engagements

Standards & accreditations

TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434, UNECE R155

Upstream Security

Automotive Cybersecurity
Best fit for

OEMs and fleet operators that want cloud-scale detection, response, and a managed Vehicle SOC for connected fleets

Upstream Security operates a cloud-native, agentless AI platform purpose-built for connected vehicles and mobility IoT. It ingests telematics, OTA, diagnostic, and dealership data to deliver cybersecurity detection and response (V-XDR), automotive threat intelligence, and data-driven applications. Upstream pairs its platform with a managed 24/7 Vehicle Security Operations Center and monitors tens of millions of vehicles, making it one of the largest-scale players in connected-vehicle security. Because it works server-side without in-vehicle agents, it is typically deployed alongside embedded ECU protection rather than replacing it.

Founded

2017

Engagement

Subscription (custom)

Standards & accreditations

ISO/SAE 21434, UNECE R155, UNECE R156

VicOne

Automotive Cybersecurity
Best fit for

OEMs and suppliers wanting a broad, lifecycle automotive security portfolio backed by an established cybersecurity parent

VicOne is a wholly-owned subsidiary of Trend Micro dedicated exclusively to automotive cybersecurity for connected and electric vehicles. It leverages Trend Micro's 30-plus years of security expertise and the Zero Day Initiative's vulnerability research network. The same program behind Pwn2Own Automotive. To give OEMs and suppliers lifecycle protection from development and production through in-vehicle operation. Its portfolio covers an in-vehicle IDPS, a managed VSOC, threat intelligence, SBOM and vulnerability management, and penetration testing services.

Founded

2022

Engagement

Subscription (custom)

Standards & accreditations

ISO/SAE 21434, UNECE R155, Automotive SPICE (ASPICE) Level 2, TISAX Assessment Level 3

Related guides

Other categories you might be evaluating alongside product threat intelligence providers.

About this listing

Product Threat Intelligence Providers companies, compared on public information. The comparison table is ordered by reader upvotes, then A to Z, with paid Featured listings shown first and labelled; the full entries run A to Z. How we work →

Frequently Asked Questions

Product threat intelligence is threat intelligence focused on a specific product or device line, rather than an organization's general network or enterprise environment. It typically covers vulnerabilities in a product's own software and hardware composition, supply chain risk via software composition analysis and SBOM validation, and monitoring for attack techniques and fraud trends targeting that product category, such as payment terminals or vehicle systems.

Enterprise threat intelligence tracks threats to an organization's networks, endpoints, and users, such as phishing campaigns or ransomware groups. Product threat intelligence instead tracks threats to a manufacturer's actual product: vulnerabilities in its firmware or software stack, supply chain components, and attack techniques specifically aimed at that device or product category.