Product Threat Intelligence Providers: 6 companies compared
6 Product Threat Intelligence Providers, side by side
Featured listings are paid placements.
| company | Founded | Engagement | Specialism | Standards / accreditations |
|---|---|---|---|---|
| PCA CervusFeatured | 2019 | — | Manufacturers, importers and operators of embedded and connected products in payment, aut… | — |
| PCA Cyber Security | 2019 | Project-based engagements | Manufacturers and operators of payment devices, vehicles, industrial systems and other em… | TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434 |
| Eclypsium | 2017 | Enterprise subscription | Banks needing firmware-level integrity assurance across a large estate of laptops, server… | — |
| Finite State | — | Not publicly disclosed | Manufacturers of connected devices across IoT, automotive, medical, and industrial sector… | — |
| Upstream Security | 2017 | Subscription (custom) | OEMs and fleet operators that want cloud-scale detection, response, and a managed Vehicle… | ISO/SAE 21434, UNECE R155, UNECE R156 |
| VicOne | 2022 | Subscription (custom) | OEMs and suppliers wanting a broad, lifecycle automotive security portfolio backed by an… | ISO/SAE 21434, UNECE R155, Automotive SPICE (ASPICE) Level 2 |
PCA Cervus
Device-by-device vulnerability monitoring for embedded products, from supplier SBOMs to patch validation
PCA Cervus is a device-centric vulnerability monitoring and threat intelligence platform for embedded and connected products, made by PCA Cyber Security, the Munich- and Budapest-based embedded cybersecurity firm. PCA describes the workflow in six steps: upload an SBOM, Cervus validates the software components, new vulnerabilities are detected, affected products are identified, risk is prioritised and engineering is notified. It validates supplier SBOMs or generates them, models each device from its components, and correlates vulnerability and threat intelligence with those components, so the picture is built around the product rather than around individual CVEs. Monitoring continues after a product is released or certified, and PCA supports remediation through to patch validation. Compliance reporting covers the Cyber Resilience Act, PCI PTS, PCI DSS, UNECE R155, ISO/SAE 21434, IEC 62443-4-2 and RED / EN 18031. Cervus imports existing SBOMs, integrates with ticketing systems and exports data, and PCA says its AI-assisted analysis uses self-hosted models so product information stays under the customer's control. It is aimed at manufacturers, importers and operators of embedded products in payment, automotive, industrial, energy, medical and consumer IoT markets. PCA says the platform was developed with its offensive security researchers. Pricing and deployment options are not published.
Capabilities
- Import of existing and supplier SBOMs, with validation of the software components
- SBOM validation and/or generation for embedded products
- Device-centric model: each product's components are correlated with vulnerability and threat intelligence
- Continuous monitoring for new vulnerabilities, exploits and threats after release or certification, identifying the affected products
- Prioritisation of exploitable vulnerabilities rather than every CVE
- Remediation support through to patch validation, with engineering notified through ticketing integrations
- Compliance reports and evidence for the CRA, PCI PTS, PCI DSS, UNECE R155, ISO/SAE 21434, IEC 62443-4-2 and RED / EN 18031
- AI-assisted analysis using self-hosted models, per PCA
- Monitoring of threats targeting company secrets, infrastructure and code
Eclypsium
Product Threat IntelligenceBanks needing firmware-level integrity assurance across a large estate of laptops, servers and network devices
Eclypsium monitors firmware and hardware integrity below the operating system, covering laptops, servers, network devices, baseboard management controllers and AI data centre hardware. It verifies the integrity and authenticity of components to establish trust in hardware infrastructure, and detects indicators of compromise in hardware, firmware and software. It publishes a financial services practice aimed at bank device estates, naming First Financial as a customer with an attributed quote from its VP of Information Technology, and maps firmware controls to FFIEC cybersecurity guidelines, SOX internal controls, PCI DSS firmware integrity requirements and NYDFS cybersecurity regulations. The company was founded in 2017 by Yuriy Bulygin and Alex Bazhaniuk, both former Intel security engineers, and is based in Portland, Oregon.
Finite State
Product Threat Intelligence ProvidersManufacturers of connected devices across IoT, automotive, medical, and industrial sectors needing firmware-level vulnerability and exploit intelligence tied to compliance evidence.
Finite State positions itself as the "Product Security OS for Connected Devices," analyzing firmware, binaries, and source code to generate SBOMs, identify vulnerabilities, and produce compliance evidence, embedded directly into release workflows. Its threat intelligence capability centers on exploitability-based prioritization and execution-aware reachability analysis, aimed at cutting through vulnerability noise to surface findings that are actually reachable and exploitable. It covers IoT and embedded systems, automotive and connected vehicles, medical devices, industrial control systems, and energy and utilities infrastructure, and supports EU Cyber Resilience Act, FDA, and NIST compliance frameworks.
PCA Cervus
SBOM AnalysisManufacturers, importers and operators of embedded and connected products in payment, automotive, industrial and IoT markets that need to track vulnerabilities device by device against supplier SBOMs and produce evidence for regulations such as the Cyber Resilience Act, PCI PTS and UNECE R155
PCA Cervus is a device-centric vulnerability monitoring and threat intelligence platform for embedded and connected products, made by PCA Cyber Security, the Munich- and Budapest-based embedded cybersecurity firm. PCA describes the workflow in six steps: upload an SBOM, Cervus validates the software components, new vulnerabilities are detected, affected products are identified, risk is prioritised and engineering is notified. It validates supplier SBOMs or generates them, models each device from its components, and correlates vulnerability and threat intelligence with those components, so the picture is built around the product rather than around individual CVEs. Monitoring continues after a product is released or certified, and PCA supports remediation through to patch validation. Compliance reporting covers the Cyber Resilience Act, PCI PTS, PCI DSS, UNECE R155, ISO/SAE 21434, IEC 62443-4-2 and RED / EN 18031. Cervus imports existing SBOMs, integrates with ticketing systems and exports data, and PCA says its AI-assisted analysis uses self-hosted models so product information stays under the customer's control. It is aimed at manufacturers, importers and operators of embedded products in payment, automotive, industrial, energy, medical and consumer IoT markets. PCA says the platform was developed with its offensive security researchers. Pricing and deployment options are not published.
PCA Cyber Security
PCI PTS Compliance Testing CompaniesManufacturers and operators of payment devices, vehicles, industrial systems and other embedded products who need hands-on product security testing and monitoring against the CRA, PCI PTS, UN R155 and ISO/SAE 21434
PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.
Upstream Security
Automotive CybersecurityOEMs and fleet operators that want cloud-scale detection, response, and a managed Vehicle SOC for connected fleets
Upstream Security operates a cloud-native, agentless AI platform purpose-built for connected vehicles and mobility IoT. It ingests telematics, OTA, diagnostic, and dealership data to deliver cybersecurity detection and response (V-XDR), automotive threat intelligence, and data-driven applications. Upstream pairs its platform with a managed 24/7 Vehicle Security Operations Center and monitors tens of millions of vehicles, making it one of the largest-scale players in connected-vehicle security. Because it works server-side without in-vehicle agents, it is typically deployed alongside embedded ECU protection rather than replacing it.
VicOne
Automotive CybersecurityOEMs and suppliers wanting a broad, lifecycle automotive security portfolio backed by an established cybersecurity parent
VicOne is a wholly-owned subsidiary of Trend Micro dedicated exclusively to automotive cybersecurity for connected and electric vehicles. It leverages Trend Micro's 30-plus years of security expertise and the Zero Day Initiative's vulnerability research network. The same program behind Pwn2Own Automotive. To give OEMs and suppliers lifecycle protection from development and production through in-vehicle operation. Its portfolio covers an in-vehicle IDPS, a managed VSOC, threat intelligence, SBOM and vulnerability management, and penetration testing services.
Related guides
Other categories you might be evaluating alongside product threat intelligence providers.
About this listing
Product Threat Intelligence Providers companies, compared on public information. The comparison table is ordered by reader upvotes, then A to Z, with paid Featured listings shown first and labelled; the full entries run A to Z. How we work →