Security Stack Logo
Eclypsium Platform logo

Supply Chain SecurityHardware Security

Eclypsium Platform

Scans hardware, firmware, and low-level software for vulnerabilities, tampering, and implants.

Software Supply Chain Security

Eclypsium Platform Overview

What it does

The Eclypsium Platform is a digital supply chain security platform that secures the hardware, firmware, and low-level software inside enterprise IT infrastructure, a layer that endpoint detection and response (EDR) and traditional vulnerability scanners cannot inspect. Its distinguishing mechanism is integrity verification against a curated database of more than 12 million known-good firmware hashes, letting security teams confirm that components such as UEFI/BIOS, baseboard management controllers, and Trusted Platform Modules are authentic and have not been tampered with.

How it works

The platform discovers components across laptops, servers, network devices, and AI data center hardware, then generates software, firmware, and hardware bills of materials for each system. It baselines firmware and configurations, flags drift and unauthorized modifications, and surfaces vulnerabilities for prioritization. Detection covers rootkits, bootkits, implants, and backdoors that persist below the operating system and can survive a full reinstall. Teams remediate by pushing firmware updates from the console or through a REST API, and route findings into existing security operations tooling via SIEM and SOAR integration. Version 4.0 added integrity monitoring for GPUs and NVIDIA-based servers.

Credentials and traction

Eclypsium reports SOC 2 Type II compliance, and the platform is listed on CISA's Continuous Diagnostics and Mitigation (CDM) Approved Products List, the first firmware and hardware supply chain product added to it. It won a 2024 Global InfoSec Award for Market Leader in Software Supply Chain Security from Cyber Defense Magazine. Adoption spans Fortune and Global 2000 organizations, including multiple top-ten U.S. banks, Fortune 100 financial services and oil and gas firms, U.S. defense industrial base companies, and U.S. government agencies.

Key Capabilities

mapped to solution categories
Software Supply Chain Security

Deep analysis of binaries and packages to detect tampering, malware, and hidden threats beyond manifest-based scanning.

Verification of build integrity and artifact provenance through signing, attestation, and change attribution.

Continuous monitoring of device firmware integrity and configuration against known-good baselines, detecting unauthorized modification and drift below the operating system.

On-demand generation of software, firmware, and hardware bills of materials (SBOM, FBOM, HBOM) for endpoints, servers, and network devices, extending component inventory below the application layer.

Detection of implants, bootkits, rootkits, and indicators of compromise in firmware and hardware, including threats that evade or disable endpoint detection agents.

Detection, prioritization, and remediation of known and unknown vulnerabilities in device firmware and components, including automated patching of vulnerable firmware.

Compliance

certifications
SOC 2 Type II

Integrations

compatible tools
Cloudflare AccessIBM QRadarIntelJAMFKenna SecurityMicrosoft IntuneMicrosoft SCCMOktaPing IdentitySplunkTaniumVMware Workspace ONE

Implementation & support

Deployment model
CloudOn-Premises
Support channels
Ticketing Portal

Info last updated on June 27, 2026

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.