Vulnerability handling for connected products
Firmpath figures out which ones actually reach the firmware you've shipped, and drafts the customer notices, VEX statements and disclosure records that go with them. Someone on your team looks over each call before anything goes out.
Free for one product: upload an SBOM, see what reaches it. No card, no password — we email you a code.
Built for teams shipping on ESP-IDF, Zephyr, STM32Cube, Yocto and Buildroot.
One thing to decide, and four "not affected" statements ready to send — already written up and dated.
What it does
Most tools will tell you a component has a vulnerability. The harder questions are whether it reaches a product you've already shipped, what to tell the customer who asks, and how to show a year later what you decided and why.
Step one
A small step in your CI picks up what the build actually contained — which SDK release, what got linked, which options were switched on — and keeps a component list for every product, revision and firmware version. It only ever sends metadata, so your source and your images stay where they are.
Step two
Public vulnerability feeds, the exploited-in-the-wild lists, and the PDF and email notices your chip vendors send out instead of machine-readable ones. Everything gets checked against your actual builds rather than a general list of components.
Step three
Whether the vulnerable code was even compiled in, which builds and units are involved, and which customers have them. You get a short queue with the reasoning laid out, and you can agree with it or say otherwise.
Step four
Customer advisories in whatever format each one asks for, VEX statements for the ones that don't affect you, a disclosure entry when the fix goes out, and a dated trail you can hand to an auditor.
The deadline
It covers anything with digital elements sold into the EU, wherever it was built, and penalties go up to €15M or 2.5% of worldwide turnover. Most of the work isn't the emergency reporting. It's the ongoing expectation that you know what's in your products, deal with what turns up, and can show your working later on.
Manufacturer obligations became law and the phase-in began.
An actively exploited vulnerability starts a 24-hour clock, then 72 hours, then a final report. Affected users have to be told as well.
A machine-readable SBOM, a disclosure policy and contact, security updates across a support period of at least five years, published fixes, and documentation kept for ten.
What you get
Most of a security questionnaire is asking whether you're exposed to things you're not. These answer that once, in a format your customer's tools can read, so a review takes an afternoon rather than a fortnight.
OpenVEX · CycloneDX VEX · CSAF
Written in the format each customer's procurement team asks for, with a record of who was told, when, and who acknowledged it.
email · PDF · CSAF · portal
One for every firmware version, hardware revision and release you have out in the world, rather than a single file standing in for the whole product.
CycloneDX · SPDX
Fixed vulnerabilities go up with their impact and remediation when the update ships, alongside your security contact and disclosure policy.
hosted · security.txt
Your vulnerability-handling process, support periods, update history, and every decision with its reasoning and who signed it off.
CE documentation bundle
Anything known to touch your builds gets checked against the exploited-in-the-wild lists as those change. If one shows up there, you hear about it that morning and the report is already drafted.
24-hour clock · ready to file
Works with
If you run a firmware scanner already, Firmpath picks up its findings and carries on from there. If you don't, the CI step is enough on its own — it reads the vendor SDKs directly, including what a given release bundles and what your configuration turned on.
You won't need to replace a scanner, change build systems, or upload firmware anywhere.
Findings in
Builds
Fits your pipeline
Where we're at
The advisory pipeline is running now. The rest we'd rather work out alongside people who do this job than guess at on our own, so if you get in touch, expect questions from us as much as answers.
Pricing
A product is one thing you ship. Uploading its next release replaces the last one, so keeping it current never counts against you.
Free
€0
1 product
Pro
€200/month
up to 5 products · or €2,000 a year · excl. VAT
Pro is opening to early customers now — tell us what you ship on.
Larger teams
Let's talk
more than 5 products
Questions
Get in touch
Send us a note and one of us will get back to you, usually within a couple of working days. If it doesn't sound like a fit, we'll tell you that too.
Thanks — we've got it, and one of us will be in touch.
Prefer email? Write to [email protected]. We'll only use your address to reply to you.