Manifest, a leading provider of software and AI supply chain security solutions, has announced a new strategic partnership with NetRise, bringing together their expertise to deliver the industry’s first unified view of risk spanning software and firmware layers—from development environments to deployed devices.
As organizations adopt software supply chain security programs with tools for source code analysis, container scanning, and Software Bill of Materials (SBOM) generation, one critical blind spot remains: firmware. This vendor-supplied, compiled code runs beneath the operating system on hardware devices and is often excluded from traditional security assessments. The result is an incomplete risk picture—particularly for cyber-physical systems—leaving devices exposed to firmware-level attacks that are growing in frequency and sophistication.
Cyber Technology Insights : AMI Achieves Industry First with Successful Implementation of Post-Quantum Cryptography
Manifest’s platform is already trusted by Fortune 500 companies, government agencies, and critical infrastructure operators to secure every stage of the AI and software supply chain. It enables organizations to build, purchase, and deploy trusted software without compromising speed. Users gain a complete inventory of software components and AI models, proactively identify and manage risks, and maintain compliance through automated remediation workflows. The platform continuously monitors and quantifies third-party software risks and automates open-source and AI supply chain assessments.
To extend this comprehensive visibility down to the firmware layer, Manifest turned to NetRise, a firm recognized for its deep expertise in firmware security. Built specifically for analyzing compiled and binary code, the NetRise platform examines the software embedded within firmware, real-time operating systems, and similar environments. Its advanced analysis generates detailed SBOMs that reveal hidden vulnerabilities, misconfigurations, and security weaknesses—helping security teams prioritize remediation of risks that are network-exposed or auto-executing at system startup.
Unlocking End-to-End Transparency in the Supply Chain
The partnership integrates NetRise’s firmware intelligence directly into the Manifest Platform. This new capability enables Manifest users to automatically generate and analyze firmware SBOMs and embedded system components—achieving visibility that was previously unattainable without source code access. Through this integration, organizations can:
- Gain actionable insight into software running on hardware devices.
- Conduct more precise and holistic risk assessments across all technology layers.
- Strengthen compliance with evolving firmware and SBOM transparency standards.
- Eliminate long-standing security blind spots in the device layer.
Cyber Technology Insights : SonicWall Drives Growth in Managed Security Services and Cloud Secure Edge / ZTNA
With NetRise’s deep firmware analysis now embedded into Manifest’s workflows, organizations can identify vulnerabilities, hard-coded secrets, misconfigurations, weak cryptographic keys, and outdated components hidden inside firmware. This ensures even legacy or vendor-supplied systems are accounted for in security and compliance programs. The capability is especially valuable in industries that rely on legacy equipment, such as healthcare, where devices like older MRI machines still operate on decades-old firmware. Through this integration, these organizations can now evaluate the software supply chain embedded in such devices—improving patient safety and regulatory compliance.
Robbie Robbins, Vice President of Partnerships at NetRise, emphasized the mission alignment behind the collaboration:
“NetRise was created to eliminate blind trust in software. Our goal is to give product security and third-party risk management teams the confidence to answer, ‘Am I exposed?’ when an incident occurs. Partnering with Manifest allows leading enterprises and agencies to transition from reactive risk management to proactive, full-stack transparency.”
Daniel Bardenstein, CEO of Manifest, added:
“Organizations have long been able to analyze their own code and containerized environments, but not the firmware embedded in their devices. By incorporating NetRise’s firmware and compiled code analysis, we’re enabling visibility deeper than ever before. This bridges the gap between source code analysis and real-world deployed systems—and it’s only the beginning of what our partnership will deliver.”
Cyber Technology Insights : Bruce Schneier and Brian LaMacchia Join American Binary’s Advisory Board
To participate in our interviews, please write to our CyberTech Media Room at info@intentamplify.com
