ONEKEY built its platform around a specific and expanding threat surface: the firmware and software that runs industrial control systems, manufacturing lines, and connected devices. Founded in 2020, the company operates in the intersection of IT and OT security, where a vulnerability isn't just a data breach risk - it can mean physical disruption to critical infrastructure. Their core product is an automated analysis platform designed to find and prioritize vulnerabilities in this space, including zero-day detection in firmware and embedded systems.
The platform's technical approach centers on automated security and compliance analysis. Key capabilities include automated Software Bill of Materials (SBOM) generation and management, continuous monitoring, and impact assessment for detected vulnerabilities. This is built to serve sectors where supply chain transparency and device integrity are non-negotiable: manufacturing, automotive, medical devices, and telecommunications. The system is designed to help organizations move from manual, slow audits to continuous, automated proof of their security and compliance posture.
ONEKEY is headquartered in Germany with a distributed technical team spanning four countries - Germany, Hungary, Austria, and Belgium - across nine cities. The team reports fluency in 13 languages, a practical asset for serving a European industrial client base. The company's NPS stands at 8.5, a metric they track closely. The work spans deep firmware analysis, vulnerability research in OT protocols, and building the tooling that automates what was previously manual, expert-driven assessment of industrial systems.




