Exposure discovery EU-developed

ONEKEY Platform

Analyzes embedded firmware binaries to inventory components, generate SBOMs, identify known vulnerabilities and monitor product risk over subsequent releases.

By ONEKEY GmbH · Germany

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Exposure discovery
Developer or maintainer
ONEKEY GmbH
Recorded country
Germany
Product model
Commercial
Deployment
SaaS
Software license
Commercial license; full terms not publicly verified
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

ONEKEY says it launched in 2020 as IoT-Inspector, a SEC Consult spin-off, and built its firmware platform with a team across Germany, Hungary, Austria and Belgium. The contracting company is in Düsseldorf.

Reported capabilities

  • Binary firmware component analysis
  • SBOM generation and CVE matching
  • Ongoing product vulnerability monitoring

Scope and limits

The reviewed platform is a business-customer hosted service requiring registration and a license key. Its bundled public terms reserve service intellectual-property rights but are dated July 2020; current negotiated customer terms and any private deployment option were not verified. Its separate MIT-licensed unblob extractor does not make the entire platform open source.

Inspect the research evidence 7 source observations
  1. identity / capabilities

    Vendor describes a centralized firmware-product security platform with binary component inventory, SBOM import/generation, vulnerability detection and lifecycle monitoring.

    Read source
  2. origin

    Vendor says the IoT-Inspector platform launched in 2020 as a SEC Consult spin-off, rebranded to ONEKEY in 2022, and its growing team in Germany, Hungary, Austria and Belgium developed the Compliance Wizard.

    Read source
  3. country

    ONEKEY GmbH lists its registered seat and street address in Düsseldorf, Germany. Combined with the company development account, this supports a German lead, not German-only engineering.

    Read source
  4. license / deployment

    The /tos page loads this first-party JavaScript bundle, which embeds terms describing ONEKEY-hosted Services, corporate-customer license keys and reserved IP rights. The embedded terms are dated July 2020; current complete commercial terms were not verified.

    Read source
  5. capabilities

    Official guide covers firmware extraction, software-component identification, CVE matching and binary analysis. It describes how the platform works rather than promising exhaustive detection.

    Read source
  6. maintenance

    Official documentation front page was updated 16 September 2026 and continues to link live platform/API guides; an update is not an assurance of support or scan accuracy.

    Read source
  7. license

    Documentation distinguishes the open-source unblob firmware extractor from the ONEKEY platform that invokes it.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Scope exposure discovery, validate vulnerability findings, prioritize affected assets and verify remediation. Practical guidance with documented European tools.

From vulnerability finding to verified remediation