RevEng.AI raises $15M to reverse-engineer binaries and catch supply chain threats
What's the deal? British cybersecurity startup RevEng.AI has raised $15M in Series A funding to help organisations analyse compiled software at the binary level — without needing source code — to root out hidden vulnerabilities and backdoors. The round was led by the NATO Innovation Fund, with participation from Sands Capital, In-Q-Tel, IQ CapitalDealroom has a profile for this one. Try Dealroom →, and Episode One.
The company, officially known as Binary AI Ltd., built a foundational model called BiNet, trained alongside elite government cybersecurity units and top commercial security firms. It reverse-engineers machine-executable code to detect malicious or high-risk functionality embedded in software that organisations use but didn't build themselves.
Why now? Software supply chain attacks have become one of the most consequential risks facing enterprises and critical infrastructure providers. Once software is compiled into an executable format, its components are no longer easily visible — creating dangerous blind spots.
The rise of AI coding bots has made the problem more urgent. "In a world where AI increasingly writes the code, the only universal source of truth is the executable binary files that actually run on machines," said founder and chief executive James Patrick-Evans. "Much of the software being built today is never reviewed or seen by a human, making it untrustworthy."
What could go wrong? RevEng.AI says it has seen "strong demand" from enterprises and defence organisations but doesn't provide revenue figures. The company faces a competitive landscape — its BiNet model draws comparisons to Anthropic's Mythos — and will need to prove it can deliver reliable results at scale across diverse software environments.
The signal: The NATO Innovation Fund leading a Series A for a British binary-analysis startup — with In-Q-Tel, the CIA-linked investment fund, also on the cap table — underscores that software supply chain security has crossed from corporate IT concern into hard national security territory. As AI-generated code proliferates faster than human reviewers can keep up, expect more defence-adjacent capital to flow into tools that treat the compiled binary, not the source code, as the ultimate audit layer.
Read more: siliconangle.com