# Binarly Transparency Platform ## Docs - [Why Binarly](https://docs.binarly.io/user-guides/about/why.md): The Binarly Transparency Platform gives software producers and enterprise buyers ground-truth visibility into compiled software and firmware — without source code access. - [Use cases](https://docs.binarly.io/user-guides/about/use-cases.md): Primary use cases for the Binarly Transparency Platform: secure product development, third-party risk management, and post-quantum cryptography readiness. - [The Binarly advantage](https://docs.binarly.io/user-guides/about/comparison/the-binarly-advantage.md): How Binarly's binary-native analysis finds what source-code tools structurally cannot, and the capabilities that set it apart. - [Binary vs. source scanning](https://docs.binarly.io/user-guides/about/comparison/binary-vs-source.md): How binary scanning compares to source-code scanning across different SDLC security approaches. - [Deployment architectures](https://docs.binarly.io/user-guides/about/deployment-architectures/SaaS-vs-onprem.md): The Binarly Transparency Platform is available as a fully managed SaaS offering and as a self-hosted on-premises installation for air-gapped and regulated environments. - [Security & compliance](https://docs.binarly.io/user-guides/about/security.md): How the Binarly Transparency Platform handles deployment security, access control, authentication, and compliance certification. - [Supported platforms](https://docs.binarly.io/user-guides/about/supported-platforms.md): Binary formats, operating systems, processor architectures, and analysis capabilities supported by the Binarly Transparency Platform. - [Customer support](https://docs.binarly.io/user-guides/about/customer-support.md): How to get help with the Binarly Transparency Platform. - [Requirements](https://docs.binarly.io/user-guides/get-started/requirements.md) - [Login](https://docs.binarly.io/user-guides/get-started/login.md) - [First Scan](https://docs.binarly.io/user-guides/get-started/first-scan.md) - [Remediate Vulnerabilities](https://docs.binarly.io/user-guides/get-started/fix-unknown.md) - [Glossary](https://docs.binarly.io/user-guides/get-started/glossary.md) - [The Dashboard](https://docs.binarly.io/user-guides/image-scans/the-dashboard.md) - [Products](https://docs.binarly.io/user-guides/image-scans/products.md) - [Reviewing findings, images, and product trends](https://docs.binarly.io/user-guides/image-scans/all-about-details.md): Organize images by product, review analysis findings, and track vulnerability trends over time in the Binarly Transparency Platform. - [Prioritizing with the Risk Score](https://docs.binarly.io/user-guides/image-scans/risk-score.md): Use the Binarly Risk Score to rank findings by priority: pick a scoring profile, read the score, and sort and filter findings by risk score. - [Cryptographic Materials](https://docs.binarly.io/user-guides/image-scans/cryptographic-materials.md): Using the Cryptographic Materials tab to review algorithms, certificates, and keys discovered in an image scan. - [Compare Images](https://docs.binarly.io/user-guides/image-scans/compare.md) - [Findings Scope](https://docs.binarly.io/user-guides/image-scans/findings-scope.md): Findings Scope limits reported findings for a product by disabling certain finding types not relevant to the product threat model. This helps with noise reduction and fine-tuning of reports and dashboard content. - [CVSS Vector Filtering](https://docs.binarly.io/user-guides/image-scans/cvss-vector-filtering.md): Filter the Findings Grid by CVSS v3 vector elements to focus on specific attack characteristics and prioritize remediation. - [Filtering findings by reachability](https://docs.binarly.io/user-guides/image-scans/reachability-filtering.md): Read the Code Reachability and Environment Reachability columns together to scope the Findings grid to vulnerabilities whose code both loads in the deployment and is reachable inside its binary. - [Finding Variants](https://docs.binarly.io/user-guides/image-scans/finding-variants.md): Finding Variants provides an ability to use vulnerability information from alternative sources for finding prioritization. - [Saved Views](https://docs.binarly.io/user-guides/important-findings/saved-views.md) - [Widget](https://docs.binarly.io/user-guides/important-findings/widget.md) - [Image and Detail Reports](https://docs.binarly.io/user-guides/export/reports.md) - [PQC Compliance Report](https://docs.binarly.io/user-guides/export/pqc.md) - [Automatic Advisories](https://docs.binarly.io/user-guides/export/advisories.md) - [SBOM (Software Bill of Materials)](https://docs.binarly.io/user-guides/export/sbom.md) - [CBOM (Cryptographic Bill of Materials)](https://docs.binarly.io/user-guides/export/cbom.md): Export a Cryptographic Bill of Materials (CBOM) to inventory all cryptographic algorithms, certificates, and keys discovered in a scanned image. - [VEX (Vulnerability Exploitability Exchange)](https://docs.binarly.io/user-guides/export/vex.md) - [JIRA Integration](https://docs.binarly.io/user-guides/advanced/jira.md) - [Notifications](https://docs.binarly.io/user-guides/advanced/notifications.md) - [Roles](https://docs.binarly.io/user-guides/rbac/roles.md) - [Users](https://docs.binarly.io/user-guides/rbac/user-management.md) - [Quotas](https://docs.binarly.io/user-guides/rbac/quotas.md) - [Custom Rule Manager](https://docs.binarly.io/user-guides/rule-management/overview.md): Write, test, and deploy your own detection rules on the Binarly Transparency Platform. - [Playground](https://docs.binarly.io/user-guides/rule-management/playground.md): Interactively write and test detection rules against images before packaging them into a Ruleset. - [Rulesets](https://docs.binarly.io/user-guides/rule-management/rulesets.md): Package and push your detection rules to the Binarly Registry as OCI artifacts. - [Deployments](https://docs.binarly.io/user-guides/rule-management/deployments.md): Deploy Rulesets to run automatically on image scans at the organization or product level. - [Detection Methods and Limitation](https://docs.binarly.io/resource-center/detection-methods.md): How Binarly identifies vulnerabilities using version-based and rule-based detection, including ecosystem filtering to reduce false positives. - [Vulnerability Data Sources](https://docs.binarly.io/resource-center/vdb-sources.md): Reference for all vulnerability data sources used by the Binarly platform. - [Cryptographic Detection](https://docs.binarly.io/resource-center/cryptographic-detection.md): How the Binarly Transparency Platform detects cryptographic materials in firmware and binary images. - [Secrets Detection](https://docs.binarly.io/resource-center/secrets-detection.md): How the Binarly Transparency Platform detects hardcoded secrets across firmware, container images, source files, and binary artifacts. - [Hardening Analysis](https://docs.binarly.io/resource-center/hardening-analysis.md): How the Binarly Transparency Platform detects missing security mitigations and binary weaknesses in compiled binaries. - [Cryptographic Algorithm Detection Reference](https://docs.binarly.io/resource-center/algorithm-compliance.md): Full reference of cryptographic algorithms, protocols, and certificate issues detected by BTP, with classification status and NIST IR 8547 PQC compliance assessment. - [Finding Types & Classes](https://docs.binarly.io/resource-center/finding-types.md): Reference documentation for finding types and their associated finding classes. - [Finding Classes Reference](https://docs.binarly.io/resource-center/finding-classes.md): Complete reference documentation for all finding classes generated by the Binarly analysis pipeline. - [Accuracy & Confidence in Findings](https://docs.binarly.io/resource-center/accuracy-confidence.md) - [Binarly Risk Score](https://docs.binarly.io/resource-center/binarly-risk-score.md): How the Binarly Risk Score turns exploitation, impact, decision, and finding-type signals into one transparent 0 to 1 priority score, with selectable profiles. - [Attack Surface Approximation and Prioritisation (ASAP)](https://docs.binarly.io/resource-center/asap.md): How Binarly computes reachability across four levels, from within a single binary up to the environment-aware attack surface, to prioritise the findings that actually matter. - [Severity Levels](https://docs.binarly.io/resource-center/risk-scoring.md) - [EMS Escalations: Exploitation Maturity Score scale and triggers](https://docs.binarly.io/resource-center/ems-escalations.md): Learn how the Exploitation Maturity Score (EMS) rates vulnerabilities on a 0-10 scale, when escalations trigger, and how ransomware and KEV signals apply. - [Transitive Dependencies](https://docs.binarly.io/resource-center/transitive-dependencies.md) - [Debugging Symbols](https://docs.binarly.io/resource-center/debugging-symbols.md) - [ISA/IEC 62443 Compliance Capability Mapping](https://docs.binarly.io/resource-center/isa-iec-62443-compliance-mapping.md): How the Binarly Transparency Platform maps to ISA/IEC 62443 industrial cybersecurity requirements for firmware and software component security. - [Release cadence & versioning](https://docs.binarly.io/release-notes/release-cadence.md): How Binarly versions and ships the Transparency Platform. - [3.75.0+2026.08.11](https://docs.binarly.io/release-notes/v3.75.0.md): Binarly v3.75.0 release notes: environment-aware risk scoring, new Alpine/Debian/Rocky Linux vulnerability data sources, and VulHunt detection for BRLY-2026-044 in BMC firmware. - [3.68.1+2026.08.04](https://docs.binarly.io/release-notes/v3.68.1.md): Binarly v3.68.1 release notes: PQC Compliance reachability display update, RPM package details for generic image scans, and a fix for vulnerability source prioritization. - [3.66.0+2026.07.28](https://docs.binarly.io/release-notes/v3.66.0.md): Binarly v3.66.0 release notes: Environment Reachability enabled for all platform instances, Linux kernel ELF support, and a new CVE-2026-43499 detection rule. - [3.63.3+2026.07.21](https://docs.binarly.io/release-notes/v3.63.3.md): Binarly v3.63.3 release notes: license info in apk and rpm package details, updated severity tags, a Product Admin upload fix, and an Activity tab crash fix. - [3.59.0+2026.07.14](https://docs.binarly.io/release-notes/v3.59.0.md): Binarly v3.59.0 release notes: saved filters now use Code Reachability, plus a severity column bug fix. - [3.57.3+2026.07.13](https://docs.binarly.io/release-notes/v3.57.3.md): Binarly v3.57.3 release notes: bug fixes for finding details, vulnerable code snippet retrieval, report formatting, and reachability display. - [3.56.2+2026.07.09](https://docs.binarly.io/release-notes/v3.56.2.md): Binarly v3.56.2 release notes: risk score in the findings grid, Code and Environment Reachability columns, Alpine vulnerability advisory source, plus bug fixes. - [3.53.4+2026.07.01](https://docs.binarly.io/release-notes/v3.53.4.md): Binarly v3.53.4 release notes: new UEFI detections for writable SPI flash and Secure Boot Setup Mode, VulHunt U-Boot coverage, and apk package support. - [3.53.0+2026.06.23](https://docs.binarly.io/release-notes/v3.53.0.md): Binarly v3.53.0 release notes: MCUboot bootloader and Zephyr firmware analysis support, plus CVEHunt dependency scanning for MCUboot, Zephyr, U-Boot. - [3.50.1+2026.06.17](https://docs.binarly.io/release-notes/v3.50.1.md): Binarly v3.50.1 release notes: RPM dependency vulnerability detection for RockyLinux ISO images, debug symbol exclusion, dependencies grid fix. - [3.49.1+2026.06.10](https://docs.binarly.io/release-notes/v3.49.1.md): Binarly v3.49.1 release notes: logarithmic EMS score normalization, VulHunt detection for CVE-2026-45185 in Exim, RSA badkeys CryptoScan checks. - [3.47.1+2026.06.02](https://docs.binarly.io/release-notes/v3.47.1.md): Binarly v3.47.1 release notes: secret validity filtering GA, Mitigate detection for Insyde FDM misconfigurations, more finding identifier types, and Python analysis fixes. - [3.41.0+2026.05.26](https://docs.binarly.io/release-notes/v3.41.0.md): Binarly v3.41.0 release notes: VulHunt detection for CVE-2026-33243 in U-Boot, extended CVE-2022-37434 zlib coverage, a KSPP ARM hardening check, and CryptoScan key formats. - [3.38.1+2026.05.19](https://docs.binarly.io/release-notes/v3.38.1.md): Binarly v3.38.1 release notes: secret validity in reports, VulHunt detection for CVE-2022-37434 in zlib and NVIDIA DGX Spark MM modules, and a git processing fix. - [3.35.1+2026.05.13](https://docs.binarly.io/release-notes/v3.35.1.md): Binarly v3.35.1 release notes: secret validity in the findings grid, standalone UEFI MM module analysis, U-Boot image support, and CVE-2026-33243 detection. - [3.31.1+2026.05.06](https://docs.binarly.io/release-notes/v3.31.1.md): Binarly v3.31.1 release notes: redesigned findings page by default, SSVC column reorder, improved SSVC scoring, and VulHunt detection for CVE-2024-25178. - [3.25.2+2026.04.28](https://docs.binarly.io/release-notes/v3.25.2.md): Binarly v3.25.2 release notes: CycloneDX SBOM output fix, restored Components tab hierarchy, and more reliable vulnerability database queries. - [3.22.0+2026.04.21](https://docs.binarly.io/release-notes/v3.22.0.md): Binarly v3.22.0 release notes: a default comparison column, plus general availability of CVSS vector display, triage improvements, and findings scope filtering. - [3.19.2+2026.04.15](https://docs.binarly.io/release-notes/v3.19.2.md): Binarly v3.19.2 release notes: finding variants in SBOM, VEX, and CBOM exports, VulHunt detection for CVE-2024-56171 in libxml2, and reliability fixes. - [3.11.3+2026.04.07](https://docs.binarly.io/release-notes/v3.11.3.md): Binarly v3.11.3 release notes: large-scale scan stability, expanded secrets scanning file types and validators, and an SBOM version reporting fix. - [3.8.1+2026.04.01](https://docs.binarly.io/release-notes/v3.8.1.md): Binarly v3.8.1 release notes: redesigned finding details, variants management, an AI triage assistant, and CycloneDX SBOM enrichment. - [v3.6](https://docs.binarly.io/release-notes/v3.6.md) - [v3.5](https://docs.binarly.io/release-notes/v3.5.md) - [v3.0](https://docs.binarly.io/release-notes/v3.0.md) - [v2.8](https://docs.binarly.io/release-notes/v2.8.md) - [v2.7](https://docs.binarly.io/release-notes/v2.7.md) - [v2.5](https://docs.binarly.io/release-notes/v2.5.md) - [v2.0](https://docs.binarly.io/release-notes/v2.0.md) - [Get Started](https://docs.binarly.io/api-reference/introduction.md): Welcome to the Binarly Transparency Platform API - [Setup API Client](https://docs.binarly.io/api-reference/authentication/create-api-client.md) - [M2M Authentication](https://docs.binarly.io/api-reference/authentication/get-m2m-token.md) - [User Authentication](https://docs.binarly.io/api-reference/authentication/generate-token.md) - [SaaS API Considerations](https://docs.binarly.io/api-reference/deployment/saas-considerations.md): API specifics for SaaS deployments - [On-Prem API Considerations](https://docs.binarly.io/api-reference/deployment/onprem-considerations.md): API specifics for On-Premise deployments - [Troubleshooting](https://docs.binarly.io/api-reference/troubleshooting.md): Get help with the Binarly Transparency Platform - [Overview](https://docs.binarly.io/api-reference/use-cases/cicd/overview.md): Learn how to automate firmware security scanning in your CI/CD pipeline. - [Bash Script](https://docs.binarly.io/api-reference/use-cases/cicd/bash.md): Universal bash script for CI/CD integration - [GitHub Actions](https://docs.binarly.io/api-reference/use-cases/cicd/github-actions.md): GitHub Actions workflow for firmware scanning - [Jenkins Pipeline](https://docs.binarly.io/api-reference/use-cases/cicd/jenkins.md): Jenkinsfile pipeline for firmware scanning - [GitLab CI](https://docs.binarly.io/api-reference/use-cases/cicd/gitlab-ci.md): GitLab CI/CD configuration for firmware scanning - [Verify Results](https://docs.binarly.io/api-reference/use-cases/cicd/verify-results.md): Pass/fail CI/CD builds based on findings analysis with comparison statistics - [Triage & Analysis](https://docs.binarly.io/api-reference/use-cases/triage-and-analysis.md): Identify regressions and analyze security findings. - [Compliance Artifacts](https://docs.binarly.io/api-reference/use-cases/compliance-artifacts.md): Generate SBOMs, VEX, CBOM, and PQC compliance reports for supply chain security. - [List Products](https://docs.binarly.io/api-reference/product/list-products.md) - [Get Product](https://docs.binarly.io/api-reference/product/get-product.md) - [Create Product](https://docs.binarly.io/api-reference/product/create-product.md) - [List Images](https://docs.binarly.io/api-reference/image/list-images.md) - [Get Image](https://docs.binarly.io/api-reference/image/get-image.md) - [Upload Image](https://docs.binarly.io/api-reference/image/upload-image.md) - [Upload Debug Symbols](https://docs.binarly.io/api-reference/file/create-file-attachment.md) - [Get Scan](https://docs.binarly.io/api-reference/scan/get-scan.md) - [List Components](https://docs.binarly.io/api-reference/scan/scan-components.md) - [List Scans](https://docs.binarly.io/api-reference/scan/list-scans.md) - [SBOM Reports](https://docs.binarly.io/api-reference/report/sbom-report.md) - [VEX Reports](https://docs.binarly.io/api-reference/report/vex-report.md) - [CBOM Reports](https://docs.binarly.io/api-reference/report/cbom-report.md) - [PQC Compliance Report](https://docs.binarly.io/api-reference/report/pqc-report.md) - [Findings Report](https://docs.binarly.io/api-reference/report/findings-report.md) - [Compare Findings](https://docs.binarly.io/api-reference/finding/compare-findings.md) - [Considerations](https://docs.binarly.io/on-prem/v3/considerations.md) - [Configuration](https://docs.binarly.io/on-prem/v3/configuration.md) - [Installation](https://docs.binarly.io/on-prem/v3/installation.md) - [Uninstallation](https://docs.binarly.io/on-prem/v3/uninstallation.md) - [Virtual Machine Deployment](https://docs.binarly.io/on-prem/v3/virtualmachine.md) - [Considerations](https://docs.binarly.io/on-prem/v2/considerations.md) - [Configuration](https://docs.binarly.io/on-prem/v2/configuration.md) - [Installation](https://docs.binarly.io/on-prem/v2/installation.md) - [Removal](https://docs.binarly.io/on-prem/v2/uninstallation.md) ## Optional - [Free Scanner](https://risk.binarly.io) - [VulHunt](https://vulhunt.re) - [Github](https://github.com/binarly-io/) - [Advisories](https://www.binarly.io/advisories) - [Product Blog](https://www.binarly.io/blog) - [Research Blog](https://www.binarly.io/articles)