Testing Matched to Your Devices
Embedded security depends entirely on what you are building, who it is built for, and how easily it can be updated once it leaves your control. These are the organizations we most often work with.
IoT and Connected Product Manufacturers
Consumer and commercial devices where firmware, wireless communication, and the component supply chain each introduce risk.
Communications and Network Equipment Vendors
Routers, gateways, and access equipment that sit at the edge of the network and stay in service long after they ship.
Industrial and ICS Operators
Environments where operational technology meets corporate networks, and where downtime carries a direct and measurable cost.
Automotive and Mobility Suppliers
Vehicles and their subsystems, where in-vehicle networks, wireless entry, and telematics extend the attack surface well beyond the ECU.
Medical Device Manufacturers
Teams working to regulatory expectations, where device security cannot be separated from patient safety.
Semiconductor and Hardware Vendors
Organizations validating secure boot, cryptographic implementations, and resistance to physical attack before a product ships.
Industry Experts in Embedded Security
Anvil’s Embedded Security Lab brings deep expertise across a broad range of embedded technologies, including IoT, industrial systems, automotive, communications, medical devices, and hardware platforms. Our engineers assess security across hardware, firmware, software, wireless communications, and system architecture, from early design through deployed products.
Anvil Secure is also an approved Open Compute Project (OCP) Security Review Provider, performing OCP SAFE assessments for hardware manufacturers and device vendors that require a standardized security evaluation of data-center hardware and firmware.
What Our Testing Covers
- Comprehensive device testing
- Component testing
- Device teardowns
- Secure boot
- Side channel attacks and glitching
- Reverse engineering
- Bluetooth and cellular (5G and LTE)
- Proprietary RF security
- Hardware and software security design review
- Secure code review
The Anvil Difference

Quality
We deliver exceptional work, executed by highly skilled engineers and guided by a commitment to continuous improvement.

People
We are an employee-owned and led firm, driven by a people-first approach in everything we do.โ

Contribution
We're active members of the information security community, advancing research, responsible disclosure, and inclusivity.
Clear Outcomes for Your Organization
Embedded findings are rarely convenient to fix after the fact. Every engagement is designed to deliver three outcomes your organization can act on:
Find Weaknesses Before Production
Identify design and firmware issues while they can still be corrected, rather than once a device is in the field and a fix requires a recall.
Meet Regulatory, Industry, and Customer Expectations
Independent, evidence-based testing that supports regulatory submissions, industry assurance programs such as OCP SAFE, and the security requirements your customers and partners expect.
Protect Devices You Cannot Easily Update
Understand how your device withstands physical access, side channel analysis, and wireless attacks in environments where patching is slow or impossible.
When to Commission Embedded Testing
Embedded security rewards early engagement more than any other kind of testing, because the cost of a change rises sharply as a device moves toward production.
■During Design, Before Hardware Is Committed
Architecture review at this stage prevents issues from becoming permanent once tooling and silicon are fixed.
■Before a Product Launch
Firmware, secure boot, and wireless interfaces validated before a device reaches customers.
■Ahead of a Regulatory Submission, Certification, or Industry Review
Independent security testing produced early enough to identify and remediate findings before review begins, including assessments supporting programs such as OCP SAFE.
■When Entering a New Market or Sector
Different regions and industries carry different security expectations for connected devices.
■Following a Component or Supplier Change
A new module, chipset, or firmware vendor alters the security posture of a device that was previously assessed.
What to Expect from an Engagement
Scoping
Project Mobilization
Testing and Validation
Our engineers use the techniques best suited to the device and problem at hand. Depending on the scope, this may include hardware and firmware analysis, reverse engineering, secure boot and update testing, wireless and protocol testing, fuzzing, code analysis, teardown, fault injection, or custom-built tooling. We follow findings across hardware, firmware, communications, and supporting software to understand what can be realistically exploited and the impact to the overall system.
Reporting
You receive an executive summary and detailed technical report with identified vulnerabilities prioritized by risk and business impact, supported by evidence, technical analysis, and practical remediation guidance. Critical findings are communicated as they are discovered rather than held for the final report.
Debrief and Closeout
We review the results with your team, answer questions, discuss remediation priorities and next steps, and gather feedback before delivering the final report. Where appropriate, we can also provide an optional estimate for retesting remediated firmware, software, or hardware changes. Retesting is only billed if performed and is generally expected within 60 days of the original assessment, though timing can be adjusted based on the nature of the remediation.
Why Embedded Testing Requires a Dedicated Lab
Embedded security cannot be assessed from the network alone. Establishing whether secure boot can be bypassed, whether a cryptographic key can be recovered through side channel analysis, or whether a debug interface remains accessible on a production unit requires physical access to the device and the equipment to work with it. Anvil’s Embedded Security Lab exists for that purpose.
It is also why our findings tend to be structural rather than superficial. Issues discovered at the firmware and hardware level often cannot be patched once a device is deployed, which is precisely why they are worth identifying before it ships.
Lab Capabilities
Board-level access and rework
Soldering and hot-air stations, microscopes, and BGA re-balling equipment for attaching test leads, lifting flash memories, and restoring devices to working order afterward.
Firmware extraction
eMMC, SPI, I2C, and parallel flash readers for pulling images directly off memory, including devices where the debug path is closed.
Bus interception
SPI, I2C, and UART capture for observing what a device says to its own components.
Debug interface exposure
JTAG and SWD adapters spanning multiple MCU and SoC vendors, with pinout discovery and brute forcing, plus UART and serial console access.
Fault injection and side channel analysis
ChipWhisperer Husky for voltage and clock glitching and power analysis, backed by oscilloscopes and logic analyzers.
Wireless and RF
Ettus software defined radios plus BLE, Zigbee, LoRa, and 802.15.4 hardware for protocol analysis and traffic capture.
Cellular and network
A private LTE/5G network for devices that phone home over cellular, and dedicated Wi-Fi and Ethernet test networks isolated from production.
Direct memory access
PCIe FPGA hardware for reading and modifying system memory directly.
Vehicle networks
CAN, LIN, and Automotive Ethernet interfaces for testing in-vehicle bus traffic and ECU behavior.
What the Lab Makes Possible
A dedicated lab changes what can be tested. Rather than stopping at theoretical analysis, our engineers can work directly with hardware, reproduce physical attack conditions, and determine whether security controls actually hold up in practice.
The Lab in Action
Firmware Trust Controls Bypassed
Using our firmware extraction and device-analysis capabilities, Anvil engineers acquired and analyzed the software running on an embedded device, then manipulated the update process to determine whether modified components would be rejected. The device accepted unauthorized firmware, demonstrating that its trust controls could be bypassed.
The lab turned a potential concern into a demonstrated attack path. We were able to show how the weakness could be exploited in practice and what it would mean for devices already in the field.
Hardware Security Control Bypassed Through Fault Injection
Using dedicated fault-injection equipment, precision triggering, and hardware instrumentation, Anvil engineers interfered with a security-sensitive operation at a specific point during execution. Under controlled conditions, the device skipped a validation step intended to enforce a hardware-backed security guarantee.
This demonstrated that a control assumed to be enforced by the hardware could be bypassed with physical access, an issue that cannot be resolved with a firmware update once the device has shipped.
Frequently Asked Questions
You do not need to define the testing methodology before contacting us. During scoping, we work with you to understand the device architecture, firmware, hardware, interfaces, communications, development stage, and security objectives, then recommend the combination of hardware, firmware, software, wireless, and architecture testing that will provide the most useful coverage.
Usually, we ask for approximately three devices: one that can be disassembled, one for dynamic testing, and one as a spare. Some testing, such as fault injection or glitching, may require additional units. The exact number depends on the scope and is agreed before testing begins.
Some embedded security testing can be invasive or destructive, particularly teardown, fault injection, component removal, or other physical techniques. We identify potentially destructive testing during scoping and agree on what is permitted before proceeding.
Yes. We can assess devices from a blackbox or graybox perspective, including extracting and reverse engineering firmware where appropriate. Source code, design documentation, build artifacts, or other engineering information can enable deeper analysis and reduce the time spent reconstructing how the system works, but they are not always required.
Embedded assessments can range from a few weeks to longer engagements depending on device complexity, interfaces, testing objectives, and the amount of hardware or firmware analysis required. As one example, a Linux-based connected device assessment covering secure boot, firmware updates, web interfaces, network communications, and firmware analysis may require approximately four person-weeks. The specific level of effort is defined during scoping.
We can assess products at multiple stages, from architecture and design through production. Engaging earlier can make it easier and less costly to address design-level findings before hardware and firmware decisions are fixed, while testing later in the lifecycle can validate the security of the product that will actually be deployed.
Embedded devices often require testing across multiple layers, including hardware, firmware, communications, and supporting applications. There may also be proprietary protocols, physical interfaces, or security controls that require custom analysis. Our engineers tailor the assessment to the device, using techniques such as reverse engineering, hardware analysis, fuzzing, code review, and specialized tooling to understand how weaknesses interact across the full system.
Critical or time-sensitive findings are communicated as they are identified rather than held until the final report. We agree on escalation contacts and communication expectations during scoping so your team knows how urgent issues will be handled.
You will receive an executive summary and detailed technical report documenting identified vulnerabilities, supporting evidence, risk and impact, and practical remediation guidance. We also conduct a readout with your team to walk through the results, answer questions, and discuss remediation priorities.
Yes. Anvil Secure is an approved Open Compute Project (OCP) Security Review Provider and performs OCP SAFE assessments for hardware manufacturers and device vendors. If your product has specific regulatory, customer, or industry security requirements, we can discuss those during scoping and determine the appropriate assessment approach.
Where appropriate, we can provide documentation confirming that an independent security assessment was completed. If you have specific regulatory, customer, or submission requirements, we can discuss those during scoping and determine what documentation is appropriate.
We can include an optional estimate for retesting as part of the engagement. Retesting is only billed if it is needed and performed. We generally recommend completing retesting within 60 days of the original assessment, although timing can be adjusted depending on the complexity of the remediation.
Anvil can retain devices through any agreed retesting period. Once testing and any agreed retesting are complete, devices can be returned or securely destroyed based on client preference. Depending on the techniques used, some devices may be returned disassembled, modified, or non-functional. We agree on device handling, return, or destruction before testing begins.
Start securing now.
Be proactive about threats to your embedded systems and devices. Reach out to Anvil for advanced security testing, in-depth analysis, and custom solutions.
