GrammaTech Launches REAFFIRM 1.0 for Advanced Firmware Security

New release helps organizations determine which vulnerabilities are actually exploitable and prioritize the risks that matter

ITHACA, N.Y. – October 1, 2026 – GrammaTech, a leading provider of advanced AI and cybersecurity research, software assurance technologies, and cyber resilience products, today announced REAFFIRM 1.0, a major release of its firmware and binary security analysis platform. REAFFIRM goes beyond identifying potential vulnerabilities to determine whether vulnerable code is actually present, reachable, and exploitable.

Traditional security scanners can identify Common Vulnerabilities and Exposures (CVEs) associated with software components, but a CVE match does not necessarily mean a vulnerability can be exploited in a particular system. REAFFIRM checks whether vulnerable functions are actually present, traces whether they can be reached through the software, and analyzes how data flows to them. This provides stronger evidence of exploitability and helps security teams focus on vulnerabilities that present meaningful risk.

“Security teams don’t need another list of possible vulnerabilities. They need to know which ones actually matter,” said Dr. Lucja Kot, CEO of GrammaTech. “REAFFIRM helps provide that evidence by determining whether vulnerable code is present, whether an attacker can reach it, and whether it can be exploited. That gives organizations a much stronger basis for deciding where to focus their security resources.”

This is particularly important for firmware, the software embedded in devices that controls how they operate. Firmware is common across operational technology, mission systems, critical infrastructure, and embedded equipment, but it can be difficult for conventional security tools to inspect. Source code is often unavailable, and testing vulnerabilities directly on operational equipment can disrupt the device or the physical process it controls. REAFFIRM can analyze firmware and test important components away from operational equipment to determine whether identified vulnerabilities can manifest under realistic conditions.

REAFFIRM 1.0 also introduces AI-supported reporting and interaction to make complex findings easier to understand and act on. The platform can generate executive summaries, red-team exploitation guides, and blue-team mitigation recommendations. A conversational AI agent allows users to interactively query analysis results and binary artifacts. AI is integrated where its output can be checked against underlying evidence rather than relied upon independently to make security judgments.

The release delivers significant improvements in performance, scale, and analysis coverage. REAFFIRM now supports Kubernetes deployments through Helm and uses a Postgres-backed index for large software and firmware collections. YARA scanning performance has improved from approximately 22 seconds per binary to 0.15 seconds, while a rebuilt interface enables faster navigation of large projects.

REAFFIRM 1.0 also adds deeper support for 32- and 64-bit RISC-V, LoongArch, and big-endian ARM architectures. The platform now includes 53 analysis commands, with new capabilities for deep string analysis, taint analysis, and Software Bill of Materials (SBOM).

For organizations responsible for operational technology, mission systems, embedded equipment, and critical infrastructure, REAFFIRM provides a clearer answer to a critical question: Which vulnerabilities actually put this system at risk? That evidence helps organizations prioritize remediation, make informed deployment and acquisition decisions, and focus cybersecurity resources where they can have the greatest impact.

About GrammaTech

GrammaTech is a leading provider of advanced artificial intelligence (AI) and cybersecurity research, software assurance technologies, and cyber resilience products. For more than 35 years, GrammaTech has developed innovative solutions that help government and commercial organizations analyze, secure, and modernize critical software systems. The company applies deep expertise in AI, software analysis, cybersecurity, and binary and firmware analysis to turn advanced research into practical capabilities for some of the world’s most complex software and security challenges.