FDIE

Firmware evidence that stays connected across releases.

Firmware Delta Intelligence Engine is a product of MAGDOX Private Limited, operated by its own team at fdie.dev. This page introduces what it does and where its scope ends; fdie.dev is the authoritative source for capabilities, formats and terms.

Firmware & connected devices

Supported images.
Reviewable release evidence.

What FDIE is for

Review the artifact. Keep the context.

Connected-device teams inherit most of what ships in a firmware image. FDIE makes the image inspectable: what is inside, which known vulnerabilities apply, what changed since the last release and what a reviewer decided last time. The output is built to be cited in a release decision or an audit request.

  • Component identification and vulnerability matching
  • Delta intelligence across firmware releases
  • SBOM, CBOM and VEX exports for supported images

Capabilities and limits

What it does, stated with its boundaries.

Paraphrased from FDIE’s published documentation. Counts, supported formats and framework lists are maintained on fdie.dev and are not restated here.

Extraction and component identification

Supported firmware images are unpacked and their components identified, then matched against vulnerability and known-exploited data. Unsupported or unreadable regions remain a stated coverage limitation.

Delta intelligence across releases

Two analysed releases are compared at component level and, where supported, at function level. Earlier triage decisions are carried forward for review. A changed function informs patch review; it does not prove a fix.

Bounded dynamic analysis

Where an image can be emulated, FDIE records runtime observations and runs bounded, coverage-guided fuzzing with stated limits. Architecture support alone does not guarantee that an image will boot.

Framework checks and disclosure review

Automated control checks run across the frameworks FDIE publishes. Disclosure-related review is kept separate and is not graded. None of this replaces a conformity assessment.

Inventory and evidence exports

SBOM in CycloneDX and SPDX, CBOM and VEX for the analysed image. A VEX decision still requires a justified assessment by your team.

Hosting and deployment

Hosted by the FDIE team with region agreed per order; on-premise or air-gapped deployment on request. A single enterprise plan; evaluations are arranged with the FDIE team.

Security and assurance

Controls published by FDIE.

FDIE documents encryption at rest and in transit, organisation- scoped tenant isolation, role-based access, audit logging and the open-source components its engine builds on. It states that it holds no formal certification today and publishes its own assurance roadmap.

FDIE security documentation

Relationship to MAGDOX Code Security

Separate products, one standard.

FDIE examines firmware images. MAGDOX Code Security examines source code and dependencies. They share how a result is recorded, with evidence, coverage and decisions, and nothing else: no shared pipeline, dashboard or automatic source-to-binary link.

Compare the two products

Next step

Bring a supported image and a release pair.

The FDIE team confirms image compatibility, deployment region and evaluation scope. Contact us here if you are unsure which product fits, or go straight to fdie.dev.