Red Balloon Security
New York, US Β· Founded 2011 Β· 33 employees on LinkedIn Β· 4 known investors
Red Balloon Security develops host-based runtime defense solutions for devices in critical infrastructure environments. The company serves government agencies and Fortune 500 enterprises in aerospace, automotive, telecommunications, and other critical sectors.
Also known as RBS
Founders & leadership
Red Balloon Security was founded in 2011 by Dr. Ang Cui.
Board
Investors Β· 4
Reported raises Β· per SEC filings
Form D private placements$15.7M disclosed across 1 of 3 rounds Β· 2018β2021
βΆ$15.7MraisedMar 2018 Β· 8 investors Β· Other TechnologyRule 506(b)
- Enrique SalemDirector
- Ang CuiExecutive Officer, Director
- Offering amount
- $15.7M
- Amount sold
- $15.7M
- First sale
- Feb 2018
- Incorporated
- Corporation, Delaware
- Federal exemptions
- 06b
Source: SEC EDGAR Form D. Amounts as filed; amended filings shown once at their latest values.
Company profile
researched Aug 2026Red Balloon Security is a New York-based embedded device and firmware security provider and research firm. Its core technology, Symbiote Defense, is a host-based firmware defense that is injected into the firmware of embedded devices, where it continuously verifies the integrity of static code and memory at the firmware level so that only authorized software can execute, and reports anomalous behavior in real time. The technology is designed to work without access to source code and without changes to hardware design, and is presented as effective against both n-day and zero-day attacks, including cases where perimeter controls have been bypassed.
The product portfolio extends beyond runtime defense. Firmware hardening capabilities include Autotomic Binary Reduction (ABR), which removes unused firmware features, Binary Structure Randomization (BSR), which randomizes code layout, and the FRAK appliance, which supports hardening and micropatching of legacy devices. The Symbiote Suite adds runtime monitoring across networks of embedded devices with unified alerting and forensic analysis, and the company sells device assessments, bitstream and binary analysis (including FPGA bitstreams and reverse engineering), and on-call consulting from the researchers who built the products. Symbiote is described as operating-system agnostic β with deployments spanning Linux, Android, Windows CE, VxWorks, QNX, Cisco IOS, Nuttx, Nucleus, ThreadX, RTA-OS and LynxOS, as well as systems with no OS β and platform independent across ARM, ARM 64, ARM Thumb, MIPS, PowerPC VLE, x86, x64, AVR and MSP430 instruction set architectures.
The company is also known for public vulnerability research, including work on Cisco secure boot (Thrangrycat), Siemens SIMATIC and SIPLUS S7-1500 protected boot bypasses, the Funtenna firmware exploit that turns devices into covert radio transmitters, and the Monitor Darkly monitor-firmware vulnerabilities affecting Dell, HP, Samsung and Acer displays.
Founding story
Ang Cui developed the Symbiote firmware defense technology as a researcher in Columbia University's Intrusion Detection Systems Lab while pursuing a Ph.D. in computer science, with a dissertation titled 'Embedded System Security: A Software-Based Approach.' He founded Red Balloon Security to commercialize that technology and serves as its CEO.
Business model
Red Balloon Security licenses and deploys its Symbiote embedded security software to device manufacturers and end users, and pairs it with professional services: device security assessments, binary and bitstream analysis, integration support and on-call consulting. It also performs government-funded research and development, with programs supported by DARPA, DHS Science and Technology Directorate and other agencies feeding capabilities back into the commercial product line.
Sources describe product deployment (for example, HP's licensing of Symbiote for LaserJet Enterprise printers), government research contracts and funded pilots, and consulting/assessment services, but do not disclose pricing, contract values or revenue figures.
Traction
Company materials claim 15 years of defending critical systems, roughly 150 billion device hours protected and zero in-field exploits; the Series A announcement stated Symbiote had operated more than 15 billion continuous hours without a failure while protecting millions of endpoints. HP licensed Symbiote for its enterprise LaserJet lines in 2015, and Symbiote has been deployed by DARPA, the DoD, DHS and other agencies, with integrations into a dozen devices of interest to the U.S. Government.
Latest developments
Current company materials highlight four capability areas β firmware hardening, runtime protection, embedded device assessments, and bitstream/binary analysis β and recent research including critical vulnerabilities in Siemens SIMATIC and SIPLUS S7-1500 controllers that bypass protected boot, the DARPA RADICS power-grid program, U.S. government-funded work on network controllers at the PIADC facility, and the Thrangrycat Cisco secure boot bypass. Research projects listed for defense and aerospace include LADS (analog, air-gapped alert transmission) and AMP (applied micropatching via FRAK).
βΈFull profile β market position, technology, go-to-market, geography, history, risks & controversies
Market position
The company positions itself as a specialist in device-level, firmware-resident protection for critical infrastructure, contrasted with perimeter defenses and patch-based approaches. Its investors and press coverage frame it as a leading provider of embedded/endpoint security; Bain Capital Ventures cited a multi-billion dollar addressable market for connected-device security. The sources name no direct competitors.
Protection is applied inside device firmware rather than at the network perimeter, requires no source code or hardware modification, and is portable across operating systems (or none) and many instruction set architectures. The company emphasizes long-running field deployments without reported in-field exploits or false positives, deep government pedigree (DARPA, DoD, DHS funding and deployments), and a research team with published academic work and disclosed vulnerabilities in widely used devices.
Technology
Symbiote is a host-based firmware defense injected into existing device firmware to perform continuous integrity checking of static code and memory, blocking unauthorized code or command execution and generating real-time integrity alerts. It requires no source code access or hardware redesign and is claimed not to degrade device functionality or performance. Complementary components include ABR (binary reduction), BSR (binary structure randomization) and the FRAK appliance for firmware hardening and applied micropatching of legacy devices; AESOP collects telemetry from Symbiote payloads, and the LADS research project explores analog out-of-band alert transmission (via LED light or electromagnetic emission) for fully air-gapped reporting. Symbiote is OS-agnostic and supports a broad set of instruction set architectures.
Go-to-market
Direct enterprise and government sales supported by demo requests and contact forms on the company site, integration partnerships with device manufacturers such as HP, and government programs and pilots (DARPA RADICS, DHS-funded facility pilots, PIADC network controller research). Public security research, conference talks (Black Hat, DEF CON, RSA, Chaos Communication Congress, Escar USA) and contributions to events such as the USAF Hack-A-Sat challenge serve as visibility channels.
Government agencies and commercial enterprises operating embedded and operational technology systems, including defense and aerospace (satellites, spacecraft, telecommunications equipment), industrial control systems and building management systems, electrical grid equipment such as relays and RTUs, automotive systems, and device manufacturers. Named or cited users include HP, DARPA, the Department of Defense and the Department of Homeland Security.
Geography
Headquartered in New York City, with work concentrated on U.S. government agencies and facilities; sources do not describe offices outside the United States.
History
Founded in 2011 by Dr. Ang Cui, with Symbiote Defense originating in Columbia University's Intrusion Detection Systems Lab and developed over roughly a decade with support from DARPA and the DHS Science and Technology Directorate. HP licensed Symbiote for its LaserJet Enterprise printers in 2015; the company launched Symbiote for Automotive Defense in June 2017 and received DHS's 'Crossing the Valley of Death' distinction in July 2017 after a 12-month DHS-funded pilot at a Biosafety Level 3 facility. In-Q-Tel announced a development agreement and investment in April 2018, and the company later disclosed a $21.9 million Series A led by Bain Capital Ventures that brought total financing to $23.5 million. Note: one source dates the Ph.D. and company founding differently (Ph.D. received 2015, company founded 2011).
Risks & controversies
The company's public vulnerability research has repeatedly exposed flaws in third-party products (Cisco IP phones and routers, HP LaserJet printers, Siemens PLCs, Dell/HP/Samsung/Acer monitors), which carries disclosure and vendor-relations sensitivity. The Wikipedia biography of founder Ang Cui carries an editorial notice that a major contributor appears to have a close connection with the subject, so claims sourced there may lack neutrality. Website performance claims (150 billion device hours protected, zero in-field exploits, zero false positives) are self-reported and unverified in the available sources.
Compiled by commissioned research from 8 cited public sources β announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed β not independently audited.
Competitors Β· 3
by search overlapCompanies competing with Red Balloon Security for the same Google search keywords, organic and paid, via search-intersection analysis.
Non-dilutive funding Β· 10 SBIR/STTR awards
Federal grants β no equity taken| Agency | Phase | Year | Amount |
|---|---|---|---|
| Defense Advanced Research Projects Agency (DARPA)Defense Advanced Research Projects Agency | Phase II | 2022 | $4M |
| U.S. Air ForceAir Force | Phase II | 2021 | $749.9K |
| Department of Homeland Security | Phase II | 2019 | $999.8K |
| Defense Advanced Research Projects Agency (DARPA)Defense Advanced Research Projects Agency | Phase II | 2018 | $999.9K |
| Department of Homeland Security | Phase I | 2018 | $150K |
| Department of Homeland Security | Phase II | 2017 | $746.8K |
| Department of Homeland Security | Phase I | 2016 | $100K |
| Department of Homeland Security | Phase II | 2015 | $754.9K |
| Department of Homeland Security | Phase I | 2014 | $99.5K |
| Defense Advanced Research Projects Agency (DARPA)Defense Advanced Research Projects Agency | Phase I | 2013 | $100K |
Source: SBIR.gov award data (U.S. Small Business Administration). SBIR/STTR awards are competitive federal R&D grants and contracts β non-dilutive capital alongside any venture rounds above.
Timeline Β· 7
launches, deals, and filingsSeries A financing of $21.9 million led by Bain Capital Ventures with participation from Greycroft, American Family Ventures and Abstract Ventures, bringing total financing to $23.5 million. Proceeds earmarked for expanding business operations and commercial deployment of Symbiote Defense. Bain Capital Ventures managing director Enrique Salem commented on the investment.
$21.9M source β
The company contributed several challenges to the 2020 DEF CON Hack-A-Sat challenge presented by the U.S. Air Force.
In-Q-Tel announced a development agreement and investment with Red Balloon Security to produce government and commercial versions of the Symbiote Defense embedded security platform, building on prior work with the Departments of Defense and Homeland Security.
The U.S. Department of Homeland Security recognized the company with the 'Crossing the Valley of Death' distinction for developing a commercially available cyber defense system for critical infrastructure facilities, following a 12-month DHS-funded pilot study evaluating cyber sabotage risks to the building systems of a DHS Biosafety Level 3 facility.
Red Balloon Security announced an automotive version of its Symbiote technology at the Escar USA Conference in Detroit.
Popular Science named Symbiote one of the '9 Most Important Security Innovations of the Year' in its 2016 'Best of What's New' awards.
HP licensed the Symbiote technology as a firmware defense against cyber attacks for its LaserJet Enterprise printers and multifunction printers.
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
βΈResearch sources Β· 8
primary sources listed
- Red Balloon Securityredballoonsecurity.com Β· web
8 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does Red Balloon Security do?
- Embedded device and firmware security company whose Symbiote technology adds runtime defense to critical-infrastructure hardware.
- Who founded Red Balloon Security?
- Red Balloon Security was founded by Dr. Ang Cui in 2011.
- Who are Red Balloon Security's investors?
- Red Balloon Security's investors include Abstract Ventures, American Family Ventures, Greycroft, Bain Capital Ventures.
- How much funding has Red Balloon Security raised?
- Red Balloon Security has disclosed $15.7M raised across 1 of its 3 known rounds.
- Where is Red Balloon Security headquartered?
- Red Balloon Security is headquartered in New York, US.


