Skip to content

Product1 publisher3 min readPublished

Exein raises $270M on embedded security already running on more than two billion devices

Exein's valuation is thirty times what it was two years ago on technology already inside more than two billion devices, and the foundation model that telemetry is meant to train is not due until the first quarter of 2027.

The Product Desk · Product desk

Illustration accompanying Exein raises $270M on embedded security already running on more than two billion devices

What happened

  • Exein, a Rome-based embedded security company, raised $270 million at a $1.7 billion valuation to protect machines that act in the physical world, including robots, drones and autonomous vehicles.
  • Headline led the round, with Sofina, Goldman Sachs, European Investment Bank Group ETCI, KfW Capital and T.Capital taking part, and the company says the raise was significantly oversubscribed.
  • Exein reports around 5,000 new, non-repetitive attacks across its network each week, five times what it recorded a year ago.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision A team specifying a stack this year gets the shipping runtime and takes the 2027 model on promise, so the delivery dates belong in the purchase agreement.
  • exposure Every device shipped with Exein inside feeds the telemetry pool the company says competitors cannot copy. The OEM ends up supplying its vendor's main asset.
  • constraint Blocking execution at kernel level changes what a machine does in the field, and the device maker owns the support call when a legitimate process stops on something that moves.
  • precedent With half of revenue in Asia-Pacific and fresh semiconductor partnerships, the embedded security choice starts getting made at silicon selection, before any OEM security review opens.

For a team choosing the security package for a robot arm that ships next spring, the useful fact in this round is a date. Photon, the kernel-level runtime layer that blocks malicious execution before it can run, launched earlier this year [7]. The agentic architecture is promised by the end of 2026, and the first foundation models in the first quarter of 2027 [9]. A design decision made this quarter buys the first thing and pre-pays for the second.

The model is what the valuation prices. Exein says it has been in development for two years and is being trained on machine telemetry generated through its own technology across more than two billion devices, a dataset it says competitors would find difficult to replicate [8]. From the device maker's side, that works the other way round: every unit shipped with Exein inside is a contributor, and the advantage grows with the installed base.

Work the valuation backwards. Thirtyfold growth in two years [2] against $1.7bn puts the company somewhere near $57m in early 2024 [16]. First-half 2026 ARR was up four times year on year [4], and the announcement does not disclose the base it grew from, so the two billion devices and the revenue multiple cannot be joined into a picture of how much of that fleet is paid. The round also came alongside an upsizing of the existing revolving credit facility led by J.P. Morgan, with KfW joining as an additional lender [6].

Exein says it now sees around 5,000 new, non-repetitive attacks across its network each week, five times the level of a year ago [10]. That puts last year's figure near 1,000 a week [17]. The count comes from devices running Exein technology, and the installed base was growing over the same period, so the multiple tracks what the company can see as well as what attackers are doing.

The company's case for spending this money on machine-speed defence sits in one line of the announcement: "Frontier models are pushing the patch window to zero" [14].

Since its previous round in December 2025, Exein has set up its APAC headquarters in Taiwan and added partnerships across semiconductors, industrial computing and connected infrastructure [13]. About half of its revenue already comes from Asia-Pacific [11]. Those partnerships are a chip-and-board channel. A lot of device makers will encounter this stack as a default in a supplier's package before anyone in their own building evaluates it.

Two questions sort the decision. First, do you choose the embedded security stack, or does it arrive with the silicon? Second, does your product ship before or after Q1 2027? Choose-and-ship-early: price Photon on what it does today and treat the 2027 model as an option you did not pay for. Choose-and-ship-late: put the model's delivery dates in the contract, because those dates are the part of the pitch nobody can test yet. Inherit-and-ship-late: your silicon supplier's roadmap is your security roadmap, and the review to book is with them. The awkward cell is inherit-and-ship-early, where the runtime is already in the field and the first time anyone reads the datasheet is after a legitimate process gets stopped on a moving machine. The support ticket goes to whoever's name is on the robot.

What to watch

  • Whether the agentic architecture and the Q1 2027 foundation models arrive on schedule, and whether anything testable reaches buyers before then.
  • Whether Exein's customer contracts let a device maker decline to contribute machine telemetry to the training set.
  • Named design wins with chip and industrial-computing suppliers, which would show whether the stack becomes a default in board support packages.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories