---
title: Finite State Reviews
meta_title: 'Finite State Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter 12 reviews by the users' company size, role or industry to
  find out how Finite State works for a business like yours.
aggregate_rating:
  rating_value: 4.3
  review_count: 12
  scale: '5'
date_modified: '2026-07-10'
parent_category:
  name: Development
  url: https://www.g2.com/categories/development
---

# Finite State Reviews
**Vendor:** Finite State  
**Category:** [Software Supply Chain Security Solutions](https://www.g2.com/categories/software-supply-chain-security-tools)  
**Average Rating:** 4.3/5.0  
**Total Reviews:** 12
## About Finite State
Finite State empowers device OEMs to ship securely while enabling engineering teams to move at the speed of AI, immediately transforming product artifacts into audit-ready assurance through a single automated workflow. Leveraging deep binary analysis and AI-native execution, the platform unifies code, compiled components, and firmware in minutes—connecting security design with deployed software. By continuously generating SBOMs, VEX, and signed compliance packages, Finite State enables connected device companies across industries such as medical devices and automotive to meet evolving regulations, including the EU Cyber Resilience Act (CRA), and deliver continuous compliance at speed. Learn more at https://finitestate.io/




## Finite State Reviews
  ### 1. Finite State Review: Firmware Security Simplified

**Rating:** 5.0/5.0 stars

**Reviewed by:** Prasanth B. | Developer, Mid-Market (51-1000 emp.)

**Reviewed Date:** June 23, 2026

**What do you like best about Finite State?**

What I appreciate most about Finite State is its ability to make hidden risks visible. Traditional security tools often stop at surface-level checks, but Finite State digs deep into firmware and supply chain components to uncover vulnerabilities that would otherwise remain unnoticed. By generating detailed SBOMs and mapping out dependencies, it gives developers and security teams a clear picture of what’s inside their devices. This level of visibility is invaluable because it transforms complex, opaque systems into actionable insights, helping organizations prioritize fixes and strengthen their overall security posture.

**What do you dislike about Finite State?**

Finite State is powerful, but it can be resource‑intensive and complicated to adopt, which makes it harder for smaller or less security‑focused teams to get immediate value.

**What problems is Finite State solving and how is that benefiting you?**

Finite State is solving the problem of visibility and security in connected devices and their supply chains, which has traditionally been a blind spot for developers. Modern software often relies on third‑party libraries, open‑source components, and firmware bundles that are difficult to track manually. Finite State addresses this by automatically generating SBOMs, analyzing firmware, and mapping vulnerabilities to specific components.

**Official Response from Marketing Team:**

> Thanks for the thoughtful review, Prasanth. Surfacing firmware and supply chain risk, and making it clear enough to act on, is the problem we set out to solve, so we're glad that depth is proving valuable to your team. We also appreciate your perspective on adoption. Reducing the effort it takes to reach that first useful result is something we're continuously working to improve, and feedback like yours helps guide where we focus.

  ### 2. Deep Visibility Into Supply Chain Risks and CVEs—Boosting Product Security

**Rating:** 5.0/5.0 stars

**Reviewed by:** Suru S. | Manager, Enterprise (> 1000 emp.)

**Reviewed Date:** June 16, 2026

**What do you like best about Finite State?**

What I like best about Finite State is its ability to provide deep visibility into software supply chain risks by accurately identifying CVEs across third-party components and embedded dependencies. This level of insight, especially at the binary and firmware level, helps us proactively address vulnerabilities that are otherwise hard to detect. As a result, it enables better risk prioritization and contributes directly to improving the stability and security of our products.

**What do you dislike about Finite State?**

The onboarding can take some time, and the UI can feel a bit complex at first. Also, scans for larger files can be slow, which affects quick feedback. Simplifying the interface and improving speed would make it easier to use.

**What problems is Finite State solving and how is that benefiting you?**

Finite State helps us identify vulnerabilities (CVEs) in third-party and embedded components that are usually hard to detect. This improves our visibility into security risks, allowing us to fix issues early. As a result, our products become more stable, secure, and reliable before release.

**Official Response from Marketing Team:**

> Thanks for sharing your experience, Suru. Identifying CVEs across third-party and embedded components at the binary and firmware level, where they're often hardest to catch, is difficult and detailed work, so we're glad that depth is helping strengthen the security and stability of your products. We've also noted your feedback on onboarding and scan performance for larger files, and streamlining those parts of the experience is something we're continuously working to improve.

  ### 3. A Powerful Platform for Software and Firmware Security

**Rating:** 5.0/5.0 stars

**Reviewed by:** Anitha M. | Security Engineer, Enterprise (> 1000 emp.)

**Reviewed Date:** June 22, 2026

**What do you like best about Finite State?**

The platform is easy to navigate and offers strong visibility into vulnerabilities, helping teams quickly identify and address risks. Its structured approach simplifies complex security analysis, making it easier to prioritize what truly matters and improve overall product quality with reliability.

**What do you dislike about Finite State?**

One area for improvement is some parts of the interface can also feel a bit dense, making navigation less intuitive. Additionally, scan times for larger files may be longer, which can slow down feedback. Simplifying the user experience and improving integrations would make it easier for teams to adopt and use effectively.

**What problems is Finite State solving and how is that benefiting you?**

Finite State helps identify and manage security risks across software and firmware. It provides clear visibility into vulnerabilities, enabling faster remediation, improving product security, and giving greater assurance in compliance and release readiness.

**Official Response from Marketing Team:**

> Thanks for the detailed review, Anitha. Giving your team clear visibility and a structured way to focus on the risks that matter most is what we're after, so we're glad that's coming through. We've also noted your feedback on interface density and scan times for larger files. Both are areas we're actively working to improve, and detailed feedback like yours helps us prioritize the right things.

  ### 4. Efficient Vulnerability Scanning, Needs Exploration

**Rating:** 3.5/5.0 stars

**Reviewed by:** venkat a. | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 02, 2026

**What do you like best about Finite State?**

I like using Finite State for Binary Scanning and Vulnerability analysis, especially since certain features like the FS-CLI command line interface and UI options are more straightforward compared to Blackduck. I appreciate the Vulnerability Reporting on critical items and find the license pricing per project to be an advantage. The initial setup was smooth, thanks to a demo session from partners.

**What do you dislike about Finite State?**

As of now there is no such, but the UI could be more interactive while reports downloads.

**What problems is Finite State solving and how is that benefiting you?**

I use Finite State for Binary Scanning and Vulnerability analysis. It has a straightforward FS-CLI and UI options, and the vulnerability reporting on critical items is beneficial. The license pricing per project is also an advantage.

**Official Response from Marketing Team:**

> Thanks for sharing your experience, Venkat. We're pleased to hear that the simplicity of the FS-CLI, intuitive UI, and binary scanning capabilities are helping your team analyze vulnerabilities more efficiently. It's also great to know that the reporting, project-based licensing, and onboarding experience provided value from the start.

We appreciate your suggestion about making report downloads more interactive. Feedback like this helps us continue refining the user experience while keeping the platform focused on delivering clear, actionable security insights for product security teams.

  ### 5. Friendly UI and timely scans, but organization and ECU component definitions need work

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Automotive | Enterprise (> 1000 emp.)

**Reviewed Date:** June 16, 2026

**What do you like best about Finite State?**

The tool is good, with a solid understanding of the user, and the interface is friendly for reviewing and examining the results. Scan results are usually delivered on time and are prompt. However, the platform currently lacks integration with Git/SVN to perform code analysis; I’m waiting for that feature to become available in the portal. As a technical person, I’m not aware of the tool’s pricing details, but so far the project budgeting seems mostly aligned with what is being charged. Product onboarding is flawless on the platform, though it could be enhanced when dealing with re-use or similar kinds of projects within a customer’s scope. I haven’t used the AI features yet; however, the integrated results already demonstrate some intelligence in how the results are presented.

**What do you dislike about Finite State?**

The organization of the product could be improved a lot. While it defines the components for automotive ECU firmwares, the way those components are presented still needs significant work. Clearer structure and better labeling—ideally with the components shown in a tabulated format—would make it easier to understand the output and would increase confidence in the results.

**What problems is Finite State solving and how is that benefiting you?**

Continuous binary scanning helps ensure that the results for each binary build are recorded in the tool and can be referenced at any time to understand the fix, or the timeline for fixing the issue.

**Official Response from Marketing Team:**

> Thanks for the detailed review, and for the specific feedback. We're glad onboarding and scan turnaround are working well for you with Finite State. We've also noted your points on how ECU firmware components are organized and labeled, along with your interest in code-analysis integration. Presenting that output more clearly is an area we're focused on, and input like yours helps us prioritize where to improve.

  ### 6. Intuitive Security Management with Powerful Automation

**Rating:** 4.0/5.0 stars

**Reviewed by:** Denver M. | Small-Business (50 or fewer emp.)

**Reviewed Date:** June 18, 2026

**What do you like best about Finite State?**

I use Finite State to analyze and prioritize security vulnerabilities in our product. It scans and highlights these vulnerabilities on its dashboard, which helps us maintain product security. I like its intuitive interface and that it's possible to automate parts of the process. Access to the FS API allowed us to automate tasks that would be tedious otherwise, making it easier to manage our workload. I also like how vulnerabilities are grouped by packages, so we can quickly assess the security overview and decide which packages need urgent attention. The team was very helpful in resolving previous issues, which I appreciate.

**What do you dislike about Finite State?**

N/A

**What problems is Finite State solving and how is that benefiting you?**

I use Finite State to analyze and prioritize security vulnerabilities. It scans our product and highlights issues on a dashboard, giving us visibility. Automation through the FS API reduces tedious tasks, and vulnerabilities are grouped by package, helping us focus on urgent issues easily.

**Official Response from Marketing Team:**

> Thanks for the kind review, Denver. The dashboard, package-level grouping, and API automation are all built to help your team cut through the noise and focus on what's most urgent, so we're glad they're delivering that in practice. We'll also pass your note along to the support team, who will be glad to know they made a difference. Please don't hesitate to reach out if there's anything we can help with.

  ### 7. Finite State Gives Us Everything We Need

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Security and Investigations | Enterprise (> 1000 emp.)

**Reviewed Date:** June 22, 2026

**What do you like best about Finite State?**

We use it with an integration with armorcode - I have no idea why we integrate it with armorcode given finite state gives us everything I need to the point I let the architects worry about it

**What do you dislike about Finite State?**

I work on a linux based product where I spend most of my time verifying via rpm changelog 'yea suse patched this ages ago'. I've used the API to create automation to deal with these cases however

**What problems is Finite State solving and how is that benefiting you?**

Its a metric to keep the architects busy whilst we focus on clearing vulnerabilities

**Official Response from Marketing Team:**

> Thanks for taking the time to share this. We're glad Finite State is giving your team what it needs to stay focused on the work that matters most. We also appreciate you describing how you've put the API to work in your own environment; seeing teams build around it that way is always encouraging. We've noted your feedback on verifying patched components, and refining that part of the experience is an area we're continuing to invest in.

  ### 8. Improved UI, Integrations, and Support—Though Risk Reports Can Be Overcautious

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Industrial Automation | Enterprise (> 1000 emp.)

**Reviewed Date:** June 24, 2026

**What do you like best about Finite State?**

Finitestate has some solid UI enhancements after the migration, and it also makes our job easier through integration with other security tools. Overall, the performance and customer support have improved drastically. Pricing is comparatively lower than other tools, especially considering the advanced AI features included and ongoing enhancements.

**What do you dislike about Finite State?**

Finitestate still reports risk for certain components, even though the issue has already been addressed through the upgraded Linux patch.

**What problems is Finite State solving and how is that benefiting you?**

Finitestate does a good job scanning for and reporting vulnerabilities across firmware, cloud services, APKs, and thick-client applications.

**Official Response from Marketing Team:**

> Thanks for the clear picture of how it's working for you. The UI work since the migration, the tie-ins with your other security tools, and Finite State's coverage across firmware, cloud, APKs, and thick-client apps are all meant to take friction out of the day-to-day, so it's encouraging that performance and support have moved in the right direction. On components that still flag as risky after a patch has landed, we've taken your note on board, and getting that to reflect reality more reliably is something we want to get right.

  ### 9. Flexible Scanning with Engaged Support

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User | Small-Business (50 or fewer emp.)

**Reviewed Date:** June 25, 2026

**What do you like best about Finite State?**

I use Finite State for SAST/SCA/SBOM scans in our Cyber Security organization and appreciate its flexible scan engine that allows us to scan most of our products pretty easily. I like that they are open to feedback and constructive criticism, and their customer support is always engaged and willing to help. I also found the initial setup to be fairly straightforward.

**What do you dislike about Finite State?**

The next generation update has a lot of kinks to work out - some of which are not solely the fault of Finite State. External vendor integration needs some tweaking.

**What problems is Finite State solving and how is that benefiting you?**

I find Finite State's flexible scan engine lets us easily perform SAST/SCA/SBOM scans across our products.

**Official Response from Marketing Team:**

> Appreciate you taking the time to write this up. A scan engine flexible enough to run SAST, SCA, and SBOM across most of your products, without much lift to get going, is a big part of what we want Finite State to do well, and we're glad the support team has stayed engaged with you throughout. We've registered your comments on the next-generation rollout and external integrations, and smoothing out those edges is something we're paying close attention to.

  ### 10. Expert, Indefatigable Service from the Finite State Team

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer Networking | Mid-Market (51-1000 emp.)

**Reviewed Date:** June 19, 2026

**What do you like best about Finite State?**

The Finite State team have expert knowledge and are indefatigable service providers.

**What do you dislike about Finite State?**

Finite State billed me on an annual basis; I prefer monthly.

**What problems is Finite State solving and how is that benefiting you?**

Finite State helped us design a secure development program and team architecture.

**Official Response from Marketing Team:**

> Thanks for the generous feedback about the Finite State team. Supporting you in building a secure development program, and the right structure around it, is the kind of work we value most, and we appreciate you recognizing it. We've also noted your preference around billing and are looking into it. If you'd like to discuss it further, please reach out to your account contact and we'll be glad to talk it through.

  ### 11. Great company, excellent support

**Rating:** 4.5/5.0 stars

**Reviewed by:** Jose Carlos M. | Small-Business (50 or fewer emp.)

**Reviewed Date:** March 27, 2024

**What do you like best about Finite State?**

My experience with Finite State has been great. Their binary SCA platform is not only user-friendly but also comprehensive, covering all the essential features one expects from an SBOM management tool. However, what truly distinguishes them is their personalized customer support. The Finite State team is consistently available to address inquiries, provide expert guidance toward optimal solutions, and demonstrate a genuine willingness to consider customer feedback for feature enhancements.

**What do you dislike about Finite State?**

While the Finite State platform excels at extracting valuable information from its analyses, it currently falls short in offering customizable reporting features. Despite this, I am optimistic that the team will soon update the platform to meet these ever-changing needs, but at present, the system’s customization features are somewhat limited.

**What problems is Finite State solving and how is that benefiting you?**

Finite State helps analyze a complete software solution in a very easy manner making the team save time and effort by not doing all the assessments manually.

  ### 12. Best Risk Management Tool for Software

**Rating:** 5.0/5.0 stars

**Reviewed by:** Venkatramanan S. | Enterprise (> 1000 emp.)

**Reviewed Date:** April 13, 2023

**What do you like best about Finite State?**

Continuous monitoring of security risks. Views help to identify the risk and security vulnerabilities

**What do you dislike about Finite State?**

The data / graph can be bit more elaborate which helps the user to segregate different risk categories

**What problems is Finite State solving and how is that benefiting you?**

Earlier detection of security vulnerabilities and risks. Critical findings can be found with more details. Can integrate with other tools to get the data into Finite State.


## Finite State Discussions
  - [What is medical device vulnerability management?](https://www.g2.com/discussions/what-is-medical-device-vulnerability-management) - 1 upvote
  - [What is medical device cybersecurity?](https://www.g2.com/discussions/what-is-medical-device-cybersecurity) - 1 upvote

- [View Finite State pricing details and edition comparison](https://www.g2.com/products/finite-state/reviews?section=pricing&secure%5Bexpires_at%5D=2026-07-23+04%3A03%3A52+-0500&secure%5Bsession_id%5D=3c84f5c4-f1cd-4d76-b392-8c7548c90569&secure%5Btoken%5D=bf2d516fb318bd39d2ceb7ebd89d561dd374ac18b64f1a8c576273bfb4d7c5ad&format=llm_user)
## Finite State Integrations
  - [ArmorCode Agentic AI Platform](https://www.g2.com/products/armorcode-agentic-ai-platform/reviews)
  - [Azure DevOps Labs](https://www.g2.com/products/azure-devops-labs/reviews)
  - [Bitbucket](https://www.g2.com/products/bitbucket/reviews)
  - [CircleCI](https://www.g2.com/products/circleci/reviews)
  - [Docker](https://www.g2.com/products/docker-inc-docker/reviews)
  - [GitHub](https://www.g2.com/products/github/reviews)
  - [GitLab](https://www.g2.com/products/gitlab/reviews)
  - [Google Cloud Application Integration](https://www.g2.com/products/google-cloud-application-integration/reviews)
  - [Jenkins](https://www.g2.com/products/jenkins/reviews)
  - [Jira](https://www.g2.com/products/jira/reviews)
  - [Kubernetes](https://www.g2.com/products/kubernetes/reviews)
  - [macOS Sierra](https://www.g2.com/products/apple-macos-sierra/reviews)
  - [Microsoft Teams](https://www.g2.com/products/microsoft-teams/reviews)
  - [PostgreSQL](https://www.g2.com/products/postgresql/reviews)
  - [REST](https://www.g2.com/products/rest/reviews)
  - [ServiceNow DevOps](https://www.g2.com/products/servicenow-devops/reviews)
  - [Slack](https://www.g2.com/products/slack/reviews)
  - [Travis CI](https://www.g2.com/products/travis-ci/reviews)
  - [Windows 11](https://www.g2.com/products/windows-11/reviews)

## Finite State Features
**Administration**
- API / Integrations
- Extensibility

**Performance**
- Issue Tracking
- Detection Rate
- False Positives
- Automated Scans

**Functionality - Software Composition Analysis **
- Language Support
- Integration
- Transparency

**Connected Device Security**
- Vulnerability Assessment
- Alerts & Notifications

**Security**
- Tampering
- Malicious Code
- Verification
- Security Risks

**Functionality - Software Bill of Materials (SBOM)**
- Format Support

**Analysis**
- Reporting and Analytics
- Issue Tracking
- Static Code Analysis
- Code Analysis

**Network**
- Compliance Testing
- Perimeter Scanning
- Configuration Monitoring

**Effectiveness - Software Composition Analysis**
- Remediation Suggestions
- Continuous Monitoring
- Thorough Detection

**Platform**
- Dashboard
- Performance
- Reporting

**Tracking**
- Bill of Materials
- Audit Trails
- Monitoring

**Management - Software Bill of Materials (SBOM)**
- Monitoring
- Dashboards
- User Provisioning

**Testing**
- Command-Line Tools
- Manual Testing
- Test Automation
- Compliance Testing
- Black-Box Scanning
- Detection Rate
- False Positives

**Application**
- Manual Application Testing
- Static Code Analysis
- Black Box Testing

**Agentic AI - Vulnerability Scanner**
- Autonomous Task Execution
- Proactive Assistance

**Agentic AI - Static Application Security Testing (SAST)**
- Autonomous Task Execution

## Top Finite State Alternatives
  - [GitHub](https://www.g2.com/products/github/reviews) - 4.7/5.0 (2,315 reviews)
  - [GitLab](https://www.g2.com/products/gitlab/reviews) - 4.5/5.0 (882 reviews)
  - [Wiz](https://www.g2.com/products/wiz-wiz/reviews) - 4.7/5.0 (822 reviews)

