When Dr. James Patrick-Evans started pitching investors on analyzing software at the binary level—the machine code that actually runs on chips, rather than the human-readable source code developers write—he encountered skepticism. After all, most cybersecurity companies focus on source code reviews, vulnerability scanning, and endpoint detection. The idea of training AI to understand compiled executables seemed, to him, perhaps too esoteric for venture interest.
NATO didn't see it that way.
The NATO Innovation Fund (NIF) has led a $15 million Series A round in RevEng.AI, the London-based cybersecurity startup Patrick-Evans founded in 2023. Announced on May 27, 2026, the round brings the company's total funding to $19.5 million and marks one of the clearer signals yet that defense establishments view binary-level security verification as critical infrastructure—not academic curiosity.
Joining NATO Innovation Fund in the round: Sands Capital, In-Q-Tel (the CIA's venture arm), IQ Capital, and Episode One. Several had already backed RevEng.AI's $4.15 million seed round roughly a year prior.
"In a world where AI increasingly writes the code, the only universal source of truth is the executable binary files," Patrick-Evans said when the funding was announced. It's a provocative framing, but one that resonates in an era where software supply chains fracture across dozens of dependencies and where malicious actors increasingly compromise third-party components downstream from source repositories.
Why Binaries Matter Now
RevEng.AI's core product, BinNet, does something unusual: it analyzes compiled software—executables, firmware, the actual bits running in production systems—without requiring access to source code. The platform hunts for backdoors, vulnerabilities, and malicious insertions invisible to traditional security audits.
The use case becomes obvious when you consider how much software organizations actually run. Third-party libraries, closed-source vendor tools, legacy firmware—none of which comes with readable source. A government agency procuring defense systems, for instance, might receive compiled binaries from contractors but have no practical way to verify what's inside.
That's where BinNet slots in. The platform, which Patrick-Evans developed during doctoral research at Royal Holloway, University of London (in collaboration with Germany's Universität der Bundeswehr München), uses proprietary AI models trained to parse the semantics of machine code. It integrates into existing reverse engineering workflows—tools like IDA Pro and Ghidra—through plugins, alongside a command-line interface and automated threat signature generation.
Roughly 60% of RevEng.AI's customer base comes from defense and security organizations, according to an interview Patrick-Evans gave around the time of the funding announcement. The remainder are commercial enterprises—think critical infrastructure providers or companies with complex supply chains. Patrick-Evans describes the company's clients as "elite cyber teams in Western governments," though it doesn't name them publicly. Total customer count sits at roughly ten, a small but concentrated base that reflects the platform's specialized application.
The Supply Chain Problem That Won't Go Away

RevEng.AI's pitch has gained urgency as software supply chain compromises escalate. Recent industry analyses—including reports released this spring—documented record highs in malicious package attacks and flagged emerging threats around AI agent supply chains, where automated coding assistants might introduce vulnerabilities at scale.
The company has published technical research on real-world malware campaigns, including dissections of KorPlug/PlugX and LummaStealer, demonstrating that BinNet isn't just theoretical. It's being used in active threat hunting.
With the Series A capital, RevEng.AI plans to more than double its team—from 22 employees to around 45, according to Patrick-Evans—and open a New York office. The expansion suggests the company sees traction beyond its current government-heavy base, though according to the company's leadership, defense contracts remain the anchoring revenue stream.
There's a certain irony here. As generative AI floods the world with more code written faster than ever, the security industry finds itself returning to first principles: What's actually executing? What does the machine understand, stripped of comments and variable names and human intent?
For NATO, at least, betting on that question seems less speculative than it might have a few years ago. Whether commercial enterprises follow suit at scale—well, that's the next test for Patrick-Evans and his team.
