Rapid BLE/firmware security remediation that gets India's budget EV OEMs' apps reinstated and their BMS breach-proof.
Budget electric two-wheeler OEMs in India outsource their Bluetooth connectivity and battery-management-system (BMS) firmware to a handful of white-label vendors (Generic BAT BMS, Lossigy, Epoch Li-ion) that ship with weak or default access controls. Attackers within 10-15 metres can pair over Bluetooth and remotely disable battery output, stranding riders who depend on these vehicles for daily income.
Why now
- MeitY has an active investigation and asked Google and Apple to remove at least seven apps, creating a hard deadline and budget for remediation that did not exist a month ago.
- Named, independently verified OEMs (Yatri, Mayuri, Vande Bharat, City Life) give a concrete, reachable first customer list rather than a hypothetical market.
- Because the vulnerable firmware is shared white-label software across many OEMs, one remediation product can be resold to the entire affected segment rather than needing custom engineering per customer.
- The pain is acute and human, not abstract: riders whose livelihood depends on these vehicles were physically stranded, which raises reputational urgency for OEMs beyond pure compliance risk.
Catalyst. MeitY's active investigation and the Google/Apple app removals give named OEMs an immediate, budgeted, and time-boxed reason to pay for remediation instead of treating security as a someday project.
The idea
A security engineering studio that runs a rapid BLE/firmware penetration test against an OEM's BMS and companion app, ships a patched firmware access-control layer (pairing authentication, command signing, rate limiting) within days, and produces a compliance dossier formatted for MeitY and app-store reinstatement review. After the emergency engagement, OEMs subscribe to ongoing firmware monitoring and pre-release security testing so future releases do not reintroduce the same class of vulnerability. Over time, the same hardened firmware module is offered directly to the white-label BMS vendors as a licensable reference stack, so new OEM customers inherit the fix by default instead of needing a bespoke engagement.
What's different. Generalist cybersecurity firms do not know the BLE pairing quirks or BMS command protocols specific to budget Indian EV firmware stacks, and the original white-label vendors cannot credibly self-certify their own fix to a regulator. This studio combines automotive-specific firmware pentesting with a regulator-ready compliance dossier format, letting an OEM go from app-store takedown to reinstatement in days. The reference-firmware licensing model then lets the same fix propagate to every OEM using the same white-label vendor, turning a single remediation engagement into a distribution channel across the entire budget EV segment.
| Beachhead | Budget electric two-wheeler OEMs in India (sub-₹150,000 retail price, under 50,000 annual unit volume) whose companion app runs on the Generic BAT BMS, Lossigy, or Epoch Li-ion white-label stack and has been named, flagged, or removed under the MeitY investigation |
|---|---|
| Wedge | A rapid BLE/firmware security audit and remediation engagement that produces a patched access-control layer plus a compliance dossier the OEM can hand to MeitY and the app stores to get its app reinstated within days, not months |
| Non-obvious insight | This is not a one-off bug at a single OEM — dozens of unrelated budget EV brands license the same handful of white-label BMS/Bluetooth firmware stacks, so one supplier-side vulnerability propagates across the entire low-cost segment. None of these OEMs have in-house security engineering, and the MeitY app-store takedown has turned a latent defect into an urgent, budgeted, existential problem overnight. |
| Venture-scale path | Start as a paid audit-and-remediation engagement for the first named OEMs, then package the fix as a licensed secure-BMS reference firmware/SDK sold to the white-label vendors themselves, then stand up a recurring monitoring and recertification subscription so it becomes the de facto security compliance layer for India's budget EV supply chain, and expand the same secure-by-default retrofit playbook to adjacent low-cost connected device categories (e-rickshaws, solar inverters, smart locks) facing similar MeitY-style scrutiny. |
| Primary user | Head of Engineering or Founder/CTO at a budget electric two-wheeler OEM (sub-₹150,000 price point) whose companion app was removed or flagged by an app store following the MeitY directive |
|---|---|
| Secondary user | The white-label BMS/connectivity firmware vendors (e.g. Generic BAT BMS, Lossigy, Epoch Li-ion) that license software to multiple budget OEMs |
| Economic buyer | Founder/CTO or Head of Engineering at the affected OEM, sometimes with dealer-network pressure pushing the decision |
| First customer | One of the four named budget e-2W OEMs (Yatri, Mayuri, Vande Bharat, or City Life) whose app was flagged or removed following the MeitY directive and needs it reinstated to keep selling and onboarding new riders |
|---|---|
| Buying trigger | MeitY investigation notice or an actual Google Play / App Store takedown of the OEM's companion app, which blocks new vehicle activations and dealer onboarding until the app is reinstated |
| Current alternative | Generalist cybersecurity consultants unfamiliar with automotive BLE/BMS protocols, or simply asking the original white-label firmware vendor for a quiet patch with no independent verification or compliance documentation |
| Switching reason | Automotive-specific BLE/firmware pentesting expertise moves faster than generalist consultants, and an independent compliance dossier is what MeitY and app-store trust-and-safety teams actually need to approve reinstatement — something the original vendor cannot credibly self-certify. |
| Pricing hypothesis | Fixed-fee emergency remediation engagement priced against the OEM's daily revenue loss from a pulled app, followed by a per-vehicle-fleet monthly subscription for ongoing firmware security monitoring and recertification |
Jobs to be done
| Job | Current alternative | Success metric |
|---|---|---|
| When our companion app gets flagged or pulled by MeitY/app stores, help our engineering team fix the underlying firmware fast, so we can get reinstated and keep onboarding new riders. | Generalist cybersecurity consultants or a quiet unverified patch from the original vendor | Days from engagement start to app-store reinstatement |
| When we license our BMS firmware to many OEMs, help us harden the shared stack once, so a single vulnerability does not become a fleet-wide incident again. | Ad hoc, per-OEM patching with no shared security standard | Number of licensee OEMs running the hardened reference firmware |
flowchart LR MeitY[MeitY investigation flags app] --> Takedown[App removed from stores] Takedown --> OEM[Budget EV OEM CTO] OEM --> Audit[Rapid BLE/firmware pentest] Audit --> Patch[Patched access-control firmware] Patch --> Dossier[Compliance dossier for MeitY/app stores] Dossier --> Reinstated[App reinstated, riders unblocked] Patch --> Monitoring[Ongoing monitoring subscription] Monitoring --> Vendor[Licensed to white-label BMS vendors]
- Signal · 5/5MeitY investigation, named OEMs, and app-store takedowns give a concrete, independently verified, and time-boxed regulatory catalyst.
- Pain · 5/5Riders were physically stranded and OEMs face app-store removal mid-sales-cycle — both operational and reputational pain are acute.
- Wedge · 4/5The emergency remediation-plus-dossier engagement is narrow and reachable via four named OEMs, though the long-term licensing motion to white-label vendors still needs validation.
- Defense · 3/5Automotive-specific firmware expertise and a compliance-dossier format are a real moat, but a large BMS supplier or the white-label vendors themselves could eventually build this in-house.
- Scale · 3/5The beachhead is narrow (India's budget e-2W segment), but expansion into vendor-side licensing and adjacent low-cost connected-device categories gives a credible path to a larger platform business.
- MeitY and app-store trust-and-safety review contacts
- EV OEM industry associations and dealer networks
- White-label BMS firmware vendors as distribution partners
- Rapid penetration testing of BMS and companion app firmware
- Firmware patch development and access-control hardening
- Compliance dossier preparation and regulator/app-store liaison
- Automotive BLE/BMS firmware security engineering team
- Regulator-facing compliance documentation templates
- Hardened reference firmware/SDK IP
- Days-not-months app-store reinstatement via automotive-specific security remediation
- Regulator-ready compliance dossier that generalist consultants cannot produce
- Shared-vendor fix that scales across many OEMs from one remediation product
- Emergency fixed-fee engagement followed by recurring subscription relationship
- Dedicated security engineer as point of contact through the reinstatement process
- Direct outreach to named OEMs following MeitY/app-store action
- Partnerships with EV industry associations and dealer networks
- Referrals from app store trust-and-safety teams handling reinstatement requests
- Budget electric two-wheeler OEMs with flagged or removed companion apps
- White-label BMS/connectivity firmware vendors serving multiple budget OEMs
- Security engineering salaries
- Firmware testing lab and BLE hardware tooling
- Compliance and regulatory liaison overhead
- Fixed-fee emergency remediation and compliance dossier engagements
- Per-fleet monthly subscription for ongoing firmware monitoring and recertification
- Licensing fees from white-label BMS vendors adopting the hardened reference firmware
Market
| TAM | $5.4M Modeled as 30 exposed OEMs × $120k annual remediation plus monitoring and 6 shared-stack suppliers × $300k annual hardening plus support. The OEM count is conservative versus the visible 622,718 annualized residual high-speed e2W units left after TVS, Bajaj, and Ather, and that published slice excludes low-speed e2Ws. |
|---|---|
| SAM | $2.6M Constrained to a near-term reachable subset of 12 OEMs in higher penetration states plus 4 BMS or connectivity suppliers already serving connected EV programs, before broader three-wheeler expansion. |
| SOM | $1.3M Year-3 reachable share assumes 8 OEM accounts plus 1 supplier or reference-stack account, which is ambitious but plausible if the startup wins the first incident-led logos and one channel partner. |
Executive takeaways
- This is a compliance-speed market, not a generic cyber market: MeitY-linked app removals and app-store rules turn weak BLE access control into a distribution outage for OEMs, not just a QA bug [1][2][13][14].
- The reachable beachhead is the long tail. In Jan-May 2026 the top three e2W OEMs sold 515,458 of 774,924 high-speed units, leaving a visible residual 259,466 units before low-speed e2Ws are even counted [23].
- Buyer pain is operational and human: remote shutdowns strand working drivers, while fleets already report false BMS positives and downtime from weak diagnostics [1][3][31][32].
- Most adjacent competitors sell enterprise automotive cyber platforms or generic IoT pentests; few are optimized for India-local BLE/BMS remediation plus regulator-ready evidence [77][78][79][89].
- The strategic upside is supplier leverage: once one secure reference stack exists, the same fix can spread across multiple OEMs using shared tooling and BMS protocols [1][37][100].
Market definition
The initial market is emergency remediation, secure-update hardening, and recurring firmware security assurance for India's long-tail connected EV OEMs and the shared-stack suppliers behind them. Two-wheelers already sit in more than 60% of Indian households, which explains why even a narrow EV slice can matter commercially at Indian scale [21]. The visible high-speed e2W market already leaves a large residual beyond TVS, Bajaj, and Ather, while public Vahan-based analysis explicitly excludes low-speed e2Ws where white-label electronics are common, so the practical exposure is likely broader than the visible high-speed slice [23][29][41].
Customer and buyer
The first buyer is usually the founder/CTO or engineering head at a budget OEM because the failure spans firmware triage, app availability, dealer onboarding, and rider downtime. The second buyer is the BMS/connectivity supplier, which can remediate once and roll a secure build across many OEM licensees using the same tools and protocols [1][2][3][37][95].
Buying triggers
- A MeitY notice, viral incident, or app-store takedown that blocks new activations and forces an immediate remediation sprint. [1][2][3]
- Repeated field failures, false BMS alarms, or weak diagnostics that make fleets and dealers question the stack even before a regulator acts. [31][32][37]
- Cybersecurity or software-update questions appearing in homologation, partner diligence, or OTA release reviews. [8][9][41][95]
Willingness to pay
OEMs in this segment are price sensitive, but the pain is interruption driven rather than compliance theatre: remote shutdowns strand working drivers, and weak diagnostics already create avoidable downtime. That supports a short fixed-fee emergency remediation purchase when tied to app reinstatement or avoided dealer/fleet disruption, while recurring monitoring will be harder unless it bundles release testing and supplier coordination [2][3][29][30][31]. [2][3][29][30][31]
Category dynamics
Tailwinds
- High-speed e2Ws already reached 8.1% of Indian 2W registrations in Jan-May 2026, with strong concentration in south and west India.
- MeitY and app-store action converted a latent firmware weakness into an immediate go-to-market and distribution risk.
- Diagnostics, OTA, and battery-intelligence tooling are already part of Indian EV operations, which makes security hardening easier to attach to existing workflows.
Headwinds
- The budget segment remains highly price sensitive and financing dependent, which can compress willingness to buy more than a minimal fix.
- Data ownership and supplier opacity make root-cause work slower and can leave the OEM dependent on a third-party board vendor.
- Many buyers may default to a quiet supplier patch instead of paying for independent validation unless the regulator or app stores demand it.
Validation signals
- MeitY-linked takedowns prove the problem is urgent enough to trigger distribution intervention.
- FAME II had already supported 14.35 lakh e-2Ws and 1.65 lakh e-3Ws by June 2025, so even a narrow security wedge sits on a large installed base.
- Ather’s public vulnerability disclosure program shows Indian EV OEMs already understand third-party security intake.
- Vecmocon’s Battery Buddy notes show flashing, PIN protection, and board support are live operational workflows, not theoretical asks.
- Fleet analytics vendors are already quantifying false BMS positives and uptime gains, which gives buyers an ROI language beyond pure compliance.
Regulatory & technical constraints
- App-store and CERT-In obligations mean any incident may require legal and reporting process, not just a firmware fix.
- Heterogeneous boards and mixed CAN, UART, and RS485 paths make a reusable lab rig mandatory.
- A remediation without supplier cooperation may stall at firmware signing, OTA, or flashing stages.
- Formal AIS-189 and AIS-190 adoption could change customer evidence requirements mid-sales cycle.
Competition
Competition comes from above, beside, and inside the stack. Above: global automotive cyber vendors such as VicOne and PlaxidityX sell ECU security, virtual patching, and compliance programs. Beside: India-local device firms such as SecureLayer7 can test firmware/BLE, but their public pitch is generic IoT rather than homologation-aware EV incident response. Inside: BMS/VIM vendors already sell the electronics, diagnostics, and OTA layer, so the most common substitute will be a quiet supplier patch rather than another startup [34][37][77][78][79][89].
| Competitor | Stage | Wedge | Pricing | Strength | Weakness vs. us |
|---|---|---|---|---|---|
| SecureLayer7 | scale-up | India-local IoT firmware, radio, OTA, and mobile-app pentesting | Quote-based services | Bench-level hardware, BLE, and companion-app testing in one motion | Not visibly EV-specific or homologation and app-reinstatement oriented |
| PlaxidityX | incumbent | ECU-level automotive penetration testing and compliance support | Enterprise quote-based programs | Deep automotive protocol expertise and strong compliance fit | Overbuilt and likely slower or costlier for low-cost incident-response sprints |
| VicOne | scale-up | ECU intrusion detection and virtual patching | Platform license plus services | Lightweight ECU monitoring and strong virtual patch narrative | Better at in-vehicle protection than app-store reinstatement and supplier mediation |
| Block Harbor | scale-up | Vehicle-native red teaming and validation | Quote-based specialist services | High-signal offensive automotive depth | Premium global-service posture, not India-budget operational focus |
| Vecmocon | scale-up | Local BMS, VIM, charger, and firmware tooling sold into EV OEM workflows | Bundled hardware and software contracts | Already inside OEM electronics and flashing workflows | Conflict of interest when the supplier stack is the root cause and not a neutral remediator |
Why incumbents do not win by default
- Global automotive cyber platforms. Strong on CSMS, IDPS, and ECU pentesting, but optimized for larger OEM programs rather than fast India-budget remediation and dossier work.
- India-local IoT pentesters. Can do hardware, firmware, radio, and OTA testing, but their public positioning is generic IoT rather than EV-specific homologation support.
- EV electronics and BMS vendors. Already own BMS, VIM, and flashing workflows, but OEMs may still want an independent fixer because the supplier stack is implicated in the flaw.
- Public test and homologation labs. Useful as validation and referral channels, yet they do not ship emergency patches or own the field incident.
Business plan
The company starts as an incident-led BLE and firmware remediation studio for India's budget electric two-wheeler OEMs using white-label BMS stacks implicated in the July 2026 remote-shutdown episode. The first customer is a sub-50,000-unit OEM whose companion app was flagged or removed and whose founder or CTO needs dealer activations and rider trust restored fast. The wedge is not generic automotive cybersecurity; it is a fixed-scope sprint that inventories the board and protocol path, patches authentication and command control, and produces an evidence pack for MeitY, app-store, and lab review. Research suggests this wedge is reachable because the long tail beyond TVS, Bajaj, and Ather still represented 259,466 high-speed units in Jan-May 2026, while low-speed exposure is likely broader. The business only works as venture-backed if it moves quickly from one-off services into recurring release assurance and supplier licensing, because the researched initial market is only about $5.4M TAM, $2.6M SAM, and $1.3M three-year SOM. The planned sequence is to win 2-3 OEM incidents, reuse the protocol and flashing harness across the first common board families, and then sell a secure reference layer to the suppliers serving multiple OEMs. The moat is operational speed and evidence: a reusable CAN, UART, and RS485 harness library, reinstatement dossier templates, and field failure data that generic pentesters and implicated suppliers do not own. The biggest disconfirming risk is that Google, Apple, MeitY, or lab reviewers accept minimal supplier patching without independent evidence, leaving this as a low-margin services niche. Research also could not verify which named OEMs were actually removed from stores versus only exposed in reporting, so the first 90 days must prove actual removal status, acceptance criteria, and board overlap before scaling hiring.
Problem
- Budget Indian e2W OEMs share white-label BLE and BMS stacks with weak access controls, so one supplier flaw can trigger remote shutdowns, rider downtime, and store-removal risk across multiple brands.
- The likely buyers do not have in-house firmware security teams, and their fallback options — generic pentests or a quiet supplier patch — do not reliably produce independent evidence or repeatable hardening.
Solution
- Deliver a rapid remediation sprint that inventories the board, app, and protocol stack, patches pairing, authentication, and high-risk battery commands, and hands the OEM a regulator-ready evidence pack.
- Turn repeated incident lessons into a secure reference layer, release-test checklist, and recurring assurance offering that suppliers and OEMs can adopt before the next OTA or firmware release.
Why we win
- The company is optimized for India-budget EV incident response and app-reinstatement evidence, not generic enterprise automotive cyber programs or generic IoT pentests.
- Each engagement compounds a reusable asset base — board and protocol harnesses, flashing workflows, and dossier templates — that can raise speed, margins, and supplier-side leverage after the first few wins.
- As a neutral fixer, the company can be more credible than an implicated BMS supplier and more operationally focused than public labs or global platforms.
| Beachhead | Budget Indian electric two-wheeler OEMs selling sub-INR 150,000 vehicles, under roughly 50,000 annual units, whose companion app runs on the Generic BAT BMS, Lossigy, or Epoch-style white-label stack and has been named, flagged, or removed during the MeitY investigation. |
|---|---|
| Wedge rationale | An app-store or MeitY incident creates a hard budget trigger, a named buyer, and a measurable recovery goal within weeks, which is faster proof than trying to sell a broad CSMS or in-vehicle security platform to the same price-sensitive OEMs. This wedge also forces access to the real board, protocol, flashing, and evidence problems the later supplier product must solve. |
| Sequencing | OEM incident work comes first because it produces the fastest customer truth on which boards repeat, which evidence reviewers accept, and whether buyers convert into retainers. Only after 2-3 OEM proofs should the company push hard on supplier licensing, because a supplier deal without demonstrated OEM outcomes risks turning into a long enterprise sales cycle with no neutral credibility. Hiring stays skewed toward firmware and field-test talent before broad sales headcount because protocol reuse, not lead volume, is the main gating factor in the first 18 months. |
| Not yet | Expansion into e-rickshaws, e-carts, or other EV segments before the first supplier license proves the same board and protocol families recur. · Full automotive CSMS, in-vehicle intrusion detection, or multi-country compliance programs for large OEMs. · Adjacent connected-device categories such as solar inverters or smart locks before the EV supply-chain wedge is repeatable. |
| Wedge | Sell a fixed-fee "get the app back or clear the safe release" sprint to named or adjacent OEMs on the vulnerable stacks, then convert the delivered harness and evidence workflow into a quarterly or annual release-assurance retainer. |
|---|---|
| Channels | Founder-led direct outreach to named OEM founders, CTOs, dealer heads, and service leads immediately after an incident or takedown. · Referral and credibility through ARAI, iCAT, NATRAX, and EV test-lab relationships when an OEM is already in a validation workflow. · Supplier-first introductions through BMS, VIM, and flashing-tool vendors that already provision firmware into OEM programs. |
| Funnel targets | target OEM and supplier list→qualified incident or diligence call 35-45%; qualified call→paid remediation sprint 35%+ during an active issue; sprint→annual release-assurance retainer 40%+; OEM proof→supplier licensing pilot 20%+ |
| Pricing | Fixed-fee emergency remediation priced against blocked activations, dealer disruption, and app downtime, with milestone billing for patch delivery and evidence submission; successful OEMs then move to a $60k-$120k annual release-assurance retainer, while suppliers buy a separate reference-stack license priced by supported OEM programs. |
| MVP | A 1-2 week engagement for one OEM stack that identifies the board and protocol path, patches BLE authentication and high-risk battery commands, produces a regression test report, and ships an evidence pack for app-store, regulator, or lab review. No full OTA platform, no autonomous remediation, and no expansion beyond the affected e2W workflow in v1. |
|---|---|
| 6 months | Cover the first 2-3 common board or protocol families with a reusable lab rig, flashing workflow, and dossier template library, then convert the first paid sprint into a recurring pre-release testing and release-gate retainer. |
| 12 months | Add a supplier-facing secure reference layer for at least one shared stack, plus a lightweight release-assurance workflow that tests new firmware or app builds before OEM rollout. |
| 24 months | Standardize the secure reference layer across multiple supplier-installed stacks, make recurring release assurance the default expansion path after an incident sprint, and only then extend into e-rickshaws or adjacent vehicle categories that reuse the same hardware and protocol assumptions. |
| Key bets | The first ten target OEMs collapse into a few reusable board and protocol families instead of ten bespoke reverse-engineering jobs. · Independent evidence materially changes reinstatement, homologation, or partner-diligence outcomes enough to support premium pricing over a quiet supplier patch. · Suppliers will license a neutral secure reference layer once one or two OEM remediations prove the operational and reputational value. |
| Revenue streams | Fixed-fee OEM remediation and evidence-pack engagements · Annual or quarterly release-assurance retainers for firmware and app updates · Supplier reference-stack licensing and support |
|---|---|
| Unit of value | Per OEM app and BMS stack under active assurance, with supplier licenses priced per shared reference stack |
| Target gross margin | 70% |
| Expansion levers | Convert each incident sprint into a recurring release-assurance retainer · Turn OEM wins into one supplier license that propagates across multiple downstream OEMs · Add adjacent EV programs only when the same harnesses and secure module can be reused with limited new engineering |
| North-star metric | Median days from incident intake to patched release and accepted evidence package |
|---|---|
| Input metrics | Percentage of remediation engagements that end with app reinstatement, secure-release sign-off, or equivalent acceptance without major rework · Share of paid engagements that reuse an existing board or protocol harness · OEM sprint-to-retainer conversion rate within 60 days · Number of supplier-backed OEM programs running the secure reference layer |
| Moats to build | Cross-board protocol and flashing library across CAN, UART, and RS485 BMS variants · Reinstatement and diligence dossier templates mapped to Apple, Google, CERT-In, and lab-review language · Field dataset linking battery events, false positives, firmware versions, and downtime across repeated incidents |
| Kill criteria | Fewer than 2 paid OEM remediation engagements close from the first 6 qualified targets within 6 months. · Less than 50% of the first 4 paid engagements reuse an existing board or protocol harness, implying a bespoke services business. · No reviewer evidence shows that an independent dossier materially changes reinstatement or secure-release outcomes after the first 3 cases. · No supplier signs a paid reference-stack pilot within 12 months of the first OEM proof. |
Milestones
- Close 2-3 paid OEM remediation engagements in the budget e2W beachhead.
- Achieve one documented app reinstatement, secure-release sign-off, or equivalent accepted outcome using the company's evidence workflow.
- Reuse the lab harness across at least 2 common board or protocol families.
- Convert at least 2 OEMs into recurring release-assurance retainers.
- Secure one lab-aligned evidence checklist and one supplier-side pilot conversation.
- Sign the first paid supplier reference-stack pilot and deploy the secure module across multiple downstream OEM programs.
- Reach 4-6 total paying accounts across OEM retainers and supplier relationships.
- Standardize the release-assurance workflow for firmware and companion-app updates.
- Decide whether e-rickshaw expansion shares enough stack overlap to justify entry.
- Reach the researched three-year SOM target of roughly $1.3M with 8 OEM accounts plus 1 supplier account.
- Make supplier-led distribution the majority of new deployments rather than one-off OEM incidents.
- Expand only into adjacent EV categories where the existing harnesses and secure module still provide meaningful code reuse.
flowchart LR Wedge[Flagged budget e2W OEMs on shared BMS apps] --> MVP[Rapid audit patch and evidence MVP] MVP --> Proof[Accepted evidence retained OEMs and reusable harnesses] Proof --> Expansion[Supplier license release assurance and 3W adjacency]
Founding team
| Role | Start timing | Rationale |
|---|---|---|
| Founder / OEM incident lead | Month 0 | The first sales and delivery cycles require a credible operator who can win trust with OEM founders, frame the incident in business terms, and coordinate remediation through evidence submission. |
| Founding firmware security engineer | Month 0 | Reverse engineering the shared stacks, patching access controls, and turning incidents into a reusable secure module are the technical core of the wedge. |
| Field applications and test engineer | Month 2-3 | Bench testing, flashing, regression, and protocol harness maintenance are the main operational bottlenecks once more than one engagement runs at a time. |
| Supplier partnerships and account lead | Month 6-9 | This hire only makes sense after OEM proof exists; then the job is to convert incidents into supplier pilots and keep retained customers on the release-assurance workflow. |
Experiment roadmap
| Horizon | Experiment | Hypothesis | Success metric | Owner |
|---|---|---|---|---|
| 0-90 days | Run structured incident outreach with the first 6 named or adjacent OEMs to verify removal status, blocked activations, and willingness to hire a third party. | At least 2 of the first 6 reachable OEMs have an urgent enough problem to sign a paid remediation sprint. | 2 paid sprints or signed LOIs from the first 6 qualified OEM targets. | Founder / OEM incident lead |
| 0-90 days | Map the first 10 target OEMs by board, app, protocol path, and supplier lineage. | Most of the reachable long-tail exposure sits inside a small number of repeated board and protocol families. | 2-3 families account for at least 60% of the first 10 mapped targets. | Founding firmware security engineer |
| 0-90 days | Define an evidence checklist with one lab, counsel partner, or reviewer-aligned advisor for what a reinstatement or secure-release packet must contain. | There is a stable enough evidence package that can be templatized across customers. | One documented checklist accepted as decision-useful by a lab partner or customer reviewer. | Founder / regulatory and partnerships lead |
| 3-6 months | Deliver the first paid remediation sprint from intake through patch, regression testing, and evidence submission. | The team can reduce customer time-to-safe-release or reinstatement within weeks rather than months. | One customer reaches patched release or app reinstatement within 30 days of kickoff. | Founder / OEM incident lead |
| 3-6 months | Build the reusable BLE, CAN, UART, and RS485 lab rig for the first common board families. | A shared harness meaningfully lowers engineering hours on the second and third engagement. | Engineering hours per engagement fall by at least 30% between the first and third paid case. | Field applications and test engineer |
| 6-12 months | Convert the first OEM wins into recurring release-assurance retainers. | Customers will pay to gate future firmware and app releases once the cost of another incident is clear. | 2 recurring retainers signed from the first 4 paid remediation customers. | Founder / customer success lead |
| 6-12 months | Pitch a supplier-side secure reference layer using OEM case studies and measured reuse data. | A shared-stack supplier will license the secure module to reduce repeated downstream incidents. | 1 paid supplier pilot or LOI covering at least 3 downstream OEM programs. | Founder / supplier partnerships lead |
Risk assessment
- R1Reviewers may accept a minimal supplier patch without requiring independent evidence, collapsing the startup's premium wedge. — Validate acceptance criteria early, price the first sprints around operational recovery rather than paperwork alone, and be ready to shift toward supplier-side hardening if the dossier proves non-essential.
- R2Hardware fragmentation and supplier opacity may make engagements too bespoke to reach software-like margins. — Focus on the repeated white-label stacks first, instrument every case for board and protocol reuse, and narrow the beachhead if one supplier family dominates.
- R3Budget OEMs may buy only the cheapest incident fix and reject recurring release assurance once the crisis fades. — Tie the retainer to concrete release gates, dealer activation continuity, and avoided downtime, and test conversion immediately after each sprint instead of waiting for annual budgeting.
- R4The supplier licensing path may stall, leaving the company trapped inside a very small services-led market. — Treat supplier LOIs and paid pilots as a board-level milestone in year one and avoid scaling general sales spend before that proof exists.
| Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|
| Reviewers may accept a minimal supplier patch without requiring independent evidence, collapsing the startup's premium wedge. | High | High | Validate acceptance criteria early, price the first sprints around operational recovery rather than paperwork alone, and be ready to shift toward supplier-side hardening if the dossier proves non-essential. |
| Hardware fragmentation and supplier opacity may make engagements too bespoke to reach software-like margins. | High | High | Focus on the repeated white-label stacks first, instrument every case for board and protocol reuse, and narrow the beachhead if one supplier family dominates. |
| Budget OEMs may buy only the cheapest incident fix and reject recurring release assurance once the crisis fades. | Medium | High | Tie the retainer to concrete release gates, dealer activation continuity, and avoided downtime, and test conversion immediately after each sprint instead of waiting for annual budgeting. |
| The supplier licensing path may stall, leaving the company trapped inside a very small services-led market. | Medium | High | Treat supplier LOIs and paid pilots as a board-level milestone in year one and avoid scaling general sales spend before that proof exists. |
| Title | Founder or CTO at a budget Indian e2W OEM running a Generic BAT BMS, Lossigy, or Epoch-style app stack |
|---|---|
| Profile | A sub-50,000-unit annual OEM selling dealer-distributed commuter vehicles in high-penetration states, with outsourced BMS firmware and a rider-facing activation or diagnostics app. |
| Trigger | A MeitY notice, app-store takedown, dealer activation freeze, or public remote-shutdown incident. |
| Buyer | Founder/CTO or Head of Engineering |
| Initial contract | $20k-$40k emergency remediation and evidence sprint, converting to a $60k-$120k annual release-assurance retainer if the app is reinstated and future releases are gated through the startup. |
What must be true
- At least 2 of the first 6 named or adjacent target OEMs hire a third-party remediator instead of relying only on the original supplier.
- A $20k-$40k sprint price is acceptable because app unavailability or activation delays create measurable dealer or fleet loss.
- The first 10 target OEMs collapse into 2-3 reusable board and protocol families rather than a fully bespoke reverse-engineering backlog.
- App-store, regulator, or lab reviewers value independent evidence enough to make the dossier a real purchase driver.
- At least 1 BMS or connectivity supplier converts OEM proof into a paid reference-stack license within 12 months.
Open diligence questions
- Which named OEMs were actually removed from Google Play or the App Store, and for how long were activations blocked?
- What board, app, and protocol families dominate the first 10 targets, and how much code or harness reuse do they allow?
- Do Google, Apple, MeitY, ARAI, or iCAT require third-party evidence, or would a supplier patch alone satisfy the buyer?
- What measurable commercial loss per day makes the proposed sprint pricing credible for budget OEMs?
- Which supplier has both enough white-label reach and enough urgency to pilot a neutral secure reference layer?
| Call | Watch |
|---|---|
| Conviction | Medium conviction on acute customer pain; low conviction on venture-scale market until supplier licensing and evidence-driven reinstatement are proven. |
| Why believe | The incident created named buyer pain in a segment with shared white-label stacks, so one successful remediation can propagate across multiple OEMs rather than staying a one-logo consulting win. |
| Why doubt | The researched initial market is small and service-led, and the case collapses if independent evidence is not required or if board fragmentation prevents reusable economics. |
| Next diligence | Confirm one paid OEM remediation, one accepted evidence checklist, and one supplier LOI before treating this as more than a narrow incident-response wedge. |
Financial model
| Year 1 revenue | $240K EBITDA $-508K · Cash EOP $992K |
|---|---|
| Year 2 revenue | $660K EBITDA $-409K · Cash EOP $583K |
| Year 3 revenue | $1.23M EBITDA $15K · Cash EOP $598K |
| ARPU (annual) | $153K |
|---|---|
| Gross margin | 72% |
| CAC | $98K Payback 10.6 months |
| LTV / CAC | 3.8x LTV $368K |
| Round | pre-seed · $1.5M |
|---|---|
| Runway | 18 months |
| Milestone | Close 3 paid OEM remediations, convert at least 2 into recurring retainers, and sign the first paid supplier pilot by Q2Y2. |
Model sanity
- Revenue engine. Base-case revenue starts with three OEM incident proofs, converts them into recurring assurance, and then uses those references to add one $300K-class supplier account by Y3.
- Must go right. Board overlap has to be real enough that a five-person team can support nine paying accounts without adding a services bench.
- Model breaks if. If independent evidence does not change buyer behavior and the supplier pilot slips, the downside case falls to about $0.9M Y3 revenue and cash can compress toward the low-$200Ks.
- Next-round proof. The next financing story is at least two retained OEMs plus a paid supplier pilot by Q2Y2, proving the wedge is moving from incident work into repeatable distribution.
- Revenue (line, area)
- Cash EOP (dashed)
- EBITDA (bars, gray = loss)
- Founder / OEM incident lead
- Firmware security engineering
- Field applications / test
- Supplier partnerships / account
| Y3 revenue | Y3 EBITDA | Cash low point | Description | |
|---|---|---|---|---|
| Downside | Independent evidence matters less, supplier licensing slips, and more work stays bespoke services. | |||
| Base | Three OEM proofs in Y1 convert into retainers, then one supplier pilot lifts blended account value and the company reaches 8 OEM accounts plus 1 supplier account by Q4Y3. | |||
| Upside | The first supplier pilot closes earlier, OEM proofs cluster around the same board families, and recurring assurance attaches at the top end of the pricing range. |
| Variable | Downside | Upside | Cash impact | Revenue impact |
|---|---|---|---|---|
| supplier licensing timing | The paid supplier pilot slips from Y2 into mid-Y3. | Supplier licensing starts one quarter earlier and spreads across multiple downstream OEM programs faster. | ||
| sales cycle | Sprint-to-retainer and OEM-to-supplier conversion slip by one to two quarters. | A successful first dossier shortens both retainer and supplier close cycles. | ||
| hiring pace | A third engineering or operations hire is pulled forward before supplier leverage is proven. | The same 5 FTE team supports more accounts because supplier-led deployments reduce bespoke work. | ||
| ARPU | OEM retainers stay near $90K ARR and supplier pricing tops out below the $300K research benchmark. | OEMs buy the top end of the assurance package and supplier support lands modest add-on scope. | ||
| CAC | Higher founder and partner travel plus slower close rates push CAC above $120K. | Referrals from labs and suppliers pull CAC toward $80K. | ||
| gross margin | Exit gross margin stalls near 65% because too much firmware and field work stays bespoke. | Gross margin reaches about 75% if the board families cluster cleanly and evidence templates standardize. | ||
| churn | Monthly churn rises toward 4.0% as budget OEMs revert to patch-only behavior after the incident fades. | Monthly churn stays near 1.5% because the evidence pack becomes the default release step. |
Scenarios
| Scenario | Y3 revenue | Y3 EBITDA | Cash low point | Description | Key changes |
|---|---|---|---|---|---|
| Downside | $900K | $-220K | $210K | Independent evidence matters less, supplier licensing slips, and more work stays bespoke services. |
|
| Base | $1.23M | $15K | $552K | Three OEM proofs in Y1 convert into retainers, then one supplier pilot lifts blended account value and the company reaches 8 OEM accounts plus 1 supplier account by Q4Y3. |
|
| Upside | $1.53M | $210K | $620K | The first supplier pilot closes earlier, OEM proofs cluster around the same board families, and recurring assurance attaches at the top end of the pricing range. |
|
Sensitivity
| Variable | Downside | Base | Upside |
|---|---|---|---|
| ARPU | OEM retainers stay near $90K ARR and supplier pricing tops out below the $300K research benchmark. | Exit blended annualized revenue per active account reaches about $153K because one $300K supplier account lifts the OEM mix. | OEMs buy the top end of the assurance package and supplier support lands modest add-on scope. |
| CAC | Higher founder and partner travel plus slower close rates push CAC above $120K. | CAC is about $97.5K using Y2-Y3 S&M spend over 6 net new accounts. | Referrals from labs and suppliers pull CAC toward $80K. |
| churn | Monthly churn rises toward 4.0% as budget OEMs revert to patch-only behavior after the incident fades. | Monthly churn holds near 2.5% once the release-gate workflow is in place. | Monthly churn stays near 1.5% because the evidence pack becomes the default release step. |
| sales cycle | Sprint-to-retainer and OEM-to-supplier conversion slip by one to two quarters. | Paid incidents convert into retainers within roughly 30-60 days and the supplier pilot begins in Y2. | A successful first dossier shortens both retainer and supplier close cycles. |
| gross margin | Exit gross margin stalls near 65% because too much firmware and field work stays bespoke. | Gross margin reaches the low-70s once harness reuse and supplier tooling mature. | Gross margin reaches about 75% if the board families cluster cleanly and evidence templates standardize. |
| hiring pace | A third engineering or operations hire is pulled forward before supplier leverage is proven. | Headcount stays flat after the second engineer, with Y3 scale coming from reuse rather than a larger bench. | The same 5 FTE team supports more accounts because supplier-led deployments reduce bespoke work. |
| supplier licensing timing | The paid supplier pilot slips from Y2 into mid-Y3. | The supplier pilot begins in Y2 and reaches about $300K annualized by Y3. | Supplier licensing starts one quarter earlier and spreads across multiple downstream OEM programs faster. |
Key assumptions (23)
| ID | Name | Value | Unit | Source |
|---|---|---|---|---|
| A1 | Model start month | 2026-08 | month | [BP date 2026-07-05] the operating model starts in the first full month after the business plan date. |
| A2 | Opening cash and pre-seed raise | $1.5M | USD | [BP fundingAsk targetFundingRangeUsd $1.5-2.5M; BP fundingAsk.runwayMonths 18] the base case uses the low end of the stated range because the team stays India-local and hiring remains lean through the first supplier pilot. |
| A3 | Starting paying accounts | 0 | count | [BP milestones 0-12 months; BP experimentRoadmap] the company begins pre-revenue and must first convert incident outreach into the first paid sprint. |
| A4 | Active paying account definition | A paid OEM remediation sprint, OEM release-assurance retainer, or supplier reference-stack pilot/license. | definition | [BP businessModel.revenueStreams; BP businessModel.unitOfValue] customersEop counts any account paying for live remediation, assurance, or supplier-stack scope at period end. |
| A5 | OEM incident sprint pricing | $30K per OEM remediation sprint | USD/account | [BP investorMemo.firstCustomer.initialContract $20k-$40k; BP product.mvp] the model uses the midpoint of the stated emergency remediation range. |
| A6 | OEM recurring assurance value | $90K ARR in early retainers, rising toward $120K ARR by Y3. | USD/account/year | [BP gtm.pricing $60k-$120k annual release-assurance retainer; research.bottomUpSizingDrivers annual OEM spend $120k] recurring OEM revenue ramps from the middle of the BP range toward the researched annual spend level once evidence and release-gate work are proven. |
| A7 | Supplier pilot and license value | $15K-$25K per month, reaching roughly $300K annualized in Y3. | USD/account | [BP businessModel.revenueStreams supplier reference-stack licensing; research.bottomUpSizingDrivers annual supplier spend $300k] the supplier account starts as a paid pilot and reaches the research benchmark only after OEM proofs exist. |
| A8 | Customer ramp | 3 active paying accounts by M12, 6 by Q4Y2, and 9 by Q4Y3. | customersEop | [BP milestones 0-12, 12-24, and 24-36 months; research.market.som] this matches the plan to reach roughly 8 OEM accounts plus 1 supplier account by year 3. |
| A9 | Revenue recognition convention | Period-end active accounts multiplied by the blended realized revenue per active account for that period. | formula | [BP businessModel.unitOfValue; BP gtm.pricing] this keeps revenue directly tied to account count and the mix of sprints, retainers, and supplier licensing. |
| A10 | Blended realized revenue per active account path | Late Y1 about $7.5K monthly; Y2 about $8.8K-$12.5K monthly; Y3 about $12.1K-$13.8K monthly as the supplier account lifts the mix. | USD/account/month | [A5-A8 derived from BP pricing and customer mix] the quarterly revenue rows reflect a gradual shift from one-off OEM sprints to higher-value recurring assurance plus one supplier license. |
| A11 | Gross margin ramp | 50%-65% in Y1, 62%-68% in Y2, and 70%-72% in Y3. | gross margin percent | [BP businessModel.targetGrossMarginPct 70; BP operatingAssumptions harness reuse; research.adoptionFrictionMatrix] early work is services-heavy, then margin improves as repeated board families and evidence templates reduce delivery hours. |
| A12 | Hiring timeline | Founder and founding firmware engineer in M1; field applications/test engineer in M4; supplier partnerships lead in M7; second firmware engineer in M16; no further base-case FTE adds through Y3. | timeline | [BP team; BP strategicChoices.sequencingRationale] hiring stays skewed toward firmware and field execution before adding any broader scale team. |
| A13 | Founder loaded compensation | $90K | USD/year | India deep-tech startup-finance heuristic mapped to [BP team Founder / OEM incident lead]; lean founder cash pay is assumed. |
| A14 | Firmware engineering loaded compensation | $90K | USD/year | India embedded-security startup-finance heuristic mapped to [BP team Founding firmware security engineer]; compensation reflects scarce BLE, firmware, and protocol talent without using global enterprise pay levels. |
| A15 | Field applications and test loaded compensation | $45K | USD/year | India hardware-test startup-finance heuristic mapped to [BP team Field applications and test engineer]; this role is operationally critical but below senior firmware pay. |
| A16 | Supplier partnerships loaded compensation | $60K | USD/year | India industrial B2B GTM startup-finance heuristic mapped to [BP team Supplier partnerships and account lead]; includes travel and variable pay for partner development. |
| A17 | Payroll allocation to P&L lines | Founder 60% S&M and 40% G&A; firmware engineering 100% R&D; field applications/test 20% S&M and 80% R&D; supplier partnerships 100% S&M. | allocation | [BP team role rationales; BP operations] payroll is rolled into the functional opex lines rather than shown as a separate P&L expense. |
| A18 | Non-payroll operating spend ramp | Monthly non-payroll S&M/R&D/G&A rises from about $8K/$15K/$6K in late Y1 to about $15.5K/$18.5K/$8K by Q4Y3. | USD/month | [BP operations shared bench lab and evidence-pack workflow; BP fundingAsk.useOfFundsSummary; startup-finance heuristic] this covers lab rig build, travel, legal, validation, insurance, and basic tools. |
| A19 | Cash conversion convention | EBITDA approximates cash movement after the financing close. | method | Startup-finance heuristic for a small asset-light remediation and software business with no separate debt, tax, or capex schedule modeled. |
| A20 | Monthly churn | 2.5% | percent | Startup-finance heuristic for a sticky but budget-sensitive industrial software and services hybrid; customers should renew if incidents are painful, but down-market OEM budgets still create real churn risk. |
| A21 | CAC convention | Y2-Y3 sales and marketing spend divided by 6 net new accounts from 3 at Y1 exit to 9 at Y3 exit. | formula | [BP gtm.funnelTargets; model calc] this captures founder-led and partner-led acquisition for the scale-up period rather than only direct ad spend. |
| A22 | Next-round milestone for funding sizing | By Q2Y2 the company should have 3 paid OEM remediations, at least 2 recurring retainers, and the first paid supplier pilot underway. | milestone | [BP fundingAsk.useOfFundsSummary; BP milestones 0-12 and 12-24 months] the pre-seed raise is sized to reach the first supplier-proof milestone with buffer. |
| A23 | Flat Y3 headcount base case | Headcount stays at 5 FTE from Q4Y2 through Q4Y3 because Y3 growth is assumed to come from harness reuse and supplier distribution rather than adding a services bench. | operating posture | [BP strategicChoices.sequencingRationale; BP operatingAssumptions at least half of early engagements reuse an existing harness] if this reuse does not appear, the model must hire earlier and margins fall. |
flowchart LR Leads[Incident-led OEM leads] --> Sprints[Paid remediation sprints] Sprints --> Retainers[Release-assurance retainers] Retainers --> Revenue[Revenue] Retainers --> SupplierLicense[Supplier reference-stack license] SupplierLicense --> Revenue Revenue --> GrossProfit[Gross profit] GrossProfit --> Cash[Cash and runway]
Flags: One supplier account plus high-end OEM retainers still drives a large share of Y3 revenue, so account concentration remains real. · The model assumes headcount stays flat from Q4Y2 through Q4Y3; if board fragmentation remains bespoke, both gross margin and delivery capacity will miss. · OEM ARPU reaches the high end of the BP's stated retainer range and assumes buyers continue paying for release assurance after the immediate crisis has passed.
Top risks
- Regulatory urgency fades. If MeitY issues a blanket amnesty or the app stores quietly reinstate apps without per-OEM certification, the time-boxed budget and urgency driving this wedge could disappear. Mitigation: Sell recurring value beyond the one-time compliance event — ongoing monitoring, pre-release testing, and a dealer-facing "security certified" badge — so demand persists independent of any single regulatory action.
- Thin OEM budgets and low willingness to pay. Budget EV OEMs operate on thin margins and may treat security as a cost to minimize rather than invest in, especially once the immediate app-store crisis passes. Mitigation: Price against measurable downside (lost sales per day the app is pulled), offer success-based or milestone billing tied to reinstatement, and aggregate demand through OEM associations or dealer networks to lower per-customer acquisition cost.
- White-label vendors or large OEMs build this in-house. The original firmware vendors (Generic BAT BMS, Lossigy, Epoch Li-ion) could patch the flaw themselves at low cost, or a larger EV player could build in-house security tooling, cutting off the need for a third party. Mitigation: Move fast to become the neutral, regulator-trusted certifying party and embed the hardened reference firmware as licensed IP early, creating switching costs before vendors or large OEMs can replicate the compliance-dossier relationship with regulators.
Evidence
Cited sources (39)
- Inc42. Remote EV Shutdowns Expose India's Connected Device Security Gap · https://inc42.com/features/remote-ev-shutdowns-expose-indias-connected-device-security-gap/
- ETAuto. Government pulls BAT-BMS apps amid cybersecurity fears for e-rickshaws · https://auto.economictimes.indiatimes.com/news/auto-technology/government-pulls-bat-bms-apps-amid-cybersecurity-fears-for-e-rickshaws/132157408
- CNBC TV18. Govt cracks down on Chinese apps that could remotely switch off e-rickshaws · https://www.cnbctv18.com/technology/chinese-battery-apps-banned-over-e-rickshaw-security-flaw-19938229.htm
- Autocar India. India drafts cybersecurity rules for connected vehicles · https://www.autocarindia.com/industry/india-drafts-cybersecurity-rules-for-connected-vehicles-440072
- ETAuto. MoRTH proposes phased rollout of automotive cybersecurity norms; all OTA-enabled vehicles to comply by 2029 · https://auto.economictimes.indiatimes.com/news/auto-technology/morth-proposes-phased-rollout-of-automotive-cybersecurity-norms-ota-enabled-vehicles-to-comply-by-2029/132014580
- CERT-In. Directions under sub-section (6) of section 70B of the IT Act, 2000 · https://www.cert-in.org.in/Directions70B.jsp
- Apple. App Store Transparency Report (2025) · https://www.apple.com/legal/app-store/transparency/2025/
- Google. Malware - Play Console Help · https://support.google.com/googleplay/android-developer/answer/9888380?hl=en
- Google. Device and Network Abuse - Play Console Help · https://support.google.com/googleplay/android-developer/answer/16559646?hl=en
- Data For India. Vehicle ownership in India · https://www.dataforindia.com/vehicle-ownership/
- IBEF. Electric Vehicle Industry in India: Growth, Trends & Policy · https://www.ibef.org/industry/electric-vehicle
- EVreporter. Electric 2Ws capture over 8% of India’s 2W market; Kerala records 19% EV penetration in 2W sales (Jan 2026–May 2026) · https://evreporter.com/electric-2ws-capture-over-8-of-indias-2w-market-marketkerala-records-19-ev-penetration-in-2w-sales-jan-2026-may-2026/
- EVreporter. India’s electric vehicle sales trend | June 2026 · https://evreporter.com/indias-electric-vehicle-sales-trend-june-2026/
- EVreporter. Indian OEMs, 48V configuration & logistics · https://evreporter.com/indian-oems-48v-configuration-logistics-amit-arora/
- EVreporter. Ampere launches Reo VYB low-speed electric scooter at ₹69,499 · https://evreporter.com/ampere-launches-reo-vyb-low-speed-electric-scooter-at-%e2%82%b969499/
- EVreporter. The invisible stack: data, diagnostics, and charging infrastructure will make or break India’s EV future · https://evreporter.com/the-invisible-stack-data-diagnostics-and-charging-infrastructure-will-make-or-break-indias-ev-future/
- EMO Energy. What 10 million Kilometers of EV Fleet Data Reveals About Battery Intelligence · https://www.emoenergy.in/blog/what-10-million-kilometers-of-ev-fleet-data-reveals-about-battery-intelligence
- Vecmocon. Smart Battery Management Systems (BMS) for Electric Vehicles · https://vecmocon.com/battery-management-system/
- Vecmocon. Vehicle Intelligence Module (VIM) for Connected Mobility · https://vecmocon.com/vim/
- Vecmocon. Battery Buddy release notes · https://vecmocon.com/docs/battery-buddy/release-notes/
- Vecmocon. Supported boards & features · https://vecmocon.com/docs/battery-buddy-mobile/release-notes/supported-boards-features/
- ARAI. Centre of Excellence – Green Mobility · https://www.araiindia.com/centre-of-excellence/centre-of-excellence-green-mobility
- Ather Energy. Responsible Vulnerability Disclosure Program · https://www.atherenergy.com/bug-bounty
- NIST. SP 800-121 Rev. 2: Guide to Bluetooth Security · https://csrc.nist.gov/pubs/sp/800/121/r2/final
- Bluetooth SIG. Bluetooth Pairing Part 4: LE Secure Connections – Numeric Comparison · https://www.bluetooth.com/blog/bluetooth-pairing-part-4/
- NIST. SP 800-193: Platform Firmware Resiliency Guidelines · https://csrc.nist.gov/pubs/sp/800/193/final
- Uptane. Uptane Standard 2.0 · https://uptane.org/docs/2.0.0/standard/uptane-standard
- Google Android Developers. Android Keystore system · https://developer.android.com/privacy-and-security/keystore
- GOV.UK. Principles of cyber security for connected and automated vehicles · https://www.gov.uk/government/publications/principles-of-cyber-security-for-connected-and-automated-vehicles
- VicOne. xCarbon - Intrusion Detection and Prevention System · https://vicone.com/products/xcarbon/
- Block Harbor. Red Team Services · https://www.blockharbor.io/services/red-team
- PlaxidityX. Automotive Penetration Testing · https://plaxidityx.com/services/automotive-penetration-testing/
- SecureLayer7. IoT Penetration Testing Services · https://securelayer7.net/us/services/iot-security-penetration-test
- ARAI. Homologation Management & Regulation · https://www.araiindia.com/departments-laboratories/homologation-management-regulation
- ARAI. Member Companies · https://www.araiindia.com/about-arai/member-companies
- ACMA. The Automotive Component Manufacturers Association of India - ACMA · https://www.acma.in/
- NATRAX. Battery Test Systems · https://www.natrax.in/battery-test-systems/
- Karamba Security. Karamba and Upstream Partner to Deliver an End-to-End Automotive Threat & Vulnerability Management (TVM) Solution · https://karambasecurity.com/press/2023-09-04-karamba-upstream-partner-end-to-end-automotive-vulnerability-mgmt-tvm
- AUTOCRYPT. AUTOCRYPT teams up with Foxconn’s MIH Alliance as security partner · https://www.autocrypt.io/autocrypt-teams-up-with-foxconns-mih-alliance-as-security-partner/