Corellium
Also known as: Corellium Atlas, Arm Virtual Hardware, AVH, Corellium Inc
Virtual Arm hardware for firmware teams and their agents: Corellium boots real firmware on modeled boards, driven through a REST API, SDKs and MCP servers.
Corellium runs real firmware on virtual Arm hardware, so firmware teams and the coding agents working for them can build, boot and test without a physical board. Its catalog covers boards such as Raspberry Pi 4 and 5, NXP i.MX8M Plus and i.MX93, STM32U5, NXP S32K and TI AM62P, plus Arm reference platforms. Each is modeled to the memory map, so the image that runs on the virtual device is the one that runs on the real part, and teams can load device models of their own through the CHARM Developer Kit. Teams snapshot a device, roll it back after a failed run, clone it or share it with another team, and CoreModel attaches outside peripheral models over UART, I2C, SPI, CAN, GPIO and USB.
Agents and pipelines reach Corellium through a REST API with API keys, Python, JavaScript and TypeScript clients, a C API and a CLI. Cellebrite's June 2026 Atlas walkthrough names two MCP servers, one for device lifecycle and one for peripheral signals, and shows the Kiro IDE running the loop of build, deploy, exercise and observe against a virtual i.MX93. Corellium itself runs no agent and has no approval step for the actions an agent takes, though project roles decide who can create and delete devices.
Arm Virtual Hardware, the self serve edition, costs $0.50 per core hour after a 30 day trial. Atlas, the automotive and embedded edition aimed at software defined vehicles, adds private cloud and on premises deployment and is priced through sales. Corellium has been part of Cellebrite since December 2025. Its pages now sit on cellebrite.com beside the iOS and Android virtualization products sold for security research, which this record does not cover.
Vendor details
Canonical URL
https://cellebrite.com/en/products/corellium/
Category
Agent infrastructure
Subcategory
Virtual Arm hardware for firmware development and testing
Funding status
Acquired by Cellebrite (Nasdaq: CLBT). The acquisition closed in December 2025.
Company status
acquired
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
CI pipelines in GitHub Actions, GitLab, Jenkins, CircleCI and Travis CI create and run virtual devices through the Corellium CLI. Development tools from Vector, Lauterbach, Arm, Visual Studio and IAR connect to the virtual hardware. Agents reach it through the REST API and SDKs, and Cellebrite names two MCP servers, one for device lifecycle and one for peripheral signals.
In practice
Your team writes firmware for an NXP i.MX93 board that is months from arriving. Corellium boots the same image on a virtual board modeled to the chip's memory map, so the work starts now.
Your coding agent needs a device to try its changes on. Through the REST API or Corellium's MCP servers it creates a virtual board, deploys the build, drives peripheral signals and reads the console.
A test run leaves a device in a broken state. Restoring a snapshot puts it back in seconds, and a shared snapshot gives another team the exact same starting point.
Sources & related URLs
Related / legacy domains
Research sources
Agentic Index coverage score
4.5 / 14 capabilities · 32%
| Integrations & Tool Calling | Not documented |
|---|---|
|
Corellium is the hardware that agents and pipelines drive, not an agent that acts in other systems. Its integrations point inward: CI services such as GitHub Actions, GitLab, Jenkins, CircleCI and Travis CI create and run virtual devices through the Corellium CLI, and development tools from Vector, Lauterbach, Arm, Visual Studio and IAR connect to the virtual hardware for building and debugging. CoreModel lets outside peripheral models attach to a device's UART, I2C, SPI, CAN, GPIO and USB host buses over the network. Corellium offers no connectors through which an agent would act in business systems such as a ticketing tool or a code host. Sourcecellebrite.com/en/products/corellium/atlasread 2026-10-08 |
|
| Workflow Orchestration | Not documented |
|
Multi step work belongs to whatever calls Corellium. In Cellebrite's own Atlas walkthrough, the Kiro IDE runs the loop of design, code, build, deploy, exercise and observe against a virtual NXP i.MX93, while Corellium supplies the board through two MCP servers and a VS Code extension gives a console into it. Devices in the same project share a virtual network, so a pipeline can stand up several boards that talk to each other. Corellium itself has no workflow engine, step model or way for agents to hand work to one another. Sourcecellebrite.com/en/blog/virtual-arm-hardware-firmware-development-corellium-atlasread 2026-10-08 |
|
| Knowledge Grounding & RAG | Not documented |
|
What Corellium stores is virtual devices, firmware images, storage files and snapshots, not a knowledge base. Each supported board has its own reference pages (details, supported hardware components, quickstart and stock firmware), written for the engineers using it. Corellium keeps no searchable index of a customer's documents and has no assistant that answers questions from one. Sourcesupport.avh.corellium.com/sdk/apis/restread 2026-10-08 |
|
| Human Oversight & Guardrails | Not documented |
|
Calls through the API, the CLI and the MCP servers run straight away, whether they create a device, load firmware, restore a snapshot or drive a peripheral signal. There is no point where a person approves, pauses or rejects an agent's action on a virtual device before it happens. What Corellium does offer is control over who can act at all: project administrators decide which users and teams can create and delete devices in a project, and domain administrators set each project's share of CPU cores. A failed run can be rolled back to a known good snapshot in seconds. Sourcecellebrite.com/en/blog/virtual-arm-hardware-firmware-development-corellium-atlasread 2026-10-08 |
|
| Security, Identity & Governance | Full |
|
Sign in can run through the customer's own identity provider. Corellium supports SAML 2.0 with any compliant provider, naming Azure AD, Okta, ADFS and Ping Identity, and OpenID Connect, with accounts created at first sign in and SAML group mappings assigning each user a role and a team. Domain administrators invite and manage users, create teams and assign them to projects, where a Project Administrator manages membership and a Member creates and deletes devices. Virtual device data is encrypted at rest with AES-256-CBC, with keys held by the main database and passed only temporarily to the compute node running a device, and remote access uses TLS 1.2 or later. Each virtual device runs on dedicated CPU cores, and on Enterprise each project gets an isolated network with its own VPN key. Any administrator access to a customer account is recorded for audit. Cellebrite, which owns Corellium, holds ISO 27001:2022 and ISO 27017 certificates and a SOC 2 Type II report, all stated at company level. Its compliance page names no product scope for them and does not mention Corellium. Sourcesupport.avh.corellium.com/authentication/sso/samlread 2026-10-08 |
|
| Observability & Auditability | Not documented |
|
The views Corellium offers show what the firmware did: the serial console, which can capture input, kernel and system logs, a network monitor of the device's traffic, and CoreXight, a code flow trace off the CPU core available to select customers. Those help an engineer see how the device behaved. The one access record described is internal: administrator access to a customer account is logged for audit, with no customer view of that log. Corellium offers no customer facing record of which user, API key or agent created, changed or deleted a device. Sourcesupport.avh.corellium.com/security/limited-accessread 2026-10-08 |
|
| Memory & State Persistence | Partial |
|
Virtual devices keep their own state between runs. A standard snapshot saves a device's storage and can be taken with the device powered off. A live snapshot also saves its RAM, so the device resumes with apps still running, while a device cloned from a live snapshot gets the filesystem but boots fresh. Each device holds up to five snapshots, including the initial one, and restoring a snapshot removes everything that changed after it. On Business plans, once a domain administrator turns sharing on, users can share a snapshot by access code, with a password, across their domain or with invited users only, and recipients clone it into a project of their own. All of this is the device's saved state. Corellium keeps no memory of an agent's past work for it to read back. Sourcesupport.avh.corellium.com/features/snapshotsread 2026-10-08 |
|
| Deployment & Data Residency | Full |
|
Customers choose where Corellium runs. Arm Virtual Hardware and the public cloud serve the API at app.avh.corellium.com, Enterprise Cloud gets its own subdomain, and an on premises appliance serves the same API from the customer's own hostname, with documented server roles for a site installation. Atlas is also offered through AWS Marketplace and as a private cloud deployment. On Enterprise, each project's cores, devices and network are separated from every other project, so teams can share one installation without sharing a network. Sourcesupport.avh.corellium.com/sdk/apis/restread 2026-10-08 |
|
| Prebuilt Agents / Templates / Packs | Partial |
|
A catalog of virtual boards comes ready to run, including Raspberry Pi 4 and 5, NXP i.MX8M Plus and i.MX93, STM32U5, NXP S32K, TI AM62P and Arm reference platforms, many with stock firmware, quickstart guides and examples such as a TF-M build, an HTTP client and audio detection on the STM32U5 or a safety island demo on an Arm automotive reference design. Microcontroller targets take firmware as a 32 bit ELF, a raw binary or a ZIP with a load map. Shared snapshots, such as the i.MX93 PLC demo and a generic Linux sensor simulator, hand a working setup to another team, and the CHARM Developer Kit lets teams load device models of their own. These are environments to build in; no prebuilt agents or agent templates come with them. Sourcesupport.avh.corellium.com/devicesread 2026-10-08 |
|
| Triggers & Channel Coverage | Not documented |
|
Virtual devices start when a person works in the web interface, or when a script, an agent or a pipeline calls the REST API or the CLI. The published GitHub Actions example runs on each push to the customer's repository: it installs the Corellium CLI, logs in with an API token, creates a device, waits for it to boot, works with it and deletes it. GitLab, Jenkins, CircleCI and Travis CI follow the same pattern. In every case the event belongs to the customer's own CI service. Corellium has no scheduler, webhook or event listener of its own that starts a device. Sourcesupport.avh.corellium.com/sdk/ci-cd/github-actionsread 2026-10-08 |
|
| Model Flexibility & Routing | Not documented |
|
No model runs inside Corellium for the agent. Whatever drives it, Kiro in Cellebrite's walkthrough or any client calling the REST API or the MCP servers, brings its own model, so model choice happens in that tool rather than in Corellium. Sourcecellebrite.com/en/blog/virtual-arm-hardware-firmware-development-corellium-atlasread 2026-10-08 |
|
| APIs / SDKs / MCP Extensibility | Full |
|
Every deployment, cloud or on premises, exposes its own interactive API reference at /api/docs. Devices and projects are controlled through that REST API, authenticated with API keys generated in the administration settings, and Python, JavaScript and TypeScript clients, a C API and a CLI with commands for authentication, instances and projects build on it. Published examples cover bulk device setup and uploading firmware with the Python client, and a VS Code extension opens a console into a running device. Cellebrite's Atlas walkthrough names two MCP servers: Corellium MCP for device lifecycle (create, start, stop, snapshot, share, inspect) and CoreModel MCP for driving SPI, GPIO, CAN, I2C and UART signals into a running device. The 7.12 release in August 2026 describes MCP integrations as a key investment, though no public endpoint or tool list has been published yet. Sourcesupport.avh.corellium.com/sdk/apis/restread 2026-10-08 |
|
| Testing, Debugging & Optimization | Partial |
|
Teams run their own firmware on the virtual board and debug it with GDB, LLDB, kernel debugging and CoreSight trace. CoreModel lets a team write C test benches that drive peripheral signals into a running device, and Cellebrite's walkthrough shows CoreModel MCP injecting SPI, GPIO, CAN, I2C and UART stimulus so tests run as function calls. The CI examples create, use and delete devices inside a pipeline, but none checks results or reports a pass or fail. Corellium offers no test format, scoring or release gate of its own; the checks a team writes live in its own pipeline. Sourcesupport.avh.corellium.com/features/connect/coremodelread 2026-10-08 |
|
| Browser / Computer-use | Not documented |
|
Agents drive Corellium through API and MCP calls that boot, snapshot and signal a virtual board. The device's console and display belong to the virtual hardware under test, which Corellium itself runs, and no browser or desktop is operated by the agent on someone else's software. Sourcecellebrite.com/en/blog/virtual-arm-hardware-firmware-development-corellium-atlasread 2026-10-08 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Arm Virtual Hardware $0.50 per core hour after a 30 day free trial · Atlas through sales
Core hours: each active CPU core of a running virtual device is billed per hour
Included quota
The 30 day trial includes up to 15 active cores at once, 100 core hours and 25 device slots. After the trial, every core hour bills at $0.50, so a five core device running for an hour costs $2.50.
What is public
Arm Virtual Hardware publishes a single usage rate of $0.50 per core hour after a 30 day free trial, with discounts for open source, academic and volume use. Atlas, the edition with private cloud and on premises deployment, is priced through sales.
Billing mechanics
Each active CPU core of a running virtual device is billed by the hour, with no prepaid minimum. A five core device for one hour costs $2.50; a single core device for three hours costs $1.50.
Cost watchouts
Devices left running keep billing per core hour, and larger boards use more cores, so an agent loop that boots a multicore device for every change can add up quickly. Atlas features such as private cloud and on premises deployment are priced through sales.
Variable cost rationale
There is no plan fee. Every running core is metered by the hour, so the bill grows with the size of each virtual device, how many run at once and how long they stay up, which is exactly what an agent testing every change drives.
Additional watchouts
Shut devices down when a run ends, and size each virtual board by its core count before an agent starts booting one per change.
Overage / add-ons
Usage beyond the trial limits, or after the trial ends, bills at $0.50 per core hour under an activated subscription.
Sales call required
Mixed (some tiers require a call)
Free / trial
30 day free trial on registration: up to 15 active cores, 100 core hours and 25 device slots
Lowest paid plan
Arm Virtual Hardware at $0.50 per core hour, billed on usage
Commercial notes
Corellium has been part of Cellebrite since December 2025, and its virtual hardware also runs Arm Virtual Hardware. Atlas is sold through AWS Marketplace as well as directly.
Key ambiguities
Atlas pricing is not published, and the support page does not say whether snapshot storage or idle devices carry any charge beyond core hours.
Missing data
Atlas pricing, any storage charge for snapshots, and cancellation and refund terms.
Related vendors
- AgentOps — Agent observability and debugging platform: open source SDKs trace…
- Agno — Python agent framework and AgentOS runtime (formerly Phidata) for…
- AIsa — Resource and payment gateway for AI agents, with one key to 110+…
- AlphaBitCore — AI control plane for regulated financial firms: one gateway enforces…
- Anchor Browser — Cloud hosted browser infrastructure that lets AI agents operate real…
- Apify — Cloud platform and marketplace of more than 73,000 ready-to-run…