What security startups sell: attack evidence, threat intelligence and access control
Armadin, Osavul and Zaperon address different decisions inside a security organization. Their products show why the buyer’s workflow matters when assessing a funding announcement.
Start with the decision the customer needs to make
Three companies in the funding archive illustrate how much a broad security label can conceal. Armadin helps a team establish whether an attacker can reach a valuable target. Osavul helps analysts understand hostile activity directed at an organization. Zaperon controls whether a person and device should reach an application. Each produces a different operational result, and each depends on a different part of the customer’s organization.
The useful commercial comparison is the work that follows adoption. Who uses the output, what can they change because of it, and what must already be connected for the product to deliver? Those questions give a founder or investor a more concrete way to examine these businesses than the shared use of AI.
Armadin: turn a possible weakness into a demonstrated attack path
Armadin’s platform maps an organization’s attack surface, probes weaknesses and tests whether they can form a chain to an objective such as sensitive data or domain compromise. Its output is a validated path accompanied by remediation guidance. In its October financing announcement, the company says it is running campaigns in production for large enterprises and government customers.
Our reading of the product is that its adoption depends on both the team commissioning the exercise and the teams responsible for fixing what it finds. A useful customer reference would show how an identified path became an assigned remediation, then whether a subsequent exercise established that the path had closed. The commercial proof is the customer’s ability to turn repeated testing into completed defensive work.
Osavul: connect a hostile campaign to an operational response
Osavul starts with external information. Nebula collects and structures material across messaging apps, websites and other communities, giving analysts a way to search across platforms and languages. Janus tracks actors and activity around a customer’s personnel, sites and suppliers. The resulting work is investigation and warning: establishing what is happening, who appears involved and which assets may be exposed.
This creates a different adoption question. An intelligence team needs useful source coverage and evidence it can examine, followed by a route to the people responsible for security or continuity decisions. In our assessment, a compelling reference would trace a relevant warning through analyst review to a concrete response. A larger stream of alerts alone would leave the buyer with more material to process.
Zaperon: make an access policy operate on a real application
Zaperon connects identity, device posture and application access rules. Its website includes a customer account from New Allenberry Works: the IT team used the product to restrict Tableau access to authorized devices. That example makes the workflow tangible. The user may have a legitimate account, while the device still fails the organization’s conditions for access.
NIST’s Zero Trust Architecture describes authentication and authorization of both the subject and device before access to an enterprise resource. Zaperon’s product sits in that operational area. Our commercial reading therefore centers on application coverage, policy administration and the experience of legitimate users. A rollout that reaches more resources while remaining manageable for IT establishes a different kind of value from an intelligence report or a security exercise.
Three different kinds of evidence to ask for
For these selected companies, the next useful diligence step follows directly from the product. Ask how attack findings reach the team that closes them; how intelligence reaches the person who can act; and how an access policy behaves across the applications employees actually use. Customer references should make that handoff visible.
The funding announcement establishes that capital is available for the next phase. The adoption story establishes what the company must accomplish with it. Looking at the operational handoff gives a sharper view of each business: the people it needs to win over, the integrations it must support and the customer outcome that can justify renewal.