Dossier · Acquired asset · 1 independent source
Armis
Last updated: Jul 31, 2026
Armis is a cyber exposure management and asset intelligence company whose Armis Centrix platform discovers, classifies, monitors, and helps protect managed and unmanaged IT, OT, IoT, IoMT, cloud, and cyber-physical assets. ServiceNow completed its acquisition of Armis on April 20, 2026, so the record now describes an acquired strategic capability rather than an independent startup.
Visit WebsiteCompany Overview
Armis Centrix is built around an agentless asset-intelligence approach for environments in which endpoint agents or active scanning are incomplete, impractical, or operationally risky. The platform passively analyzes network traffic and integrates with existing infrastructure to identify devices, enrich them with manufacturer, model, operating-system, software, firmware, vulnerability, and behavioral context, and maintain a continuously updated view of the attack surface. Its coverage spans conventional enterprise IT as well as unmanaged IoT, industrial control and operational technology, medical devices, cloud assets, cellular IoT, and other cyber-physical systems. Armis also describes smart active querying, behavioral baselining, exposure prioritization, threat detection, segmentation support, and workflow integrations as parts of the Centrix product family.
The commercial problem is persistent and concrete: asset inventories and configuration databases are often incomplete, while security and operations teams still need to understand which connected devices are exposed, communicating abnormally, or unsafe to patch. Armis sells into large enterprises and regulated or operationally sensitive sectors such as healthcare, manufacturing, energy, utilities, public sector, and financial services. The product can be delivered through cloud, hybrid, and on-premises models, including an on-premises option intended for air-gapped or highly restricted OT environments. Armis announced FedRAMP Moderate authorization for its federal edition in 2023, which is a meaningful public-sector readiness signal, although authorization is not evidence that every defense or classified deployment requirement is met.
Competition is substantial. Forescout overlaps in broad device visibility and network access control; Claroty and Nozomi Networks are strong OT and industrial-security alternatives; Microsoft Defender for IoT and Palo Alto Networks offer bundled capabilities inside larger security platforms; and specialist medical-device, exposure-management, vulnerability-management, and network-monitoring tools can substitute for parts of the platform. Armis differentiates through breadth across IT, OT, IoT, IoMT, cloud, and physical assets, a large asset-intelligence knowledge base, passive deployment, and the ability to connect discovery with risk scoring and remediation workflows. Those advantages must be tested against classification accuracy, protocol coverage, telemetry quality, deployment friction, and the customer’s willingness to consolidate security tooling.
The acquisition is the clearest commercialization signal now available. ServiceNow announced the transaction at approximately $7.75 billion and said Armis had exceeded $340 million in annual recurring revenue, grown ARR more than 50% year over year, and had approximately 950 employees before closing. Those figures are transaction-era company disclosures rather than a current standalone operating forecast, and Armis is no longer an independent company for direct diligence after the completed acquisition. Strategically, the combination gives ServiceNow real-time asset context across physical and operational layers that can feed security, risk, IT service, and governance workflows. That makes Armis relevant to defense bases, government facilities, hospitals, utilities, ports, factories, and other mission-critical environments, but the database should not infer classified use, military contracts, or cleared deployments without direct evidence. The strongest diligence questions are whether the combined product preserves Armis’s technical depth and deployment flexibility, how much of the value comes from ServiceNow distribution, and whether organizations can act on findings in segmented, intermittent-connectivity, or safety-critical networks.
Dual-Use Assessment
Armis's core asset discovery, exposure assessment, behavioral monitoring, and segmentation capabilities apply substantively to commercial and defense environments because both contain unmanaged endpoints, OT, medical, building-management, and other cyber-physical assets. The applicability is credible for bases, government facilities, utilities, and defense supply chains, but public evidence here does not establish classified deployments or military contracts.
Strategic Fit Assessment
Armis is not an independent venture strategic-screening signal after ServiceNow completed its acquisition on April 20, 2026. It remains a strong strategic reference case: the transaction and the disclosed scale of the business validate demand for asset intelligence that connects discovery, exposure prioritization, and remediation across IT and operational environments. Diligence should now focus on post-acquisition product integration, retention of technical talent, deployment and data-residency options, and whether ServiceNow can expand adoption without weakening Armis's specialist OT and IoMT capabilities.
Strategic Value to U.S.-Israel Alliance
Armis has high strategic value as an acquired capability inside ServiceNow. Its asset context can connect otherwise fragmented security, risk, IT-service, and operational workflows, while its coverage of unmanaged and cyber-physical assets addresses blind spots left by conventional endpoint tooling. This is relevant to critical infrastructure, healthcare, manufacturing, utilities, government facilities, and defense-adjacent supply chains. The value is primarily as a platform capability and integration channel now, not as a standalone startup priority; public evidence should not be stretched into claims of classified or military deployment.
Key Technologies
- Agentless passive network-traffic analysis for managed and unmanaged device discovery
- AI-driven asset intelligence and device fingerprinting across IT, OT, IoT, IoMT, cloud, and cellular IoT
- OT/ICS protocol-aware asset classification and safe smart active querying
- Continuous cyber-exposure assessment, vulnerability prioritization, and risk scoring
- Behavioral baselining, anomaly detection, and threat intelligence for connected assets
- Cloud-native SaaS with hybrid and on-premises deployment for restricted or air-gapped environments
- Integrations with SIEM, SOAR, XDR, ITSM, CMDB, firewalls, and network controls
Use Cases & Applications
- Unified inventory and risk context for managed, unmanaged, and unknown enterprise assets
- Medical-device and hospital-network visibility without installing software on clinical equipment
- Industrial control, manufacturing, energy, and utility OT monitoring with non-disruptive collection
- Government and defense-facility asset discovery, exposure prioritization, and network-segmentation planning
- Detection of rogue, contractor-supplied, or vulnerable devices on sensitive networks
- Incident-response scoping by affected device class, model, vulnerability, behavior, and communication path
- CMDB enrichment, compliance evidence, and remediation workflow orchestration
- Air-gapped or intermittently connected OT asset monitoring through local deployment models
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 6 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- newsroom.servicenow.com Public source used for profile verification.
- armis.com Public source used for profile verification.
- armis.com Public source used for profile verification.
- armis.com Public source used for profile verification.
- armis.com Public source used for profile verification.
- Official website
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.