Cervello
Last updated: Jul 31, 2026
Cervello, now rebranded as Opera Security, built a rail-specific cyber-physical security platform that passively maps operational environments, detects threats, and prioritizes remediation by service and safety impact. Its current platform broadens that rail-origin capability into agentic security operations for critical physical processes.
Visit WebsiteCompany Overview
Cervello originated as a Tel Aviv rail-cybersecurity company and developed a platform for environments where a conventional IT alert is meaningful only when it can be connected to an operational consequence. The product family described in the company's rail materials includes Cervello-XE passive collectors, a Cervello Brain analysis layer, and a management console. Together they discover and classify IT, IoT, OT/ICS, signaling, rolling-stock, telecom, and legacy assets; monitor traffic without changing live operations; identify vulnerabilities and misconfigurations; and provide rail-contextual risk, investigation, and response guidance. The company also markets an AI assistant, Margo, for translating security findings into language usable by rail operations and security teams. In 2026, the company announced that Cervello had become Opera Security, with a broader cyber-physical exposure-management platform that maps from network layers down toward field communications and ranks exposures by potential impact on continuity.
The customer problem is unusually consequential and difficult to solve. Rail operators, infrastructure managers, rolling-stock owners, signaling suppliers, and system integrators must secure heterogeneous systems while preserving availability, functional safety, and predictable train service. Rail networks combine modern IP and wireless links with proprietary or legacy equipment, distributed stations, control centers, onboard systems, and third-party maintenance interfaces. Passive collection, on-premise or air-gapped deployment, rail-specific context, and integrations with SIEM/SOC workflows can reduce deployment friction, but they do not remove the need for lengthy validation, safety review, procurement, and local support. The commercial opportunity is therefore strategically important but narrower and slower-moving than horizontal enterprise cybersecurity.
There are credible commercialization signals, although the public record does not establish revenue, renewal rates, or unit economics. The company says its platform covers more than 550 stations, 5,500 track kilometers, and 2.7 million daily passenger and freight journeys; these are company-reported figures that require customer-level diligence. Independent reporting has described Cervello deployments or engagements involving Swiss Federal Railways signaling, a CAF/Bynet-supported Tel Aviv light-rail project, and collaboration with Vossloh. The official site also presents customer and integrator references involving SBB, Thales Austria, CapMetro, and Fincons, but the scope, contract value, and current status of each reference should be verified directly. The Vossloh relationship is especially relevant because it places the product inside a broader rail digital-services channel rather than relying only on direct sales.
Competitive dynamics include rail specialists such as Cylus, broad OT visibility vendors such as Nozomi Networks, Claroty, and Dragos, and signaling or infrastructure integrators that can bundle monitoring into larger projects. Cervello's defensibility depends on accumulated rail protocol and asset knowledge, safe passive deployment, operational-impact modeling, and trusted implementation relationships—not simply on generic anomaly detection or an AI label. The rebrand creates a potential category expansion opportunity into utilities, manufacturing, and other cyber-physical environments, but it also creates execution risk: the company must prove that rail-derived expertise transfers to new processes without diluting product focus or customer support.
The defense and national-security relevance is substantive but indirect. Rail is critical infrastructure and supports civilian mobility, freight, energy logistics, and military movement; detecting manipulation or disruption in signaling, control, and communications can improve resilience during coercion, cyber conflict, or crisis. Opera's broader cyber-physical framing may extend to defense-adjacent industrial and infrastructure operators, especially where systems are on-premise or air-gapped. This is defensive infrastructure protection, not a weapons capability. Diligence should test deployment assurance, safety boundaries, evidence of actual government or defense customers, export-control exposure, data residency, incident liability, and whether the agentic features are sufficiently explainable for high-consequence operations.
Dual-Use Assessment
Cervello's core capability protects rail and other cyber-physical operational environments, where compromise can disrupt transportation, logistics, or safety-related services. That creates credible defensive and national-security applicability, including resilience for infrastructure supporting military mobility, but public evidence does not establish a military customer or offensive use. The dual-use case is therefore strong as infrastructure defense and bounded by deployment assurance, export controls, and the need to prove that broader Opera Security claims transfer beyond rail.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Cervello has a credible strategic fit for a dual-use infrastructure-security thesis because it addresses rail operations with domain-specific passive monitoring and has publicly described deployments, integrator relationships, and a transition toward broader cyber-physical exposure management. The priority signal is conditional rather than a recommendation: diligence should verify the reported Series A, recurring software or service revenue, customer retention, gross-margin profile, ownership and cap table, deployment references, product liability posture, and whether the Opera rebrand is producing repeatable demand outside rail.
Strategic Value to U.S.-Israel Alliance
The company can contribute to resilience of rail networks that carry passengers, freight, energy inputs, and potentially military logistics. Its on-premise and air-gapped orientation is relevant to sensitive operators, while operational-impact prioritization could help bridge the gap between enterprise SOC data and mission continuity. Strategic value is reduced by the narrow rail sales cycle, unclear public financial scale, and the unproven breadth of the post-rebrand cyber-physical market.
Key Technologies
- Passive, agentless network collection across rail IT, OT/ICS, IoT, signaling, rolling stock, telecom, and legacy assets
- Rail-specific asset discovery, classification, protocol and traffic analysis
- Operational-impact modeling and automated risk prioritization beyond CVE or alert counts
- Vulnerability, misconfiguration, threat, and anomaly detection for safety-critical environments
- On-premise and air-gapped deployment with SIEM, SOC, and NOC integrations
- Incident investigation, response playbooks, compliance monitoring, and rail-context reporting
- Agentic AI assistance for cyber-physical exposure triage and remediation guidance
Use Cases & Applications
- Passive monitoring of signaling, interlocking, control-center, and rolling-stock networks
- Asset inventory and attack-surface mapping across stations, trains, depots, and telecom sites
- Prioritizing vulnerabilities and misconfigurations by likely service, safety, or continuity impact
- Detection and investigation of malicious commands, lateral movement, protocol anomalies, and operationally relevant threats
- Evidence and reporting for TS 50701, IEC 62443, NIS2, TSA rail directives, and related governance workflows
- SOC integration and safe incident-response guidance for passenger and freight rail operators
- Resilience monitoring for logistics corridors and transportation infrastructure with defense relevance
- Expansion of cyber-physical exposure management into other high-consequence industrial environments
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.
This record lists 8 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- operasecurity.io Public source used for profile verification.
- cervello.security Public source used for profile verification.
- cervello.security Public source used for profile verification.
- cervello.security Public source used for profile verification.
- vossloh.com Public source used for profile verification.
- LinkedIn company page Public source used for profile verification.
- railjournal.com Public source used for profile verification.
- calcalistech.com Public source used for profile verification.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Investor Lens
What this entry is
Private startup
Why it may matter
Cervello may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.
How an independent investor should read this
Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify traction
- Verify cap table/funding
- Verify technical claims
- Verify regulatory/export-control issues
- Verify customer concentration
Main investor questions
- Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
- What customer, revenue, product, and technical evidence supports the company story?
- What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Cervello's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.