Dossier · Private startup · 1 independent source

Claroty

Cybersecurity Dual-Use Technology Founded 2015

Last updated: Jul 31, 2026

Claroty is a cyber-physical systems (CPS) protection company securing industrial, healthcare, commercial, and public-sector environments. Its platform combines asset visibility, exposure management, network protection, secure remote access, and threat detection across cloud and on-premise deployments.

Visit Website

Company Overview

Claroty addresses the security gap between conventional IT controls and the operational systems that make physical services work. Its platform is designed for industrial control systems, operational technology networks, medical devices, building-management systems, and other extended Internet of Things environments where an outage, unsafe change, or compromised controller can affect production, patient care, public services, or physical safety. Claroty xDome provides the cloud-delivered platform, while Claroty Continuous Threat Detection (CTD) supports on-premise and hybrid environments. The product family covers asset inventory, exposure and vulnerability management, network protection, secure access, threat detection, and operational efficiency rather than treating visibility as an end in itself.

The core technical challenge is difficult and persistent: CPS estates contain legacy equipment, proprietary protocols, vendor-managed devices, long replacement cycles, and safety or uptime constraints that make aggressive scanning and rapid patching unsuitable. Claroty's differentiation therefore depends on domain-specific protocol knowledge, passive monitoring, safe queries, project-file analysis, device and vulnerability context, and integrations with CMDB, CMMS, EDR, firewalls, SIEM, and SOAR systems. The company's public-sector material describes more than 450 supported OT and automation protocols, five asset-collection methods, and deployment through SaaS, virtual machines, physical appliances, or hybrid architectures. Those capabilities are commercially meaningful because they reduce the chance that security tooling itself disrupts operations.

Claroty has moved well beyond early product-market-fit risk. In its June 2025 ten-year update, the company reported more than 1,000 customers, over $100 million of ARR in 2023, more than 700 employees in 27 countries, and relationships with 24 Fortune 100 companies. In January 2026 it announced a $150 million Series F led by Golub Growth, with additional participation from existing investors, and described an expansion strategy that includes organic and inorganic growth. In May 2026 it introduced Claire, a CPS-native AI security agent, and said the company then served more than 1,300 customers. These are company-reported signals rather than audited financial results, but together they indicate substantial commercial scale and a platform strategy aimed at becoming the operational source of truth for CPS risk.

Competitive pressure remains serious. Claroty competes with OT specialists such as Nozomi Networks and Dragos, asset- and identity-centric CPS vendors such as Armis and Forescout, vulnerability-management providers such as Tenable, and broad security platforms including Microsoft Defender for IoT. Its advantage is the combination of CPS-specific research, broad protocol and device coverage, secure access, and risk-to-action workflows across industrial, healthcare, commercial, and public-sector buyers. The counter-risk is that large vendors can bundle adjacent controls into existing contracts while customers consolidate security platforms. Claroty's proof will be repeatable deployment, high-quality asset context, safe operational integrations, and measurable reduction in exploitable exposure rather than category language alone.

The dual-use case is substantive but bounded. The same asset discovery, segmentation, secure third-party access, threat detection, and vulnerability-prioritization capabilities used in factories and hospitals apply to military facilities, defense suppliers, ports, utilities, water systems, transportation, and government operations. Claroty's public-sector materials and 2026 announcements document federal and intelligence-community positioning, STIG-hardened CTD configuration controls, and public-sector ecosystem activity. They support defense and national-security adjacency, but they do not by themselves prove classified deployments, accreditation, or government-contract revenue. Strategic diligence should therefore separate documented product applicability from unverified end-user claims and examine procurement vehicles, accreditation, incident-response performance, retention, gross margins, valuation, and the economics of maintaining protocol and device-model coverage.

Dual-Use Assessment

Military & Commercial Applications

Claroty's core CPS security technology has direct commercial and defense/security applicability: asset discovery, exposure prioritization, network protection, secure remote access, and threat detection are relevant to factories, hospitals, utilities, transportation, defense suppliers, military facilities, and government infrastructure. Its public-sector materials cite federal and critical-infrastructure use cases and STIG-hardened CTD controls, but public evidence does not establish classified deployments, accreditation, or government-contract revenue.

Strategic Fit Assessment

Claroty has credible technology, market traction, and strategic fit, but its mature private-company profile and January 2026 Series F make it a late-stage strategic diligence subject rather than a priority signal for an early-stage startup database. The relevant questions are valuation, liquidity path, retention and expansion economics, platform defensibility, margin profile, and whether public-sector growth is repeatable; this flag is not an investment recommendation.

Strategic Value to U.S.-Israel Alliance

Claroty is strategically relevant because it provides a control layer for cyber-physical assets that conventional endpoint and cloud tooling often cannot safely inventory or interpret. Its footprint across industrial, healthcare, commercial, and public-sector environments makes it relevant to infrastructure resilience, defense-supplier risk, hospital continuity, remote-maintenance governance, and cyber incident response. The value is strongest where operational downtime or unsafe control changes have consequences beyond data loss, while the national-security case still requires customer, accreditation, and contract-level diligence.

Key Technologies

  • Passive OT and CPS asset discovery with deep packet inspection
  • Safe native queries and project-file analysis for PLC, RTU, medical-device, and control-system inventory
  • CPS asset profiling, device context, and protocol coverage across 450+ OT and automation protocols
  • Exposure and vulnerability management for operational environments
  • OT/CPS network threat detection and segmentation integrations
  • Zero Trust secure remote access for employees and third-party vendors
  • CPS-native AI context and agentic security workflows through the Claire initiative

Use Cases & Applications

  • Industrial plant and manufacturing-line asset inventory and exposure reduction
  • Hospital and medical-device security with clinical-operations context
  • Utility, water, energy, and transportation critical-infrastructure monitoring
  • Building-management and commercial-facility CPS protection
  • Controlled remote access for equipment vendors and maintenance contractors
  • Public-sector and federal OT visibility, hardening, and SOC integration
  • Defense-supplier and military-facility segmentation and threat detection
  • Incident prioritization and compliance evidence across distributed CPS estates

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 8 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.