Dossier · Private startup · 4 independent sources

Cyvore

Cybersecurity Dual-Use Technology Priority Signal Founded 2024

Last updated: Sep 3, 2026

Cyvore is an Israeli cybersecurity startup securing the full digital workspace, including email, chat, video, CRM, and other communication channels, against phishing, fraud, impersonation, and social engineering. Its three-agent architecture combines visual phishing recognition, natural-language and behavioral analysis, and proactive threat intelligence to produce an evidence-linked verdict rather than another isolated alert.

Visit Website

Company Overview

**Product and the concrete problem it solves.** Cyvore addresses a security gap created by the way organizations actually communicate. Email security has become a mature control category, but employees and executives now move between Google Workspace, Microsoft 365, Slack, Zoom, WhatsApp, SMS, CRM systems, and other collaboration surfaces. A malicious interaction can begin as a message, continue as a video call, point to a lookalike website, and use a compromised identity that appears familiar at every step. Conventional tools often inspect one channel at a time, while security analysts receive disconnected alerts without the identity, relationship, or campaign context needed to make a fast decision. Cyvore's proposition is workspace security: observe relevant interactions across the communication spectrum, investigate the visual, linguistic, behavioral, and external-intelligence clues together, and stop an impersonation or social-engineering attempt before money, credentials, or sensitive data move. Its current website illustrates the workflow with deepfake voice and video, optical phishing, lookalike domains, business email compromise, social engineering, and insider impersonation. The practical buyer problem is alert overload combined with an expanding attack surface. The practical user outcome is a defensible conclusion with a chain of evidence that a security team can act on, rather than a warning that still requires a manual investigation.

**Core technology and how it actually works.** Cyvore publicly describes three specialized agents, also identified in Israeli industry coverage as OPR, TIAO, and DAN. Optical Phishing Recognition examines visual content that can fool a person even when text-based scanners see nothing unusual: spoofed logos, rendered lookalike pages, manipulated screenshots, deepfake faces, and document or brand forgeries. The Data Analysis and Natural Language Understanding layer reads the message and conversation as a social interaction, looking for intent, urgency, coercion, secrecy, identity mismatch, relationship anomalies, and other behavioral indicators of manipulation. The Threat Intelligence and Autonomous Operation layer works outside the immediate message, monitoring the open and dark web for compromised credentials, domains, leaks, related events, and infrastructure linked to an emerging campaign. Cyvore's public case-board model then connects the organization, person, domain, actor, event, and findings into one conclusion. That design is materially different from simply placing an LLM on top of an email gateway: the intended unit of analysis is the cross-channel identity and campaign. The company also says its agents work continuously and can hand a verdict with supporting evidence to analysts. Public materials do not disclose precision and recall by channel, model-training data, latency, deployment isolation, retention defaults, or whether the system can make autonomous blocking decisions in every integration. Those are critical diligence items, particularly for a platform that processes sensitive communications and may be asked to reason about both human employees and AI agents.

**Market, customers, and go-to-market.** Cyvore sells into enterprise security and trust teams that cannot protect a distributed workforce by securing email alone. Calcalist Tech identified finance, healthcare, and high-tech organizations as its primary target sectors, all of which have valuable data, high payment-fraud exposure, and large volumes of executive or customer communication. The company says it has deployed its solution in public and private organizations and is in advanced stages with leading banks and financial firms in the United States and Europe; those statements are company-reported and the individual customers are not named. A recent Ynet profile reports the National Cyber Directorate as an Israeli client and says Cyvore works with several large U.S. companies while expanding its U.S. sales operation. Its consumer-facing scanner integration with Israeli financial-services brand MAX is a useful distribution and public-safety signal: suspicious messages can be checked through a public MAX workflow, while the enterprise product remains a security platform. The likely commercial motion is bottom-up incident visibility combined with top-down CISO procurement: start with a focused deployment in collaboration channels or high-risk business processes, demonstrate prevented fraud and reduced investigation time, then expand across the organization's communication graph. The company must still prove that broad integration is an advantage instead of an implementation burden. Every connector creates permission, privacy, rate-limit, data-residency, and support requirements, and financial institutions will demand strong isolation and auditability before allowing a young vendor to inspect sensitive conversations.

**Traction, funding, and third-party validation.** Cyvore was founded in 2024 and emerged from stealth in April 2025 with an initial $2.5 million pre-seed round from 1948VC, Ineffable VC, and angel investors, according to Calcalist Tech. A later Ynet report says the financing expanded to $4 million and that the company is raising a Series A. Dealroom and LinkedIn provide ecosystem cross-checks for an Israeli private company, a 11-50 employee range, and the cyvore.com domain, although database headcounts and locations vary. Cyvore's own current website adds a SOC 2 Type II badge and demonstrates the three-agent investigation flow, which is stronger productization evidence than a static landing page but remains company-controlled evidence. The Ynet report provides more consequential traction claims: a National Cyber Directorate client, several major U.S. corporate clients, a U.S. patent, and ongoing expansion. Those claims should be verified in diligence because the public record does not identify contract values, renewal rates, deployment counts, prevented-loss measurements, patent number, or the exact scope of the government relationship. The MAX collaboration and continuing 2026 product and hiring activity indicate that the company is operating rather than merely preserving a launch announcement. Conversely, there is no audited revenue, valuation, published independent benchmark, or formal government procurement document. The evidence supports a real early product and customer-development motion, not yet a proven category leader.

**Founders and team background.** Cyvore has a distinctive founder structure. Ori Segal is co-founder and CEO; public company material describes him as a serial entrepreneur and former founder of MUGO, which was acquired by Deezer in 2020, while the Ynet profile describes roughly three decades across company building, fundraising, and exits. Yiftach Rotem is co-founder and CPO, the cyber analyst who originally built a link-checking page for his mother and developed the research behind the product. Ynet reports that he led a cyber team in the Israeli Air Force and later worked as an analyst and threat hunter at Cyrebro. Yoav Rotem is co-founder and CTO, a software engineer and cybersecurity specialist; Ynet reports prior work at Aqua Security, Cybellum, and JFrog, IDF cyber-defense service, and wartime reserve work on a cyber-defense system. Ella Rotem handles DevOps and client management and is reported to have experience at Elbit Systems, Promisec, and Eleos Health; Assaf Rotem contributes as a data analyst after helping the family recruit an experienced CEO. The unusual family formation is not itself a moat, but it combines threat research, software development, client operations, and a professional business leader. The team's technical story maps to the product's three engines rather than relying only on generic AI credentials. Gaps remain: public materials do not provide a complete engineering roster, security-clearance posture, patent details, customer-success depth, or organizational succession plan. A diligence process should test whether the company has enough independent leadership and research capacity to scale beyond the founding family while maintaining access to sensitive customer data.

**Competitive dynamics.** Cyvore competes in several overlapping markets, which is both an opportunity and a positioning risk. Abnormal Security and Proofpoint are strong email- and identity-focused incumbents with large enterprise distribution, threat data, and mature administrative workflows. Microsoft Defender for Office 365 and Google Workspace security controls are embedded alternatives that benefit from the customer's existing identity, mail, and collaboration telemetry. SlashNext and IRONSCALES compete in advanced phishing and messaging protection, while Cofense and KnowBe4 emphasize phishing defense, user reporting, and security awareness. For the broader identity and fraud problem, vendors such as BioCatch use behavioral signals to detect anomalous user activity, and ZeroFox or Recorded Future contribute external threat intelligence. Cyvore's proposed edge is to combine three evidence types across several communication interfaces: what the user sees, what the message is trying to make the user do, and what external infrastructure or actor context says about the event. Its case-board workflow could reduce analyst time if cross-channel correlation produces fewer false positives and better explanations. That edge is not automatically defensible. Platform vendors can expose more native telemetry, email specialists have enormous malicious-message datasets, and threat-intelligence companies can add automation and relationship graphs. Cyvore must show that its visual and behavioral analysis catches attacks missed by existing gateways without creating an unacceptable false-positive burden, privacy concern, or deployment project. The most important comparison is measured prevented fraud and investigation time per protected user, not the number of AI agents named in a demo.

**Defense, security, and resilience dual-use relevance.** Cyvore's core technology is credibly dual-use because it serves commercial organizations while addressing the same identity, impersonation, and communication threats that affect governments, public agencies, defense contractors, and critical infrastructure. The National Cyber Directorate relationship reported by Ynet is a strategically relevant signal, although the scope and procurement status are not publicly detailed. State-backed actors can use convincing messages, deepfakes, lookalike government sites, compromised accounts, and social engineering to reach citizens, officials, suppliers, or military-adjacent organizations. A system that links visual forgery detection, natural-language manipulation analysis, and external infrastructure intelligence could help a security team recognize a campaign that looks harmless inside one channel but is suspicious when the whole interaction is considered. It may also protect AI-agent workflows, where an instruction delivered through a trusted communication path can cause an automated system to expose data or take an unsafe action. Resilience value comes from preserving trusted human and organizational coordination during a crisis, not just from blocking routine spam. The limits are material: Cyvore is not a network sensor, endpoint defense platform, secure communications system, or substitute for identity hardening and user training. Its public sources do not establish classified deployments, military fielding, operation in air-gapped environments, resistance to nation-state evasion, or performance under degraded connectivity. The dual-use assessment is therefore positive at the cyber-defense and organizational-resilience layer, with government relevance supported by a reported customer but tactical or classified capability left unverified.

**Growth stage, trajectory, and key diligence risks.** Cyvore is early-stage and moving from initial product validation toward repeatable enterprise sales. The progression is coherent: a family-built link checker became a company in July or August 2024 depending on the source, a $2.5 million initial round was reported in April 2025, later reporting places total funding at $4 million and says a Series A is being pursued, the website now presents a developed multi-agent investigation product and SOC 2 Type II status, and recent activity points to Israeli government and U.S. enterprise engagement. The most important diligence risks are (1) customer concentration and unverified customer claims, because the public record names few organizations and does not disclose revenue or renewals; (2) detection quality, especially false positives, adversarial examples, multilingual messages, deepfake evolution, and the difficult trade-off between blocking quickly and preserving analyst control; (3) privacy and data-governance exposure from ingesting email, chat, video, CRM, and potentially sensitive government communications; (4) integration complexity across six or more high-change communication platforms; (5) competition from bundled Microsoft and Google controls plus well-funded email and threat-intelligence vendors; (6) funding and hiring pressure while moving from early deployments to a global enterprise sales motion; and (7) patent, model, and data defensibility, since a reported U.S. patent is not yet independently identified and many individual detection techniques are available to larger rivals. Cyvore merits a strong watch position because it targets an escalating attack surface with a specific architecture, current product evidence, an experienced CEO, a technically credible founding team, a reported government relationship, and U.S. expansion. The score must remain below mature cyber leaders until the company publishes or permits verification of independent efficacy, repeatable revenue, deployment scale, and durable customer retention.

Dual-Use Assessment

Military & Commercial Applications

Cyvore's core workspace-security technology serves commercial enterprises while addressing phishing, impersonation, social engineering, compromised identities, and malicious communication campaigns that also target governments, defense contractors, public agencies, and critical infrastructure. Its reported National Cyber Directorate relationship supports government relevance, and its multi-channel evidence model could strengthen organizational resilience during crisis communications. The connection is bounded: no classified deployment, military fielding, air-gapped operation, or nation-state benchmark is publicly verified, and Cyvore is not a secure-communications or endpoint-defense replacement.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Cyvore is a legacy priority-signal candidate, not an investment recommendation. (1) It targets a real and expanding attack surface: important work now happens across chat, video, collaboration, CRM, and mobile channels that are not uniformly covered by email defenses. (2) The product architecture is concrete, with separate visual, behavioral-language, and external-threat-intelligence engines that converge on an evidence-linked case rather than a generic alert. (3) The founding team combines threat research, software engineering, operational client work, and an experienced Israeli serial entrepreneur; Ynet reports prior IDF cyber roles and a MUGO exit. (4) Public reporting supports a $2.5M initial round, later $4M total funding, deployments in public and private organizations, a reported National Cyber Directorate client, major U.S. companies, and a U.S. patent. The counterweight is material: most customer, contract, efficacy, revenue, renewal, patent-number, and deployment-scale claims remain unverified in public sources; Microsoft, Google, Proofpoint, Abnormal, and threat-intelligence incumbents can bundle or replicate parts of the feature set; and ingesting sensitive communications creates privacy and deployment friction. Priority should focus on independently measured catch rates, false positives, time-to-verdict, data handling, enterprise renewals, and whether the multi-channel graph creates a durable advantage.

Strategic Value to U.S.-Israel Alliance

Cyvore has strategic value at the organizational-trust layer of cyber defense. It can potentially detect attacks that evade channel-specific tools by combining what a message looks like, what it asks a person to do, who is communicating, and what external infrastructure is associated with the event. That matters for Israeli and allied public institutions, banks, healthcare systems, defense suppliers, and critical infrastructure, where a trusted-looking interaction can become an entry point or a payment diversion. The reported National Cyber Directorate relationship and the MAX public scanner collaboration are useful signals of local relevance and public-facing deployment. The value is not unlimited: public evidence does not establish classified use, air-gapped support, resistance to sophisticated evasion, or independent performance benchmarks. Strategic diligence should therefore treat Cyvore as a promising cross-channel cyber-resilience layer whose importance depends on measurable efficacy, privacy-safe deployment, and repeatable integration into existing SOC and identity workflows.

Key Technologies

  • Optical Phishing Recognition for pixel-level logo, brand-spoof, screenshot, document, and deepfake visual forensics
  • Natural-language and behavioral analysis for intent, coercion, urgency, manipulation, anomaly, and identity-relationship modeling
  • Threat Intelligence Autonomous Operation for open-web and dark-web infrastructure, leak, credential, domain, and campaign correlation
  • Cross-channel workspace telemetry spanning email, Slack, Zoom, Teams, WhatsApp, CRM, Google Workspace, and Microsoft 365
  • Evidence-linked case graph connecting people, organizations, domains, actors, events, and agent findings
  • Human-supervised AI-agent workflow that converts distributed signals into an actionable verdict and investigation trail

Use Cases & Applications

  • Business email compromise and executive impersonation detection before a payment or data transfer
  • Cross-channel phishing analysis across email, Slack, Teams, Zoom, WhatsApp, SMS, and CRM workflows
  • Deepfake voice, video, logo, screenshot, and document inspection for high-risk communications
  • Protection of banking, healthcare, and high-tech organizations with sensitive data and payment workflows
  • Threat-intelligence correlation of lookalike domains, compromised credentials, leaks, and related attack infrastructure
  • Government and national-cyber-defense monitoring for impersonation campaigns targeting public institutions
  • AI-agent communication security where malicious instructions can reach automated enterprise workflows

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 7 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

  • Cyvore — Official Website Verifies the current product positioning, supported communication channels, three investigator agents, optical phishing recognition, natural-language and behavioral analysis, threat-intelligence operation, evidence-linked case workflow, public demo, founder roster, and the displayed SOC 2 Type II status.
  • Cyvore emerges from stealth to secure digital workspaces (Calcalist Tech, April 21, 2025) Verifies the Israeli company's August 2024 founding, Ori Segal/Yiftach Rotem/Yoav Rotem founding team, initial $2.5M funding from 1948VC, Ineffable VC, and angels, target sectors, reported deployments and bank discussions, product engines, and U.S. go-to-market intent.
  • From mom's inbox to global clients: How four siblings built a fast-growing anti-phishing startup (Ynet Global) Verifies the founding origin, detailed founder backgrounds, the July 2024 formation date, reported expansion from $2.5M to $4M total funding, Series A process, National Cyber Directorate client, large U.S. companies, reported U.S. patent, MAX-related public scanning, and the three-layer threat-intelligence, optical, and behavioral architecture.
  • Cyvore | LinkedIn company profile Cross-checks the cyvore.com domain, Tel Aviv headquarters, 2024 founding, 11-50 employee range, private-company status, founder roster, and current public activity around phishing, AI, government impersonation, and MAX collaboration.
  • Cyvore Security Ltd. (IVC Data & Insights) Cross-checks the Givatayim address, founder titles, enterprise target markets, B2B model, and the named proprietary engines OPR, TIAO, and DAN.
  • Cyvore company information, funding and investors (Dealroom) Provides an ecosystem-database cross-check for Cyvore's Israeli location, cyvore.com website, 2024 launch, 11-50 employee range, cybersecurity and AI classification, and the $2.5M seed entry from 1948 Ventures and Ineffable VC.
  • Cyvore Anti-Phishing Startup Secures $4M in Funding (Ynet-linked founder account) Corroborates the later $4M funding figure, U.S. and National Cyber Directorate customer claims, three-layer platform description, and reported U.S. patent while linking to the Ynet article.
  • Profile update timestamp Last updated in the Claw & Talon database on Sep 3, 2026.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.