Dossier · Private startup · 7 independent sources
Envoid Shield
Last updated: Sep 2, 2026
Envoid Shield is an Israeli-linked mobile security startup developing real-time threat prevention and forensic analysis for smartphones and tablets. Its Envoid Protect and Envoid Scan products are positioned for enterprises, governments, military, law enforcement, intelligence, and other high-risk users that need mobile-device visibility without depending on a public cloud.
Visit WebsiteCompany Overview
**Product and problem.** Envoid Shield addresses the security gap created by mobile devices becoming the primary endpoint for executives, field personnel, public officials, and distributed workforces while receiving less inspection than conventional laptops. The company presents two complementary products: Envoid Protect, a real-time mobile threat-prevention platform, and Envoid Scan, a family of tools for deeper inspection and forensic analysis. The public product material describes EnScan Kiosk, Tablet, and Remote workflows, suggesting that the offer spans routine screening, controlled-device examination, and remote investigation rather than a single consumer antivirus application. This distinction matters because sophisticated mobile compromise can involve malicious profiles, configuration abuse, suspicious traffic, spyware indicators, or interaction-triggered behavior that a conventional MDM policy or an after-the-fact handset reset may not reveal. Envoid's stated target segments include enterprises, governments, military organizations, law enforcement, intelligence bodies, and high-risk individuals. No named customer or fielded government deployment was identified in the reviewed public sources, so the commercial problem and target buyer are clear while production penetration remains to be verified.
**Core technology and operating model.** The company describes a behavioral engine combining deep inspection, traffic analysis, threat fingerprinting, and real-time prevention. Its central architectural claim is that analysis and protection can run locally or on premises, reducing the need to send sensitive device telemetry to a vendor cloud. The website also advertises sub-second response time and zero personal-data collection; these are company-published claims, not independently benchmarked results in the sources reviewed. The Korean open-innovation profile expands the product vocabulary to zero-click and interaction-based hacking, BYOD, travel, executive, forensic, offline-analysis, and sovereignty scenarios. In practical terms, the differentiation is an attempt to join continuous endpoint defense with an analyst-controlled inspection path: Protect can watch for suspicious behavior during device use, while Scan can provide a more deliberate examination when a device, user, or incident warrants it. The exact operating-system permissions, sensor coverage, supported iOS and Android versions, detection methodology, and handling of encrypted or locked devices are not publicly detailed enough to assess independently. Those implementation details are critical because mobile platforms tightly control telemetry and because advanced spyware can exploit privileged or previously unknown attack paths.
**Market, customers, and go-to-market.** Envoid is pursuing a security market with several overlapping budgets: mobile threat defense for enterprises, high-assurance communications protection for public-sector and defense users, and mobile forensics for incident-response or investigative teams. Its official positioning is explicitly sector-led rather than consumer-led, with governments, military, law enforcement, intelligence, enterprises, and high-risk people named as audiences. The Envoid iOS application on Apple's App Store is described as a companion to a deployed enterprise platform, not as a standalone scanner, which supports a channel model in which an organization buys a managed service or appliance and users receive a controlled client. Envoid's presence in the Cybertech Tel Aviv 2026 catalog, participation in a Korea-Israel open-innovation delegation, and appearance in the ODO Bang Korea program provide evidence of ecosystem-oriented business development. A visit by Panama's ambassador to Israel also publicly described a briefing on the company's mobile-protection platform, although that is diplomatic and ecosystem engagement rather than customer evidence. The likely sales motion is high-touch and trust-driven, with pilots, security evaluations, and public-sector procurement cycles; the company has not publicly disclosed pricing, channel partners, annual recurring revenue, win rates, or conversion from pilots.
**Traction, funding, and third-party validation.** Several public signals establish that Envoid is an operating company with a live product surface. The App Store record identifies Envoid Shield Ltd as the developer and shows a version history beginning in April 2025 and continuing through August 2026, while the website maintains product, privacy, and contact material. IVC lists Envoid Shield Inc as privately held, identifies a United States address and an Israel branch, and records a seed round dated June 1, 2026; the public profile does not disclose the amount or investor identity. Cybertech's 2026 Tel Aviv catalog includes Envoid as a mobile-security participant, and the company's public professional presence references Milipol Paris 2025. The KOISRA summit page places Envoid Shield among an Israeli deep-tech and cybersecurity delegation hosted through an event co-organized with the Israel Economic and Trade Office in Seoul and the Korea International Trade Association. A January 2026 UK trademark publication for ENVOID covers mobile-security, real-time threat-prevention, and forensic-analysis categories, showing active brand and IP formalization, but it is a trademark filing rather than evidence of patented technology. Collectively these are meaningful operating and ecosystem signals; they do not establish recurring revenue, referenceable deployments, independent efficacy testing, or a large financing history.
**Founders and team.** IVC identifies Itay Forlit as CEO and co-founder and Lior Forlit as CBO and co-founder, and lists Iryna Kulish as COO, Ariel Liberman as CPO, and Ian Khatib as VP of business development. Merage Institute's public participant directory separately identifies Lior Forlit as an Envoid Shield co-founder and CBO. The available record therefore shows a deliberately distributed early team spanning executive leadership, operations, product, and business development, which is a sensible shape for a security company selling into regulated and mission-sensitive buyers. It also indicates that Envoid is building an Israeli operating and market network while maintaining a United States corporate or commercial footprint. Public sources reviewed do not provide reliable biographies for each executive, prior exits, security-clearance status, engineering headcount, research publications, or an independently documented history in mobile OS security. The team score is consequently moderated: the role coverage and ecosystem access are visible, but technical depth, founder-market fit, and the company's ability to support global enterprise deployments require direct diligence.
**Competitive dynamics and edge.** Envoid competes with mobile threat-defense specialists such as Lookout and Zimperium, endpoint and device-management platforms such as Microsoft Intune with Defender controls and Jamf, and mobile-forensics providers such as Cellebrite. It also faces the platform advantage of Apple's and Google's native security layers and the practical substitute of an in-house MDM, EDR, mobile-telemetry, and incident-response stack. Envoid's claimed edge is the combination of prevention, traffic and behavioral analysis, forensic scanning, and local or offline operation in one mobile-focused workflow. That combination could be valuable where an organization cannot centralize handset data in a third-party cloud, needs examination at a controlled facility, or wants to protect a small population of especially sensitive devices. The edge is not yet proven as a durable moat: large vendors have distribution, OS relationships, security research budgets, and bundling power, while specialist competitors may have deeper independently validated detection coverage. The most important diligence questions are whether Envoid sees signals unavailable to MDM/EDR tools, whether it can operate within Apple and Android entitlements without compromising usability, how often detections are independently reproduced, and whether its scan workflow creates a defensible data or analyst advantage.
**Defense, security, and resilience relevance.** This is a credible dual-use company because the core capability is mobile-device threat prevention and forensic analysis, not a civilian product with a merely speculative military adjacency. The same controls can protect an enterprise executive, a diplomat, a military commander, an investigator, or a government employee whose phone is an attractive target for commercial spyware and targeted intrusion. Local or on-premises processing is strategically relevant to defense and sovereign environments that cannot expose device telemetry, investigation artifacts, or identity relationships to a foreign SaaS platform. Kiosk, tablet, remote, offline, travel, and BYOD scenarios map to deployed personnel, border or critical-infrastructure teams, incident-response cells, and officials operating outside a normal corporate network. The public evidence supports a defense and national-security go-to-market thesis through the company's stated target sectors, Cybertech participation, Milipol-related presence, and Korean and diplomatic ecosystem engagement. It does not prove a classified capability, a military contract, or operational deployment, so the strategic case should be treated as strong relevance with unverified field traction. If the product's claimed zero-click and interaction-based detection works across current mobile versions, it could improve resilience against a class of compromises that conventional perimeter controls and user training do not address.
**Stage, trajectory, and diligence risks.** Envoid should be classified as early-stage: it has a live companion application and public product architecture, but IVC records only a seed financing event and the reviewed sources do not disclose revenue, customer count, headcount beyond a LinkedIn 11-50 range, or a later institutional round. Its trajectory is promising enough to merit strategic attention because the company is formalizing its brand, participating in Israeli and international cybersecurity ecosystems, and exposing a product to Apple users while positioning for sovereign and enterprise deployments. The principal risks are technical validation of performance claims; operating-system changes and restricted privileges; false positives or device disruption in high-stakes environments; privacy, export-control, and procurement requirements; the fast-moving spyware and exploit arms race; and competitive bundling by platform and endpoint incumbents. Publicly named customers, independent red-team results, supported-device matrices, certifications, patent filings, security architecture documentation, and financing terms remain diligence gaps. The record therefore assigns strong dual-use and strategic-alignment scores but holds down team, market, and overall potential scores until deployment evidence and repeatable commercial traction are available.
Dual-Use Assessment
Envoid's core products address mobile-device threat prevention and forensic analysis for both commercial and security-sensitive users. The company explicitly names governments, military, law enforcement, intelligence, enterprises, and high-risk individuals as target segments, and its local, on-premises, offline, travel, and executive workflows are relevant to sovereign and field environments. Public sources establish credible dual-use relevance, but do not establish a classified capability, named military contract, or fielded defense deployment.
Strategic Fit Assessment
Envoid is a high-priority strategic diligence candidate, not an investment recommendation. 1. The company targets a consequential gap between mobile-device ubiquity and the limited visibility available to many enterprise, public-sector, and defense security teams. 2. Its claimed combination of prevention, traffic and behavioral analysis, and forensic scanning could create a differentiated workflow where cloud restrictions or sovereignty requirements rule out ordinary SaaS tooling. 3. A live App Store companion, continued product releases, IVC's June 2026 seed listing, Cybertech participation, and international ecosystem activity show more substance than a directory-only concept. The case remains conditional because public sources do not identify customers, revenue, funding amount, independent detection benchmarks, certifications, or patent depth. Direct diligence should establish technical efficacy, supported platform coverage, deployment references, retention economics, and whether the seed-stage team can sell and support high-assurance accounts.
Strategic Value to U.S.-Israel Alliance
Envoid has strategic value for Claw & Talon's Israeli technology thesis because mobile endpoints are a cross-cutting dependency in defense, government, critical infrastructure, diplomacy, and executive communications. Local or on-premises analysis may reduce sovereignty and data-exfiltration concerns in environments where sensitive telemetry cannot be sent to a foreign cloud. The product scope also connects prevention with forensic response, potentially shortening the path from a suspicious device to an actionable investigation. The evidence supports strategic relevance and international ecosystem access, including Cybertech Tel Aviv and Korea-Israel programming, while the absence of named deployments means this value is based on capability and market position rather than proven operational scale.
Key Technologies
- Behavioral mobile-threat detection and prevention
- Deep inspection of smartphone and tablet security state
- Mobile network-traffic analysis and threat fingerprinting
- On-device, on-premises, and offline security analysis
- Forensic scanning through EnScan Kiosk, Tablet, and Remote workflows
- Zero-click and interaction-based compromise detection
Use Cases & Applications
- Continuous protection for executive and government mobile devices
- Pre-deployment or periodic screening of military and field personnel phones
- BYOD and enterprise mobile-fleet risk assessment
- Offline or sovereign forensic examination of suspected compromised devices
- Travel-security checks for officials and high-risk individuals
- Incident-response triage for spyware and targeted mobile intrusion
- Controlled kiosk or tablet screening in law-enforcement and intelligence workflows
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 9 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- Envoid official website Verifies the company's product names, mobile-security positioning, behavioral and traffic-analysis claims, local/on-premises model, response-time claim, and stated government, military, law-enforcement, intelligence, enterprise, and high-risk-user audiences.
- Envoid on the Apple App Store Verifies Envoid Shield Ltd as the developer, the live iPhone/iPad companion application, its enterprise-platform role, privacy disclosures, and release history beginning in 2025.
- IVC Envoid Shield company profile Verifies the private-company profile, US and Israel operating footprint, Itay Forlit as CEO/co-founder, Lior Forlit as CBO/co-founder, additional executive roles, and a June 1, 2026 seed-round listing without public amount or investor details.
- Cybertech Global Tel Aviv 2026 catalog Verifies Envoid's participation in the Israeli Cybertech ecosystem and its description as a mobile-security company focused on protecting organizational mobile devices.
- KOISRA Korea-Israel Open Innovation Summit Verifies Envoid Shield's inclusion in an Israeli deep-tech and cybersecurity delegation at a Korea-Israel open-innovation event involving the Israel Economic and Trade Office in Seoul and KITA.
- ODO Bang Korea mobile-security challenge profile Corroborates the Envoid Protect and Envoid Scan product family and describes zero-click, interaction-based, BYOD, travel, executive, forensic, offline, and sovereignty-oriented scenarios.
- UK Intellectual Property Office trade mark journal 2026-013 Verifies the January 2026 ENVOID trademark publication and relevant mobile-security, real-time threat-prevention, and forensic-analysis categories; this is trademark evidence, not proof of patents.
- Merage Institute participant directory Provides independent ecosystem corroboration for Lior Forlit's role as Envoid Shield co-founder and CBO.
- Envoid Shield LinkedIn company profile Verifies the public company profile, stated 11-50 employee range, US headquarters listing, specialties, and professional-market activity.
- Profile update timestamp Last updated in the Claw & Talon database on Sep 2, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.