Dossier · Private startup · 0 independent sources

EyeR Security

Cybersecurity Dual-Use Technology Priority Signal Founded 2024

Last updated: Aug 12, 2026

EyeR Security is an Israel-based cybersecurity startup combining an AI-native managed detection and response platform with human-led incident response for organizations that need broad coverage without building a large SOC. Its public materials describe autonomous investigation across cloud, SaaS, identity, endpoints, email, and dark-web exposure, with on-premise and customer-controlled deployment options for regulated or sovereignty-sensitive environments.

Visit Website

Company Overview

**Product and the concrete problem it solves.** EyeR Security addresses a familiar but strategically important failure mode in cyber defense: organizations collect more alerts and telemetry than their security teams can investigate, while attackers move across cloud services, SaaS, identities, endpoints, email, and exposed credentials. EyeR packages a managed-defense service around a proprietary AI platform that the company says handles tier-one and tier-two operations autonomously, leaving human practitioners to handle high-consequence judgment, incident response, and forensics. This is not simply a dashboard or an alert feed. The public service model combines continuous monitoring, threat detection, investigation, containment, reporting, and escalation, with additional offerings for penetration testing, architecture review, emergency response, and discreet VIP protection. The concrete buyer problem is therefore operating a credible 24/7 defensive function when an organization cannot recruit or afford a full internal SOC.

**Core technology and how it actually works.** EyeR's platform is presented as an agentic MDR and threat-detection-and-response layer that turns raw security telemetry into an evidence-backed decision. The official platform description organizes the capability into cloud security posture management, SaaS security posture management, identity threat detection, endpoint detection and response, email security, and dark-web intelligence. Its stated mechanisms include asset discovery, configuration-baseline analysis, identity and service-account behavior analytics, anomalous-authentication detection, ransomware and fileless-malware detection, phishing and business-email-compromise analysis, underground-source monitoring, MITRE ATT&CK mapping, attack timelines, IOC enrichment, and automated quarantine or remediation. The company says its agents were trained on hundreds of real incident datasets and that the system can analyze alerts in under 60 seconds. Those are company claims rather than independently published benchmarks, but they describe a coherent technical architecture: normalize signals from existing tools, apply context-specific reasoning, produce a traceable investigation, and recommend or execute bounded response actions.

**Market, customers, and go-to-market.** EyeR sells through a hybrid model that can reach both organizations and managed-service providers. Its managed-defense page says the service can sit on top of an approved customer telemetry stack such as Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, or Cybereason, which reduces the need for a rip-and-replace endpoint decision. Service tiers range from a smaller-team package to unlimited-scale enterprise coverage, while the platform materials emphasize REST APIs, webhooks, executive dashboards, compliance reporting, and multi-tenant isolation. The company also presents EyeR as a provider for MSSPs and multi-entity security teams, where tenant boundaries and per-customer context are important operating constraints. Its public company page reports 50 customers and up to 80% cost savings, but no customer names, contract values, retention figures, revenue, or independently audited cost study were located. The go-to-market thesis is credible for resource-constrained enterprises, regulated businesses, and channel partners, but conversion from service engagement to scalable software revenue remains a central diligence question.

**Traction, funding, and third-party validation.** The public evidence shows a company that is beyond a slideware concept but still early in disclosure maturity. EyeR reports 50 trusted customers, 24/7 service, an under-60-second AI analysis window, and ISO 27001 certification on its public materials. Its managed-defense service describes production-oriented integrations with widely deployed EDR and XDR platforms, and the emergency-response page lays out a three-phase operating procedure covering immediate containment, forensic investigation, and recovery or hardening. The company profile on LinkedIn identifies EyeR Security as a privately held Tel Aviv cybersecurity company founded in 2024 with an 11-50 employee range. These are useful public signals, but most performance numbers and customer outcomes are company-reported. The reviewed sources did not establish a financing round, named enterprise reference, revenue scale, renewal rate, patent portfolio, or independent efficacy study. Funding stage is therefore recorded as Unknown rather than inferred from the product's apparent maturity.

**Founders and team background.** EyeR's public company page describes the founding insight as coming from veteran security analysts who saw analysts drowning in false positives and wanted AI to reason over context rather than merely detect anomalies. The public materials do not provide a complete named founding roster, but LinkedIn identifies Orel Asper as Co-Founder and CEO. EyeR says its security team includes practitioners with OSCP, OSWE, GCFA, and GCFR credentials and experience in threat hunting, incident response, digital forensics, security operations, machine learning, autonomous systems, distributed security telemetry, and workflow automation. The combination is relevant to the product because MDR quality depends on more than model output: analysts must understand evidence, containment safety, legal preservation, customer communications, and the operational consequences of a false positive. The team is still small by the standard of supporting a 24/7 global service, so diligence should verify on-call coverage, automation boundaries, responder depth, customer concentration, and whether the named certifications belong to employees or contractors.

**Competitive dynamics.** EyeR competes against both software platforms and outsourced security operations. **CrowdStrike Falcon Complete** and **SentinelOne Vigilance** combine endpoint telemetry, threat intelligence, and managed response at global scale; **Microsoft Defender XDR** can bundle identity, endpoint, email, cloud, and security-operations data into an incumbent ecosystem; **Arctic Wolf** and **Expel** compete directly for outsourced MDR budgets; **Torq** and other Israeli automation vendors compete on workflow orchestration and autonomous response; and internal SOCs or regional MSSPs remain the default substitute for many buyers. EyeR's plausible edge is the combination of AI-led investigation, vendor-flexible ingestion, human escalation, sovereignty-oriented deployment, and a service layer that also covers emergency response and VIP exposure. That edge will be durable only if the company proves lower analyst workload, faster containment, fewer false positives, explainable decisions, and materially simpler deployment than a buyer's existing stack. Large incumbents possess more telemetry, distribution, certifications, and response capacity, so a small provider must win on responsiveness, local trust, and measurable outcomes rather than broad feature count.

**Defense, security, and resilience dual-use relevance.** EyeR's core technology credibly serves both commercial and defense or resilience contexts, so dual_use is set to true, with the important caveat that public evidence verifies a commercial security offering rather than a fielded military program. Defense ministries, defense contractors, utilities, hospitals, ports, financial institutions, and government agencies all face the same structural problem: privileged identities, endpoints, cloud systems, email, and third-party services create a large attack surface, while a shortage of expert defenders increases time-to-detection and time-to-containment. An AI layer that correlates telemetry, reconstructs attack timelines, and supports bounded response can improve continuity during ransomware, credential theft, supply-chain compromise, and coordinated intrusion campaigns. EyeR's stated on-premise, air-gapped, customer-controlled, and tenant-isolated options are particularly relevant to sovereign or disconnected environments. The limits matter equally: no reviewed source verifies an IDF contract, classified accreditation, government deployment, critical-infrastructure program, operation in a disconnected enclave, or defense export authorization. The dual-use case is therefore a credible cyber-resilience transfer path, not evidence of defense adoption.

**Growth stage, trajectory, and key diligence risks.** EyeR is classified as early because the public profile gives a 2024 founding year, an 11-50 employee range, and customer and certification claims, but does not disclose financing, revenue, headcount detail, or independently validated scale. Its trajectory could be attractive if the company converts the labor scarcity behind MDR into an efficient, sovereign-friendly operating model that MSSPs and regulated organizations can deploy without surrendering sensitive telemetry to a third-party AI cloud. The principal diligence risks are: (1) customer-quality risk, because 50 customers may include pilots, small accounts, or service engagements rather than durable recurring contracts; (2) efficacy risk, because under-60-second analysis and up-to-80% savings require reproducible definitions and third-party measurement; (3) automation risk, because an incorrect containment action can interrupt a hospital, utility, or defense supplier while a missed threat can create catastrophic exposure; (4) platform-bundling risk from Microsoft, CrowdStrike, SentinelOne, and hyperscalers; (5) service-scaling risk as a small team supports 24/7 response; (6) data-governance and export-control risk for sovereign deployments; and (7) moat risk if the platform's advantage is mainly orchestration around third-party telemetry. The milestones to watch are named customer references, audited ISO scope, paid retention, independently tested response precision, disclosed funding, and demonstrated operation in high-consequence or disconnected environments.

Dual-Use Assessment

Military & Commercial Applications

EyeR's core capability—AI-assisted detection, investigation, containment, incident response, and evidence generation across cloud, SaaS, identity, endpoints, email, and dark-web exposure—has direct commercial and defense or resilience applicability. The same operational problem affects enterprises, hospitals, utilities, defense contractors, government agencies, and other high-consequence operators: too much telemetry, too few expert defenders, and a need to contain attacks without handing sensitive investigation data to an external AI service. EyeR's stated on-premise, air-gapped, customer-controlled, and tenant-isolated options strengthen the sovereign-deployment case. Public evidence does not verify an IDF or government contract, classified accreditation, disconnected-enclave deployment, or critical-infrastructure program, so the defense connection is a credible transfer path rather than fielded defense traction.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

EyeR is a high-priority strategic diligence candidate, not an investment recommendation. (1) It targets a persistent operational bottleneck: the volume and heterogeneity of defensive telemetry exceed the staffing capacity of many organizations. (2) Its public product architecture combines AI-led investigation with human incident responders, which is more credible for high-consequence use than an autonomous-only claim. (3) The company reports 50 customers, ISO 27001 certification, 24/7 service, under-60-second AI analysis, and up-to-80% cost savings, while its public deployment model can sit on top of existing EDR and XDR stacks. (4) On-premise, air-gapped, and customer-controlled options create strategic differentiation for regulated and allied environments. Counterweights are material: financing, revenue, retention, named customers, independent efficacy benchmarks, exact headcount, and defense adoption are not disclosed in the reviewed sources; incumbents can bundle adjacent capabilities; and response automation creates operational liability. The next diligence step is to validate paid customer quality, outcome definitions, false-positive and false-negative rates, service economics, and deployment controls.

Strategic Value to U.S.-Israel Alliance

EyeR's strategic value is concentrated in cyber resilience at the operational edge. (1) It could help organizations maintain defensive coverage despite the global shortage of experienced SOC analysts. (2) Cross-domain correlation and evidence-backed response can reduce the time between an identity, endpoint, cloud, email, or dark-web signal and a containment decision. (3) Sovereign and air-gapped deployment options are relevant to governments, defense suppliers, utilities, healthcare networks, and other operators that cannot export raw investigation data to a third-party AI cloud. (4) MSSP-oriented tenant isolation could extend scarce expertise across many organizations without collapsing customer boundaries. The value remains conditional on independently verified response accuracy, support for disconnected environments, secure model operations, and evidence that the service scales beyond founder-led or bespoke engagements.

Key Technologies

  • Agentic security-operations workflow for autonomous alert triage, investigation, evidence gathering, and bounded response
  • Cross-domain telemetry correlation spanning cloud, SaaS, identity, endpoints, email, and dark-web intelligence
  • Behavioral anomaly detection with identity-threat, service-account, lateral-movement, and privilege-escalation analysis
  • MITRE ATT&CK-mapped attack timelines with IOC enrichment, root-cause analysis, and auditable incident reports
  • Multi-tenant isolation and per-tenant AI context for MSSP and multi-entity security operations
  • On-premise, air-gapped, and customer-controlled deployment options for sovereign or regulated environments
  • Automated containment, quarantine, remediation, and forensic workflows integrated with existing EDR, XDR, SIEM, SOAR, REST, and webhook systems

Use Cases & Applications

  • 24/7 managed detection and response for mid-market enterprises without an internal SOC
  • Sovereign or air-gapped cyber defense for government, defense-industrial, and regulated environments
  • Ransomware, credential theft, lateral movement, and business-email-compromise investigation and containment
  • MSSP operation across multiple customer tenants with isolated data, context, dashboards, and escalations
  • Cloud, SaaS, identity, endpoint, and email monitoring for hospitals, utilities, financial institutions, and critical suppliers
  • Emergency incident response, digital forensics, evidence preservation, recovery, and post-incident hardening
  • Executive and high-value-individual protection covering dark-web exposure, impersonation, social engineering, and private-device compromise
  • Compliance evidence and security-posture reporting for ISO 27001, SOC 2, NIST CSF, GDPR, HIPAA, and customer-specific controls

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 8 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

  • About EyeR Security Verifies the Israeli company identity, AI detection-and-response positioning, managed-defense model, reported 50 customers, ISO 27001 claim, team capability areas, and company origin story.
  • EyeR Platform — Autonomous MDR and TDIR Verifies the platform's cloud, SaaS, identity, endpoint, email, and dark-web capability areas, telemetry correlation, threat workflows, audit trails, reporting, and integration model.
  • Managed Defense — 24/7 MDR and SOC Verifies the managed-service tiers, under-60-second AI analysis claim, 24/7 monitoring, human oversight, autonomous investigation and containment, and compatibility with Microsoft Defender, CrowdStrike, SentinelOne, and Cybereason.
  • For Regulated Industries — Sovereign MDR and On-Premise AI Verifies the customer-controlled and sovereign deployment positioning, local-processing and auditability claims, and stated relevance to privacy-regulated and defense or critical-infrastructure environments.
  • Emergency Incident Response — 24/7 Cyber Crisis Support Verifies the public emergency-response workflow for containment, forensic investigation, evidence preservation, recovery, and hardening, including the company's stated 24/7 response model.
  • EyeR Security — LinkedIn company profile Verifies the public company profile, Tel Aviv headquarters, privately held status, 2024 founding year, and 11-50 employee range.
  • Orel Asper — LinkedIn profile Verifies Orel Asper's public identification as EyeR Security Co-Founder and CEO.
  • Official website
  • Profile update timestamp Last updated in the Claw & Talon database on Aug 12, 2026.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.