Dossier · Acquired asset · 3 independent sources
Hyperwise
Last updated: Jul 31, 2026
Hyperwise was a Tel Aviv cybersecurity startup that developed CPU-level threat-prevention technology intended to stop exploits at the pre-infection stage. Check Point completed its acquisition of Hyperwise Ltd. in February 2015, integrating the team and technology into its threat-prevention portfolio; Hyperwise is therefore an acquired asset rather than an independent current company.
Company Overview
Hyperwise developed a CPU-level threat-prevention engine for identifying and blocking malicious activity before an exploit could complete its infection or payload-execution path. Check Point's contemporaneous acquisition announcement describes the product as an exploit-prevention capability that operated at the pre-infection stage and was intended to improve protection against previously undetected attacks. That evidence supports a precise description of the core proposition: prevention close to the execution substrate, complementing malware detection, sandboxing, signatures, and post-compromise response. It does not, by itself, establish every implementation detail in the earlier record, such as a particular kernel architecture, a specific machine-learning method, or coverage of named exploit classes.
The company was founded in 2013, operated from Tel Aviv, and remained in stealth mode until the acquisition. Public disclosures describe it as early-stage and privately held, with a skilled engineering team; the available sources do not provide a dependable current employee count, customer list, product revenue figure, or independently verified acquisition consideration. Check Point said the transaction was not expected to have a material effect on its financial results and that the Hyperwise team would be integrated into Check Point operations. These are meaningful commercialization signals because a large security vendor selected the technology for portfolio integration, but they are not proof of broad standalone sales or deployment at military customers.
The market problem remains important even though the company no longer exists independently. Attackers can exploit vulnerable software before conventional endpoint telemetry, reputation systems, or sandbox verdicts are available, while patching and application modernization take time. CPU- and execution-aware controls can reduce the window between exploit delivery and detection, but they compete with platform mitigations such as ASLR, Control-flow Enforcement Technology, Control-flow Guard, exploit-protection settings, and secure software development. They also compete with broader endpoint platforms from Microsoft, CrowdStrike, SentinelOne, Palo Alto Networks, and Check Point itself. The durable edge would have been prevention efficacy at low performance and compatibility cost; the public record does not provide enough benchmark data to quantify that edge.
Hyperwise has credible dual-use relevance because the underlying defensive problem is shared by enterprises, public-sector networks, industrial operators, and defense organizations. A pre-infection exploit control could be valuable on endpoints handling sensitive communications, operational technology management, or mission-support software, but public evidence found here does not establish a Hyperwise defense contract, classified deployment, certification, or specific government customer. Its strategic significance is consequently best understood as an Israeli cyber-technology acquisition case and a signal about the value large security vendors placed on prevention-layer innovation. Check Point's acquisition and subsequent integration provide stronger evidence of strategic fit than of independent company maturity, long-term product autonomy, or validated national-security adoption.
Dual-Use Assessment
CPU-level, pre-infection exploit prevention has substantive applicability across commercial and national-security environments because both face memory-safety failures, malicious code execution, and targeted exploitation. The dual-use case is technological and credible: the same prevention layer can protect enterprise endpoints and sensitive government or defense networks. Public evidence confirms Check Point acquired the capability for its threat-prevention portfolio, but does not confirm a military customer, classified deployment, or defense certification; the score therefore reflects plausible applicability rather than documented defense traction.
Strategic Fit Assessment
Hyperwise is not an active standalone diligence target: Check Point completed its acquisition in February 2015 and stated that the team and technology would be integrated into Check Point operations. The acquisition is a useful historical validation signal for CPU-level prevention technology and Israeli cyber talent, but the public record does not support treating Hyperwise as an independently actionable company today. Any present-day diligence would need to shift to Check Point's product architecture, integration outcomes, and continuing exploit-prevention performance rather than a Hyperwise financing, customer, or exit pipeline.
Strategic Value to U.S.-Israel Alliance
Hyperwise is strategically relevant as an acquired Israeli cyber capability addressing a persistent weakness in conventional detection: the interval between exploit execution and a reliable security verdict. Its CPU-level approach aligns with layered endpoint and threat-emulation architectures and illustrates why a platform vendor might acquire specialized prevention IP and engineering talent. The record supports ecosystem and technology-transfer significance, but not a claim that Hyperwise independently supplied defense systems or that its exact post-acquisition contribution can be separated from Check Point's broader product development.
Key Technologies
- CPU-level threat prevention
- Pre-infection exploit detection and blocking
- Execution-aware endpoint protection
- Exploit-chain interruption
- Behavioral analysis of malicious execution
- Integration with malware emulation and endpoint security
Use Cases & Applications
- Blocking exploit delivery before a payload becomes active on enterprise endpoints
- Reducing exposure during vulnerability-disclosure and patch-deployment windows
- Protecting servers and workstations running sensitive business applications
- Hardening public-sector and mission-support endpoints against targeted intrusion
- Adding execution-layer controls to sandboxing and malware-emulation workflows
- Defense-in-depth for software and networks that cannot be patched immediately
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Open-web verification is limited. Readers should confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 3 public references used for company identity, status, positioning, or material-claim review.
Verification note: public information is limited; this entry is retained for ecosystem-mapping purposes and should not be relied on without further confirmation.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- Check Point acquisition announcement Official announcement identifying Hyperwise as a privately held early-stage company, founded in 2013, headquartered in Tel Aviv, and acquired for CPU-level pre-infection threat prevention; it also describes team integration and portfolio integration.
- Check Point 2015 Form 20-F Check Point filing records completion of the Hyperwise Ltd. acquisition on February 17, 2015 and describes the acquired CPU-level threat-prevention engine.
- Hyperwise Ventures team biography Founder-affiliated source identifying Nathan Shuchami, Ben Omelchenko, and Aviv Gafni as Hyperwise Security co-founders and describing the February 2015 Check Point acquisition; used cautiously for team context.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.