Infinipoint

Cybersecurity Acquired asset Dual-Use Technology Founded 2019

Last updated: Jul 31, 2026

Infinipoint developed a zero-trust workforce-access platform that combined phishing-resistant user authentication with device identity, continuous posture checks, and self-service remediation. Outpost24 acquired the company in December 2025 and integrated its product capabilities into the Specops identity-security portfolio as Specops Device Trust.

Visit Website

Company Overview

Infinipoint was an Israeli identity-security startup founded in 2019 around a specific weakness in conventional zero-trust deployments: strong user authentication does not establish that the device presenting the credential is trustworthy. Its platform combined passwordless or MFA authentication with device identity, user-device binding, granular posture checks, and policy-based access decisions. Public product material described checks across operating-system configuration, active threats, security controls, and software state, with posture evaluated at login and repeatedly during an active session. The platform also offered one-click user remediation for conditions such as disabled encryption, an outdated operating system, or a disabled firewall, allowing security policy enforcement without turning every exception into an IT ticket.

The commercial problem was well defined. Enterprises increasingly support hybrid workforces, contractors, BYOD, and applications spread across cloud and on-premise environments, while identity providers typically answer who is signing in more reliably than whether the endpoint is safe to use. Infinipoint targeted IT and security teams that needed device-aware conditional access without deploying a full mobile-device-management stack to every user or unmanaged endpoint. Its documented integrations included Okta, Microsoft Entra ID/Azure AD, and Ping Identity, and its supported endpoint scope included Windows, macOS, Linux, iOS, and Android. That breadth made the product relevant to organizations with heterogeneous fleets, although it also increased the burden of endpoint-agent quality, policy configuration, and integration support.

The principal competitive advantage was product focus at the intersection of identity and endpoint trust rather than ownership of either category. Infinipoint differentiated its pitch through continuous checks, device-bound authentication, visibility into unmanaged devices, and remediation at the point of access. These capabilities addressed risks such as phishing, stolen credentials, session hijacking, and lateral movement. The competitive field remained difficult: Microsoft, Okta, Cisco Duo, CrowdStrike, Zscaler, Kolide, Beyond Identity, and endpoint-management platforms all covered parts of the same decision. Large identity and security vendors could bundle adjacent controls into broader contracts, while specialist vendors could compete on deployment simplicity or endpoint telemetry. Sustainable differentiation therefore depended on detection quality, low user friction, broad platform coverage, and measurable reduction in access-related incidents.

The strongest current traction signal is strategic rather than standalone operating data. Outpost24 announced the acquisition of Infinipoint on December 9, 2025, stating that the transaction would add device identity, posture validation, secure workforce access, and one-click remediation to its Specops identity-security division. Outpost24 later described completion of the Infinipoint product-suite integration in 2026, and Specops now markets the resulting capability as Specops Device Trust. The acquisition validates that the technology was valuable to an established cybersecurity platform, but it also means the former startup should not be analyzed as an independent Series A company. Public sources do not establish current standalone revenue, customer retention, valuation, or the extent to which the original product remains separately operated.

The dual-use case is credible but bounded. Device-bound authentication and continuous posture enforcement can protect enterprise, government, defense, and intelligence workforces from compromised endpoints and stolen credentials. In sensitive environments, the technology could help enforce access to mission-support applications, contractor portals, and segmented administrative systems. However, the public evidence supports a workforce-access and identity-security product, not a military-specific system, classified deployment, or operational defense contract. Its strategic relevance is therefore strongest as cyber-infrastructure enabling secure access, with integration into Outpost24 and Specops improving distribution potential while reducing the relevance of independent startup financing as a diligence question.

Dual-Use Assessment

Military & Commercial Applications

Infinipoint's core capabilities are substantively dual-use: binding user authentication to an authorized device and continuously checking endpoint posture can reduce credential abuse, session hijacking, and unauthorized access in commercial, government, defense, and intelligence environments. The public record supports secure workforce access and identity security, but does not substantiate a defense-specific deployment or government contract, so the defense case should be treated as an enabling cyber-security adjacency rather than proven military traction.

Strategic Fit Assessment

Infinipoint addressed a durable identity-security problem and produced technology valuable enough for Outpost24 to acquire and integrate into Specops Device Trust. That is a positive strategic-validation signal, but the asset is no longer an independent startup opportunity and should not be treated as a current venture investment candidate. Diligence should instead focus on the acquisition's product integration, customer continuity, roadmap ownership, endpoint telemetry quality, privacy and data-residency controls, and whether the combined offering can win against Microsoft, Okta, Cisco Duo, and other bundled access platforms.

Strategic Value to U.S.-Israel Alliance

The asset adds the device-trust pillar that identity systems often lack: access can depend on both the authenticated user and the current state of the endpoint. Integrated into Outpost24's Specops division, the capability can strengthen zero-trust workforce access, reduce the usefulness of phished credentials, and extend protection to contractors and unmanaged devices. Its value to national-security buyers is indirect but meaningful as secure-access infrastructure; public sources do not demonstrate classified-network deployment, defense procurement, or mission-specific specialization.

Key Technologies

  • Device identity and user-device binding
  • Continuous endpoint posture verification
  • Phishing-resistant passwordless and MFA authentication
  • Risk-based conditional access policies
  • Identity-provider integrations for Okta, Microsoft Entra ID, and Ping Identity
  • One-click endpoint self-remediation
  • Cross-platform coverage for Windows, macOS, Linux, iOS, and Android

Use Cases & Applications

  • Blocking stolen credentials when the login originates from an untrusted device
  • Continuous access enforcement for hybrid and remote workforces
  • Secure access for contractors and unmanaged BYOD endpoints
  • Phishing-resistant authentication for enterprise applications
  • Self-service remediation of encryption, firewall, and operating-system compliance gaps
  • Device-aware access controls for government and defense administrative systems
  • Reducing lateral-movement risk after endpoint compromise

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.

This record lists 6 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Investor Lens

What this entry is

Acquired asset

Why it may matter

Infinipoint may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify technical claims
  • Verify regulatory/export-control issues

Main investor questions

  • Is this entry a benchmark, buyer, ecosystem node, acquired asset, or strategic reference rather than a live startup opportunity?
  • What does this reference clarify about buyers, sector structure, public-market context, or strategic demand?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies Infinipoint's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • Is the company a live venture opportunity, a mature strategic reference, an acquired asset, or primarily a market-mapping entry?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.