Dossier · Private startup · 3 independent sources

IntelEye

Cybersecurity Dual-Use Technology Priority Signal Founded 2023

Last updated: Sep 8, 2026

IntelEye is an Israeli intelligence-technology startup building a sovereign digital-visibility platform that collects, fuses, and analyzes signals from the clear, deep, and dark web and restricted messaging environments. Its stated customers span governments and enterprises using web intelligence for cybersecurity, counterterrorism, fraud investigations, threat monitoring, and situational awareness.

Visit Website

Company Overview

**Product and the concrete problem it solves.** IntelEye addresses the widening gap between the amount of relevant information available online and the ability of an organization to collect, corroborate, and act on it in time. Its official positioning is a sovereign intelligence platform for national digital visibility, combining intelligence collection, deep investigations, predictive analysis, and actionable insights. The company and its public profile describe coverage across the clear, deep, and dark web, as well as restricted groups in popular instant-messaging services. That matters because a government security team, cyber-defense unit, fraud investigator, or enterprise risk group may need to follow a person, organization, campaign, threat narrative, or illicit transaction across multiple online environments rather than search one public website at a time. IntelEye is therefore presented as an intelligence workflow layer: it aims to reduce the manual work of finding relevant information, connect otherwise isolated observations, and give analysts a structured basis for investigation and mitigation. Public materials do not specify a named product catalog, pricing model, collection volume, or customer-specific workflow, so the record should not imply a mature end-to-end case-management suite beyond the capabilities the company publicly claims.

**Core technology and how it actually works.** The disclosed technical proposition has three connected components. First, IntelEye orchestrates collection from several classes of online source rather than limiting itself to ordinary search-engine indexing. Second, it applies artificial-intelligence and machine-learning algorithms to extract meaningful insights from that large data ocean, according to the company profile. Third, it presents the result as fused intelligence that can support investigation, threat detection, asset protection, and decision-making. The public record does not expose the underlying crawler architecture, source connectors, language coverage, entity-resolution method, graph model, model providers, human-review process, or confidence scoring. Those omissions are important: it is reasonable to describe the technology as AI-assisted web intelligence and data fusion, but not to claim proprietary foundation models, guaranteed dark-web access, real-time latency, or autonomous attribution. A credible technical diligence process would test source authorization, collection continuity, multilingual extraction, duplicate suppression, entity disambiguation, temporal versioning, evidence provenance, analyst feedback loops, and whether predictions are genuinely useful beyond keyword search. The most strategically interesting possibility is a controlled fusion layer that lets an analyst move from raw online observations to a time-linked and source-linked investigative picture; whether IntelEye has built that depth remains a central open question.

**Market, customers, and go-to-market.** IntelEye targets buyers with a high cost of missing weak signals: governments, intelligence and security organizations, law-enforcement bodies, cybersecurity teams, fraud-prevention groups, and enterprises managing digital risk. Its LinkedIn description explicitly names cybersecurity, de-anonymization, market research, counterterrorism and security, fraud prevention, and law enforcement as application areas. This is a broad market, but there is a coherent beachhead in organizations that already employ investigators and need better collection and fusion rather than a consumer-facing monitoring app. The likely commercial motion is consultative and account-based: demonstrate a specific investigation, integrate authorized data sources, prove analyst time savings or earlier detection, then expand into recurring monitoring and additional teams. Public activity also points toward international security-industry networking. IntelEye has promoted participation in ISS World 2026 and GLOBSEC Forum 2026, both relevant venues for government, defense, intelligence, and security buyers. These appearances show go-to-market intent and ecosystem participation, not signed contracts. No public source reviewed here names a paying customer, contract value, renewal rate, channel partner, government framework agreement, or procurement win, so commercial scale remains unverified.

**Traction, funding, and third-party validation.** IntelEye was incorporated in Israel on June 1, 2023, and the Israeli company record reviewed in August 2026 lists INTELEYE LTD as an active private company in Tel Aviv. LinkedIn describes the operating company as founded in 2023, privately held, headquartered in Tel Aviv, and employing 11-50 people; its public page currently exposes 13 employees and about 2,000 followers. Those are useful existence and activity signals, but they are not audited headcount or revenue evidence. Intelligence Online independently reported in December 2023 that Maor Sellek and Ziv Haba, two former employees of Israeli cyber-intelligence company NSO Group, joined business-development specialist Oshrat Kakon Faribai to found IntelEye. The company has also maintained a current official website and published public intelligence material through its social channels, including reports framed around terrorism, radicalization, and online networks. No disclosed venture round, grant, valuation, revenue figure, certification, patent portfolio, or named customer was found in the sources used for this record. The strongest third-party validation is therefore the combination of an active legal entity, independent founder coverage, a consistent public product identity, and sustained participation in relevant industry forums; it is meaningful for an early company but substantially weaker than customer or funding disclosure.

**Founders and team background.** The founding team combines relevant intelligence and commercialization experience, although the public record is thin on current organizational depth. Intelligence Online identifies Maor Sellek and Ziv Haba as former NSO Group employees and Oshrat Kakon Faribai as the business-development co-founder. The Israeli registry page lists Ziv Haba and Maor Sellek as directors, corroborating their connection to the legal entity. IntelEye's LinkedIn page lists Maor Sellek, Seggev Shoresh, Yiftach Lewinsky, and Shir Frumerman among employees, while the public company page describes the team as operating at the intersection of web intelligence, AI, cybersecurity, government, and investigations. This background is strategically relevant because building a usable intelligence platform requires more than generic machine learning: it requires understanding how analysts frame questions, preserve evidence, assess source reliability, and turn collection into an operational decision. Former cyber-intelligence experience may help with those workflows and with access to security buyers, but it is not proof of product quality or responsible governance. Diligence should establish the current leadership split, engineering and research headcount, experience with lawful data acquisition, model evaluation, privacy controls, customer support, and whether the company has the compliance and oversight expertise required for sensitive government and enterprise deployments.

**Competitive dynamics.** IntelEye competes in a dense intelligence and risk-analytics market. Recorded Future and Flashpoint offer large-scale threat intelligence and dark-web monitoring with extensive research operations; KELA focuses on cybercrime intelligence and underground-market visibility; Cobwebs Technologies and ShadowDragon provide investigation-oriented collection and link-analysis workflows; Babel Street sells multilingual data and intelligence capabilities to government and enterprise customers; and Bright Data, Vetric, and similar infrastructure providers can supply public-web collection inputs without presenting themselves as a sovereign intelligence platform. Large government contractors and national intelligence agencies can also build internal collection and fusion systems, while general-purpose search, commercial data brokers, and analyst-written scripts remain substitutes at the low end. IntelEye's plausible edge is the combination of collection, AI-assisted extraction, cross-source fusion, and a government-oriented positioning from an Israeli team with cyber-intelligence roots. That can be valuable if it produces better investigative speed, source breadth, and evidence continuity than point tools. The edge is not yet demonstrated as a durable moat: larger competitors have more data, researchers, integrations, and procurement history; models and collection methods can be replicated; and sensitive buyers may prefer established vendors or in-house systems. Independent benchmark results, reference customers, and evidence of sustained analyst adoption are needed to substantiate differentiation.

**Defense, security, and resilience dual-use relevance.** IntelEye's dual-use case is direct at the information and investigation layer, while remaining subject to unusually serious legal, ethical, and operational constraints. Commercially, its stated capabilities can support cyber-threat intelligence, fraud prevention, de-anonymization, brand and asset protection, and enterprise investigations. In government and security contexts, the same collection and fusion functions could support counterterrorism research, online-radicalization monitoring, illicit-network mapping, public-safety investigation, cyber incident context, sanctions and fraud analysis, and early warning around coordinated influence or threat activity. A platform that helps an analyst connect open-source and restricted-channel signals can improve resilience when an organization must operate across fragmented information environments. This is credible dual-use relevance because the core product is explicitly marketed to both governments and enterprises, not because a commercial analytics tool can automatically become a defense system. Public sources do not establish an Israeli Ministry of Defense contract, classified deployment, military customer, operational intelligence program, security accreditation, or fielded defense capability. The strategic value therefore depends on lawful collection, source authorization, privacy and human-rights safeguards, auditable provenance, retention controls, analyst review, and resistance to false attribution. The same capabilities that help legitimate investigators can also enable intrusive surveillance or abuse; responsible governance is part of the product's strategic viability, not a peripheral issue.

**Growth stage, trajectory, and key diligence risks.** IntelEye is best classified as early: it has operated since 2023, presents an identifiable product thesis, maintains an active legal entity and public website, and appears to have a small but real team, yet public evidence does not show disclosed financing, scaled revenue, named customers, or mature product validation. Its trajectory could be attractive if it turns founder-level intelligence expertise into a repeatable platform with recurring monitoring, defensible data and workflow integrations, and referenceable government or enterprise deployments. The principal diligence points are: (1) **commercial proof** — verify paying customers, revenue, retention, pipeline, and procurement status rather than treating event participation or social-media reports as traction; (2) **technical reliability** — measure coverage, uptime, recall, precision, entity resolution, latency, multilingual performance, and analyst time saved; (3) **legal and governance exposure** — review collection authorization, jurisdictional restrictions, privacy, retention, export controls, auditability, and safeguards against misuse; (4) **data and model risk** — test poisoned sources, coordinated deception, false positives, hallucinated links, and whether every high-consequence conclusion retains source-level evidence; (5) **competitive pressure** — assess whether Recorded Future, KELA, Flashpoint, Cobwebs, or a government integrator can bundle equivalent functionality faster; (6) **team-scale risk** — determine whether an 11-50-person organization can support secure deployments, research, customer success, and compliance simultaneously; and (7) **reputational risk** — understand how the founders' NSO background affects customer trust, regulatory scrutiny, and access to allied public-sector markets. IntelEye merits monitoring because the strategic problem is real, but its priority should rise only with verifiable deployments, responsible-governance evidence, and repeatable commercial outcomes.

Dual-Use Assessment

Military & Commercial Applications

IntelEye's core platform is credibly dual-use because the same intelligence collection, AI-assisted extraction, and cross-source data-fusion capabilities are marketed for commercial cybersecurity, fraud, and investigations as well as government, counterterrorism, law-enforcement, and security workflows. The defense relevance is information-layer adjacency rather than a demonstrated military capability: no public source reviewed here verifies an Israeli Ministry of Defense contract, classified deployment, military customer, or security accreditation. The strategic case depends on lawful collection, source authorization, privacy safeguards, auditable evidence, human review, and controls against intrusive or abusive use.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

IntelEye is a strategic-priority signal rather than a recommendation to invest. (1) The problem is durable: governments and enterprises increasingly need to combine fragmented web, dark-web, and messaging signals while reducing analyst overload. (2) The product thesis is tightly aligned with Israel's cyber-intelligence talent base, and the founders' reported NSO experience may provide relevant operational knowledge and buyer access. (3) The company has credible existence signals — an active Israeli entity, official website, LinkedIn operating profile, and independent founder coverage — but no public funding, revenue, named customer, certification, or contract evidence. (4) The largest upside would come from a repeatable, auditable intelligence workflow that earns recurring government and enterprise deployments; the largest downside is a small team with limited disclosed validation entering a crowded market with high legal and reputational exposure. Priority should increase only after verifying deployments, data governance, product benchmarks, and commercial durability.

Strategic Value to U.S.-Israel Alliance

IntelEye could contribute strategic value at the digital-intelligence layer by helping authorized analysts collect and connect signals that are otherwise dispersed across public websites, underground environments, and restricted messaging channels. That capability is relevant to cyber defense, counterterrorism research, fraud disruption, public safety, and resilience against coordinated online threats. Its value is conditional rather than proven: a sovereign or allied buyer would need trustworthy provenance, lawful collection, access controls, retention policy, reproducible analysis, and safeguards against false attribution or abuse. The platform is strategically interesting because it may strengthen information advantage without requiring a new physical sensor, but it should not be treated as a fielded defense system absent public contract or deployment evidence.

Key Technologies

  • Clear-web, deep-web, dark-web, and restricted-messaging intelligence collection
  • AI and machine-learning extraction of entities, relationships, threats, and investigative signals
  • Cross-source data fusion for national digital-visibility and investigation workflows
  • Web intelligence and OSINT search, monitoring, and forensic investigation tooling
  • De-anonymization and location-threat monitoring workflows subject to legal authorization
  • Cyber-threat intelligence, fraud-investigation, and asset-protection analytics
  • Predictive analysis and analyst-oriented conversion of collected signals into actionable insights

Use Cases & Applications

  • Cyber-threat intelligence and incident-context enrichment for enterprise security teams
  • Counterterrorism and online-radicalization research by authorized government or law-enforcement users
  • Fraud, impersonation, and illicit-network investigations across public and restricted online sources
  • Digital asset, executive, brand, and critical-organization exposure monitoring
  • Open-source mapping of coordinated influence, threat narratives, and public safety signals
  • Government situational awareness and investigative support across fragmented online ecosystems
  • Enterprise market, risk, and competitive intelligence using web and messaging signals
  • Forensic evidence discovery and source-linked investigative case development

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 5 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

  • IntelEye official website Verifies the current company identity and official positioning around sovereign intelligence collection, deep investigations, predictive analysis, and actionable national digital visibility.
  • INTELEYE LinkedIn company profile Verifies the 2023 founding, Tel Aviv headquarters, private-company status, 11-50 employee range, current public employee list, and stated applications across web intelligence, AI, government, cybersecurity, counterterrorism, fraud prevention, law enforcement, and OSINT.
  • NSO Group veterans launch OSINT start-up IntelEye - Intelligence Online Independent intelligence-industry report identifying Maor Sellek and Ziv Haba as former NSO employees and Oshrat Kakon Faribai as the business-development co-founder who launched IntelEye.
  • INTELEYE LTD company record - CheckID Israeli company-registry data verifies the legal name INTELEYE LTD, company number 516819653, active private-company status, June 1, 2023 incorporation date, Tel Aviv address, and directors including Ziv Haba and Maor Sellek.
  • inteleye - Crunchbase company profile Secondary ecosystem profile corroborating IntelEye's Tel Aviv, Israel location, private status, 11-50 employee range, domain, and cybersecurity, AI, dark-web, law-enforcement, fraud, and national-security category positioning.
  • Profile update timestamp Last updated in the Claw & Talon database on Sep 8, 2026.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.