Onyxia
Last updated: Jul 31, 2026
Onyxia Cyber provides an operational cyber-resilience and cybersecurity-management platform that unifies security telemetry, control coverage, stack economics, exposure prioritization, and executive reporting for CISOs and security teams.
Visit WebsiteCompany Overview
Onyxia Cyber is a privately held cybersecurity software company founded in October 2021 by Sivan Tehila and co-founders identified in public company profiles. Its product is a management and decision-support layer above an enterprise's existing security tools, rather than another endpoint, network, or identity control. The platform connects data from security and IT systems, normalizes it into a cross-domain view, and helps a security leader move from a list of assets and alerts to an operating picture of coverage, gaps, priorities, and business impact. The company's current positioning calls this an Operational Cyber Resilience Engine and emphasizes the bridge between day-to-day operations, organizational context, and measurable outcomes.
The product's most concrete capabilities are a Security Stack Map, exposure and control-gap analysis, benchmarking, compliance-oriented program measurement, budget and return-on-investment views, and automated or AI-assisted reporting. Onyxia says it integrates with more than 40 security products spanning endpoint and vulnerability management, identity, cloud security, application security, email, SIEM, security awareness, network controls, device management, attack-surface management, and IT service management. This breadth is strategically useful because CISOs commonly inherit a fragmented stack whose individual tools cannot explain whether the overall program is reducing risk. It is also a technical dependency: the quality of the platform's conclusions depends on connector coverage, data freshness, normalization, permissions, and the validity of the assumptions used to compare unlike controls.
The target market is enterprise security organizations and, according to earlier public coverage, managed security service providers. The buyer problem is credible: security leaders must allocate limited staff and license budgets, demonstrate compliance, explain program performance to boards, and decide whether a new control closes a meaningful gap or merely duplicates an existing capability. Onyxia's public materials claim SOC 2 Type II and ISO 27001 certification, AICPA auditing, AWS Marketplace availability, alignment with NIST CSF and MITRE ATT&CK, and a 30-day time-to-value message. These are useful commercialization signals, but they are not substitutes for diligence on paying-customer retention, deployment depth, quantified exposure reduction, gross margin, and the proportion of product value that is repeatable rather than services-assisted. Public reporting confirms a $5 million seed round led by World Trade Ventures with Silvertech Ventures and angels in September 2022; a later undisclosed round is reported in third-party company data, but a Series A is not adequately substantiated by the sources reviewed.
Competition is broad and comes from several directions. Security-rating and cyber-risk vendors such as Bitsight, SecurityScorecard, and Safe Security compete for executive risk measurement; exposure-management and attack-path vendors such as XM Cyber compete for prioritization; and asset-inventory or security-operations platforms such as Axonius compete for normalized visibility and stack context. Large security vendors can also add overlapping dashboards and reporting to existing suites. Onyxia's potential edge is the combination of stack rationalization, program governance, exposure prioritization, and board communication in one workflow. That edge will hold only if the company can prove that its models improve decisions beyond spreadsheets, native vendor consoles, and consulting-led assessments.
The national-security relevance is defensive and operational. A military, government, or critical-infrastructure operator also needs to understand heterogeneous asset coverage, identity and endpoint hygiene, control gaps, compliance posture, and the effect of remediation choices across a constrained cyber workforce. Onyxia does not appear to sell offensive access, exploit tooling, or intelligence collection; its dual-use case is therefore a force-multiplication and governance application for sensitive networks. The evidence supports credible adjacency, not proof of defense deployment. Security accreditation, data-residency options, disconnected or restricted-network operation, classified-environment handling, procurement eligibility, and references from government or defense customers would be important diligence questions before assigning a stronger defense thesis.
Dual-Use Assessment
Onyxia's core product is defensive cybersecurity management, and the same technology has substantive applicability to defense, government, and critical-infrastructure networks that must prioritize control gaps across large heterogeneous estates. The crossover is in exposure analysis, asset and control coverage, resource allocation, and resilience reporting. There is no reliable public evidence of a defense contract or classified deployment, and the platform does not appear to provide offensive capabilities, so the dual-use case should be treated as credible defensive adjacency rather than demonstrated defense traction.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Onyxia addresses a persistent enterprise problem: security teams accumulate tools and telemetry but still struggle to prove coverage, prioritize remediation, and explain spending. Its strategic fit is supported by a product that spans data integration, exposure management, stack optimization, and governance, plus a reported $5 million seed round and current claims of certification and marketplace distribution. The priority signal remains conditional. Diligence should establish recurring revenue quality, deployment and retention, connector reliability, model validation, sales efficiency, and whether customers pay for differentiated software rather than bespoke reporting. This is a strategic diligence assessment, not an investment recommendation.
Strategic Value to U.S.-Israel Alliance
Onyxia could help government, allied-defense, and critical-infrastructure operators allocate scarce cyber personnel and budget across complex estates, while helping commercial partners turn low-level telemetry into remediation queues and decision-ready reporting. Its value is greatest as an interoperability and governance layer that improves the use of existing controls. The absence of public evidence for defense contracts, restricted-network deployments, or government procurement should cap confidence in the strategic case until verified.
Key Technologies
- Cross-domain security data fabric and telemetry normalization
- Agentic AI and predictive analytics for cyber-program management
- Security Stack Map for control coverage, overlap, and redundancy analysis
- Threat-exposure and control-gap prioritization
- Connectors for endpoint, identity, vulnerability, cloud, application, SIEM, and ITSM systems
- NIST CSF and MITRE ATT&CK aligned benchmarking and measurement
- Security budget, ROI, compliance, and executive-reporting automation
Use Cases & Applications
- Continuous exposure and control-gap management for enterprise security teams
- Security-tool coverage mapping and redundant-license rationalization
- Prioritization of vulnerability, identity, endpoint, cloud, and application remediation
- Measurement and reporting of security-program performance against NIST CSF or MITRE ATT&CK
- Board and executive reporting that links cyber investments to business outcomes
- MSSP-assisted governance and recurring security-program reviews
- Critical-infrastructure cyber-resilience planning across heterogeneous environments
- Defensive prioritization and readiness assessment for government or military networks
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.
This record lists 8 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- onyxia.io Public source used for profile verification.
- onyxia.io Public source used for profile verification.
- onyxia.io Public source used for profile verification.
- onyxia.io Public source used for profile verification.
- onyxia.io Public source used for profile verification.
- calcalistech.com Public source used for profile verification.
- prweb.com Public source used for profile verification.
- Company announcement Public source used for profile verification.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Investor Lens
What this entry is
Private startup
Why it may matter
Onyxia may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.
How an independent investor should read this
Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify traction
- Verify cap table/funding
- Verify technical claims
- Verify regulatory/export-control issues
- Verify customer concentration
Main investor questions
- Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
- What customer, revenue, product, and technical evidence supports the company story?
- What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Onyxia's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.