Orchid Security

Cybersecurity Dual-Use Technology Priority Signal Founded 2024

Last updated: Jul 31, 2026

Orchid Security provides identity-first security orchestration that discovers applications, analyzes authentication and authorization behavior, and brings unmanaged identity controls into existing IAM, IGA, PAM, and audit workflows.

Visit Website

Company Overview

Orchid Security addresses the part of enterprise identity infrastructure that conventional IAM systems often cannot see: authentication and authorization behavior implemented inside SaaS, legacy, self-hosted, and custom applications. Its platform continuously discovers applications and identity paths, analyzes how access actually works, identifies control gaps such as hidden login routes, local accounts, hardcoded credentials, and privilege drift, and creates an identity baseline that can be monitored over time. Orchid says its analysis uses large language models and application telemetry to interpret identity-related logic without requiring application recoding; the practical value is the combination of visibility, explanation, remediation guidance, and evidence rather than an LLM in isolation.

The buying problem is credible and operationally expensive. Large enterprises accumulate hundreds or thousands of applications through organic growth, SaaS adoption, and acquisitions, while IAM, IGA, and PAM teams remain dependent on manual questionnaires, bespoke connectors, and application-owner knowledge. Orchid is designed to augment those existing systems rather than replace them: its stated workflow is to discover the application estate, assess authentication and authorization controls against security or regulatory requirements, route changes through the identity stack, and preserve an auditable record. The company has disclosed work with enterprise customers including Costco and Repsol, and its website carries customer commentary from ISS and other organizations. Those are useful traction signals, but the company's percentage improvements remain vendor-reported and should be validated by reference calls and deployment data.

Competition is substantial. SailPoint, Saviynt, Okta, Microsoft, CyberArk, and Omada already own important identity budgets, while identity threat detection, CIEM, application security, and software supply-chain products can address parts of the same exposure. Orchid's most defensible wedge is application-centric identity intelligence: it attempts to reveal why access exists and how controls are enforced in applications that directory-centric products cannot model cleanly. That wedge could reduce onboarding and professional-services work, especially during mergers or in estates with many bespoke applications, but it must translate analysis into safe, repeatable integrations and measurable risk reduction. The AWS Marketplace listing is a modest commercialization signal because it shows a SaaS delivery path and an enterprise procurement route, not proof of broad market adoption.

The company has unusually strong disclosed early-stage cybersecurity credentials for this category. Co-founders Roy Katmor and Ido Kelson previously founded enSilo, later acquired by Fortinet, while Robert Wiseman came from Team8 and identity/security operating roles; the current company page also lists experienced product and revenue leadership. Orchid announced a $36 million seed round co-led by Team8 and Intel Capital in January 2025, alongside statements that it was already working with large enterprises. LinkedIn currently places the company in the 11–50 employee band, which is consistent with a well-funded but still early commercial organization. These signals support meaningful diligence priority, but they do not establish renewal rates, recurring revenue, gross margins, or deployment scalability.

The national-security relevance is real but indirect. Identity compromise, unmanaged service accounts, excessive privilege, and opaque application access paths are common contributors to intrusion and lateral movement in critical infrastructure, defense contractors, and government-adjacent environments. A platform that makes those paths observable and governable could improve cyber resilience without requiring every legacy application to be rewritten. There is no basis here to claim defense or government contracts, so the dual-use case should be framed as transferable cyber infrastructure capability. The central diligence questions are whether passive discovery is complete, whether model-derived findings are explainable and low-noise, how sensitive telemetry is handled, and whether remediation can be safely enforced in high-assurance environments.

Dual-Use Assessment

Military & Commercial Applications

Orchid's core capability—discovering and governing hidden application identity behavior—has substantive commercial identity-security value and transfers credibly to defense contractors, critical infrastructure, and other high-assurance environments. The public evidence supports a cyber-resilience adjacency, not a claim of defense procurement or operational military use.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Orchid is a credible strategic-priority signal for a dual-use cybersecurity database because it targets a persistent enterprise identity problem with a differentiated application-centric approach, disclosed enterprise traction, and a well-capitalized seed round. The leadership background and AWS Marketplace route strengthen the commercialization case. This is not an investment recommendation: diligence should focus on recurring revenue, retention, false-positive rates, deployment effort, model explainability, data handling, and whether incumbents can reproduce the workflow inside broader identity platforms.

Strategic Value to U.S.-Israel Alliance

Orchid could become strategically valuable as a visibility and control layer for identity in complex application estates. By exposing unmanaged authentication, machine and local accounts, privilege drift, and application-specific access logic, it may reduce intrusion paths and improve auditability for regulated and defense-adjacent operators without requiring wholesale re-platforming. The strategic case is strongest if the product can operate with low noise, preserve evidence, and integrate safely with existing control systems; public materials do not yet establish government adoption or mission-specific deployments.

Key Technologies

  • Passive application and identity discovery across SaaS, cloud, on-premise, legacy, and custom systems
  • LLM-assisted analysis of authentication and authorization flows
  • Application identity graph and control-gap mapping
  • Identity posture baselining and continuous drift monitoring
  • IAM, IGA, PAM, SSO, and MFA orchestration integrations
  • Framework-aligned compliance and remediation evidence
  • Identity telemetry for human, machine, and agentic-AI access

Use Cases & Applications

  • Onboard custom and legacy applications into enterprise IAM and IGA programs
  • Find shadow applications, local accounts, alternate authentication paths, and hardcoded credentials
  • Prioritize privilege drift and least-privilege remediation across hybrid estates
  • Generate continuous evidence for NIST, ISO 27001, SOX, PCI, HIPAA, GDPR, and similar control programs
  • Support identity discovery and access-control review during mergers and acquisitions
  • Give incident responders identity visibility and preserved evidence in unmanaged applications
  • Establish guardrails for autonomous or agentic identities
  • Improve identity resilience for defense contractors and critical-infrastructure operators without rewriting every application

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.

This record lists 7 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Investor Lens

What this entry is

Private startup

Why it may matter

Orchid Security may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify traction
  • Verify cap table/funding
  • Verify technical claims
  • Verify regulatory/export-control issues
  • Verify customer concentration

Main investor questions

  • Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
  • What customer, revenue, product, and technical evidence supports the company story?
  • What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies Orchid Security's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.