Polyrize

Cybersecurity Acquired asset Dual-Use Technology Founded 2018

Last updated: Jul 31, 2026

Polyrize was an Israeli cybersecurity startup that built a proxyless cloud identity and authorization platform. Varonis acquired Polyrize Security Ltd. in October 2020 and used its technology to extend visibility across cloud applications and infrastructure.

Visit Website

Company Overview

Polyrize built software for the authorization problem created by fragmented SaaS and IaaS environments. Its platform collected and normalized identity, privilege, access, and activity information across services such as Salesforce, G Suite, AWS, and Okta. Public launch materials described a proxyless architecture, a machine-learning engine, and a proprietary identity graph intended to correlate permissions with actual identity behavior rather than treating a login or a static role assignment as sufficient evidence of safe access. That was a technically meaningful approach to a problem that otherwise requires security teams to understand each provider's permission vocabulary separately.

The immediate customer was an enterprise security team responsible for reducing excessive privilege, shadow access, and unauthorized use of business-critical data. Polyrize positioned a unified access model as a way to identify high-impact users and actions, prioritize risky permissions, and maintain controls after authentication. Its 2020 general-availability announcement said the platform had been developed with US-based design customers across multiple industries and supported a broad set of SaaS, IaaS, and identity services. Those statements are useful traction signals, but they do not establish customer count, recurring revenue, retention, or independent scale; the database should therefore avoid treating early design-customer references as proof of durable commercial traction.

Polyrize entered a market that later converged with cloud infrastructure entitlement management, identity threat detection and response, data security posture management, and broader cloud-security platforms. Its differentiation was the combination of cross-service identity correlation, permission analysis, and behavior context, while its commercial challenge was the cost of maintaining accurate integrations as cloud APIs and authorization models changed. Native IAM tools remained essential substitutes, and larger vendors could bundle adjacent controls into platforms with established enterprise distribution. The acquisition outcome is the strongest available commercialization signal: Varonis announced the deal as a way to extend its existing user-to-data relationship mapping, and later filings state that Polyrize technology supported DatAdvantage Cloud and Data Classification Cloud coverage for services including AWS, Box, GitHub, Google Drive, Jira, Okta, Salesforce, Slack, and Zoom.

The acquisition also changes how the company should be assessed today. Polyrize is no longer an independent startup with a current product roadmap, headcount, or financing path. Its technology appears to have been absorbed into Varonis's data-security portfolio, so current diligence should focus on which Polyrize-originated capabilities remain identifiable, how much of the original architecture was retained, and whether the integration produced measurable product adoption. Varonis's public reporting confirms the product lineage but does not disclose a Polyrize standalone revenue contribution or acquisition price. Historical funding is better supported than current operating metrics: Polyrize announced a $4 million seed round in 2019 and a later investment from Silicon Valley CISO Investments.

The defense and national-security case is credible but indirect. Identity, entitlement, and data-access mapping are foundational to zero-trust programs, government cloud security, defense-industrial environments, and protection of sensitive operational data. The same controls can help identify which human, application, and service identities can reach mission systems or cloud-hosted datasets. However, the public record does not establish defense customers, classified deployments, government contracts, or accreditation. Polyrize should therefore be treated as dual-use cybersecurity infrastructure with defense adjacency, not as a proven defense vendor. Its strategic relevance is primarily the transfer of authorization and data-relationship technology into a larger security platform.

Dual-Use Assessment

Military & Commercial Applications

The core technology for correlating identities, privileges, behavior, and data access has direct commercial and security value in enterprise cloud environments and credible defense applicability to zero-trust and mission-data access control. Public sources do not establish defense customers, classified use, government contracts, or accreditation, so the defense case is adjacency rather than demonstrated deployment.

Strategic Fit Assessment

Polyrize is not a live independent investment candidate: Varonis acquired Polyrize Security Ltd. in 2020 and incorporated its technology into commercial cloud-data-security products. The acquisition validates the strategic usefulness of the capability, but standalone financial performance, present ownership, team continuity, and an independent financing path are no longer available for normal startup diligence.

Strategic Value to U.S.-Israel Alliance

Polyrize is strategically valuable as an example of identity-and-data relationship technology that strengthened a larger data-security platform. Its capability addressed a persistent control-plane gap across SaaS and IaaS environments and remains relevant to zero-trust, cloud migration, insider-risk reduction, and protection of sensitive government or defense data. The value is now primarily embedded in Varonis rather than available as an independent company.

Key Technologies

  • Proxyless collection across SaaS, IaaS, and identity services
  • Cross-cloud identity and entitlement normalization
  • Identity graph linking users, privileges, actions, and data
  • Machine-learning analysis of authorization and access behavior
  • Shadow privilege and excessive-access discovery
  • Risk prioritization for cloud data access
  • Integration with enterprise data-security posture workflows

Use Cases & Applications

  • Enterprise visibility into fragmented cloud identities and permissions
  • Detection of excessive, unused, or shadow privileges
  • Correlation of user behavior with access to sensitive cloud data
  • Authorization review across Salesforce, Google Workspace, AWS, Okta, and similar services
  • Least-privilege and zero-trust program support
  • Cloud access review for defense contractors and government environments
  • Data-security posture monitoring across SaaS and IaaS estates

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.

This record lists 6 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Investor Lens

What this entry is

Acquired asset

Why it may matter

Polyrize may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify technical claims
  • Verify regulatory/export-control issues

Main investor questions

  • Is this entry a benchmark, buyer, ecosystem node, acquired asset, or strategic reference rather than a live startup opportunity?
  • What does this reference clarify about buyers, sector structure, public-market context, or strategic demand?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies Polyrize's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • Is the company a live venture opportunity, a mature strategic reference, an acquired asset, or primarily a market-mapping entry?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.