Dossier · Private startup · 1 independent source
Reflectiz
Last updated: Jul 31, 2026
Reflectiz is an Israeli cybersecurity company that provides agentless web exposure management: it observes live browser execution to identify security, privacy, compliance, and offensive-testing risks in first-, third-, and fourth-party web components.
Visit WebsiteCompany Overview
Reflectiz addresses the runtime layer of web security that conventional server, network, WAF, code-scanning, and point-in-time assessment tools can miss. Its remote sandbox browser crawls selected pages and user journeys, including authentication and checkout flows, then observes scripts, iframes, tags, pixels, cookies, headers, JavaScript execution, and network requests. The platform builds an inventory of the components and external destinations present on a live site, compares observed behavior with baselines and reputation or vulnerability intelligence, and prioritizes changes such as keylogging, unauthorized tracking, PII harvesting, suspicious communications, malicious code, and other data-exposure paths. Reflectiz says the process is agentless and requires no embedded code or installation, which reduces deployment friction but also makes the quality and breadth of simulated journeys central to coverage.
The company now presents a unified platform organized around Security Hub, Privacy Hub, Offensive Hub, and a PCI Module. Security Hub targets Magecart, web-skimming, client-side supply-chain compromise, malicious scripts, and behavioral changes that occur after a page loads. Privacy Hub tests whether consent and opt-out controls are enforced in actual browser behavior, rather than merely configured in a consent-management platform. The PCI Module focuses on PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1 by maintaining payment-page script inventories, detecting unauthorized changes, and producing audit evidence. Offensive Hub extends the product toward continuous, agentic web penetration testing. These modules broaden the addressable buyer set across security, privacy, digital, marketing, compliance, and application-security teams, while creating a diligence question about product focus and the relative maturity of each module.
The commercial case is strongest in enterprises whose revenue, payments, regulated data, or brand reputation depend on complex public websites. Reflectiz identifies financial services, e-commerce, healthcare, and other global enterprises as target markets, and its public customer material references organizations including DAZN, Cox Communications, Village Roadshow, Leeds United, and lastminute.com. Those references demonstrate market validation, but they are not the same as disclosed recurring revenue, retention, deployment scale, or independent customer references; those metrics remain important diligence gaps. The company announced a Series A of more than $5 million in 2020 and currently states that it is backed by $22 million in Series B funding. Its public profiles indicate a transition from a small Israeli startup toward a 51–200-person, globally operated private company with Tel Aviv/Ramat Gan R&D, Boston commercial operations, and an ANZ presence.
Competition includes dedicated client-side security vendors such as c/side, Feroot, Source Defense, and Jscrambler, as well as adjacent website-privacy, digital-risk, continuous-penetration-testing, WAF, CDN, and broader application-security products. Reflectiz’s potential edge is the combination of remote browser observation, third- and fourth-party visibility, cross-functional risk context, and compliance evidence without a page-side agent. The trade-off is that a remote monitor must model meaningful authenticated and geographic journeys, distinguish legitimate dynamic behavior from attacks, and turn findings into prevention or remediation rather than merely producing another inventory. Larger platforms can bundle adjacent controls, while specialist competitors may offer deeper blocking, runtime enforcement, or code-level workflows.
The dual-use case is credible but should be framed as critical digital-service protection rather than battlefield technology. Government agencies, public-sector portals, financial infrastructure, healthcare systems, and defense contractors all operate public web properties whose third-party code and browser data flows can become supply-chain or privacy risks. Reflectiz can help those organizations discover and validate exposure, but the public evidence does not establish classified-system deployments, government contracts, or defense-specific certifications. Strategic relevance therefore rests on strengthening the resilience and trustworthiness of sensitive digital services, with customer authorization, data-handling controls, deployment coverage, and operational response procedures requiring verification.
Dual-Use Assessment
Reflectiz has substantive dual-use relevance because the same client-side supply-chain, malicious-script, data-exfiltration, and privacy failures affect commercial enterprises and sensitive public-sector or defense-contractor web services. The platform can improve discovery and validation of exposure on public digital services, but available public evidence does not confirm classified deployments, government contracts, or defense-specific certifications; the adjacency is cyber-resilience and digital-service protection rather than direct military capability.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Reflectiz is a credible strategic-priority signal for a dual-use cybersecurity database: it has an identified runtime-security gap, public enterprise customer evidence, a Series B financing profile, and a product architecture relevant to regulated digital services. The thesis is not risk-free. Buyers may consolidate web security into larger platforms, and the company’s expansion from client-side monitoring into privacy, PCI, and agentic testing may dilute focus. Diligence should prioritize recurring revenue, retention, gross margin, customer concentration, independent validation of the claimed coverage, and evidence that findings lead to measurable prevention or remediation.
Strategic Value to U.S.-Israel Alliance
Reflectiz can contribute to digital resilience by exposing changes and data flows in public-facing web services that are often outside traditional perimeter controls. Its agentless model may reduce deployment friction for regulated environments, while its PCI and privacy workflows connect technical findings to audit and governance processes. Strategic value is highest for organizations operating high-volume payment, citizen-service, healthcare, or other sensitive web journeys; it is lower for isolated systems without meaningful browser-facing exposure.
Key Technologies
- Remote sandbox browser simulation of authenticated and checkout journeys
- Runtime JavaScript, DOM, iframe, tag, pixel, cookie, header, and network-request observation
- First-, third-, and fourth-party web asset inventory and dependency mapping
- Behavioral baselining and anomaly detection for unauthorized script changes and data flows
- Cyber-reputation and vulnerability correlation for web components and external destinations
- Agentless PCI DSS 4.0.1 script inventory, approval, integrity monitoring, and evidence generation
- Continuous AI-assisted web penetration testing and exposure prioritization
Use Cases & Applications
- Detecting Magecart, formjacking, web skimming, and malicious checkout scripts
- Monitoring third- and fourth-party supply-chain behavior across e-commerce and payment journeys
- Validating PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1
- Testing consent, opt-out, GPC, and unauthorized PII transmission behavior for privacy teams
- Maintaining a cross-team inventory of public web assets, vendors, tags, and external destinations
- Continuous security testing of authenticated web applications and APIs
- Hardening government, critical-infrastructure, healthcare, and defense-contractor web services where authorized
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 7 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- reflectiz.com Public source used for profile verification.
- reflectiz.com Public source used for profile verification.
- reflectiz.com Public source used for profile verification.
- reflectiz.com Public source used for profile verification.
- reflectiz.com Public source used for profile verification.
- LinkedIn company page Public source used for profile verification.
- finder.startupnationcentral.org Public source used for profile verification.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.