Dossier · Acquired asset · 4 independent sources

Rezilion

Cybersecurity Acquired asset Dual-Use Technology Founded 2018

Last updated: Jul 31, 2026

Rezilion developed runtime-aware software supply-chain security technology that mapped software components to vulnerabilities, filtered findings by execution context, and automated remediation workflows across cloud, on-premises, container, and IoT environments. Its software assets were acquired by Rezolve AI in May 2024, so this record represents an acquired technology asset rather than an active independent startup.

Company Overview

Rezilion was founded in 2018 and built a DevSecOps platform around a Dynamic Software Bill of Materials (SBOM). Its product combined software-component discovery with runtime analysis: rather than treating every vulnerable package version reported by a scanner as equally urgent, it attempted to determine whether the relevant component was present, loaded, and exposed in an operating environment. Public product material described coverage across development and production, cloud and on-premises infrastructure, hosts, containers, applications, and IoT devices. It also described aggregation of scanner results, grouping vulnerabilities into fewer component-level remediation actions, and exporting SBOM or vulnerability-exchange data.

The underlying customer problem is substantial. Security teams routinely face more CVEs than engineering teams can patch, and static package inventories do not show whether vulnerable code is actually executed. A runtime-aware layer can reduce investigation effort, improve prioritization, and connect security findings to tickets or CI/CD remediation. AWS Marketplace materials described SaaS delivery, AWS integrations including EC2 and EKS, and a product claim of filtering out as much as 85% of identified vulnerabilities; that is a vendor or marketplace claim, not independently verified performance. The marketplace listing and 2022 product announcements are useful evidence that the product was commercialized, but they do not establish current availability, recurring revenue, retention, or post-acquisition support.

The technology competed with several overlapping categories rather than a single direct substitute. Tenable, Qualys, Rapid7, Snyk, JFrog, Aqua Security, Wiz, and Vulcan Cyber could address portions of vulnerability management, software composition analysis, cloud security, or remediation orchestration. Rezilion's strongest differentiation was the attempt to turn runtime evidence into fewer, more actionable remediation decisions, especially in heterogeneous estates where static scanner output creates operational overload. Durability depended on broad deployment coverage, low agent or permission friction, accurate reachability analysis, integrations with incumbent scanners and ticketing systems, and proof that customers saved measurable engineering time. Consolidation by larger security platforms remained a structural competitive threat.

The strategic outcome is now clearer than the former startup record suggested. Rezolve AI disclosed that it completed an asset acquisition of Rezilion Inc. and Rezilion Ltd. on May 23, 2024 for approximately $7.3 million in cash, primarily acquiring software intellectual property. That supports treating Rezilion as an acquired asset and prevents current startup metrics from being presented as active-company facts. The acquired capability still has national-security relevance: defense contractors, government operators, critical-infrastructure owners, and connected-device programs all face software inventories and patch queues that are difficult to manage. However, public evidence does not demonstrate classified, disconnected, or government deployments, and the old corporate website now redirects to an unrelated destination. Diligence should focus on whether Rezolve retained, integrated, commercialized, or retired the technology; the state of the code and customer contracts; vulnerability-validation accuracy; offline deployment; data handling; and any continuing support obligations.

Dual-Use Assessment

Military & Commercial Applications

The acquired runtime inventory, vulnerability-validation, and remediation-orchestration capabilities have substantive commercial and security applicability. They could help defense contractors, government operators, critical-infrastructure owners, and connected-device programs prioritize exploitable software exposure, but public evidence does not confirm defense customers, classified use, government contracts, or deployment in disconnected environments; the dual-use case is capability-based rather than deployment-proven.

Strategic Fit Assessment

The technology addressed a real enterprise security bottleneck and had credible commercialization signals, including a Series A, AWS Marketplace presence, and product claims centered on runtime-aware vulnerability reduction. It is not an strategically relevant independent startup record today: Rezolve AI disclosed a 2024 asset acquisition, and the former website now redirects away from Rezilion. The relevant diligence question is strategic asset performance rather than venture financing. Reviewers should verify whether Rezolve retained and commercialized the software, what intellectual property and customer obligations transferred, and whether the capability complements or duplicates Rezolve's current portfolio. This is an internal research assessment, not an investment recommendation.

Strategic Value to U.S.-Israel Alliance

The acquired technology may have strategic value as a software-supply-chain visibility and prioritization layer for large, heterogeneous, or difficult-to-patch estates. Runtime evidence is relevant to defense and critical infrastructure because it may separate theoretical package exposure from code that is actually loaded and reachable, helping scarce security personnel focus on material risk. The strongest fit would be secure development, fleet vulnerability management, and connected-device programs. Current value is unproven until Rezolve's product strategy, integration work, support status, offline deployment, data handling, assurance evidence, and customer references are established.

Key Technologies

  • Dynamic software bill of materials generation
  • Runtime execution and reachability analysis
  • Vulnerability-to-component correlation across environments
  • Cloud, host, container, and IoT software inventory
  • Scanner aggregation and risk-based prioritization
  • Automated remediation planning and CI/CD ticketing
  • CycloneDX and VEX-oriented software supply-chain reporting

Use Cases & Applications

  • Prioritizing enterprise CVE backlogs using runtime evidence
  • Continuous software inventory across cloud and on-premises hosts
  • Container and Kubernetes vulnerability triage
  • Software supply-chain risk review for products shipped to customers
  • IoT and connected-device component exposure assessment
  • Defense-industrial and critical-infrastructure patch prioritization
  • Automated remediation workflows for DevSecOps teams

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Open-web verification is limited. Readers should confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 5 public references used for company identity, status, positioning, or material-claim review.

Verification note: public information is limited; this entry is retained for ecosystem-mapping purposes and should not be relied on without further confirmation.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

  • Rezilion LinkedIn company profile Company profile identifies the historical official website, 2018 founding year, Be'er Sheva headquarters, and 51-200 employees.
  • AWS Marketplace: Rezilion Marketplace listing describes Dynamic SBOM, runtime exploitability filtering, cloud and on-premises coverage, and remediation workflows.
  • Rezilion Dynamic SBOM announcement 2022 company announcement describes the Dynamic SBOM, runtime execution context, and development-to-production coverage.
  • Calcalist Tech Series A coverage 2021 report states that Rezilion raised a $30 million Series A and had raised $38 million in total; this is historical financing evidence, not current capitalization.
  • Rezolve AI SEC filing, Note 6 Acquisitions Rezolve AI disclosed that on May 23, 2024 it acquired certain assets, primarily software intellectual property, of Rezilion Inc. and Rezilion Ltd. for approximately $7.3 million in cash.
  • Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.