Dossier · Acquired asset · 4 independent sources

Secure Islands

Cybersecurity Acquired asset Dual-Use Technology Founded 2006

Last updated: Jul 31, 2026

Secure Islands Technologies was an Israeli information-protection company whose IQProtector platform classified and protected unstructured data at creation or first access. Microsoft acquired the company in 2015 and integrated its technology into Azure Information Protection, the lineage that later became Microsoft Purview Information Protection.

Company Overview

Secure Islands developed IQProtector around a persistent data-protection model: inspect files and email as they are created or enter an organization, classify them using content and context, and attach policy-driven labels, metadata, encryption, and usage rights. The product was aimed at unstructured information rather than only network traffic or a fixed repository. Historical product material describes support for many file types, content and pattern rules, identity and location context, SharePoint interception, mobile access, auditing, and integration with Microsoft Rights Management. The important architectural idea was to make protection travel with the information instead of relying solely on perimeter controls or a later DLP decision at an egress point.

The commercial problem was significant but difficult: enterprises need to share documents and messages with employees, partners, and customers while retaining control after data leaves a primary network. Classification quality, policy administration, identity assurance, application support, and user experience all determine whether persistent protection works in practice. Secure Islands sold into regulated and information-intensive sectors, and Microsoft stated at the acquisition announcement that customers including UBS, OSRAM, Vodafone, and Credit Suisse used the technology. Those customer references are evidence of commercial traction at the time, but they do not establish current standalone revenue, retention, or independent operations.

Microsoft announced an agreement to acquire Secure Islands in November 2015 and reported completion in December 2015. Microsoft said the technology would be integrated with Azure Rights Management and used to extend protection across on-premises systems, Microsoft cloud services, third-party services, and devices. Current Microsoft documentation describes the successor information-protection capability as a framework for discovering, classifying, labeling, encrypting, and governing sensitive data across Microsoft 365, Azure, on-premises file shares, endpoints, and non-Microsoft cloud applications. This is strong evidence that the product concepts were commercially validated and absorbed into a large platform, but it is not evidence that Secure Islands remains a separate strategically relevant company.

The dual-use case is credible at the capability level. Persistent classification, encryption, access control, and auditability are relevant to defense contractors handling controlled unclassified information, government agencies protecting sensitive records, and organizations compartmentalizing operational or intelligence data. The technology does not itself provide a military sensor, cyber-operations capability, or classified accreditation; defense suitability would depend on deployment architecture, approved cryptography, identity controls, disconnected or sovereign environments, classification taxonomies, and authorization by the relevant customer. Its strategic significance for this database is therefore as an acquired Israeli data-security capability and an example of information-centric protection, not as a current defense supplier.

Dual-Use Assessment

Military & Commercial Applications

The core capability has substantive commercial and security applications: policy-driven classification, persistent encryption, rights management, and auditing can protect sensitive defense-contractor and government information as well as enterprise data. The defense relevance is capability-level rather than proof of classified deployment; no current defense contract, accreditation, or military customer is asserted here.

Strategic Fit Assessment

Secure Islands should not be treated as a current investment priority because Microsoft completed its acquisition in 2015 and the standalone company is no longer evidenced as operating independently. The acquisition is nevertheless a useful strategic diligence case: it shows that automated classification combined with persistent rights management addressed a platform-level enterprise security need. Any current thesis would need to evaluate Microsoft Purview or successor startups rather than Secure Islands equity, and would require fresh evidence on product differentiation, deployment constraints, and defense authorization.

Strategic Value to U.S.-Israel Alliance

The lasting strategic value is information-centric protection: controls can remain attached to sensitive content as it moves between repositories, users, and services. That model is relevant to national-security organizations that must reduce accidental disclosure and enforce need-to-know handling, but it is only one layer of a secure system. Identity compromise, authorized-user misuse, endpoint compromise, unsupported applications, key-management failures, and policy errors can still expose plaintext. Secure Islands therefore matters as a proven technology lineage and acquisition precedent, not as a standalone strategic supplier.

Key Technologies

  • Content- and context-aware classification of unstructured data
  • Policy-driven sensitivity labeling and metadata tagging
  • Persistent file and email encryption with usage rights
  • Microsoft Rights Management integration
  • SharePoint, endpoint, mobile, and cloud interception workflows
  • Pattern, phrase, and regular-expression inspection
  • Centralized auditing and access reporting

Use Cases & Applications

  • Automatic classification of enterprise documents and email
  • Persistent protection for files shared across organizations
  • SharePoint and collaboration-repository data interception
  • Regulatory and privacy data handling
  • Defense-contractor CUI labeling and access control
  • Government information compartmentalization
  • Audit trails for sensitive-data access and policy enforcement

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Open-web verification is limited. Readers should confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 5 public references used for company identity, status, positioning, or material-claim review.

Verification note: public information is limited; this entry is retained for ecosystem-mapping purposes and should not be relied on without further confirmation.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.