Dossier · Private startup · 1 independent source

Sepio

Cybersecurity Dual-Use Technology Priority Signal Founded 2016

Last updated: Jul 31, 2026

Sepio develops hardware asset-risk management and Zero Trust Hardware Access software that uses physical-layer evidence to identify connected devices, assess their risk, and enforce policy against rogue, spoofed, unmanaged, or vulnerable hardware.

Visit Website

Company Overview

Sepio's core product is a hardware asset-risk management platform organized around its patented AssetDNA technology. The company says AssetDNA identifies devices from inherent physical-layer characteristics and device existence, rather than trusting only identifiers that can be changed or spoofed, such as MAC addresses, VID/PID values, or self-reported profiles. The platform is positioned as a SaaS or on-premises system that discovers network, endpoint, peripheral, IT, OT, and IoT assets; verifies what a device is; validates its role, location, ownership, and policy fit; correlates hardware and firmware context with vulnerability intelligence; and produces a risk score that can drive alerts, restrictions, isolation, blocking, or third-party orchestration. Sepio also describes agentless discovery and a hardware bill-of-materials view for some environments, but the breadth and accuracy of coverage should be tested device class by device class.

The commercial problem is the gap between an inventory record and trustworthy device identity. Network access control, endpoint, vulnerability-management, and asset-management tools often infer identity from software-reported metadata or traffic. That can leave dormant, unmanaged, misclassified, shadow, or impersonating hardware outside effective policy. Sepio's proposed workflow is to turn this blind spot into an operational control: continuously discover assets, compare observed physical identity and context with expected policy, prioritize the risk, and send an enforcement action into existing security and IT workflows. The offering is therefore complementary to NAC, SIEM, SOAR, EDR/XDR, ITAM, and segmentation products, while also competing with their increasingly broad asset-visibility features.

The stated customer set includes financial institutions, healthcare, retail, manufacturing, critical infrastructure, government agencies, and other distributed enterprises where unauthorized peripherals or network equipment can affect security and operational continuity. Its Lenovo ThinkShield material documents an OEM-oriented route to market for workstation, endpoint, server, and USB protection. The company also publishes materials for federal asset visibility, CISA BOD 23-01 alignment, NIS2, nuclear facilities, and Army security operations centers. These are meaningful commercialization and market-positioning signals, but the public record does not independently establish revenue, retention, deployed asset volume, win rates, margins, or the scale and status of each government or OEM relationship. The November 2022 announcement of a $22 million Series B confirms institutional financing, not current financial health.

Competitive dynamics are unusually important. Armis, Forescout, Cisco, Claroty, Nozomi Networks, NAC vendors, endpoint device-control products, and exposure-management platforms all address portions of asset discovery, identity, risk prioritization, or enforcement. Sepio's claimed edge is the physical-layer signal: it may identify a device that appears legitimate in software or remains quiet on the network, and it can apply a hardware-specific trust decision before that asset becomes operationally useful to an attacker. The edge is credible as a differentiated technical thesis, but not automatically a durable moat. Buyers will require evidence that AssetDNA works across hardware revisions, adapters, firmware changes, USB classes, and noisy operational environments, while producing explainable decisions with low sensor, agent, integration, and policy-tuning burden.

The defense and national-security case is substantive but bounded. Hardware identity, rogue-device detection, supply-chain assurance, and continuous asset visibility are directly relevant to federal networks, critical infrastructure, military support systems, sensitive facilities, and high-assurance industrial environments. Sepio's own 2022 announcement says it would support CISA with hardware asset visibility and vulnerability assessment, and its later public materials extend the thesis to federal, nuclear, and Army use cases. Those sources support government relevance and a dual-use cybersecurity thesis; they do not prove broad military deployment, classified adoption, or mission-critical performance. The strongest strategic interpretation is a dual-use hardware-trust control that can be sold in commercial markets while addressing a real weakness in zero-trust and supply-chain cyber-resilience programs.

Dual-Use Assessment

Military & Commercial Applications

Sepio's physical-layer hardware identity and rogue-device controls have substantive commercial applicability across enterprise IT, OT, IoT, healthcare, retail, and USB security and a credible defense adjacency in federal networks, critical infrastructure, supply-chain assurance, and high-assurance facilities. Public sources support government-market relevance, including a company-announced CISA support engagement, but do not establish broad military deployment or classified use.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Sepio is a credible strategic-priority signal for a dual-use cybersecurity database because it addresses a specific physical-layer blind spot, has a differentiated technical thesis, reports a $22 million Series B, and shows public enterprise, OEM, and federal-market activity. This flag is not an investment recommendation. Diligence should focus on recurring revenue, retention, deployment scale, gross margin, independent efficacy testing, false-positive rates, customer dependence on integrations or channel partners, and whether incumbent platforms can reproduce the core workflow.

Strategic Value to U.S.-Israel Alliance

Sepio can improve the trustworthiness of asset inventories and access decisions where software identifiers, network traffic, or endpoint coverage are incomplete. That capability is strategically relevant to zero-trust implementation, critical-infrastructure resilience, federal asset visibility, hardware supply-chain assurance, USB and peripheral defense, and defense-adjacent network protection. Its value is highest when physical-layer evidence changes a real access or remediation decision, rather than merely adding another dashboard to an existing security stack.

Key Technologies

  • Physical-layer metadata and hardware identity analysis
  • Patented AssetDNA device fingerprinting
  • Agentless continuous discovery of network, endpoint, USB, IT, OT, and IoT assets
  • Hardware and firmware vulnerability intelligence with contextual risk scoring
  • Detection of rogue, spoofed, dormant, shadow, and unmanaged devices
  • Policy-driven hardware access control, isolation, blocking, and remediation
  • Integrations with NAC, SIEM, SOAR, EDR/XDR, ITAM, and OEM security workflows

Use Cases & Applications

  • Zero Trust Hardware Access for enterprise endpoints, servers, and network equipment
  • USB allow-listing and mitigation of rogue or malicious peripherals
  • Discovery and risk prioritization for shadow IT and unmanaged assets
  • IT, OT, and IoT inventory validation in manufacturing and critical infrastructure
  • Hardware bill-of-materials and supply-chain assurance for sensitive environments
  • Federal asset visibility and vulnerability assessment aligned with CISA guidance
  • Security hardening for healthcare, retail, and distributed branch environments
  • Hardware-layer protection for defense-adjacent networks and high-assurance facilities

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 12 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.