Solvo
Last updated: Jul 31, 2026
Solvo developed an application-aware cloud security platform combining cloud security posture management, entitlement analysis, data-aware access modeling, and remediation guidance. CYE acquired the technology in January 2025 and continues to list Solvo through its AWS Marketplace channel, so this record describes an acquired asset rather than an independent startup.
Visit WebsiteCompany Overview
Solvo's core product addressed the relationship between cloud resources, applications, identities, permissions, and sensitive data. Its platform discovered cloud infrastructure and misconfigurations, mapped access paths, highlighted excessive or administrator-level permissions, and helped security and engineering teams create narrower least-privilege policies. Public technical descriptions identify a combination of CSPM and CIEM capabilities, with data posture and compliance features layered around that core. A notable technical theme was contextual analysis: instead of treating an IAM permission as risky in isolation, Solvo aimed to understand which application or machine identity used which resource and to recommend a policy matched to observed behavior. The company also described adaptive remediation and generated infrastructure-as-code or policy fixes, while research coverage cautioned that customers still retained review and deployment responsibility rather than receiving unrestricted automatic changes.
The target market was cloud-dependent organizations with security, DevOps, platform-engineering, and governance teams that needed a practical way to reduce misconfiguration and over-privilege across AWS, Azure, and Google Cloud. The product was relevant to regulated sectors such as financial services, healthcare, software, and retail because it connected technical findings to audit evidence, compliance rules, and remediation workflows. A 2023 S&P Global Market Intelligence profile reported roughly 30 employees, more than 65 customers, and approximately $11 million in venture funding at that time. Those figures are historical and should not be treated as current standalone operating metrics. The acquisition means later revenue, retention, headcount, customer concentration, and product adoption cannot be cleanly separated from CYE. Current AWS Marketplace material identifies CYE as the seller and documents a continuing commercial distribution path, but it does not disclose revenue or customer-level proof.
Solvo operated in a difficult and consolidating category. Its combination of CIEM, CSPM, data posture, runtime context, and remediation offered a sharper identity-and-configuration proposition than a single-purpose permissions tool, but the same functionality increasingly appears inside broader CNAPP and exposure-management suites. Wiz, Orca Security, Palo Alto Networks Prisma Cloud, Microsoft Defender for Cloud and Entra Permissions Management, Tenable Cloud Security, Sonrai Security, CyberArk, and native cloud-provider controls compete for overlapping budgets. Solvo's differentiation therefore depended on the quality of its application context, policy generation, integrations, cloud coverage, and ability to turn findings into safe fixes. The acquisition by CYE is consistent with this market structure: CYE gained native cloud considerations for its exposure-management platform and channel, while Solvo's technology gained access to a broader risk-prioritization environment. The key diligence question is whether CYE has preserved differentiated engineering and converted it into durable attach, retention, and expansion within Hyver.
For national-security and defense use, the capability is substantively relevant but not itself a defense-specific system. Military, intelligence, critical-infrastructure, and government organizations increasingly operate sensitive workloads in public, hybrid, or sovereign cloud environments where excessive permissions, exposed storage, and opaque machine identities can create paths to mission data. Solvo's asset inventory, attack-path context, least-privilege policying, compliance evidence, and remediation blueprints could support hardening and continuous control validation. AWS Marketplace materials reference NIST, FedRAMP, and GC Guardrails, but a marketplace listing is not evidence of authorization or deployment in those environments. The evidence does not establish classified deployment, government contracts, security authorizations, or operational defense customers. Any defense thesis should therefore be framed as security-infrastructure adjacency and integration potential, not proven defense traction.
Dual-Use Assessment
Solvo's core cloud asset, identity, entitlement, and remediation technology has substantive commercial and security-sector applicability. The same controls can reduce attack paths in defense, intelligence, critical-infrastructure, and government cloud environments, but public evidence does not confirm classified deployments, government contracts, authorizations, or defense customers. The credible claim is cloud-security adjacency with integration potential, not demonstrated defense adoption.
Strategic Fit Assessment
This is not an independent equity opportunity for the database's early-stage priority thesis: CYE acquired Solvo's technology in January 2025, and the former Solvo website now redirects to CYE. The asset remains strategically relevant for diligence on cloud-security capability, product integration, procurement, or future team spinout possibilities, but public information is insufficient to assess standalone revenue, retention, ownership economics, or current operating autonomy.
Strategic Value to U.S.-Israel Alliance
Solvo added a focused cloud-context layer to CYE's broader cyber-exposure model: inventory, permissions, application relationships, data risk, and configuration findings can make attack-path prioritization more actionable. That is strategically valuable as sensitive organizations move workloads into hybrid and multi-cloud environments. Value now depends on how completely CYE preserves and integrates the technology, its cloud-provider coverage, and whether the combined product can meet government-grade assurance and deployment requirements.
Key Technologies
- Agentless discovery of cloud resources, applications, containers, and serverless components
- Cloud Security Posture Management checks for configuration drift and policy violations
- Cloud Infrastructure Entitlement Management with graph-based identity and permission mapping
- Runtime and application-context analysis for machine-identity behavior
- Data-aware risk scoring and cloud data posture monitoring
- Least-privilege policy generation with contextual guardrails
- Compliance rules and infrastructure-as-code remediation blueprints
Use Cases & Applications
- Inventorying multi-account cloud assets and identifying exposed or misconfigured services
- Finding excessive human, workload, and third-party permissions and narrowing them to least privilege
- Mapping attack paths between applications, identities, storage, and sensitive data
- Generating reviewable policy or infrastructure fixes for security and platform-engineering teams
- Monitoring configuration drift and producing evidence for regulated-cloud audits
- Prioritizing remediation of cloud risks in financial, healthcare, software, and retail environments
- Hardening sensitive government or defense cloud workloads where cloud control validation is required
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.
This record lists 5 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- solvo.cloud Public source used for profile verification.
- aws.amazon.com Public source used for profile verification.
- solvo.cloud Public source used for profile verification.
- cyesec.com Public source used for profile verification.
- LinkedIn company page Public source used for profile verification.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Investor Lens
What this entry is
Acquired asset
Why it may matter
Solvo may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.
How an independent investor should read this
Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify technical claims
- Verify regulatory/export-control issues
Main investor questions
- Is this entry a benchmark, buyer, ecosystem node, acquired asset, or strategic reference rather than a live startup opportunity?
- What does this reference clarify about buyers, sector structure, public-market context, or strategic demand?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Solvo's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- Is the company a live venture opportunity, a mature strategic reference, an acquired asset, or primarily a market-mapping entry?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.