Sternum
Last updated: Jul 31, 2026
Sternum is an Israeli embedded-security and IoT observability company that embeds runtime protection and telemetry into connected-device firmware. Its platform is aimed at device manufacturers that need to prevent code and memory manipulation, investigate field behavior, and operate fleets that are difficult to patch or monitor remotely.
Visit WebsiteCompany Overview
Sternum provides an embedded software platform for security and observability across connected devices. Its public product material describes two closely linked capabilities: EIV runtime protection, which is embedded into firmware to prevent code and memory manipulation, and an observability platform that collects device-level events, logs, performance data, and security alerts. The company describes a binary-instrumentation and C-based integration model that can run across embedded Linux and several real-time operating systems, including FreeRTOS, Zephyr, Micrium, and OpenWrt. Its self-led demo states that the platform operates at bytecode level and advertises 1-3% overhead; those are company claims that should be validated on the target device, compiler, workload, and enabled feature set.
The commercial problem is real: embedded devices often become operational black boxes after shipment, while firmware updates can be slow, risky, or unavailable. Sternum's positioning combines product-security engineering with fleet operations. A manufacturer can use runtime telemetry to investigate crashes, connectivity, resource utilization, and user activity, while using the same embedded presence to detect and block exploitation attempts. Official material describes tracing for CPU and memory use, temperature, battery, network and Bluetooth activity, plus alert timelines and contextual forensic data. This is relevant to medical equipment, industrial systems, communications hardware, EV charging, and other products where an incident can create safety, uptime, warranty, regulatory, or reputational costs.
There are public commercialization signals, but they are not a substitute for private diligence. Sternum's site presents references or testimonials associated with Medtronic, NXP Semiconductors, Telit, and other device companies, and its public content describes a customer case in which granular Bluetooth monitoring helped reduce recurring issues. Startup Nation Central and LinkedIn list Sternum as founded in 2018 and privately held; LinkedIn identifies a Series B round in 2021 and currently displays an 11-50 employee range. That current employee range is more conservative than older directory snapshots and is the better database value until independently confirmed. The public record does not establish current ARR, net retention, deployment count, gross margin, or whether named relationships are paid production deployments, pilots, integrations, or historical references.
The competitive set spans several layers rather than one identical product category. Armis, Forescout, Claroty, and Microsoft Defender for IoT provide broader device, OT, or network security platforms; JFrog's Vdoo lineage, Karamba Security, and Exein are closer embedded-product-security comparisons; and OEMs can combine secure-boot, static-analysis, EDR-like agents, cloud monitoring, and internal controls. Sternum's potential differentiation is the combination of on-device prevention, low-footprint instrumentation, and operational observability for constrained systems. That advantage is strongest when a buyer needs protection during execution and useful field telemetry, not merely a vulnerability report or network inventory. It is also a demanding position: every unsupported architecture, false positive, performance regression, or unsafe containment decision can undermine trust.
The dual-use case is credible but should remain bounded. The technology could protect defense-adjacent sensors, radios, gateways, industrial controllers, and mission-support equipment that share the patching and visibility constraints of commercial IoT. It may contribute to resilience against exploitation of deployed edge devices and to incident investigation at remote sites. Nothing in the reviewed public material proves defense procurement, classified deployment, or a government contract, so the strategic thesis is based on technical adjacency and critical-infrastructure applicability rather than demonstrated military traction. A strategic diligence process should test secure development practices, supply-chain controls, update and rollback behavior, isolation of cloud telemetry, export or data-residency constraints, and performance on representative target hardware.
Dual-Use Assessment
Sternum's core runtime protection and device telemetry have substantive commercial applicability and credible defense and critical-infrastructure adjacency because remote embedded systems can be difficult to patch, inspect, or defend from the network alone. The reviewed public sources do not prove defense contracts or operational military deployment, so the dual-use conclusion is technical and market-based rather than evidence of government traction.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Sternum fits a dual-use deep-tech thesis because it addresses a persistent embedded attack surface with software that can become part of firmware build, validation, and fleet operations. The priority signal is supported by a productized platform, public enterprise references, and a Series B history, but it is not an investment recommendation. Key diligence gaps are current revenue quality, production deployment depth, retention, architecture coverage, integration effort, and independently validated security and overhead claims.
Strategic Value to U.S.-Israel Alliance
The strategic value is the placement of a security and visibility control inside the device runtime, where a network-only product may arrive too late and where post-deployment patching may be constrained. For critical or remote equipment, prevention plus forensic telemetry can improve resilience and shorten diagnosis. The value depends on safe containment, trustworthy updates, manageable data flows, and proof that the instrumentation works across the buyer's actual silicon, operating system, and supply chain.
Key Technologies
- Binary-instrumented firmware integration
- Embedded Integrity Verification (EIV) runtime protection
- On-device code and memory manipulation prevention
- Low-footprint C SDK for RTOS and embedded Linux
- Device and fleet telemetry with remote debugging
- Behavioral anomaly detection and alert triage
- Runtime attack forensics with event timelines
Use Cases & Applications
- Blocking memory-corruption and code-manipulation exploits in shipped IoT products
- Investigating crashes, Bluetooth or network faults, and resource behavior in remote fleets
- Monitoring medical-device and regulated-equipment firmware in the field
- Protecting industrial controllers, gateways, and energy or utility endpoints
- Adding runtime controls to legacy devices that cannot be fully redesigned
- Supporting EV-charging and other connected infrastructure product security
- Hardening defense-adjacent sensors, radios, and mission-support edge devices
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.
This record lists 6 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- sternumiot.com Public source used for profile verification.
- content.sternumiot.com Public source used for profile verification.
- sternumiot.com Public source used for profile verification.
- LinkedIn company page Public source used for profile verification.
- finder.startupnationcentral.org Public source used for profile verification.
- Official website
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Investor Lens
What this entry is
Private startup
Why it may matter
Sternum may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.
How an independent investor should read this
Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify traction
- Verify cap table/funding
- Verify technical claims
- Verify regulatory/export-control issues
- Verify customer concentration
Main investor questions
- Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
- What customer, revenue, product, and technical evidence supports the company story?
- What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Sternum's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.