Torii

Cybersecurity Dual-Use Technology Priority Signal Founded 2017

Last updated: Jul 31, 2026

Torii is a SaaS Management Platform that gives IT, finance, and security teams visibility and control over enterprise software, including discovery, shadow-IT detection, spend and renewal governance, access reviews, and employee lifecycle automation.

Visit Website

Company Overview

Torii provides a discovery-first SaaS Management Platform for organizations whose software stack has outgrown manual spreadsheets, procurement records, and identity-provider reports. Its product connects to business systems, finance data, single sign-on sources, browser signals, and other integrations to build an inventory of applications and their usage. The platform then turns that inventory into operational workflows: teams can identify shadow IT, review access, reclaim unused licenses, automate joiner-mover-leaver tasks, manage renewals, and coordinate application ownership. Torii's current product direction also includes visibility and governance for AI tools, non-human identities, and agentic software, extending the same control problem beyond conventional SaaS.

The primary buyers are enterprise IT, SaaS operations, security, procurement, finance, and business-system owners. The commercial problem is concrete: employees adopt applications faster than central teams can approve, secure, budget, and retire them; duplicate subscriptions and unused seats create avoidable spend; and incomplete ownership information makes offboarding and access reviews unreliable. Torii positions one shared system of record as a way to reduce those costs while improving accountability. Its public product materials describe more than 180 integrations, a no-code workflow canvas, renewal alerts, license and usage data, access-review support, and AI-assisted research. The company also publishes customer examples and an ROI claim of average SaaS-spend reductions above 25%; those are company-reported marketing signals rather than independently audited operating metrics.

Torii competes in a crowded SaaS-management category against BetterCloud, Zylo, Zluri, Productiv, Vendr, Flexera, Spendflo, and newer security-oriented tools such as Nudge Security. Adjacent substitutes include identity-governance suites, IT service-management platforms, software-asset-management products, procurement systems, and internally assembled integrations. The differentiation thesis is breadth plus actionability: Torii combines discovery, usage and spend context, access governance, renewal management, and lifecycle automation instead of treating SaaS inventory as a static report. That approach can improve time-to-value and reduce tool switching, but it also creates a demanding integration-maintenance burden and puts the company in direct competition with larger platforms that can bundle related capabilities.

Public evidence supports an established private growth company rather than an early prototype. Torii was founded in 2017, reported a $10 million Series A in 2021, and was reported by Calcalist in 2022 to have raised a $50 million Series B and approximately $65 million in total funding at that time. Its official site currently presents an enterprise product, a global customer and partner motion, a leadership team spanning product, engineering, sales, marketing, and finance, and security claims including SOC 2 Type II, GDPR compliance, encryption, SSO/MFA support, and annual penetration testing. Current employee-count data is inconsistent across public directories, so a 51–200 range is more defensible than the previous 201–500 estimate.

The national-security relevance is real but indirect. Torii does not appear to sell weapons, sensors, classified-data systems, or mission software. Its potential value to defense contractors, government technology suppliers, and critical-infrastructure operators comes from controlling the commercial software dependencies that support their work: shadow-IT detection, vendor and application inventory, least-privilege reviews, offboarding, audit trails, renewal control, and oversight of unapproved AI tools. Those controls can reduce attack surface and supply-chain uncertainty, but deployment in sensitive environments would require diligence on data residency, tenant isolation, government authorization requirements, classified-work separation, integration permissions, and the evidentiary quality of its audit outputs. The dual-use case should therefore be treated as cybersecurity and operational-resilience adjacency, not as evidence of existing defense contracts.

Dual-Use Assessment

Military & Commercial Applications

Torii has credible but indirect dual-use potential. Its core platform governs SaaS discovery, access, software ownership, lifecycle events, vendor dependencies, renewals, and shadow AI. Those capabilities are commercially useful and can support defense contractors, government technology suppliers, and critical-infrastructure operators that need stronger software supply-chain visibility and offboarding controls. The record should not imply that Torii has classified deployments, government contracts, or authorization for sensitive environments; the main diligence questions are data residency, tenant isolation, integration permissions, audit evidence, and separation between enterprise SaaS governance and classified systems.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Torii is a credible strategic-screening signal for a dual-use and cybersecurity-oriented database, but the case is growth-stage enterprise software rather than frontier deep technology. It addresses persistent SaaS sprawl, shadow IT, license waste, renewal leakage, and access-governance problems with a platform that can sit across IT, finance, procurement, and security workflows. The Series B history, enterprise positioning, current product breadth, and public security posture support meaningful commercialization maturity. Its strategic upside is strongest where software inventory and access control are becoming board-level or supply-chain concerns, including regulated industries and defense-adjacent suppliers. Diligence should test recurring revenue quality, retention, integration depth, sales efficiency, competitive win rates, and whether AI-management features produce durable differentiation. This is an internal priority signal, not an investment recommendation.

Strategic Value to U.S.-Israel Alliance

Torii can provide strategic value as a control plane for the commercial software layer surrounding modern organizations. Its discovery and ownership data can help security teams see applications that identity systems and procurement records miss; its workflows can connect that visibility to access removal, license reclamation, renewal decisions, and audit preparation. For defense and critical-infrastructure ecosystems, that supports resilience and third-party risk reduction at contractor and corporate IT layers, even though it does not replace classified-network controls, endpoint security, identity infrastructure, or formal authorization regimes. The company is strategically relevant to Israeli and allied cyber ecosystems because it combines Israeli-founded engineering leadership with a North American enterprise go-to-market presence, but this relevance should not be confused with government adoption or defense-specific product validation.

Key Technologies

  • SaaS application discovery using identity, finance, browser, and usage signals
  • Application inventory and ownership mapping
  • Shadow IT and shadow AI detection
  • Identity and access governance with access reviews
  • No-code lifecycle and joiner-mover-leaver workflow automation
  • License, spend, contract, and renewal analytics
  • AI-assisted application research and agentic governance

Use Cases & Applications

  • Discovering unmanaged SaaS and AI applications across an enterprise
  • Reclaiming unused licenses and consolidating duplicate subscriptions
  • Automating employee onboarding, role changes, and offboarding
  • Running auditable access reviews and identifying risky application access
  • Preparing renewal decisions with usage, ownership, and contract context
  • Monitoring third-party software dependencies for regulated or security-sensitive teams
  • Improving software inventory and offboarding discipline at defense contractors and critical-infrastructure suppliers

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.

This record lists 6 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

  • toriihq.com Public source used for profile verification.
  • toriihq.com Public source used for profile verification.
  • toriihq.com Public source used for profile verification.
  • calcalistech.com Public source used for profile verification.
  • calcalistech.com Public source used for profile verification.
  • LinkedIn company page Public source used for profile verification.
  • Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.

Investor Lens

What this entry is

Private startup

Why it may matter

Torii may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify traction
  • Verify cap table/funding
  • Verify technical claims
  • Verify regulatory/export-control issues
  • Verify customer concentration

Main investor questions

  • Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
  • What customer, revenue, product, and technical evidence supports the company story?
  • What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies Torii's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.