Dossier · Acquired asset · 1 independent source
TrapX Security
Last updated: Jul 31, 2026
TrapX Security developed DeceptionGrid, a cyber-deception platform that used realistic decoys, threat sensors, and lures to expose reconnaissance, credential abuse, lateral movement, and malware activity. Commvault acquired TrapX in 2022 and incorporated the technology into its ThreatWise cyber-resilience offering, so this record represents an acquired security asset rather than an independent current startup.
Visit WebsiteCompany Overview
TrapX built a commercial cyber-deception system around the idea that an interaction with a carefully placed false asset is a much stronger detection signal than a generic anomaly. Its DeceptionGrid product used decoys, emulated services, credentials, and other deceptive resources to make production environments appear larger and more realistic to an intruder. A touch, login attempt, scan, or lateral-movement action against one of those assets could generate a high-confidence alert and provide evidence about the attacker’s path and techniques. This is complementary to endpoint, network, identity, SIEM, and recovery controls; it is not a replacement for them.
The target market was security-conscious enterprise and public-sector organizations that needed earlier warning of stealthy intrusions, insider activity, advanced persistent threats, or ransomware staging. The practical value proposition was operational: deception can reduce alert fatigue because legitimate users should not normally access the decoys, while centralized orchestration reduces the labor required to deploy and maintain a distributed deceptive environment. The public record supports capabilities such as lightweight threat sensors, adaptive or preconfigured asset emulation, lures or honeytokens, and integrations with security workflows. It does not, by itself, establish a particular customer list, revenue level, deployment scale, or government contract.
Commvault’s acquisition provides the clearest commercialization signal and the most important current-status fact. Commvault disclosed that it completed the acquisition of 100% of TrapX on January 31, 2022, and its public product material says the acquired technology became part of ThreatWise. Current ThreatWise pages describe decoys that mimic IT, OT, network, and backup assets, with early-warning detection for reconnaissance, lateral movement, ransomware, exfiltration, and unwanted privileged access. This demonstrates continuing productization inside a larger cyber-resilience platform, but it should not be read as evidence that TrapX remains a separately strategically relevant company or that every current ThreatWise feature was developed by the former TrapX team.
The competitive field includes deception specialists such as Attivo Networks, Illusive Networks, Acalvio, CounterCraft, and Thinkst, as well as broader security platforms that can provide honeypots, canary files, identity deception, or behavioral detection. TrapX’s historical edge was the combination of high-fidelity decoys, automated deployment, and threat intelligence in a single deception-oriented system. Its later strategic value came from pairing early detection and attacker diversion with Commvault’s data-protection and recovery workflows. The limitation is that deception is a specialist control: buyers must maintain believable assets, place them where attackers will encounter them, and connect alerts to a response process.
For defense and national-security users, the dual-use case is credible but defensive. Deceptive hosts, credentials, services, and network paths can help protect mission systems, sensitive enterprise networks, critical infrastructure, and operational technology while revealing attacker tradecraft. They can also support threat hunting and purple-team validation. However, public sources do not establish classified deployments or military contracts, and government adoption would require careful authorization, segmentation, data handling, and rules-of-engagement review. The record therefore treats TrapX as strategically relevant acquired cyber-defense IP, with evidence of ongoing commercial integration but limited public evidence about the former standalone company’s present workforce or independent economics.
Dual-Use Assessment
The core deception technology has substantive commercial and defense applicability: it can detect and divert intruders in enterprise, cloud, backup, OT, and government networks while producing telemetry for investigation. The defensive use case is credible, but public sources do not confirm classified or military deployments; the strongest evidence is Commvault's continued commercial ThreatWise productization.
Strategic Fit Assessment
TrapX is not a current standalone investment or priority signal because Commvault acquired 100% of the company in 2022 and integrated the technology into ThreatWise. Its diligence value is strategic and comparative: the transaction and continuing product presence show that cyber deception can be valuable inside a broader cyber-resilience platform, while the public record does not support treating the former company as an independent financing opportunity.
Strategic Value to U.S.-Israel Alliance
High as acquired cyber-defense IP, but not as an independent company. Deception can provide unusually precise early-warning telemetry against stealthy intrusion and ransomware activity, and integration with data protection links detection to containment and recovery. The asset is relevant to sensitive enterprise, government, OT, and backup environments, although its strategic value depends on believable decoys, safe deployment, useful integrations, and Commvault's ongoing roadmap support.
Key Technologies
- Cyber-deception orchestration
- High-fidelity IT, OT, network, and backup asset emulation
- Threat sensors and adaptive decoys
- Honeytokens, lures, and deceptive credentials
- Attacker interaction telemetry and lateral-movement detection
- Security-operations and incident-response integrations
Use Cases & Applications
- Early warning of ransomware staging before encryption
- Detection of reconnaissance, credential abuse, and lateral movement
- Protection of high-value enterprise and backup environments
- Threat hunting and forensic reconstruction of attacker paths
- Deception layers for OT and critical-infrastructure networks
- Purple-team validation of monitoring and response controls
- Defensive monitoring of government and mission-sensitive networks
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 5 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- Commvault ThreatWise product page Public source used for profile verification.
- Welcoming TrapX to the Commvault Family Public source used for profile verification.
- Commvault cyber deception overview Public source used for profile verification.
- Commvault FY2022 annual report Public source used for profile verification.
- TrapX Security company profile Public source used for profile verification.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.