Votiro
Last updated: Jul 31, 2026
Votiro developed content disarm and reconstruction (CDR) and data-security technology for sanitizing files before they reach users, applications, or storage. Menlo Security acquired the operating Votiro business in February 2025 and now markets the capability as Menlo File Security.
Visit WebsiteCompany Overview
Votiro's core technology is content disarm and reconstruction (CDR), a positive-selection approach to file security. Instead of waiting for a signature, sandbox verdict, or behavioral alert, the system decomposes an incoming file, removes active or unsafe elements, and reconstructs a usable version from content treated as safe. The practical target is file-borne risk in documents, archives, email attachments, web downloads, collaboration tools, upload portals, and file-transfer workflows. Menlo currently describes the inherited technology as patented, AI-trained CDR that can process more than 220 file types, including macros, ZIP and other archives, password-protected files, CAD, video, and audio. Those capability claims are vendor-reported and should be validated in technical diligence, especially for fidelity and edge-case handling.
The corporate status is no longer ambiguous. Menlo announced the acquisition on February 19, 2025, stating that Votiro would form the data-security pillar of a broader workspace-security strategy. Votiro's domain now redirects to Menlo's file-security capabilities page, and Votiro support documentation describes a rebranded Menlo management portal. The operating asset should therefore be analyzed as part of a privately held cybersecurity vendor, not as an independent venture-backed company seeking a new financing round. Senetas's ASX disclosures also describe the sale of the Votiro operating subsidiaries to Menlo and later final consideration, providing a useful independent transaction record.
The market need is durable: organizations receive untrusted content through email, browsers, SaaS collaboration, customer portals, M&A exchanges, and partner networks, while detection-first controls can miss novel payloads or impose quarantines that disrupt operations. The commercial buyer is typically a security or infrastructure team in a document-heavy and regulated environment such as financial services, healthcare, insurance, government, manufacturing, or critical infrastructure. Menlo's current positioning emphasizes agentless or API-based deployment, protection across Teams, OneDrive, Box, SharePoint, email, web downloads, S3, and file-transfer paths, and near-real-time processing. The relevant diligence question is not whether CDR is useful in principle, but whether integrations, throughput, and reconstructed-file fidelity are good enough to win against incumbent controls.
Competitive pressure comes from specialist CDR vendors, secure email and web gateways, malware detonation, endpoint suites, and platform vendors that bundle file inspection into broader SASE, zero-trust, DLP, or collaboration-security products. Votiro's strategic advantage was the combination of broad file expertise and a workflow designed to preserve usability rather than flatten every suspicious document into a low-functionality format. Menlo adds distribution, browser-security context, and a wider workspace-security narrative, but integration can also make the former product harder to evaluate as a standalone moat. Public evidence supports product integration and a mature commercial motion; it does not establish current standalone revenue, retention, margins, government contracts, or security certifications.
The defense and national-security case is credible but bounded. Military organizations, intelligence communities, public-sector agencies, defense contractors, ports, utilities, and other critical-infrastructure operators routinely exchange files with external parties and may need to preserve document functionality while reducing the chance that hostile content reaches a trusted environment. CDR can complement email security, endpoint controls, sandboxing, segmentation, and manual review; it does not replace them, and public sources reviewed here do not prove a specific defense deployment. Strategic relevance is therefore high as a defensive cyber capability, while standalone investment relevance is low because the asset has already been acquired and its roadmap, economics, and governance sit within Menlo.
Dual-Use Assessment
Yes, with a defensive-cyber scope. File sanitization and secure ingestion apply directly to commercial collaboration, email, browser, portal, and file-transfer workflows and also to government, defense-contractor, and critical-infrastructure environments that must accept untrusted documents. The applicability is substantive because the same CDR pipeline can reduce active-content risk across both sectors, but public evidence reviewed does not verify a specific military deployment or clearance-bound use case.
Strategic Fit Assessment
The technology is a credible fit for a dual-use cyber thesis, but Votiro is not an independent startup opportunity after Menlo's acquisition of its operating business. Public sources do not establish a current standalone cap table, financing need, revenue base, or liquidity path. The appropriate internal conclusion is to preserve the record for technology and strategic mapping while setting strategically relevant to false; any future diligence would need to assess Menlo's product economics, integration success, customer retention, and whether CDR remains a differentiated platform capability.
Strategic Value to U.S.-Israel Alliance
High for defensive cyber strategy. Proactively sanitizing files at browser, email, SaaS, API, upload, and transfer boundaries addresses a recurring route for malware and data exposure while reducing dependence on post-delivery detection. The capability is relevant to regulated enterprises and defense-adjacent environments, but its value is now realized primarily through Menlo's broader platform rather than through an independent Votiro entity.
Key Technologies
- Content disarm and reconstruction (CDR)
- File sanitization and safe rebuild pipelines
- Active-content neutralization for macros, archives, and embedded objects
- Low-latency file inspection and transformation
- Multi-channel ingress protection for email, web, and collaboration tools
- Policy-based file security controls
- Telemetry and analytics for file-borne threat events
Use Cases & Applications
- Protecting inbound email attachments from document-borne malware
- Sanitizing files uploaded through managed file transfer pipelines
- Hardening SharePoint, OneDrive, Box, and Teams file workflows
- Screening web downloads before they reach endpoints
- Securing third-party vendor and customer document exchange
- Reducing risk in regulated document-heavy workflows such as claims, loans, and legal intake
- Filtering untrusted files in government, defense, and critical-infrastructure environments
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.
This record lists 5 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- menlosecurity.com Public source used for profile verification.
- menlosecurity.com Public source used for profile verification.
- support.votiro.com Public source used for profile verification.
- company-announcements.afr.com Public source used for profile verification.
- LinkedIn company page Public source used for profile verification.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Investor Lens
What this entry is
Acquired asset
Why it may matter
Votiro may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.
How an independent investor should read this
Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify technical claims
- Verify regulatory/export-control issues
Main investor questions
- Is this entry a benchmark, buyer, ecosystem node, acquired asset, or strategic reference rather than a live startup opportunity?
- What does this reference clarify about buyers, sector structure, public-market context, or strategic demand?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Votiro's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- Is the company a live venture opportunity, a mature strategic reference, an acquired asset, or primarily a market-mapping entry?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.