Claroty

United States · claroty.com · 41 vendors

Claroty provides a cyber-physical systems (CPS) protection platform designed to secure mission-critical infrastructure across industrial, healthcare, public sector, and commercial environments. The platform offers deep asset visibility, exposure management, network protection, secure access, and threat detection for the Extended Internet of Things (XIoT).

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 41 sub-vendors.

Insights

Last updated 2026-05-05 · revision 6

41 direct vendors, 336 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 10/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Claroty exhibits very high migration readiness, primarily driven by its highly modern and cloud-native internal tech stack. The use of Amazon Web Services (AWS), Kubernetes, Docker, and a SaaS-based multi-tenant cloud architecture signifies an infrastructure built for portability, scalability, and ease of transition. This architecture minimizes technical debt and facilitates seamless migration to new environments or platforms. The platform's reliance on REST APIs for integration further enhances its flexibility and reduces complexity during migration efforts. Claroty's strong regulatory compliance posture, including GDPR, HIPAA, SOC 2 Type 2, and ISO 27001:2022 certifications, means that robust processes and controls for data handling and security are already in place. This is crucial for maintaining compliance during and after any migration, especially given their management of data residency requirements across multiple regions. Financially, consistent revenue growth provides the necessary resources to fund and execute migration projects without significant strain. Regarding vendor lock-in, the ambiguity of 'Total Vendors: 0' versus 'Total Services: 65' is noted. However, the cloud-native, containerized architecture inherently reduces reliance on proprietary, on-premises solutions that typically lead to high vendor lock-in. The geographic diversity of vendor countries (6 unique) for the 65 services also suggests a flexible approach to sourcing rather than heavy concentration with a few vendors. The absence of reported 'vendor lock-in risk' further supports a low-lock-in environment. While managing data residency requirements can add complexity, Claroty's existing expertise in this area mitigates it as a significant challenge.

Compliance

5 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Compliant

Claroty has achieved ISO 27001:2022 certification, demonstrating implementation of comprehensive information security management systems (ISMS). This certification ensures confidentiality, integrity, and availability of information through risk-based controls and continual improvement. Risk is low due to current certification status and documented commitment to information security best practices.

Evidence: https://claroty.com/trust

SOC 2 (source) — Compliant

Claroty has achieved SOC 2 Type 2 certification, which validates their ongoing commitment to managing data securely across security, availability, processing integrity, confidentiality, and privacy. As a cloud-based cybersecurity service provider, SOC 2 compliance is critical for customer trust and demonstrates robust operational controls. Risk is low due to active certification status.

Evidence: https://claroty.com/trust

ISAE 3000 (source) — Assessment Required

While Claroty has SOC 2 Type 2 certification which involves assurance reporting, specific ISAE 3000 compliance is not explicitly documented. As a cybersecurity service provider that may provide assurance services to clients, ISAE 3000 could be relevant but requires further assessment. Risk is medium due to uncertainty about specific ISAE 3000 requirements and applicability to their business model.

Evidence: https://claroty.com/trust

Financials

Three-year financials

Financial Resilience Score: 7/10

Claroty is a privately held cybersecurity company with no audited financial disclosures, but available indicators suggest strong financial resilience on the funding and customer side. The company recently closed a $150M Series F round in January 2026 led by Golub Growth, with up to $50M additional from existing investors, at a valuation 80% higher than its March 2024 round. Cumulative equity capital raised exceeds $735M across Series A through F, providing substantial runway. The investor base includes top-tier VCs (Bessemer, SoftBank Vision Fund 2, Team8, Innovation Endeavors) and strategic industrial partners (Rockwell Automation, Schneider Electric, Siemens) that double as commercial channels. The company demonstrates strong commercial traction, serving 24 of the Fortune 100 and recognized as a Leader in Gartner Magic Quadrant for CPS Protection Platforms (2025, 2026), Forrester Wave for IoT Security (Q3 2025), and Best in KLAS for Healthcare IoT Security for five consecutive years. ARR reportedly crossed ~$100M by end-2021 with triple-digit YoY growth claims thereafter. The recurring subscription model (xDome) supports predictable revenue. Key concerns include lack of audited financials, unconfirmed profitability (the Series F suggests continued growth-stage burn), deferred IPO timing, intense competition from Nozomi, Dragos, Armis, Microsoft, Palo Alto, and Cisco, and geopolitical concentration of R&D in Israel. Overall the funding cushion and customer quality offset disclosure opacity.

Key strengths: $150M Series F raised January 2026 led by Golub Growth, Up to $50M additional from existing investors at Series F, 80% valuation increase vs. March 2024 round, >$735M cumulative equity capital raised across Series A-F, 24 of Fortune 100 as customers, Top-tier investor base including Bessemer, SoftBank, Team8, Strategic industrial investors: Rockwell, Schneider, Siemens, Leader in Gartner Magic Quadrant for CPS Protection 2025/2026, Best in KLAS Healthcare IoT Security 5 years running, Recurring subscription SaaS revenue model, Regulatory tailwinds (NIS2, CISA, UK Cyber Resilience Bill)

Risk factors: No audited financial statements (private company), Profitability not confirmed; likely operating at a loss, IPO deferred multiple times since 2022, Intense competition from Nozomi, Dragos, Armis, Microsoft, Palo Alto, Cisco, R&D concentration in Israel creates geopolitical risk, Dependence on enterprise/critical-infrastructure budgets with long sales cycles, Disclosure opacity for partners and counterparties, Continued reliance on equity funding rather than cash-flow self-sufficiency

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report