Sternum
Sternum sells an embedded security and observability platform for IoT and medical device manufacturers, using patented agentless EIV™ runtime protection embedded into device firmware to deterministically prevent memory and code manipulation attacks across 50+ OS platforms.
- Company typePrivate
- Founded2018
- HeadquartersTel Aviv, Israel
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Sternum does
Sternum Ltd. is an Israeli embedded security company founded in 2018 that sells an Embedded Security and Observability Platform for IoT, IoMT, and IIoT devices. The platform's core is the patented EIV™ (Embedded Integrity Verification) technology, a direct-to-binary, agentless runtime protection layer embedded into device firmware. Operating at bytecode level, EIV™ profiles code and memory in runtime, deterministically preventing memory corruption, command injection, and control-flow attacks with under 3% CPU overhead, while remaining compatible with Linux, RTOS, Zephyr, OpenWrt, FreeRTOS, and Micrium across 50+ platforms. Complementing EIV™ are real-time fleet monitoring and AI-powered threat detection modules that deliver XDR-like forensics and anomaly detection across deployed devices.
The product portfolio is sold through three enterprise go-to-market motions. First, embedded runtime protection is licensed for integration into device firmware, targeting medical device manufacturers (Medtronic, Fortune 500 medical device OEMs), semiconductor vendors (NXP), and IoT device OEMs (ChargePoint, Telit, QNAP, Wemo, HARDWARIO). Second, a cloud-based SaaS layer delivers fleet monitoring, vulnerability analytics, and AI-driven threat intelligence on top of the on-device agent. Third, the company monetizes compliance and observability add-ons such as Early Bug Detection, Cyber Compliance, and AI Anomaly Detection. Pricing is enterprise quote-based on annual subscriptions with a free evaluation kit enabling proof-of-concept engagements, and sales have expanded to the EU and United States since 2022.
Sternum has raised approximately $36M across three venture rounds — a $2.5M seed in 2018, a $6.5M round in 2020 led by Square Peg and btov Partners, and a $27M Series B in 2021 led by Spark Capital. The company holds four granted US patents and ISO 9001, ISO 27001, ISO 27799, and UL Solutions certifications, and supports regulatory frameworks including FDA 21 CFR Part 11, NIST 800-53, IEC 62443, and UL 2900. It maintains strategic technology partnerships with the Linux Foundation/Zephyr project, NXP Semiconductors, ARM, and Telit, with the engineering team led by ex-officers of the Israeli Defense Forces' elite 8200 unit.
Sternum firmographics
Firmographics- Name
- Sternum
- Legal name
- Sternum Ltd.
- Website
- https://sternumiot.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Sternum sells an embedded security and observability platform for IoT and medical device manufacturers, using patented agentless EIV™ runtime protection embedded into device firmware to deterministically prevent memory and code manipulation attacks across 50+ OS platforms.
- Ownership category
- akta.pro rank
Sternum industry classification
Industry- Product category
- IoT/Embedded Device Security Software
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Intrusion Detection & Prevention Systems (IDS/IPS) (HDAFAFAD)
- akta.pro secondary industries
- Confidential Computing & Hardware-backed Protection (TEE/HSM) (HDADAFAJ), App Security, Compliance & Review Automation Platforms (BPAMADAJ)
Keywords
Where Sternum is headquartered
LocationHeadquarters
- HQ city
- Tel Aviv
- HQ country
- Israel
- HQ region
- Middle East
Offices1 record
Markets served
Sternum business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- SaaS / Cloud Platform Subscription: Sternum provides EIV™ as downloadable runtime integrity protection components combined with SaaS (cloud) services for vulnerability analysis, continuous monitoring, and threat intelligence. Customers access the cloud platform for fleet monitoring, analytics, and threat detection. Pricing is likely subscription-based given the SaaS platform description and enterprise sales motion.
- Embedded Runtime Protection Licensing: EIV™ downloaded products are licensed for integration into device firmware. The downloadable runtime integrity protection components are provided as part of the overall service, likely with per-device or fleet-based licensing. The company offers free evaluation kits suggesting a tiered pricing model.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise Quote-Based Pricing |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels6 records
Sternum product offering
Product offeringCore offering
Sternum develops and sells an embedded security and observability platform for IoT, IoMT, and IIoT devices. Its patented EIV™ (Embedded Integrity Verification) technology is embedded into device firmware to deterministically prevent code and memory manipulation attacks (memory overflows, command injection, ROP, use-after-free, double-free) without external agents or signatures. The platform combines on-device intrusion prevention, real-time fleet monitoring with AI-powered anomaly detection, and continuous threat intelligence with less than 3% CPU overhead even on legacy devices.
Product overview
Sternum offers an Embedded Security and Observability Platform comprising three core products: EIV™ (Embedded Integrity Verification) runtime prevention technology, Real-Time Monitoring & Alerting, and AI-Powered Threat Detection. These integrate to provide on-device intrusion detection and prevention, continuous monitoring, and anomaly detection across IoT device fleets. The platform supports 50+ platforms including various RTOS and Linux distributions, operates with less than 3% overhead even on legacy devices, and provides agentless deployment through direct firmware integration. Solution modules cover Embedded Linux Security, RTOS Security, Zero-day Protection, AI Anomaly Detection, Cyber Compliance, Early Bug Detection, and Modernizing Legacy Devices.
Differentiator
Problem solved
Functional benefit
Products and services
- Embedded Runtime Prevention (EIV™) Patented on-device runtime security solution embedded directly into firmware that profiles processes in runtime and deterministically prevents exploit attempts (memory corruption, command injection, ROP, use-after-free, double-free). It serves as IDS/IPS for IoT devices and offers supply chain protection for third-party code, live alerts, and forensics. Targets device manufacturers and embedded systems engineers.
- Real-Time Monitoring & Alerting Cloud-based observability platform that provides personalized dashboards offering live device and fleet-level insights — traces, metrics, crash logs, remote debugging views, and actionable incident reports. Supports centralized fleet monitoring across geo-distributed deployments.
- AI-Powered Threat Detection XDR-like threat intelligence that triages threat data with AI signals, device telemetry, and user activity. Provides live threat intelligence, detailed forensics, panoramic view of security risks, and a customizable security policy engine with automatic AI-powered alerts.
Quantifiable outcome
- 96.5% total prevention rate of memory-based vulnerabilities in benchmark (RIPE) security tests, including 100% prevention of memory overflow vulnerabilities
- +5 more outcomes
Companies that use Sternum
Customer profileNamed customers7 records
Segments4 records
Ideal customer profiles4 records
Sternum technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability2 records
Feature7 records
Sternum partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core.
- TelitcoreStrategic partnership in the IoT market. Sternum's embedded security is integrated with Telit's IoT modules, providing baked-in runtime protection and monitoring for Telit's deployed IoT devices. Telit's CISO has publicly endorsed Sternum's solution for its seamless integration and early security intelligence capabilities.
- Linux Foundation / Zephyr ProjectcoreSternum enhances Zephyr's built-in security features by providing embedded developers and device manufacturers with additional runtime protection and monitoring capabilities that can be implemented with minimal complexity and zero performance compromises. Kate Stewart, VP of Dependable Embedded Systems at Linux Foundation, has publicly endorsed Sternum's integration with Zephyr.
- NXP SemiconductorscoreSternum's runtime protection is validated by NXP's security team. NXP crafted attacks that were all blocked by Sternum with CPU overhead of less than 3%. Marc Vauclair, Senior Security System Architect and Fellow at NXP, has endorsed Sternum as a valuable addition to many NXP products.
- ARMcoreSternum is listed as a trusted technology partner on the ARM ecosystem page. Sternum's technology is designed to work across ARM-based embedded platforms.
Scale indicators7 records
Recent moves6 records
Expansion highlights6 records
Sternum competitors and assessment
Company assessmentDirect peers
- Armis: Armis is a leading agentless IoT/OT asset management and security platform. It is a direct peer because it competes for the same enterprise device-security buyer, addresses unmanaged IoT risk, and offers fleet-level visibility similar to Sternum's monitoring layer.
- Claroty: Claroty specializes in cybersecurity for OT, IoT, and connected medical devices, with deep presence in healthcare and industrial verticals. Direct competitor to Sternum in protecting operational and medical device fleets from runtime and protocol-level threats.
- Nozomi Networks: Nozomi Networks provides OT and IoT security monitoring with anomaly detection and asset visibility. Overlaps directly with Sternum on fleet-level monitoring and threat detection for industrial and critical infrastructure environments.
- Karamba Security: Karamba Security offers embedded runtime protection for IoT and connected vehicles, with a focus on ECU-level integrity and supply-chain security. A direct peer because it competes in firmware-embedded runtime protection for resource-constrained devices, Sternum's core domain.
- JFrog (Vdoo / Runtime): JFrog acquired Vdoo, an embedded and IoT security firm focused on firmware analysis and runtime protection. Direct competitor to Sternum in device-binary security, now part of JFrog's broader DevSecOps and software supply-chain platform.
Broad incumbents
- Microsoft Defender for IoT: Microsoft Defender for IoT (formerly CyberX) is Microsoft's agentless OT/IoT security offering integrated into its broader security and Azure stack. Competes with Sternum on enterprise IoT visibility and threat detection, but as part of a much larger platform with bundled pricing and distribution.
- Palo Alto Networks IoT Security: Palo Alto Networks offers IoT security as part of its Prisma and Cortex platforms, providing device discovery, visibility, and policy enforcement. Broad incumbent that competes for the same enterprise security budgets and offers overlapping device-protection capabilities as part of a wider portfolio.
- Cisco IoT Threat Defense: Cisco's IoT Threat Defense and Cyber Vision provide visibility and segmentation for OT/IoT networks. Broad incumbent with strong installed base in industrial networking, posing indirect competition to Sternum at the fleet-monitoring layer.
- Tenable (Tenable.io / OT Security): Tenable provides vulnerability management and OT/IoT security through its Nessus and Tenable.OT platforms. Broad incumbent that addresses overlapping needs (vulnerability and asset visibility) but lacks Sternum's firmware-embedded runtime prevention layer.
Emerging players
- RunSafe Security: RunSafe Security provides runtime application self-protection and binary hardening for embedded and critical infrastructure systems. Emerging player in the same embedded runtime protection category as Sternum, with overlap in memory-safety and supply-chain security for IoT/OT.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks5 records
Key highlights7 records
Customer concentration
Sternum social profiles
Digital presenceSternum compliance and trust
Trust signalCompliance7 records
Sternum financial estimates
Financial estimateRevenue estimate
Valuation estimate
Sternum leadership team
Management profileNumber of profiles
Profiles5 records
Sternum funding detail
Funding detailFunding overview
Funding rounds3 records
Investors5 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Sternum M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Sternum
What does Sternum do?
Sternum develops and sells an embedded security and observability platform for IoT, IoMT, and IIoT devices. Its patented EIV™ (Embedded Integrity Verification) technology is embedded into device firmware to deterministically prevent code and memory manipulation attacks (memory overflows, command injection, ROP, use-after-free, double-free) without external agents or signatures. The platform combines on-device intrusion prevention, real-time fleet monitoring with AI-powered anomaly detection, and continuous threat intelligence with less than 3% CPU overhead even on legacy devices.
Is Sternum a public or private company?
Sternum is a private company. It is classified as venture growth investor backed and is currently operating.
When was Sternum founded?
Sternum was founded in 2018. It employs 11 to 50 people.
Where is Sternum based?
Sternum is headquartered in Tel Aviv, Israel, in the Middle East region.
How does Sternum make money?
Two revenue lines are on record. SaaS / Cloud Platform Subscription is the primary driver. The others are embedded Runtime Protection Licensing.
Who are Sternum's main competitors?
Direct peers on record are Armis, Claroty, Nozomi Networks, Karamba Security and JFrog (Vdoo / Runtime). Broad incumbents are Microsoft Defender for IoT, Palo Alto Networks IoT Security, Cisco IoT Threat Defense and Tenable (Tenable.io / OT Security). RunSafe Security is listed as an emerging player.
Does Sternum have an API?
No public API is recorded for Sternum.
What industry is Sternum in?
Sternum's product category is IoT/Embedded Device Security Software. Its primary akta.pro industry code is HDAFAFAD, Intrusion Detection & Prevention Systems (IDS/IPS), with a secondary code of HDADAFAJ, Confidential Computing & Hardware-backed Protection (TEE/HSM). Its NAICS code is 54151 and its SIC code is 7371.