Invary
Invary provides NSA-licensed Runtime Integrity solutions that continuously verify system state at the kernel level to detect hidden malware and tampering, serving federal defense and intelligence agencies alongside commercial enterprises in healthcare, cloud infrastructure, and confidential computing.
- Company typePrivate
- Founded2022
- HeadquartersLawrence, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Invary does
Invary (legally Ad Astra Integrity Measurement Systems, Inc.) is a Lawrence, Kansas-based cybersecurity company that provides runtime integrity solutions based on NSA-licensed Linux Kernel Integrity Measurement (LKIM) technology. The company's core platform continuously measures and appraises system runtime memory against known-good baselines built from clean systems prior to deployment, detecting deviations that indicate hidden malware, rootkits, or kernel-level tampering. Unlike signature-based endpoint detection tools, Invary verifies actual system state rather than identifying known threats. The platform supports Linux, Windows, eBPF programs, and Trusted Execution Environments including AMD SEV-SNP, and is available in two deployment models: SaaS for cloud-connected environments and air-gapped on-premises for sensitive federal and classified installations.
The product portfolio comprises the unified Invary Runtime Integrity platform plus four modules: Linux Kernel Runtime Integrity, Windows Kernel Runtime Integrity, eBPF Runtime Integrity, and TEE Attestation. Rust-based binaries and graph-based measurement baselines support performance and accuracy across commercial off-the-shelf and custom kernels. The company operates a hybrid go-to-market combining direct enterprise sales with a channel partner ecosystem led by Carahsoft for federal distribution (via NASA SEWP V and other procurement frameworks) and integration partners including Vibrint (national security), Alexander Cyber, Mission Defense Solutions, Tenfold Security, and Thrive Cyber. The primary customer segment is the Department of Defense and Intelligence Community, with expansion underway into cloud infrastructure, HPC/AI, confidential computing, healthcare, legal, and research/education verticals.
Revenue is generated through subscription SaaS, on-premises subscription with perpetual license options, and enterprise licensing, with pricing not publicly disclosed. As of February 2025, the company had raised $5.35M total across a $1.85M pre-seed (June 2023) led by Flyover Capital and a $3.5M seed led by SineWave Ventures and Flyover Capital, with the team reported at 1-10 employees and led by co-founders Jason Rogers (CEO) and Dr. Wesley Peck (CTO).
Invary firmographics
Firmographics- Name
- Invary
- Legal name
- Ad Astra Integrity Measurement Systems, Inc.
- Website
- https://invary.com
- Company type
- Private
- Founded year
- 2022
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Invary provides NSA-licensed Runtime Integrity solutions that continuously verify system state at the kernel level to detect hidden malware and tampering, serving federal defense and intelligence agencies alongside commercial enterprises in healthcare, cloud infrastructure, and confidential computing.
- Ownership category
- akta.pro rank
Invary industry classification
Industry- Product category
- Runtime Integrity Cybersecurity Software
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Code & Repository Security (Git Security, Code Integrity) (HDADACAG)
- akta.pro secondary industry
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
Keywords
Where Invary is headquartered
LocationHeadquarters
- HQ city
- Lawrence
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Invary business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel
Revenue model
- Runtime Integrity Software (SaaS): SaaS-based Runtime Integrity service with subscription billing for cloud-connected enterprise environments. Provides appraisal results via webhook or API.
- On-Premises Runtime Integrity: On-premises deployment for air-gapped sensitive environments, sold as subscription with perpetual license options.
- Enterprise Licensing: Enterprise licensing of Runtime Integrity technology with customization and integration support.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | SaaS - Cloud Connected Environments |
| Subscription | Annual | On-Premises - Air-Gapped Sensitive Environments |
Go-to-market motion3 records
Distribution channels5 records
Marketing channels8 records
Invary product offering
Product offeringCore offering
Invary provides a Runtime Integrity platform that continuously verifies system runtime state by measuring and appraising runtime memory against known-good baselines built from clean systems prior to deployment. The platform detects hidden malware, rootkits, and kernel-level tampering across Linux, Windows, eBPF, and Trusted Execution Environments (TEEs) such as AMD SEV-SNP. It is offered as both SaaS (cloud-connected) and On-Premise (air-gapped) deployments, and is built on NSA-licensed Linux Kernel Integrity Measurement (LKIM) technology.
Product overview
Invary offers a unified Runtime Integrity platform built on NSA-licensed Kernel Integrity Measurement (KIM) technology. The core Invary Runtime Integrity platform is available in two deployment modes: On-Premise (for air-gapped sensitive environments) and SaaS (for cloud-connected environments). The platform encompasses multiple product modules including Linux Kernel Runtime Integrity, Windows Kernel Runtime Integrity, eBPF Runtime Integrity, and Trusted Execution Environment (TEE) Attestation, each targeting specific runtime integrity verification needs across operating systems and execution environments.
Differentiator
Problem solved
Functional benefit
Products and services
- Invary Runtime Integrity The core Runtime Integrity platform that continuously verifies system runtime state against known-good baselines to detect hidden malware, rootkits, and kernel-level tampering. Built on NSA-licensed LKIM technology and offered to federal agencies, defense contractors, cloud infrastructure providers, and regulated commercial enterprises.
- Invary Runtime Integrity On-Premise Air-gapped capable deployment for sensitive environments, validating OS, TEE, and eBPF Runtime Integrity with Rust-based binaries and supporting any COTS or custom kernel. Best for sensitive environments requiring full isolation.
- Invary Runtime Integrity SaaS Cloud-connected deployment option with webhook and API delivery of appraisal results, supporting sign-in with Google and OIDC authentication. Best for cloud-connected enterprise environments.
- Linux Kernel Runtime Integrity Verifies the integrity of the Linux kernel at runtime using the kernel's rich instrumentation to establish a baseline of expected runtime behavior and detect anomalies. Supports any COTS or custom kernel.
- Windows Kernel Runtime Integrity Runtime integrity verification for the Windows kernel using protected memory read techniques to inspect sensitive kernel structures without interfering with PatchGuard. Detects anomalies suggesting injection, redirection, or corruption.
- eBPF Runtime Integrity
Quantifiable outcome
- Provides clear and actionable intelligence about system integrity at runtime, with failed appraisals indicating obvious and high-priority threats without requiring thresholds, noise interpretation, or tuning.
Companies that use Invary
Customer profileNamed customers6 records
Segments6 records
Ideal customer profiles5 records
Invary technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration6 records
AI capability1 record
Feature9 records
Invary partnerships and signals
Strategic signalPartnerships
13 partnerships are on record, tiered core and minor.
- CarahsoftcoreCarahsoft serves as Invary's public sector distributor for the Runtime Integrity platform, expanding access to government agencies through existing contract vehicles including NASA SEWP V and other procurement frameworks. The partnership enables detection of zero-day exploits and AI-driven attacks for government customers.
- VibrintcoreStrategic collaboration to deliver kernel-level Zero Trust solutions for national security and defense environments. Integrates Invary's Kernel Integrity Measurement technology with Vibrint's secure enterprise architecture for real-time threat detection at the kernel level.
- Cloud Security Alliance (CSA)minorAlliance partner. Invary is a CSA member participating in startup showcase and working on integrity as a foundation of zero trust.
- Center for Internet Security (CIS)minorAlliance partner in CIS CyberMarket for advancing cybersecurity standards and practices.
- Confidential Computing ConsortiumminorInvary is a member of the CCC, collaborating to foster secure, privacy-preserving computing environments.
- MITREcoreCollaboration with MITRE on forthcoming publication related to layered attestation. Partnering on advancing industry discussion around continuous, layered attestation for live systems.
- Fr0ntierXminorCollaboration with MITRE on a forthcoming publication related to layered attestation. Fr0ntierX focuses on extending confidential computing into continuously verifiable secure systems.
- NSA Laboratory for Advanced Cybersecurity ResearchcoreOngoing research partnership with NSA's Laboratory for Advanced Cybersecurity Research. Exclusive IP license for Linux Kernel Integrity Measurement technology. CRADA agreement for continued research advancement.
- University of KansasminorResearch partnership including contributions from NetWork Kansas GROWKS Equity program and KU Innovation Park in pre-seed funding.
- Alexander CyberminorChannel partner in the ecosystem for reselling and deploying Runtime Integrity solutions.
- Mission Defense SolutionsminorChannel partner for defense sector deployments of Runtime Integrity solutions.
- Tenfold SecurityminorChannel partner integrating Runtime Integrity into security solutions for cloud and virtual machines.
- Thrive CyberminorChannel partner in cybersecurity ecosystem.
Scale indicators4 records
Recent moves6 records
Expansion highlights6 records
Invary competitors and assessment
Company assessmentBroad incumbents
- SentinelOne: Endpoint security platform with deep kernel-level runtime detection capabilities via its Singularity Platform. Comparable as a broader incumbent investing in runtime behavior-based detection that overlaps with Invary's continuous runtime attestation approach for Linux/Windows.
- Microsoft Defender for Endpoint: Microsoft's enterprise endpoint security platform with kernel-level sensors, integrated into the broader Defender / Sentinel ecosystem. Comparable as a broad incumbent covering Windows and Linux runtime detection at massive scale, often bundled with E5 licensing.
- CrowdStrike: Market-leading endpoint and workload protection platform with kernel-level sensor (Falcon Sensor) providing continuous runtime telemetry. Comparable as the dominant incumbent whose platform increasingly encroaches on Invary's runtime integrity / rootkit-detection territory.
- Cybereason: Endpoint detection and response vendor with kernel-level behavioral analytics for detecting rootkits and in-memory attacks. Comparable as a broader incumbent offering overlapping runtime threat detection capabilities for enterprise and federal customers.
- Darktrace: AI-based cybersecurity platform providing autonomous runtime threat detection across endpoints, cloud, and OT environments. Comparable as a broad incumbent leveraging AI to detect behavioral anomalies at runtime, with overlap in federal and critical-infrastructure buyers.
- Palo Alto Networks Cortex XDR: Extended detection and response platform with endpoint agents providing kernel-level visibility and behavioral analysis. Comparable as a broad incumbent in endpoint / runtime threat detection competing for the same zero-trust and federal buyers as Invary.
- Trend Micro Vision One: Enterprise cybersecurity platform with endpoint, server, and workload protection including kernel-level integrity capabilities. Comparable as a broad incumbent with established federal and enterprise footprint that competes for similar zero trust / runtime integrity budgets.
Emerging players
- Deep Instinct: Prevention-first endpoint security vendor using deep learning to detect unknown malware at runtime before execution. Comparable as an emerging player focused on pre-execution and runtime prevention for endpoints, with overlap in zero-day / unknown-threat detection.
- Sternum: Runtime security and observability platform for embedded and IoT devices, applying runtime protection and integrity verification to connected systems. Comparable as an emerging player with a similar runtime integrity philosophy applied to a different (embedded) substrate.
Direct peers
- Capsule8: Was the most direct pre-acquisition competitor to Invary, focused on Linux runtime threat detection and behavioral analytics. Acquired by Sophos in 2023. Comparable because it targeted the same kernel-level runtime integrity use case for Linux servers before acquisition.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Invary social profiles
Digital presenceInvary financial estimates
Financial estimateRevenue estimate
Valuation estimate
Invary leadership team
Management profileNumber of profiles
Profiles5 records
Invary funding detail
Funding detailFunding overview
Funding rounds2 records
Investors6 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Invary M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Invary
What does Invary do?
Invary provides a Runtime Integrity platform that continuously verifies system runtime state by measuring and appraising runtime memory against known-good baselines built from clean systems prior to deployment. The platform detects hidden malware, rootkits, and kernel-level tampering across Linux, Windows, eBPF, and Trusted Execution Environments (TEEs) such as AMD SEV-SNP. It is offered as both SaaS (cloud-connected) and On-Premise (air-gapped) deployments, and is built on NSA-licensed Linux Kernel Integrity Measurement (LKIM) technology.
Is Invary a public or private company?
Invary is a private company. It is classified as venture growth investor backed and is currently operating.
When was Invary founded?
Invary was founded in 2022. It employs 1 to 10 people.
Where is Invary based?
Invary is headquartered in Lawrence, United States, in the North America region.
How does Invary make money?
Three revenue lines are on record. Runtime Integrity Software (SaaS) is the primary driver. The others are on-Premises Runtime Integrity and enterprise Licensing.
Who are Invary's main competitors?
Broad incumbents on record are SentinelOne, Microsoft Defender for Endpoint, CrowdStrike, Cybereason, Darktrace, Palo Alto Networks Cortex XDR and Trend Micro Vision One. Emerging players are Deep Instinct and Sternum. Capsule8 is listed as a direct peer.
Does Invary have an API?
Yes. Invary provides a REST API for programmatic access to Runtime Integrity functionality. The API exposes two primary resources: Endpoint (representing bare-metal machines, VMs, or containers registered with the platform) and Appraisal (representing Runtime Integrity checks). Developers can retrieve appraisal reports, list appraisals, manage endpoints (provision, deprovision, reactivate), and configure outbound webhooks for lightweight appraisal events. Authentication is via JWT bearer token. The API is documented at developers.invary.com with OpenAPI spec available. Developer documentation is at developers.invary.com.
What industry is Invary in?
Invary's product category is Runtime Integrity Cybersecurity Software. Its primary akta.pro industry code is HDADACAG, Code & Repository Security (Git Security, Code Integrity), with a secondary code of HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing). Its NAICS code is 54151 and its SIC code is 7372.