Developer docs
API playgroundTry for free, no card

Search company profiles

Cyware

Full company profile

uuid0002el1

Namestring
Cyware
Legal namestring
Cyware Labs, Inc.
Websiteurl
cyware.com
Company typeenum
Private
Founded yearint
2016
Descriptiontext

Cyware Labs, Inc. is a privately held, US-headquartered (Jersey City, Delaware-incorporated) cybersecurity software company founded in 2016 that builds an AI-powered threat intelligence platform for enterprises, government agencies, and managed security service providers. The Cyware Intelligence Suite unifies threat intelligence management, security orchestration and automation (SOAR), collaborative threat sharing, and incident response (CFTR) into a single platform architecture, supported by an Agentic AI Fabric of specialized cybersecurity agents and 400+ third-party integrations across the security ecosystem. The platform ingests 15B+ threat intelligence objects, serves 30K+ organizations, and underpins sector-specific communities (ISACs, ISAOs, CERTs) used by government, financial services, healthcare, energy, and MSSP customers.

Cyware operates primarily a subscription-based SaaS revenue model with quote-based enterprise pricing, annual or multi-year non-cancelable contracts, and supplemental professional services for custom playbook development, implementation, and training. Go-to-market is sales-led with a 'Request a Demo' motion targeting large enterprises and government agencies, complemented by an MSSP partner program, ISAC/ISAO distribution networks, and technology alliance integrations. The company maintains three disclosed offices (Jersey City HQ, Bengaluru engineering center under Cyware Labs India Pvt. Ltd., and a META region presence), holds FedRAMP Ready, SOC 2 Type 2, and ISO 27001:2022 certifications, and has raised approximately $73M across five funding rounds through a 2023 Series C led by Ten Eleven Ventures with Advent International and Zscaler participation.

Short descriptiontext

Cyware provides an AI-powered threat intelligence platform unifying threat data management, SOAR orchestration, and collaborative sharing for enterprises, government agencies, and MSSPs across financial services, healthcare, and federal sectors.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
101–250
akta.pro rankint
HeadquartersJersey City, United States
HQ citystring
Jersey City
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices3 records

Each record includes

City, Country, Type, Description, Source

Keyword5 values
threat intelligence platform, security orchestration automation, cyber threat sharing, digital risk protection, agentic AI security
Industry2 codes
1Extended Detection & Response (XDR)
CodeHDADAEABPrimaryYes
2AI Application Enablement Platforms (Copilot/Agent Frameworks, SDKs)
CodeHDAEANAJPrimaryNo
NAICS code3 codes
  • Software Publishers51321
  • Computer Systems Design and Related Services5415
  • Security Systems Services (except Locksmiths)561621
SIC code2 codes
  • Services-Prepackaged Software7372
  • Services-Computer Integrated Systems Design7373
Product category
Cybersecurity Threat Intelligence Platform
GTM motion3 records

Each record includes

Type, Description, Source

Revenue model2 records
1Subscription SaaS
TypeSubscription Recurring
Description

Cyware operates primarily on a subscription-based SaaS model with annual or multi-year contracts. Subscription fees are based on user count, data volume, and feature tiers. The platform is available in both Cyware-hosted (cloud) and client-hosted deployment options.

cyware.com
2Professional Services
TypeProfessional Services
Description

Professional services including custom playbook drafting, implementation, installation, and extended training are offered under separate ordering documents beyond standard integration and training included in subscriptions.

cyware.com
Marketing channels8 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels4 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Pricing details2 tiers
1Enterprise subscription tier with full platform access
ModelSubscriptionBilling cadenceAnnual
Notes

Quote-based pricing; tiers based on user count, data volume, and feature modules. Annual and multi-year contracts available with standard integration (up to 15 hours) included.

cyware.com
2Professional services add-on
ModelOtherBilling cadenceMulti-year contract
Notes

Playbook drafting, implementation, installation, and extended training provided under separate ordering documents at additional cost.

cyware.com
GTM typeB2B
B2B
Offering typeSoftware
Software
Brand1 of 8 records shown
1Cyware Intelligence Suite
Description

Unified threat intelligence management platform offering threat intelligence platform, feeds, digital risk protection, exposure management, malware sandbox, and threat intelligence enrichment.

cyware.com
+7 more records
Core offering1 text field

Cyware provides a unified, AI-powered threat intelligence management platform (the Cyware Intelligence Suite) that automates ingestion, deduplication, enrichment, scoring, sharing, and operational actioning of threat intelligence for enterprise and government security operations. Core products include Cyware Intel Exchange (TIP), Cyware Orchestrate (SOAR), Cyware Respond (incident response), and Cyware Collaborate (threat intel sharing across ISACs, ISAOs, and CERTs), augmented by Cyware Quarterback AI and the Agentic AI Fabric of specialized cybersecurity agents.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 3 values shown
  • Threat intelligence operationalization reduces manual effort through automated ingestion, deduplication, enrichment, and actioning
+2 more records
Product overview1 text field

Cyware offers a unified, AI-powered threat intelligence platform architecture comprising core products and modular add-ons. The Cyware Intelligence Suite serves as the overarching platform combining threat intelligence management, security orchestration and automation, and collaborative threat sharing. Core products include Cyware Intel Exchange (threat intelligence platform), Cyware Orchestrate (SOAR), Cyware Respond (incident response/CFTR), and Cyware Collaborate (sharing). These are augmented by specialized modules including Threat Intelligence Feeds, Digital Risk Protection, Exposure Management, Malware Sandbox, and AI-powered automation capabilities. The Agentic AI Fabric introduces specialized AI agents (SOC Analysis, Detection Engineering, Attack Flow, Incident Reporting, Playbook Builder) that integrate across the platform to enable autonomous threat investigation, detection generation, and workflow automation. The platform supports over 400 integrations via its App Marketplace and enables collective defense through ISAC/ISAO/CERT network connectivity.

Product and service9 records
1Cyware Intelligence Suite
CategoryPlatform
Description

Unified, fully integrated AI-powered threat intelligence platform that operationalizes threat intelligence in real time across the entire security operations lifecycle for enterprise and government security teams.

2Cyware Intel Exchange
CategoryThreat Intelligence Platform (TIP)
Description

Comprehensive threat intelligence platform for automated ingestion, deduplication, normalization, enrichment, scoring, sharing, and actioning of threat intelligence across internal teams and external ecosystems.

3Cyware Orchestrate
CategorySecurity Orchestration, Automation, and Response (SOAR)
Description

Security Orchestration, Automation, and Response (SOAR) platform providing vendor-neutral, low-code security automation and orchestration across security tools and workflows for enterprise SOCs.

4Cyware Respond
CategoryIncident Response / Cyber Fusion
Description

Automated incident analysis and threat response platform providing AI-powered case management and coordinated response capabilities for security operations centers.

5Cyware Collaborate
CategoryThreat Intelligence Sharing & Collaboration
Description

Threat intelligence sharing and collaboration platform enabling secure bidirectional sharing across teams, industry groups, ISACs, ISAOs, and government entities for collective defense.

6Cyware Quarterback AI
CategoryAgentic AI for Security Operations
Description

AI-powered threat intelligence assistant providing agentic AI workflows for security operations including alert triage, IOC enrichment, threat investigation, detection engineering, and browser-based inline threat intelligence queries.

7Agentic AI Fabric
CategoryAgentic AI Platform
Description

AI-powered platform introducing specialized agent-driven tools including Analyst Agent Hub and Agent Catalogue with Attack Flow, Contextual Intelligence, SOC Analysis, and Detection Engineering agents for autonomous threat investigation, detection generation, and workflow automation.

8Healthcare Threat Intelligence Platform
CategoryVertical-Specific Threat Intelligence
Description

Industry-tuned threat intelligence platform specifically designed for healthcare organizations to defend against cyber threats targeting patient data, medical systems, and HIPAA-regulated environments.

9Pre-Configured Threat Intelligence Platform with Team Cymru
CategoryPartner-Enabled Threat Intelligence Platform
Description

Pre-configured threat intelligence platform combining Cyware's operationalization capabilities with Team Cymru's threat data feeds, providing access to Team Cymru's threat intelligence database for enhanced cyber fusion.

Scale indicator5 records

Each record includes

Type, Value, Description, Source

Partnership4 partners
Strategic tierCoreTypeTechnology or IntegrationAnnounced on2026-06-02
Description

Integration of SOCRadar's external threat intelligence into Cyware's Security Operations Platform to enhance digital risk protection (DRP) capabilities. The integration provides external threat signals including phishing domains and stolen credentials within a unified workflow for MSSPs.

Strategic tierCoreTypeTechnology or IntegrationAnnounced on2025-01-28
Description

Launch of industry's first pre-configured threat intelligence platform combining Team Cymru's threat data with Cyware's intelligence platform. Enables AI agents to access Team Cymru's threat intelligence database through Model Context Protocol (MCP) server.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2024-11-16
Description

Partnership to strengthen government cybersecurity with enhanced Intel Exchange capabilities. ECS managed security services leverage Cyware Intel Exchange for government sector threat intelligence operations.

Strategic tierMinorTypeStrategic or Co-development PartnerAnnounced on2024-09-18
Description

Cyware joined CoSAI to advance safe and ethical AI technologies in cybersecurity, contributing to industry standards for secure AI development and deployment.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

Anomali provides a Threat Intelligence Platform that automates intelligence collection, processing, and integration with security infrastructure. It is a direct competitor to Cyware's Intel Exchange, serving similar enterprise and government customers with comparable TIP capabilities.

TypeDirect peer
Description

ThreatConnect offers a Threat Intelligence Operations Platform combining TIP and SOAR capabilities. It competes directly with Cyware's Intel Exchange and Orchestrate products, targeting enterprise security operations teams with similar intelligence-driven workflows.

TypeDirect peer
Description

EclecticIQ is a pure-play threat intelligence platform provider serving enterprises and governments, particularly in Europe. It directly competes with Cyware's Intel Exchange for TIP market share with similar intelligence aggregation and operationalization capabilities.

TypeDirect peer
Description

ThreatQuotient provides a threat intelligence platform focused on threat operations and incident response, similar to Cyware's threat intelligence management approach. It targets enterprise SOC teams with intelligence-driven security operations capabilities.

TypeBroad incumbent
Description

Palo Alto Networks offers Cortex XSOAR for SOAR and XSIAM as an extended security operations platform that includes threat intelligence and response capabilities. As a broad incumbent, it competes with Cyware's Orchestrate and Respond products as part of a wider security portfolio.

TypeBroad incumbent
Description

Splunk offers SOAR (formerly Phantom) capabilities within its broader security operations suite. As a broad incumbent, it competes with Cyware's Orchestrate SOAR platform by offering integrated orchestration within the Splunk SIEM ecosystem and broader data platform.

TypeBroad incumbent
Description

Microsoft Sentinel is a cloud-native SIEM and SOAR platform integrated with Microsoft Defender and Azure ecosystems. It competes with Cyware's Intel Exchange and Orchestrate products, particularly for enterprises standardized on Microsoft security infrastructure.

TypeBroad incumbent
Description

Recorded Future is a leading threat intelligence provider now owned by Mastercard. It competes with Cyware's threat intelligence and Digital Risk Protection offerings, with broader brand recognition and access to payment fraud intelligence.

TypeEmerging player
Description

Swimlane is an emerging SOAR vendor focused on security automation with low-code workflows and AI capabilities. It offers partial overlap with Cyware's Orchestrate product, particularly for enterprises seeking alternatives to legacy SOAR platforms.

TypeEmerging player
Description

Tines is an emerging security automation platform with a no-code workflow builder and strong developer adoption. It overlaps with Cyware's Orchestrate product for security orchestration use cases, with growing traction among enterprise security teams.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat6 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers3 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment7 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile4 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
Yes

Docs URL, Description

Integration3 records

Each record includes

Title, Type, Description, Source

AI capability10 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature10 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles10 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

Subsidiaries1 record

Each record includes

Name, Acquired on, Relationship type, Type, Business focus

Compliance6 records

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds5 records

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors9 records

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Cyware

Cybersecurity Threat Intelligence Platformcyware.com

Cyware provides an AI-powered threat intelligence platform unifying threat data management, SOAR orchestration, and collaborative sharing for enterprises, government agencies, and MSSPs across financial services, healthcare, and federal sectors.

What Cyware does

Cyware Labs, Inc. is a privately held, US-headquartered (Jersey City, Delaware-incorporated) cybersecurity software company founded in 2016 that builds an AI-powered threat intelligence platform for enterprises, government agencies, and managed security service providers. The Cyware Intelligence Suite unifies threat intelligence management, security orchestration and automation (SOAR), collaborative threat sharing, and incident response (CFTR) into a single platform architecture, supported by an Agentic AI Fabric of specialized cybersecurity agents and 400+ third-party integrations across the security ecosystem. The platform ingests 15B+ threat intelligence objects, serves 30K+ organizations, and underpins sector-specific communities (ISACs, ISAOs, CERTs) used by government, financial services, healthcare, energy, and MSSP customers.

Cyware operates primarily a subscription-based SaaS revenue model with quote-based enterprise pricing, annual or multi-year non-cancelable contracts, and supplemental professional services for custom playbook development, implementation, and training. Go-to-market is sales-led with a 'Request a Demo' motion targeting large enterprises and government agencies, complemented by an MSSP partner program, ISAC/ISAO distribution networks, and technology alliance integrations. The company maintains three disclosed offices (Jersey City HQ, Bengaluru engineering center under Cyware Labs India Pvt. Ltd., and a META region presence), holds FedRAMP Ready, SOC 2 Type 2, and ISO 27001:2022 certifications, and has raised approximately $73M across five funding rounds through a 2023 Series C led by Ten Eleven Ventures with Advent International and Zscaler participation.

Cyware firmographics

Firmographics
Name
Cyware
Legal name
Cyware Labs, Inc.
Website
https://cyware.com
Company type
Private
Founded year
2016
Operating status
Operating
Headcount range
101–250 employees
Short description
Cyware provides an AI-powered threat intelligence platform unifying threat data management, SOAR orchestration, and collaborative sharing for enterprises, government agencies, and MSSPs across financial services, healthcare, and federal sectors.
Ownership category
akta.pro rank

Cyware industry classification

Industry
Product category
Cybersecurity Threat Intelligence Platform
NAICS
Software Publishers (51321), Computer Systems Design and Related Services (5415), Security Systems Services (except Locksmiths) (561621)
SIC
Services-Prepackaged Software (7372), Services-Computer Integrated Systems Design (7373)
akta.pro primary industry
Extended Detection & Response (XDR) (HDADAEAB)
akta.pro secondary industry
AI Application Enablement Platforms (Copilot/Agent Frameworks, SDKs) (HDAEANAJ)

Keywords

  • Threat intelligence platform
  • Security orchestration automation
  • Cyber threat sharing
  • Digital risk protection
  • Agentic AI security

Where Cyware is headquartered

Location

Headquarters

HQ city
Jersey City
HQ country
United States
HQ region
North America

Offices3 records

Markets served

Cyware business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations

Revenue model

  1. Subscription SaaS: Cyware operates primarily on a subscription-based SaaS model with annual or multi-year contracts. Subscription fees are based on user count, data volume, and feature tiers. The platform is available in both Cyware-hosted (cloud) and client-hosted deployment options.
  2. Professional Services: Professional services including custom playbook drafting, implementation, installation, and extended training are offered under separate ordering documents beyond standard integration and training included in subscriptions.

Pricing tiers

ModelBillingPrice
SubscriptionAnnualEnterprise subscription tier with full platform access
OtherMulti-year contractProfessional services add-on

Go-to-market motion3 records

Distribution channels4 records

Marketing channels8 records

Cyware product offering

Product offering

Core offering

Cyware provides a unified, AI-powered threat intelligence management platform (the Cyware Intelligence Suite) that automates ingestion, deduplication, enrichment, scoring, sharing, and operational actioning of threat intelligence for enterprise and government security operations. Core products include Cyware Intel Exchange (TIP), Cyware Orchestrate (SOAR), Cyware Respond (incident response), and Cyware Collaborate (threat intel sharing across ISACs, ISAOs, and CERTs), augmented by Cyware Quarterback AI and the Agentic AI Fabric of specialized cybersecurity agents.

Product overview

Cyware offers a unified, AI-powered threat intelligence platform architecture comprising core products and modular add-ons. The Cyware Intelligence Suite serves as the overarching platform combining threat intelligence management, security orchestration and automation, and collaborative threat sharing. Core products include Cyware Intel Exchange (threat intelligence platform), Cyware Orchestrate (SOAR), Cyware Respond (incident response/CFTR), and Cyware Collaborate (sharing). These are augmented by specialized modules including Threat Intelligence Feeds, Digital Risk Protection, Exposure Management, Malware Sandbox, and AI-powered automation capabilities. The Agentic AI Fabric introduces specialized AI agents (SOC Analysis, Detection Engineering, Attack Flow, Incident Reporting, Playbook Builder) that integrate across the platform to enable autonomous threat investigation, detection generation, and workflow automation. The platform supports over 400 integrations via its App Marketplace and enables collective defense through ISAC/ISAO/CERT network connectivity.

Differentiator

Problem solved

Functional benefit

Brands

  • Cyware Intelligence Suite: Unified threat intelligence management platform offering threat intelligence platform, feeds, digital risk protection, exposure management, malware sandbox, and threat intelligence enrichment.
  • Cyware Intel Exchange
  • Cyware Collaborate
  • Cyware Orchestrate
  • Cyware Respond
  • Quarterback AI
  • Agentic AI Fabric
  • Cyware AI

Products and services

  • Cyware Intelligence Suite Unified, fully integrated AI-powered threat intelligence platform that operationalizes threat intelligence in real time across the entire security operations lifecycle for enterprise and government security teams.
  • Cyware Intel Exchange Comprehensive threat intelligence platform for automated ingestion, deduplication, normalization, enrichment, scoring, sharing, and actioning of threat intelligence across internal teams and external ecosystems.
  • Cyware Orchestrate Security Orchestration, Automation, and Response (SOAR) platform providing vendor-neutral, low-code security automation and orchestration across security tools and workflows for enterprise SOCs.
  • Cyware Respond Automated incident analysis and threat response platform providing AI-powered case management and coordinated response capabilities for security operations centers.
  • Cyware Collaborate Threat intelligence sharing and collaboration platform enabling secure bidirectional sharing across teams, industry groups, ISACs, ISAOs, and government entities for collective defense.
  • Cyware Quarterback AI AI-powered threat intelligence assistant providing agentic AI workflows for security operations including alert triage, IOC enrichment, threat investigation, detection engineering, and browser-based inline threat intelligence queries.
  • Agentic AI Fabric AI-powered platform introducing specialized agent-driven tools including Analyst Agent Hub and Agent Catalogue with Attack Flow, Contextual Intelligence, SOC Analysis, and Detection Engineering agents for autonomous threat investigation, detection generation, and workflow automation.
  • Healthcare Threat Intelligence Platform Industry-tuned threat intelligence platform specifically designed for healthcare organizations to defend against cyber threats targeting patient data, medical systems, and HIPAA-regulated environments.
  • Pre-Configured Threat Intelligence Platform with Team Cymru Pre-configured threat intelligence platform combining Cyware's operationalization capabilities with Team Cymru's threat data feeds, providing access to Team Cymru's threat intelligence database for enhanced cyber fusion.

Quantifiable outcome

  • Threat intelligence operationalization reduces manual effort through automated ingestion, deduplication, enrichment, and actioning
  • +2 more outcomes

Companies that use Cyware

Customer profile

Named customers3 records

Segments7 records

Ideal customer profiles4 records

Cyware technology and API

Technology

Technology focussed Yes

API detail

Has API
Yes
API docs
API detail

Core technology

AI maturity

App detail

Integration3 records

AI capability10 records

Feature10 records

Cyware partnerships and signals

Strategic signal

Partnerships

Four partnerships are on record, tiered core and minor.

  • SOCRadarcoreTechnology or Integration · 2 June 2026Integration of SOCRadar's external threat intelligence into Cyware's Security Operations Platform to enhance digital risk protection (DRP) capabilities. The integration provides external threat signals including phishing domains and stolen credentials within a unified workflow for MSSPs.
  • Team CymrucoreTechnology or Integration · 28 January 2025Launch of industry's first pre-configured threat intelligence platform combining Team Cymru's threat data with Cyware's intelligence platform. Enables AI agents to access Team Cymru's threat intelligence database through Model Context Protocol (MCP) server.
  • ECS (Enterprise Computing Services)coreStrategic or Co-development Partner · 16 November 2024Partnership to strengthen government cybersecurity with enhanced Intel Exchange capabilities. ECS managed security services leverage Cyware Intel Exchange for government sector threat intelligence operations.
  • Coalition for Secure AI (CoSAI)minorStrategic or Co-development Partner · 18 September 2024Cyware joined CoSAI to advance safe and ethical AI technologies in cybersecurity, contributing to industry standards for secure AI development and deployment.

Scale indicators5 records

Recent moves6 records

Expansion highlights6 records

Cyware competitors and assessment

Company assessment

Direct peers

  • Anomali: Anomali provides a Threat Intelligence Platform that automates intelligence collection, processing, and integration with security infrastructure. It is a direct competitor to Cyware's Intel Exchange, serving similar enterprise and government customers with comparable TIP capabilities.
  • ThreatConnect: ThreatConnect offers a Threat Intelligence Operations Platform combining TIP and SOAR capabilities. It competes directly with Cyware's Intel Exchange and Orchestrate products, targeting enterprise security operations teams with similar intelligence-driven workflows.
  • EclecticIQ: EclecticIQ is a pure-play threat intelligence platform provider serving enterprises and governments, particularly in Europe. It directly competes with Cyware's Intel Exchange for TIP market share with similar intelligence aggregation and operationalization capabilities.
  • ThreatQuotient: ThreatQuotient provides a threat intelligence platform focused on threat operations and incident response, similar to Cyware's threat intelligence management approach. It targets enterprise SOC teams with intelligence-driven security operations capabilities.

Broad incumbents

  • Palo Alto Networks (Cortex XSOAR/XSIAM): Palo Alto Networks offers Cortex XSOAR for SOAR and XSIAM as an extended security operations platform that includes threat intelligence and response capabilities. As a broad incumbent, it competes with Cyware's Orchestrate and Respond products as part of a wider security portfolio.
  • Splunk SOAR: Splunk offers SOAR (formerly Phantom) capabilities within its broader security operations suite. As a broad incumbent, it competes with Cyware's Orchestrate SOAR platform by offering integrated orchestration within the Splunk SIEM ecosystem and broader data platform.
  • Microsoft Sentinel: Microsoft Sentinel is a cloud-native SIEM and SOAR platform integrated with Microsoft Defender and Azure ecosystems. It competes with Cyware's Intel Exchange and Orchestrate products, particularly for enterprises standardized on Microsoft security infrastructure.
  • Recorded Future: Recorded Future is a leading threat intelligence provider now owned by Mastercard. It competes with Cyware's threat intelligence and Digital Risk Protection offerings, with broader brand recognition and access to payment fraud intelligence.

Emerging players

  • Swimlane: Swimlane is an emerging SOAR vendor focused on security automation with low-code workflows and AI capabilities. It offers partial overlap with Cyware's Orchestrate product, particularly for enterprises seeking alternatives to legacy SOAR platforms.
  • Tines: Tines is an emerging security automation platform with a no-code workflow builder and strong developer adoption. It overlaps with Cyware's Orchestrate product for security orchestration use cases, with growing traction among enterprise security teams.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat6 records

Key risks6 records

Key highlights7 records

Customer concentration

Cyware social profiles

Digital presence

Cyware compliance and trust

Trust signal

Compliance6 records

Cyware financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Cyware leadership team

Management profile

Number of profiles

Profiles10 records

Cyware subsidiaries and ownership

Company hierarchy

Subsidiaries1 record

Cyware funding detail

Funding detail

Funding overview

Funding rounds5 records

Investors9 records

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Cyware M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Cyware

What does Cyware do?

Cyware provides a unified, AI-powered threat intelligence management platform (the Cyware Intelligence Suite) that automates ingestion, deduplication, enrichment, scoring, sharing, and operational actioning of threat intelligence for enterprise and government security operations. Core products include Cyware Intel Exchange (TIP), Cyware Orchestrate (SOAR), Cyware Respond (incident response), and Cyware Collaborate (threat intel sharing across ISACs, ISAOs, and CERTs), augmented by Cyware Quarterback AI and the Agentic AI Fabric of specialized cybersecurity agents.

Is Cyware a public or private company?

Cyware is a private company. It is classified as venture growth investor backed and is currently operating.

When was Cyware founded?

Cyware was founded in 2016. It employs 101 to 250 people.

Where is Cyware based?

Cyware is headquartered in Jersey City, United States, in the North America region.

How does Cyware make money?

Two revenue lines are on record. Subscription SaaS are the primary driver. The others are professional Services.

Who are Cyware's main competitors?

Direct peers on record are Anomali, ThreatConnect, EclecticIQ and ThreatQuotient. Broad incumbents are Palo Alto Networks (Cortex XSOAR/XSIAM), Splunk SOAR, Microsoft Sentinel and Recorded Future. Emerging players are Swimlane and Tines.

Does Cyware have an API?

Yes. Cyware provides APIs for integration with its platform products (Intel Exchange, Orchestrate, and Respond). The Cyware MCP Server enables AI agents to execute dynamic tasks via natural language commands using the Model Context Protocol standard. APIs are available for enterprise customers with specific minimum version requirements for Cyware Respond, Intel Exchange, and Orchestrate. Developer documentation is at techdocs.cyware.com.

What industry is Cyware in?

Cyware's product category is Cybersecurity Threat Intelligence Platform. Its primary akta.pro industry code is HDADAEAB, Extended Detection & Response (XDR), with a secondary code of HDAEANAJ, AI Application Enablement Platforms (Copilot/Agent Frameworks, SDKs). Its NAICS code is 51321 and its SIC code is 7372.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
IndustrialcyberCyware, WaterISAC partner to deliver AI-powered threat intelligence to U.S. water and wastewater utilitiesCyware and WaterISAC announced a partnership to deliver AI-powered threat intelligence to U.S. water and wastewater utilities. The collaboration aims to strengthen collective defense against cyberattacks on critical water infrastructure, with WaterISAC serving over 20,000 utilities. Cyware will enhance intelligence collection and response capabilities beyond manual processes.CyberScoopWaterISAC reckons with range of threats after summer of cyberattacksWaterISAC is addressing cyber threats to water systems, citing exposed OT, vulnerable PLCs, and poor hygiene at smaller utilities. The center announced a partnership with Cyware to share threat intelligence, while noting Iran, China, and Russia as potential attackers. It also highlighted integrators and insider threats as entry points.PR NewswireCyware and WaterISAC Join Forces to Strengthen Water Sector Cyber DefenseCyware and WaterISAC announced a partnership to provide AI-powered threat intelligence to water utilities, aiming to strengthen collective defense against cyberattacks on critical water infrastructure. The collaboration will enhance intelligence collection and response, reducing manual effort and enabling faster threat identification across the sector.IndustrialcyberCyware supports NRECA research to improve OT monitoring, threat detection across electric cooperativesCyware announced support for NRECA's DOE-funded effort to expand operational technology monitoring across electric cooperatives. The project standardizes data collection and sharing to improve threat detection and coordination among nearly 900 cooperatives. It aims to close the market gap for smaller utilities and enable automatic sharing of validated findings.PR NewswireCyware Supports NRECA on DOE-Funded Research to Advance Automated Collective Defense for Electric CooperativesCyware announced support for NRECA's DOE-funded research to expand operational technology monitoring across electric cooperatives. The initiative aims to standardize data collection and enable centralized analysis, improving threat detection and coordination. It will focus on closing the market gap for smaller, less-resourced utilities.B2B SaaS BlogCyware Labs Revenue 2024: $49.2M Est. ARR, $30M RaisedCyware Labs reported an estimated annual recurring revenue of $49.2 million in 2024, a significant increase from the $11.2 million recorded in 2020. The cybersecurity automation company has raised a total of $30 million in funding and currently employs approximately 276 people as of late 2024.IndustrialcyberCyware and Armis partner to deliver asset-centric threat intelligence with real-time asset visibility and agentic AICyware announced a strategic partnership with Armis from ServiceNow to deliver asset-centric threat intelligence operationalization, combining Armis' real-time asset visibility through its Centrix platform with Cyware's threat contextualization and workflow automation capabilities. The integration enables security teams to correlate asset profiles with global threat intelligence and automate responses based on real-time telemetry, shifting from reactive firefighting to proactive defense against agentic AI-driven threats. The partnership addresses the growing visibility gap created by proliferation of IoT, OT, and unmanaged devices in enterprise environments.MSSP AlertCyware partners with Armis to connect asset visibility with threat intelligenceCyware has partnered with Armis to integrate real-time asset intelligence with threat intelligence and automated security workflows through a combined offering that correlates threat feeds and attacker behavior with customer environment details. The partnership is designed to help security teams identify affected devices, reduce alert volume, and prioritize remediation work across IT, cloud, IoT, and OT environments. The integration addresses the common gap where asset inventories sit apart from threat intelligence and response tools, enabling analysts to work from unified data rather than connecting information manually.PR NewswireCyware Announces Partnership with Armis from ServiceNow to Deliver Asset-Centric Threat ContextCyware has announced a partnership with Armis from ServiceNow to deliver asset-centric threat intelligence operationalization by combining Armis' real-time asset visibility platform (Armis Centrix™) with Cyware's threat contextualization and workflow automation capabilities (Cyware Intelligence Suite). The integration enables security teams to correlate asset profiles against global threat feeds and automate responses based on real-time telemetry, shifting organizations from reactive firefighting to proactive, AI-driven defense. The collaboration addresses growing enterprise security challenges including sophisticated threat landscapes and the proliferation of IoT, OT, and unmanaged devices creating visibility gaps.YahooCyware Announces Partnership with Armis from ServiceNow to Deliver Asset-Centric Threat ContextCyware announced a partnership with Armis from ServiceNow on July 29, 2026, to integrate Armis Centrix™ with the Cyware Intelligence Suite for asset-centric threat intelligence operationalization. The collaboration combines Armis' real-time asset visibility with Cyware's AI-powered threat contextualization capabilities, enabling security teams to map global threat intelligence onto their specific asset landscapes and drive preemptive mitigation. The integration uses agentic AI to correlate asset profiles against global threat feeds and automate responses based on real-time telemetry.