Assured Information Security
A Rome, New York-based cyber R&D firm doing vulnerability research, hypervisor/cross-domain security, and applied cyber capability development under two decades of DoD and intelligence community contracts.
Visit Website ↗ + Add to CompareOverview
Assured Information Security (AIS) is a cybersecurity research and engineering firm headquartered in Rome, New York, founded in 2001 near the Air Force Research Laboratory (AFRL) at Griffiss. Rather than selling a packaged commercial product, AIS operates as an applied-research and services contractor: vulnerability research and reverse engineering, hypervisor and virtualization security, cross-domain solutions, cyber range development, and embedded technical staffing for the Department of Defense and the intelligence community.
AIS staffs cyber R&D and technical-support positions directly inside government programs — at AFRL, Fort Meade, Lackland Air Force Base, the Defense Cyber Crime Center (DC3), and the 55th Wing, among others — and holds prime-contractor status on GSA’s OASIS+ Total Small Business and OASIS+ Unrestricted contract vehicles, which let federal agencies procure its R&D and technical services directly.
The company’s two-decade tenure inside DoD and IC cyber programs is itself a form of evidence: sustained contract renewals in a security-cleared, relationship-driven procurement environment are hard to fake. At the same time, that business model means almost none of AIS’s actual work product is visible to a commercial buyer or independent tester — there is no public benchmark, customer review, or MITRE-style evaluation of an AIS deliverable, because its deliverables are classified or contract-restricted research rather than shrink-wrapped software.
For a CISO, AIS is not a vendor to evaluate for direct purchase; its relevance is indirect, through the applied research on things like hypervisor security and cross-domain data transfer that has quietly shaped both government and, over time, commercial security architecture.
Innovation Matrix Assessment
Steady long-run R&D cadence across DoD contracts (DARPA, AFRL, DC3) rather than rapid commercial product releases; evidence is contract-vehicle wins (GSA OASIS+) rather than product release velocity.
AIS delivers through embedded staff and custom R&D engagements, not a self-service or easily deployed product, so 'ease of adoption' doesn't map cleanly onto a commercial buyer; there is limited public evidence beyond government engagement structure.
Roughly $41.8M in estimated 2026 revenue and continued contract-vehicle wins (OASIS+ Total Small Business and Unrestricted) signal steady, not explosive, growth after more than two decades in business.
A long history of applied offensive/defensive research (rootkit research, hypervisor security, cross-domain solutions) documented in its own contract portfolio and program affiliations has shaped elements of DoD cyber doctrine over time.
Two decades of sustained DoD/IC contract renewals (AFRL, Fort Meade, DC3, 55th Wing) is evidence of retained institutional trust, though no independent third-party efficacy test (e.g., a MITRE ATT&CK-style evaluation) exists for a services/R&D firm of this kind.
Directly relevant to a narrow but critical niche — DoD and IC offensive/defensive cyber R&D — rather than to typical enterprise CISOs; commercial applicability is limited by the nature of its business.
Why CISOs Should Care
AIS isn't a vendor most enterprise CISOs buy from directly; its relevance is indirect, through applied research on hypervisor security, cross-domain solutions, and vulnerability discovery that has influenced both government and commercial security architecture over time.
What Makes It Different
AIS operates as an applied-research and services firm embedded directly inside DoD and IC programs, rather than shipping a packaged commercial security product.
The Matrix Verdict
62/100 — INCREMENTAL INNOVATOR
A credible, long-tenured DoD/IC cyber R&D contractor with a two-decade track record, but its work product is largely inaccessible to commercial buyers and doesn't lend itself to the kind of independent efficacy testing available for packaged security products.
Editorial Note: Claims vs. Verified Findings
Revenue and employee-count figures come from third-party data providers (PitchBook-derived estimates), not self-disclosed financials. DoD contract-vehicle wins (GSA OASIS+) and program affiliations (AFRL, DC3, 55th Wing) are independently documented through federal procurement records rather than vendor marketing claims.
Sources
Alternatives to Assured Information Security
Unknown Cyber Inc.
Malware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Synack Inc
A penetration-testing-as-a-service platform pairing a vetted researcher community with AI-driven attack surface discovery for continuous security validation.
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Cogent Security
Agentic AI platform that autonomously triages, investigates, and remediates vulnerabilities as a force multiplier for security teams.
Airlock Digital
Application allowlisting (deny-by-default) platform that blocks unapproved executables, scripts, and processes to prevent ransomware and malware execution.
ReversingLabs
Software supply chain security and binary analysis vendor that inspects compiled software and packages for malware and unauthorized…