OnSystem Logic
Small application-hardening vendor building a non-bypassable, in-memory reference monitor for Windows endpoints to block trusted-tool abuse and memory-safety exploits.
Visit Website ↗ + Add to CompareOverview
OnSystem Logic builds application-hardening software for Windows endpoints centered on a single technical bet: that detection-based endpoint security will always lag attackers who abuse trusted, signed tools already present on a system. Its flagship product, OnSystem Defender, implements what the company calls a patent-pending in-memory application reference monitor that continuously validates what a running application is allowed to do, in a given execution context, before it’s allowed to do it, aiming to stop memory-safety exploits and living-off-the-land attacks that pass signature and behavioral detection.
Founded in 2015 and based in Baltimore, Maryland, OnSystem Logic has been funded primarily through non-dilutive channels, including a National Science Foundation Small Business Innovation Research (SBIR) grant that helped develop OnSystem Defender, along with early backing from Plug and Play and Maryland’s TEDCO. The University of Maryland is a disclosed customer. The company’s total disclosed funding is modest, around $350K across two rounds, consistent with a small, technically-focused team rather than a heavily venture-backed growth story.
The company’s non-bypassable execution-control approach is a genuinely different architecture from signature or behavior-based EDR, but OnSystem Logic remains a small player with limited public evidence of enterprise-scale deployment outside of grant-funded pilots and early adopters, competing in a market dominated by much larger endpoint security vendors.
Innovation Matrix Assessment
Development has been grant-funded and incremental since 2015; the core in-memory reference monitor concept appears stable rather than iterating through frequent major releases, likely reflecting the small team size.
With a very small disclosed team and funding under $500K, and only one named customer (University of Maryland) found publicly, operational scale and enterprise deployment evidence are limited.
No funding rounds, customer wins, or partnership announcements newer than the 2021 grant round were found, suggesting momentum has been slow or under-publicized.
A non-bypassable, in-memory execution reference monitor is architecturally distinct from signature- and behavior-based EDR, directly targeting the trusted-tool-abuse and living-off-the-land techniques that evade conventional detection.
The 'non-bypassable' claim is the vendor's own characterization; no independent red-team validation, MITRE ATT&CK evaluation, or third-party test results were found to substantiate it.
Memory-safety exploitation and abuse of legitimate signed tools are both persistent, well-documented attack patterns that most detection-first endpoint tools still struggle to fully close off.
Why CISOs Should Care
Offers a fundamentally different control point, execution-time validation rather than post-hoc detection, for the memory-safety and living-off-the-land techniques that routinely slip past conventional EDR.
What Makes It Different
Most endpoint vendors detect malicious behavior after the fact; OnSystem Logic's reference-monitor approach tries to make unauthorized execution structurally impossible rather than merely likely to be flagged.
The Matrix Verdict
43/100 — EMERGING / UNRANKED
A small, technically interesting endpoint-hardening vendor with a genuinely different architecture, but with thin public evidence of independent validation or enterprise-scale adoption beyond grant-funded early customers.
Editorial Note: Claims vs. Verified Findings
OnSystem Logic's characterization of OnSystem Defender as 'non-bypassable' is a vendor claim with no independent third-party testing found to confirm it. The NSF SBIR grant funding and University of Maryland customer relationship are independently corroborated through public grant records and the company's own disclosures.
Sources
Alternatives to OnSystem Logic
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…