Skip to content

BUFFERZONE

Endpoint-native containment and isolation software that traps risky browsing, email, and file activity in a virtual container without relying on the cloud.

Visit Website ↗ + Add to Compare
43/100Emerging / Unranked

Overview

BUFFERZONE (formerly Trustware) makes endpoint containment software that isolates risky content, such as web browsing sessions, email attachments, downloads, and removable-media files, inside a virtual container on the endpoint itself, rather than relying on cloud sandboxing or signature-based detection. The approach, which the company calls Protection by Containment, lets untrusted content run in a segregated environment where it cannot touch the underlying operating system, file system, or corporate network until it is either disarmed or explicitly released as safe.

Founded in 2014 and based in Tel Aviv, Israel, BUFFERZONE is a small, self-funded Israeli vendor with roughly $10 million in disclosed lifetime funding. Its Safe Workspace suite bundles containment with on-device, cloud-independent anti-phishing detection, targeting sectors such as financial services, government, and healthcare where sensitive data cannot leave the endpoint and cloud-dependent isolation tools raise data-residency or connectivity concerns.

The company’s differentiation is architectural: because containment and phishing analysis run entirely on the endpoint rather than routing traffic through a cloud proxy, BUFFERZONE avoids the latency, bandwidth, and data-sovereignty tradeoffs of cloud-based remote browser isolation vendors, at the cost of being a much smaller and less broadly deployed player than those cloud-first competitors.

Innovation Matrix Assessment

Innovation Velocity 4/10

The company has steadily added capabilities such as on-device anti-phishing to its containment suite, but public release cadence and roadmap visibility are limited for a vendor of this size.

Operational Value 4/10

A small team (roughly a dozen to a few dozen employees) with about a decade of continuous operation and deployments in financial and government sectors, but no disclosed customer count or revenue scale.

Market Momentum 3/10

Lifetime disclosed funding is roughly $10M with no recent raise reported, and the company has not published customer growth figures, suggesting slow, steady rather than fast-growing momentum.

Category Disruption 5/10

The endpoint-native, cloud-independent containment architecture is a genuinely different approach from cloud-based remote browser isolation, appealing to data-sovereignty-sensitive customers, though the category itself is not new.

Real-World Efficacy 5/10

The company has won industry recognition (including an innovation award for its containment approach) and cites deployments in the financial sector, but there are no independently published third-party test results or named customer breach-prevention case studies.

Enduring Relevance 5/10

Endpoint isolation remains a relevant complementary control against ransomware, zero-days, and phishing-delivered payloads, particularly for regulated organizations that cannot route sensitive browsing through third-party clouds, though it competes with much larger cloud isolation vendors.

Why CISOs Should Care

Offers a cloud-independent way to contain browser- and email-delivered threats for organizations with strict data-residency or connectivity constraints that rule out cloud-based isolation tools.

What Makes It Different

Runs containment and phishing detection entirely on the endpoint rather than routing traffic through a cloud proxy, avoiding the latency and data-sovereignty tradeoffs of cloud remote browser isolation vendors.

The Matrix Verdict

43/100 — EMERGING / UNRANKED

A niche but technically credible endpoint containment vendor whose cloud-independent architecture serves a real, if narrow, need; scale and independent proof points remain modest relative to larger isolation competitors.

Editorial Note: Claims vs. Verified Findings

Founding year, HQ, and approximate funding are corroborated by multiple independent sources (Crunchbase, PitchBook, CB Insights). Specific efficacy claims (threat prevention rates, 'ironclad protection' language) are vendor marketing and are not independently verified in this research.

Sources