CYSEC
CYSEC builds ARCA Trusted OS, a confidential-computing platform that protects containerized workloads and data-in-use for critical infrastructure, defense, and satellite/ground-segment systems.
Visit Website ↗ + Add to CompareOverview
CYSEC is a Swiss confidential-computing vendor that spun out of the EPFL Innovation Park in Lausanne in 2018, building on research incubated at Switzerland’s Cyber-Defence Campus. Its core product, ARCA Trusted OS, is a software-based confidential-computing layer that protects containerized workloads, applications, and data-in-use — the gap left when encryption-at-rest and encryption-in-transit are solved but the data still has to be decrypted to be processed. That gap matters most in industries where the workload itself can’t be trusted to the underlying cloud or ground infrastructure operator: defense, critical infrastructure, healthcare, and increasingly, space.
Where CYSEC has carved out real differentiation is applying confidential computing to satellite and ground-segment infrastructure — protecting the software and data running in satellite payloads, ground stations, and the cloud backends that process downlinked data. It backs this focus with CYSAT, which it created and runs as one of the larger European conferences dedicated specifically to space cybersecurity, giving it an unusual amount of visibility and credibility in a niche that most cybersecurity vendors don’t touch.
The company is small — reported at roughly 35 employees across France, Switzerland, Italy, and the UAE — and has raised a modest ~$7.6M from investors including Karista and Linebreak, positioning it as an early-stage specialist rather than a scaled platform vendor. For CISOs, CYSEC is a narrow-but-deep bet: relevant specifically to organizations running sensitive containerized workloads on infrastructure they don’t fully control, particularly in space, defense, and critical-infrastructure contexts, rather than a general-purpose cloud security tool for mainstream enterprise IT.
Innovation Matrix Assessment
CYSEC has moved from a general confidential-computing pitch to a specific, defensible niche (satellite and ground-segment confidential computing) within a few years of founding, and built out a three-part product line (ground/cloud, satellite data links, embedded systems). That's meaningful product focus for a company this size, though the customer-facing evidence of shipping velocity is limited to vendor materials.
A roughly 35-person company operating across four countries (France, Switzerland, Italy, UAE) since 2018 — old enough to be past the earliest startup risk but small enough that operational resilience is a real question if a founder or key technical lead departs. No evidence of profitability or scaled commercial operations was found.
CYSEC has built genuine ecosystem momentum by creating and running CYSAT, a dedicated European space-cybersecurity conference, which is an unusual and credible way for a small vendor to build category visibility. Funding has been modest (~$7.6M total) with no large recent round found, which tempers the momentum picture on the capital side.
Confidential computing for space and ground infrastructure is a genuinely underserved niche — most cybersecurity vendors do not touch satellite payload or ground-station software security, and CYSEC's focus there (rather than competing head-on in mainstream cloud confidential computing against hyperscaler-native offerings) is a differentiated bet on an emerging attack surface.
No independent third-party evaluation, penetration test result, or named customer case study was found publicly — efficacy claims here rest on CYSEC's own product documentation and its research pedigree from Switzerland's Cyber-Defence Campus and EPFL. That academic lineage is a positive signal but not the same as verified operational efficacy.
Satellite and space infrastructure is a fast-growing, historically under-secured attack surface as commercial and government reliance on low-earth-orbit constellations grows, and confidential computing for data-in-use is a recognized gap in most organizations' encryption strategy. CYSEC sits at the intersection of both trends.
Why CISOs Should Care
If your organization operates or depends on satellite, ground-station, or other infrastructure you don't fully control, CYSEC addresses a real and largely unaddressed gap: protecting the workload itself while it's running, not just the data around it.
What Makes It Different
Most confidential-computing vendors target general cloud workloads; CYSEC has deliberately specialized in space and ground-segment infrastructure, backed by its own industry conference (CYSAT), giving it a defensible niche rather than competing directly with hyperscaler confidential-computing offerings.
The Matrix Verdict
55/100 — INCREMENTAL INNOVATOR
A small, academically-grounded specialist with a genuinely differentiated niche rather than broad market traction. Worth evaluating specifically for space, defense, or critical-infrastructure confidential-computing needs; not yet proven at the scale or with the independent validation that would support a broader recommendation.
Editorial Note: Claims vs. Verified Findings
Independently verified: founding year and EPFL Innovation Park / Cyber-Defence Campus origin (multiple independent press sources), and CYSEC's authorship of the CYSAT conference. Vendor-sourced and not independently verified: employee count (~35), the ~$7.6M funding figure (drawn from startup-tracking databases rather than a primary funding announcement), and all product-efficacy claims, since no independent audit or named customer deployment was found.
Sources
Alternatives to CYSEC
Wiz
Agentless, graph-based cloud security platform that maps multi-cloud risk end-to-end, now owned by Google after a record $32B…
Chainguard
Provides hardened, minimal, continuously-rebuilt container images and software packages to eliminate vulnerabilities before they reach production.
Microsoft Defender for Cloud
Microsoft's built-in cloud-native application protection platform, unifying CSPM, workload protection, and DevOps security natively across Azure, AWS, and…
Obsidian Security
Obsidian Security provides a SaaS security posture management (SSPM) platform that detects identity-centric threats and misconfigurations across enterprise…
Sysdig
The company behind Falco, the CNCF's runtime security standard, offering an eBPF/kernel-level CNAPP built on live syscall-based threat…
Upwind Security
Fast-growing, venture-backed CNAPP startup combining agentless scanning with eBPF runtime sensors for real-time cloud and AI workload risk…