Skip to content

Invary

Invary is a Kansas-based startup building runtime integrity verification for Linux and Windows kernels using technology exclusively licensed from the NSA, designed to detect stealthy in-memory compromise that endpoint agents miss.

Visit Website ↗ + Add to Compare
53/100Incremental Innovator

Overview

Invary, based in Lawrence, Kansas, builds runtime integrity attestation technology that continuously verifies whether a running operating system kernel has been tampered with — a detection category distinct from conventional endpoint detection and response, which mostly inspects processes and files rather than live kernel and memory state. The company’s core technology is exclusively licensed from the National Security Agency, and Dr. Patricia Muoio, former Chief of the NSA’s Trusted Systems Group and a General Partner at investor SineWave Ventures, sits on Invary’s board.

The product line currently covers Linux runtime integrity in production, with Windows kernel runtime integrity and eBPF-based verification under active development as of the company’s 2025 seed round. Invary also supports verification of Trusted Execution Environments such as AMD’s SEV-SNP, targeting confidential-computing and cloud workload use cases where proving a system hasn’t been compromised at runtime matters as much as preventing initial compromise.

Invary raised a $1.85 million pre-seed round in 2023 led by Flyover Capital, followed by a $3.5 million seed round in early 2025 from SineWave Ventures, Flyover Capital, Hyperlink Ventures, and KCRise Fund. The NSA technology-licensing origin is a genuine differentiator worth noting, though it is also effectively a single-source technology dependency, and as an early-stage company Invary has not yet published independent third-party validation of detection efficacy against real-world rootkit or kernel-compromise techniques.

Innovation Matrix Assessment

Innovation Velocity 6/10

Invary moved from Linux-only runtime integrity to actively developing Windows kernel and eBPF-based verification within about two years of its pre-seed round, a reasonable pace for a deep-tech security startup, per its own 2025 seed announcement.

Operational Value 4/10

As an early-stage company with Linux-only general availability and Windows/eBPF support still in development, operational maturity and breadth of deployment options remain limited relative to established EDR/XDR platforms.

Market Momentum 6/10

Invary nearly doubled its total raised capital between a 2023 pre-seed ($1.85M) and 2025 seed ($3.5M) round from a credible syndicate including a former NSA Trusted Systems Group chief as board advisor, a real momentum signal even at small dollar amounts.

Category Disruption 7/10

Runtime kernel-integrity attestation is a meaningfully different detection layer from conventional file/process-based EDR, addressing stealthy in-memory and rootkit-style compromise that most endpoint agents are not designed to catch; the NSA-licensed technology origin supports the technical credibility of this approach.

Real-World Efficacy 3/10

No independent third-party test of Invary's detection efficacy against real rootkits or kernel-level implants has been published; efficacy here rests on the plausibility of NSA-derived technology and named technical advisors rather than verified results.

Enduring Relevance 6/10

Kernel-level and in-memory compromise (used in advanced persistent threat and nation-state tradecraft) is a real, underserved detection gap for security teams focused mainly on file- and process-level EDR, giving Invary's category clear relevance for high-security environments.

Why CISOs Should Care

CISOs in defense, critical infrastructure, or cloud environments concerned about advanced adversaries evading conventional EDR get a detection layer specifically aimed at kernel and runtime tampering that most endpoint tools do not check.

What Makes It Different

Invary's technology is exclusively licensed from the NSA rather than developed independently, and its detection target (live kernel/memory integrity) differs structurally from the file-and-process focus of mainstream EDR vendors.

The Matrix Verdict

53/100 — INCREMENTAL INNOVATOR

A technically differentiated, credibly-backed early-stage startup addressing a real detection gap, but still pre-scale with unproven independent efficacy and coverage limited mostly to Linux as of its most recent funding round.

Editorial Note: Claims vs. Verified Findings

The NSA exclusive-license claim and board advisor background (former NSA Trusted Systems Group chief) are corroborated by independent press coverage (SecurityWeek, PR Newswire) rather than solely vendor marketing. Detection efficacy and any specific threat-catch claims on Invary's own site are vendor-sourced and not independently verified here.

Sources