Skip to content

Vali Cyber

A Charlottesville, Virginia startup building ZeroLock, a VMware-certified runtime security platform that protects ESXi and Linux hypervisors from ransomware and exploits at the virtualization layer.

Visit Website ↗ + Add to Compare
67/100Incremental Innovator

Overview

Vali Cyber builds ZeroLock, a runtime security platform aimed squarely at a gap most endpoint security vendors do not cover: the Linux hypervisor layer itself, starting with VMware ESXi. Mass ransomware campaigns like ESXiArgs have repeatedly shown that encrypting a hypervisor directly – rather than the individual guest VMs running on it – can take down an entire virtualized data center in one move, and traditional EDR agents generally cannot run inside ESXi’s locked-down environment to stop it.

ZeroLock combines exploit prevention, virtual patching, and behavioral runtime controls to detect and block ransomware and exploit activity at the hypervisor layer, with automated rollback to restore affected data. Its most concrete technical credential is that it is digitally signed and certified by VMware and ships as a standard VIB (vSphere Installation Bundle) deployed through vCenter like any other ESXi update – meaning VMware itself has validated the packaging and signing chain for software that runs at this privileged layer, a real, checkable technical bar that most competitors in adjacent spaces have not cleared.

Founded in 2020 and based in Charlottesville, Virginia, Vali Cyber is a small company (roughly 35 employees) that raised a $15 million seed round and, per a September 2025 announcement, closed a further growth round to meet what it describes as rising demand for hypervisor ransomware protection. It has also landed a notable distribution partnership with Rimini Street, which now offers an advanced hypervisor security solution built on ZeroLock to its own third-party software support customers – an independent commercial validation of the technology beyond Vali Cyber’s own marketing.

Innovation Matrix Assessment

Innovation Velocity 7/10

Vali Cyber shipped what it and independent coverage (VentureBeat) describe as the first runtime security platform for ESXi, then followed with a formal VMware-signed VIB release and a commercial embedding deal with Rimini Street - a fast progression from early access to certified, distributable product in roughly two years.

Operational Value 6/10

A roughly 35-person team has managed to get software certified and digitally signed by VMware for deployment inside ESXi - a high technical and process bar - and closed a distribution partnership with an established third-party support vendor (Rimini Street), indicating solid execution relative to its size.

Market Momentum 7/10

A $15M seed round followed by a September 2025 growth round explicitly tied to "rising demand for hypervisor ransomware protection," plus the Rimini Street go-to-market partnership, are concrete, independently reported momentum signals rather than self-reported growth claims alone.

Category Disruption 7/10

Protecting the hypervisor layer itself, rather than the guest VMs running on it, addresses a documented and exploited blind spot (mass ESXi ransomware campaigns like ESXiArgs) that mainstream EDR/XDR agents structurally cannot reach because they cannot run inside ESXi's restricted environment - a genuinely novel category rather than an incremental feature.

Real-World Efficacy 6/10

VMware's own certification and digital signing of ZeroLock as a standard VIB is an independent, checkable technical validation (not just a vendor claim), and Rimini Street's decision to build a commercial offering on top of ZeroLock is a real third-party business validation; no independent third-party red-team or MITRE-style evaluation results were found in this research.

Enduring Relevance 7/10

Ransomware attacks against ESXi and other Linux hypervisors have been a live, well-documented attack pattern causing mass simultaneous VM encryption across data centers, making hypervisor-layer runtime protection a genuinely current and underserved CISO priority rather than a theoretical one.

Why CISOs Should Care

Any organization running production workloads on VMware ESXi or other Linux hypervisors has a real, demonstrated exposure to hypervisor-level ransomware that standard endpoint agents cannot address, and Vali Cyber is one of the few vendors with a VMware-certified product built specifically to close that gap.

What Makes It Different

Unlike EDR/XDR vendors that protect guest operating systems and workloads, Vali Cyber operates at the hypervisor layer itself and has the VMware certification and signed-VIB distribution model to prove it can run there safely - a technical foothold most endpoint security competitors do not have.

The Matrix Verdict

67/100 — INCREMENTAL INNOVATOR

A focused, technically credible startup addressing a real and increasingly exploited gap in hypervisor security, backed by genuine third-party validation in the form of VMware certification and a Rimini Street distribution deal. Worth serious evaluation for any organization with significant ESXi/Linux hypervisor exposure; as a young, small company it still warrants normal startup-vendor diligence on long-term viability.

Editorial Note: Claims vs. Verified Findings

VMware's certification/signing of the ZeroLock VIB and the Rimini Street partnership are independently verifiable through VMware's and Rimini Street's own public materials, not just Vali Cyber's claims, and are treated as verified here. Specific detection-rate or performance statistics referenced in Vali Cyber's own marketing were not independently tested or confirmed in this research.

Sources