Home  >  Companies  >  Remedio
Remedio
Cybersecurity platform providing automated device posture management to secure enterprise devices

Funding

$65.00M

2025

View PDF
Details
Headquarters
Tel Aviv
CEO
Tal Kollender
Website
Milestones
FOUNDING YEAR
2019

Valuation

Remedio closed its first institutional funding round in September 2025, raising $65 million in a Series A led by Bessemer Venture Partners, with participation from TLV Partners and Picture Capital.

The company, founded in 2019, had been entirely bootstrapped and profitable prior to this initial external capital raise. The funding is allocated to support Remedio's North American expansion and development of AI-driven product features.

Product

Remedio is an automated configuration management platform that monitors and resolves security misconfigurations across enterprise IT environments. The platform operates continuously across all laptops, servers, and cloud instances within an organization.

Deployed via lightweight agents or virtual appliances, Remedio inventories all Windows, macOS, and Linux devices in an environment upon installation. It evaluates thousands of configuration settings against established security frameworks such as CIS, NIST, and MITRE, presenting findings through a color-coded risk dashboard.

The platform's primary distinction is its autonomous remediation capabilities. Instead of merely identifying issues, Remedio can automatically resolve configuration problems at scale while accounting for operational dependencies to prevent disruptions to critical applications.

A rollback mechanism enables administrators to reverse changes instantly if necessary. The platform supports both cloud-based SaaS deployment and on-premises virtual appliances, accommodating air-gapped environments in sectors like defense and healthcare.

Remedio integrates with enterprise tools such as ServiceNow, Splunk, AWS Security Hub, SentinelOne, CrowdStrike, and Jira. It manages devices across Active Directory, Group Policy, Intune, and MDM settings, enabling centralized enforcement of security baselines.

AI-powered prioritization assigns scores to findings based on exploitability, business impact, and remediation effort, allowing security teams to address the most critical issues first.

Business Model

Remedio operates a B2B SaaS model with subscription pricing tied to the number of protected devices. The company charges $3-4 per device annually, with pricing adjusted based on deployment size and required functionality.

The platform is designed for enterprise security operations teams, CISOs, and IT administrators managing security configurations across large device fleets. Customers typically oversee thousands to tens of thousands of endpoints, making manual configuration management inefficient.

Revenue growth is driven by increases in device counts as customers add endpoints and expand coverage across their infrastructure. The platform's automated remediation and compliance reporting capabilities provide measurable value, encouraging broader adoption within existing customer organizations.

Remedio employs a hybrid deployment model that supports both cloud SaaS and on-premises installations. This approach enables the company to serve regulated industries requiring air-gapped environments, differentiating it from cloud-only competitors and expanding its addressable market.

The business benefits from high switching costs after deployment, as the platform becomes embedded in security operations and compliance workflows. Integration with existing security tools further enhances customer retention.

Competition

Platform consolidation players

Microsoft Defender Vulnerability Management, combined with Intune, represents a competitive threat due to its native Windows integration and bundled pricing. The platform integrates closely with Microsoft 365 environments and is incorporating AI-guided remediation capabilities.

CrowdStrike Falcon Exposure Management uses a single lightweight agent and adversary-driven risk scoring. The company is expanding into automated remediation and baseline enforcement to compete with specialized configuration management tools.

Palo Alto Networks Cortex XSIAM offers AI-based prioritization and playbook automation across network, endpoint, and cloud environments. These platforms compete by consolidating security operations to reduce tool sprawl.

Specialized automation tools

Automox, Tanium, and GYTPOL focus on automated patch management and configuration remediation. These competitors provide autonomous fixes with rollback capabilities, aligning with Remedio's core functionality.

ManageEngine and other endpoint management vendors include basic posture checking in their platforms, creating pricing pressure by bundling functionality. This forces specialized players to differentiate through advanced automation and cross-platform support.

Emerging AI-driven solutions

New entrants are integrating large language models and AI agents into configuration management workflows. These solutions aim to enable more intelligent remediation decisions and natural language interfaces for security operations teams.

The competitive landscape is increasingly favoring platforms that can demonstrate measurable reductions in mean time to remediation while maintaining operational stability across diverse IT environments.

TAM Expansion

Adjacent infrastructure categories

Remedio can expand its dependency-aware remediation engine to operational technology controllers, industrial IoT devices, and smart manufacturing equipment. A single modern factory typically manages over 40,000 unmanaged endpoints requiring security hardening.

Cloud and container configuration management is another potential expansion area. Kubernetes misconfigurations and container security issues exhibit patterns similar to traditional endpoint problems, enabling Remedio to apply its automated remediation approach to cloud-native environments.

Network infrastructure devices, API gateways, and cloud service configurations could also utilize the continuous monitoring and automated remediation methods Remedio currently applies to endpoints.

Compliance and regulatory expansion

New regulations, such as EU NIS2 and the Cyber Resilience Act, require secure-by-default configurations with continuous compliance evidence. Remedio could offer automated attestation, policy enforcement, and auditor dashboards as premium compliance modules.

Healthcare, financial services, and critical infrastructure sectors face increasing penalties for security misconfigurations. These industries benefit from Remedio's air-gap deployment options and instant rollback capabilities for high-priority environments.

Government and defense contractors require compliance frameworks and on-premises deployment models that align with Remedio's existing capabilities.

Geographic and market expansion

The Series A funding is allocated to North American market expansion, where enterprise cybersecurity spending continues to grow. Remedio's current customer base provides references for scaling within Fortune 500 organizations.

Mid-market companies and managed service providers represent underserved segments that could adopt lighter, multi-tenant versions of Remedio's platform. MSPs could resell configuration management services to smaller clients without internal security expertise.

European markets face increasing regulatory demands for cybersecurity controls, driving demand for automated compliance and configuration management solutions.

Risks

Platform competition: Microsoft, CrowdStrike, and Palo Alto Networks are incorporating automated configuration management into their security platforms, which could commoditize Remedio's core functionality. These competitors can package configuration management with endpoint detection, vulnerability scanning, and other security tools at pricing levels that may reduce the appeal of standalone solutions.

Operational complexity: Implementing automated remediation across diverse enterprise environments introduces risks of disrupting critical applications or causing system outages. High-profile incidents involving Remedio's automated fixes leading to business disruptions could undermine customer confidence and slow adoption, particularly in regulated industries where uptime is critical.

Market maturity: As configuration management becomes increasingly standardized and cloud providers enhance native security controls, demand for third-party remediation tools may decline. Organizations are showing a preference for security capabilities integrated into their existing infrastructure to minimize additional agents and management complexity.

DISCLAIMERS

This report is for information purposes only and is not to be used or considered as an offer or the solicitation of an offer to sell or to buy or subscribe for securities or other financial instruments. Nothing in this report constitutes investment, legal, accounting or tax advice or a representation that any investment or strategy is suitable or appropriate to your individual circumstances or otherwise constitutes a personal trade recommendation to you.

This research report has been prepared solely by Sacra and should not be considered a product of any person or entity that makes such report available, if any.

Information and opinions presented in the sections of the report were obtained or derived from sources Sacra believes are reliable, but Sacra makes no representation as to their accuracy or completeness. Past performance should not be taken as an indication or guarantee of future performance, and no representation or warranty, express or implied, is made regarding future performance. Information, opinions and estimates contained in this report reflect a determination at its original date of publication by Sacra and are subject to change without notice.

Sacra accepts no liability for loss arising from the use of the material presented in this report, except that this exclusion of liability does not apply to the extent that liability arises under specific statutes or regulations applicable to Sacra. Sacra may have issued, and may in the future issue, other reports that are inconsistent with, and reach different conclusions from, the information presented in this report. Those reports reflect different assumptions, views and analytical methods of the analysts who prepared them and Sacra is under no obligation to ensure that such other reports are brought to the attention of any recipient of this report.

All rights reserved. All material presented in this report, unless specifically indicated otherwise is under copyright to Sacra. Sacra reserves any and all intellectual property rights in the report. All trademarks, service marks and logos used in this report are trademarks or service marks or registered trademarks or service marks of Sacra. Any modification, copying, displaying, distributing, transmitting, publishing, licensing, creating derivative works from, or selling any report is strictly prohibited. None of the material, nor its content, nor any copy of it, may be altered in any way, transmitted to, copied or distributed to any other party, without the prior express written permission of Sacra. Any unauthorized duplication, redistribution or disclosure of this report will result in prosecution.