Semperis

Identity AccessDetection Response also known as Cloudify D.R. Technologies Ltd

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2013
Last updated 2026-09-04

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Semperis sells software that protects Active Directory, Entra ID and Okta, and its portfolio also carries professional incident response services for the moments those systems fall over. TechCrunch names Lenovo, Sanofi, United Airlines, Starbucks and Hertz among its customers, and a June 2024 round of $125 million from J.P. Morgan and Hercules Capital, part equity and part debt, valued it above $1 billion. Its Purple Knight assessment tool is free to download, and CISA lists it among no-cost cybersecurity services while stating that it endorses no commercial product. Semperis states ISO 27001 certification and SOC 2 Type II for its cloud services, and says United States federal authorization is still ahead of it. It fits an enterprise whose operations stop when the directory does.

Sourced Details

Description Semperis protects and recovers the enterprise identity systems that everything else authenticates against, covering Active Directory, Entra ID, and Okta. Its products span posture assessment, threat detection and response, forest recovery, and cyber crisis coordination. [f1]
Founded 2013 [f2]
HQ Hoboken, New Jersey, United States [f3]
Latest funding $125M equity and debt from J.P. Morgan and Hercules Capital at over $1B valuation (Jun 2024) [f3]

Products

Product What it does
Directory Services Protector Monitors Active Directory and Entra ID for risky changes, attack patterns, and service account exposure, and can roll back changes it flags.
Active Directory Forest Recovery Automates recovery of a whole Active Directory forest to a clean state, restoring to any hardware and separating the directory from the operating system it ran on.
Disaster Recovery for Entra Tenant Backup and recovery for Entra ID tenant resources, with hosted storage, aimed at shortening downtime after a tenant-level incident.
Recovery for Okta Continuous backup and recovery for Okta tenants, including monitoring of changes to what has been backed up.
Identity Runtime Protection Attack pattern detection for identity activity as it happens, listed alongside Directory Services Protector on the platform.
Lightning Intelligence Cloud-delivered posture assessment and attack path management for Active Directory and Entra ID, run continuously rather than as a point-in-time scan.
Delegation Manager for AD Manages Active Directory delegation so administrators can find and remove permissions that grant more privilege than a role needs.
Migrator for Active Directory Migrates and consolidates Active Directory forests and domains while assessing the security posture of both the source and the destination.
Ready1 Crisis management platform that coordinates decisions, communication, and task assignment across teams during a cyber incident.
Purple Knight Free assessment tool that scans Active Directory, Entra ID, and Okta against a catalog of security indicators and returns prioritized remediation guidance.
Forest Druid Community tool that discovers attack paths leading to Tier 0 assets in Active Directory.

Matrix Coverage

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Purple Knight and Lightning Intelligence assess identity posture, Directory Services Protector detects and rolls back attacks on Active Directory and Entra ID, and Active Directory Forest Recovery restores a compromised forest. These capabilities are mapped to the Cyber Defense Matrix. [f1]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 28 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 The buyers, on the one analyst description in the record, sit in large enterprises and regulated industries, and the record quantifies how widespread the dependency is rather than what an outage costs. TechCrunch reports that Active Directory is used by more than 90 percent of Fortune 1000 companies, calls it a giant target, and describes NotPetya as one of the most devastating attacks in cyber history. The one recovery-impact figure, Maersk's nine days, was supplied by Semperis to SecurityWeek, so the impact side of the case is vendor-asserted. [s6, s8, s14]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 Semperis publishes concrete mechanism detail on its own pages: recovery to any physical or virtual hardware, restoring only what a server role needs from a clean operating system, object-level restore, and detection drawn from the Active Directory replication stream. The external check that the next rung asks for is not in the reviewed record. CSO Online describes the migration product but sources its technical claims to a Semperis manager, and no independent evaluation, benchmark, or inspectable implementation appears. [s5, s3, s13]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 Semperis dates its origin to 2013, as TechCrunch and Calcalist both report, so the reviewed record supplies one kind of timing signal rather than several. Help Net Security relayed in 2022 that Gartner categorizes Directory Services Protector as identity threat detection and response, which is an analyst category note four years old. KuppingerCole publishes a current vendor profile placing Semperis in directory and identity system resilience. No dated buyer-side signal of another kind, such as budget movement or a regulatory driver, appears in the reviewed record within the last year. [s9, s14, s6, s7]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 Mickey Bresman, Guy Teverovsky and Matan Liberman hold the top jobs on the company's current leadership page, and Calcalist and Help Net Security both name them as the founders. Calcalist, interviewing Liberman, reports Teverovsky arriving from Microsoft disaster-recovery consulting, and says Semperis was selected the most promising Israeli startup of 2023. SecurityWeek described two products shipping by 2020, and TechCrunch reports a 2024 executive bench hired out of established cyber companies. [s7, s9, s8, s6, s2]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 5/5 Traction is corroborated outside the company and at scale. TechCrunch names Lenovo, Prime Healthcare, Sanofi, United Airlines, Starbucks and Hertz as customers covering some 100 million user identities. Calcalist reports more than 1,000 organizations including government agencies and over a quarter of the 100 largest United States companies. KuppingerCole publishes a vendor profile, and Altice Portugal's chief security officer is quoted by name on Semperis' own site about buying the recovery product. [s6, s12, s14, s1]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 Capital is proportional to the motion and shipping is visible, from the two products SecurityWeek recorded in 2020 to a platform and a services practice today, but efficiency itself is unconfirmed. The $100 million annual recurring revenue figure comes from Semperis' own newsroom. SecurityWeek carried the company saying it had been profitable for six quarters, and that was 2020, with no later margin or growth efficiency measure on record. TechCrunch reports the 2024 round taking debt alongside equity, which is a capital choice rather than a confirmed result. [s8, s2, s6, s3, s14]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 4/5 Outside parties place Semperis without needing its help, and they place it the same way. SecurityWeek called it an enterprise identity protection company in 2020, TechCrunch called it a specialist in Active Directory security in 2024, Help Net Security relayed Gartner's identity threat detection and response categorization, and KuppingerCole files it under directory and identity system resilience. Buyers reaching for Active Directory protection know which shelf this sits on. [s8, s6, s9, s14]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Microsoft publishes Active Directory and Entra ID, so the platform holder is also the party best placed to absorb this. Real friction exists: the product wires into recovery drills against a replica forest and into Cohesity's backup workflow, and Semperis contrasts its automation with a 28-step manual Microsoft process. That contrast is Semperis' own characterization, and the reviewed record shows no accumulated asset or procurement position that bundling could not eventually match. [s5, s6, s16]
Business Risks Microsoft could automate Active Directory forest recovery in the platform itself, which would remove the specific gap Semperis' recovery pitch is built against…
  • Microsoft could automate Active Directory forest recovery in the platform itself, which would remove the specific gap Semperis' recovery pitch is built against.
  • The FedRAMP authorization Semperis says it is targeting for 2026 could slip, leaving its federal solutions page advertising a practice against a credential the same page says it does not yet hold.
  • The Active Directory install base TechCrunch puts at more than 90 percent of Fortune 1000 companies could shrink as enterprises move to cloud-only identity, faster than the Entra ID and Okta lines grow.
  • The 2024 financing included debt as well as equity, so a slowdown in growth would meet fixed repayment obligations rather than only diluted ownership.
  • Purple Knight is downloadable by anyone, competitors included, so a rival can run it and see which conditions Semperis flags without buying anything.
  • Cohesity announced an identity resilience offering powered by Semperis, so part of the route to market runs through a partner that also sells its own data protection platform.
Problem & Market The problem has an independent measure and a vendor-supplied one, and they are worth telling apart. TechCrunch reports that Active Directory, the Microsoft directory service, is used by more than 90 percent of Fortune 1000 companies, calls it a giant target for malicious hackers, and describes NotPetya as one of the most devastating attacks in cyber history. SecurityWeek publishes a nine-day Maersk recovery figure, and its own article says Semperis supplied that example. KuppingerCole files Semperis under directory and identity system resilience and describes its products and professional services as being for large enterprises and regulated industries. Semperis puts the dependency the same way, that every user, workload and agent relies on identity providers like Active Directory, Entra ID and Okta. What the record does not settle is how much of that spending is addressable by a specialist rather than absorbed by the platform. Active Directory belongs to Microsoft, and no source in this record measures how many enterprises buy separate protection for it…

The problem has an independent measure and a vendor-supplied one, and they are worth telling apart. TechCrunch reports that Active Directory, the Microsoft directory service, is used by more than 90 percent of Fortune 1000 companies, calls it a giant target for malicious hackers, and describes NotPetya as one of the most devastating attacks in cyber history. SecurityWeek publishes a nine-day Maersk recovery figure, and its own article says Semperis supplied that example.

KuppingerCole files Semperis under directory and identity system resilience and describes its products and professional services as being for large enterprises and regulated industries. Semperis puts the dependency the same way, that every user, workload and agent relies on identity providers like Active Directory, Entra ID and Okta.

What the record does not settle is how much of that spending is addressable by a specialist rather than absorbed by the platform. Active Directory belongs to Microsoft, and no source in this record measures how many enterprises buy separate protection for it. [s6, s8, s14, s1]

Product Capabilities Semperis sells a portfolio across four jobs: assess posture, detect attacks, recover the directory, and run the crisis…

Semperis sells a portfolio across four jobs: assess posture, detect attacks, recover the directory, and run the crisis. Purple Knight and Lightning Intelligence do the assessment, Active Directory Forest Recovery rebuilds a compromised forest, and Ready1 coordinates the humans during an incident.

Directory Services Protector does the detection. It covers prevention, detection and response across Active Directory and Entra ID, and CSO Online describes it tracking changes and, together with the recovery product, rolling back unintended ones. The recovery product carries the most specific mechanism. Semperis describes technology it calls patented that separates Active Directory from the operating system underneath, so a restore from an infected backup does not carry the malware back, and it recovers to physical or virtual hardware without matching the original. Directory Services Protector draws on several data sources including the Active Directory replication stream, which Semperis says gives it sight of attacks that security monitoring platforms miss.

Purple Knight is free. It scans Active Directory, Entra ID and Okta against a published set of security indicators, and CISA lists it among no-cost cybersecurity tools and services while stating plainly that it endorses no commercial product. Forest Druid, which Semperis calls a community tool, discovers Tier 0 attack paths in Active Directory. [s3, s5, s4, s10, s1, s13]

Competitive Positioning The party that supplies what Semperis protects is Microsoft…

The party that supplies what Semperis protects is Microsoft. It publishes Active Directory and Entra ID, and Semperis' own pitch is framed against a Microsoft artifact, the 28-step manual recovery process it says buyers are otherwise stuck with. A vendor whose argument is that the platform holder's own procedure is unworkable depends on that staying true.

Against general backup vendors the separation is cleaner. Semperis argues that data protection products back up domain controllers as servers rather than recovering the directory as a system, which is a distinction a buyer can test. Cohesity, one of those vendors, announced an offering it calls Cohesity Identity Resilience powered by Semperis, and supports managing Active Directory backups from its own dashboard.

What the reviewed sources do not establish is which specialists enterprises choose between when they shortlist. No independent comparison of Semperis against a named rival appears in this record. [s5, s6, s1]

Go-to-Market & Traction The customer evidence is unusually specific for a private company…

The customer evidence is unusually specific for a private company. TechCrunch names Lenovo, Prime Healthcare, Sanofi, United Airlines, Starbucks and Hertz, covering some 100 million user identities. Calcalist reported in February 2026 that Semperis serves more than 1,000 organizations, including government agencies and over a quarter of the 100 largest United States companies.

Distribution runs through partners and a free tool. Semperis describes a channel sales approach and gives partners the free assessment tools, and Purple Knight is downloadable from its own page. CISA lists Purple Knight among no-cost tools and services for audiences that include federal, state, local and tribal government.

No price appears on any reviewed page. CSO Online reported that Semperis did not disclose pricing or a release date for the software-as-a-service version of its migration product. [s6, s12, s10, s13, s1]

Team & Credibility The founders are still running the company…

The founders are still running the company. Calcalist reports Mickey Bresman, Guy Teverovsky and Matan Liberman founding Semperis in 2013, with Teverovsky arriving from Microsoft disaster-recovery consulting work and Bresman from a recovery consulting business, and Help Net Security names the same three. Liberman leads the Tel Aviv operation.

The start date splits across the sources. Calcalist's 2024 article says 2013, TechCrunch says the company has been around since 2013 and began offering services in 2015, and Calcalist's 2026 article says 2015. The difference is founding against first commercial delivery, and the reader should read any age claim about Semperis with that gap in mind.

Around them sits a hired bench and an advisory roster. TechCrunch reports Jeff Bray, Mike DeGaetano and Annabel Lewis joining in 2024 out of established cyber companies as the company positioned for a public offering. Semperis lists General David Petraeus, a partner at KKR and former director of the CIA, as a strategic advisor.

The advisory names are a signal about access rather than about engineering. What the independent record supports is that the same three people who identified the recovery problem in the 2010s have shipped against it since, which SecurityWeek was already describing in 2020. [s7, s9, s6, s2, s8]

Trust Readiness Semperis states the two attestations an enterprise buyer expects and names what it does not yet hold. Its federal page records ISO 27001:2013 certification and SOC 2 Type II certification for its cloud-based services, naming Disaster Recovery for Entra Tenant. Federal authorization is stated as work in progress rather than achieved. The same page says Semperis is on target to secure FedRAMP authorization in 2026, working with a third-party assessment organization and seeking agency sponsorship, and that Common Criteria certification is being pursued and a NIST SP 800-171 gap analysis is under way. Nothing in the reviewed record is independently inspectable. A probe of trust.semperis.com on 2026-09-04 redirected to a customer community login, and no certificate or audit report was found on any probed surface, so the attestations rest on the company's own statement of them…

Semperis states the two attestations an enterprise buyer expects and names what it does not yet hold. Its federal page records ISO 27001:2013 certification and SOC 2 Type II certification for its cloud-based services, naming Disaster Recovery for Entra Tenant.

Federal authorization is stated as work in progress rather than achieved. The same page says Semperis is on target to secure FedRAMP authorization in 2026, working with a third-party assessment organization and seeking agency sponsorship, and that Common Criteria certification is being pursued and a NIST SP 800-171 gap analysis is under way.

Nothing in the reviewed record is independently inspectable. A probe of trust.semperis.com on 2026-09-04 redirected to a customer community login, and no certificate or audit report was found on any probed surface, so the attestations rest on the company's own statement of them. [s16, s15]

Competitors Microsoft, Cohesity…
Company Relationship Note Compare
Microsoft adjacent Publishes Active Directory and Entra ID, the systems Semperis protects and restores, so it holds the platform Semperis' products sit alongside. N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product.
Cohesity adjacent Sells data protection into the same recovery budget, and also partners with Semperis on an offering Cohesity markets as Cohesity Identity Resilience.

Add analyzed competitors to compare them side by side with Semperis.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 14 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Semperis sells more than software. Alongside the products it runs a breach preparedness and response team that works directory incidents directly, and KuppingerCole lists professional incident response among what Semperis delivers. The rest is thinner. Semperis states it holds ISO 27001 and SOC 2 Type II for its cloud services and says federal authorization is still ahead of it. Its own pages call the recovery technology patented, but no granted patent appears in the reviewed record. Semperis also sits beside the directory rather than inside the login path, so a customer who removes it keeps authenticating. The services practice is the strongest differentiated asset the reviewed record documents.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 2/3 Semperis sells code and expertise together. Its own pages describe a breach preparedness and response team that runs posture assessments, works forensic investigations and answers emergencies around the clock, and KuppingerCole lists professional incident response services alongside the products. The portfolio combines software with professional judgment rather than selling that judgment as the product, so this sits between the two.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 The mechanism is documented and the exit is not sized. Recovery drills, backup schedules into Azure storage and an isolated test forest accumulate operational practice around the product, and Cohesity customers can route Active Directory backups through the Cohesity dashboard. The cited record does not state what leaving would cost in duration, parties or complexity, so the migration stays unsized.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Semperis states ISO 27001:2013 and SOC 2 Type II for its cloud services. Both are ordinary enterprise-market preparation that a funded competitor can obtain. The company's own federal page says it is still working toward FedRAMP authorization with a 2026 target and is pursuing Common Criteria, so the reviewed record shows no authorization that would block a replacement.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Rebuilding an Active Directory forest without carrying malware back needs real systems engineering. The vendor's account of the mechanism is specific: decouple the directory from its host operating system, restore only what a server role requires onto hardware that need not match the original, and draw on several data sources including the replication stream to see attacks that security monitoring platforms miss. CSO Online describes the same engine reused across migration work.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 The buyers are regulated enterprises and governments. TechCrunch names Sanofi, United Airlines, Starbucks, Hertz, Lenovo and Prime Healthcare, Calcalist reports government agencies and more than a quarter of the 100 largest United States companies, and Semperis sells into critical infrastructure, federal, financial services, healthcare, insurance and public sector verticals.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Semperis is a platform that sits beside the identity infrastructure rather than being it. Active Directory and Entra ID are Microsoft's, and the documented functions are watching them, hardening them and rebuilding them, not serving authentication. That is what separates this from infrastructure other applications call at runtime.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The reviewed record evidences no retained asset. Semperis calls the recovery technology patented on its own pages, and no granted patent appears anywhere in the sources gathered. What the record shows on the research side is a free assessment tool and a published indicator count, not a retained corpus, and nothing in it describes telemetry accumulating to Semperis across customers.
Strategic Market Segmentation Semperis sells into large enterprise and regulated industries, the buyer segments KuppingerCole names for it, and its own industry list narrows that further. The company organizes around critical infrastructure, federal, financial services, healthcare, insurance, retail, public sector and transportation, and its own framing of why is blunt: when identity fails, business stops. The segment is defined by scale of dependency. TechCrunch reports that Active Directory is used by more than 90 percent of Fortune 1000 companies, and Semperis' own framing is that every user, workload and agent depends on identity providers like Active Directory, Entra ID and Okta. The portfolio has widened inside that segment. SecurityWeek recorded two products in 2020, Directory Services Protector and Active Directory Forest Recovery, against a platform and a services practice today. Calcalist reported in February 2026 that Semperis serves more than 1,000 organizations including government agencies and over a quarter of the 100 largest United States companies…

Semperis sells into large enterprise and regulated industries, the buyer segments KuppingerCole names for it, and its own industry list narrows that further. The company organizes around critical infrastructure, federal, financial services, healthcare, insurance, retail, public sector and transportation, and its own framing of why is blunt: when identity fails, business stops.

The segment is defined by scale of dependency. TechCrunch reports that Active Directory is used by more than 90 percent of Fortune 1000 companies, and Semperis' own framing is that every user, workload and agent depends on identity providers like Active Directory, Entra ID and Okta.

The portfolio has widened inside that segment. SecurityWeek recorded two products in 2020, Directory Services Protector and Active Directory Forest Recovery, against a platform and a services practice today. Calcalist reported in February 2026 that Semperis serves more than 1,000 organizations including government agencies and over a quarter of the 100 largest United States companies.

Product Capabilities & AI Advantages The most specific engineering claim is about the recovery…

The most specific engineering claim is about the recovery. Semperis' pages describe technology it calls patented that separates Active Directory from the operating system underneath, so a restore taken from an infected backup does not carry the infection forward, along with recovery onto hardware that does not match the original and an object-level restore that avoids a full forest rebuild.

Detection reuses the directory's own plumbing. Directory Services Protector draws on several data sources including the Active Directory replication stream, which Semperis says gives it sight of attacks that security monitoring platforms are blind to, and it pairs that with rollback of the changes it flags.

The AI positioning is thinner than the recovery case. Semperis says it helps discover exposure and roll back damaging changes for service accounts, automations and AI agents across Active Directory, Entra ID, Okta and Ping, and it lists monitoring for AI agent indicators of exposure inside Directory Services Protector. That is a feature of an existing product, and the reviewed record carries no separate AI product and no independent assessment of it.

Sales Engagement & Go-to-Market A free tool comes first…

A free tool comes first. Purple Knight scans Active Directory, Entra ID and Okta against a catalog of security indicators and hands back prioritized guidance, and Semperis offers it for download rather than through a quote. CISA lists it among no-cost cybersecurity tools and services, exposing it to audiences that include federal, state, local and tribal government, and CISA states in the same listing that it endorses no commercial product.

Selling then runs through partners. Semperis describes a channel approach it calls 100 percent channel, with guaranteed margins and free assessment tools handed to partners.

The independent traction record is specific and current for a private vendor. TechCrunch names six customers among a wider base it says covers some 100 million user identities, Calcalist reports the organization count and the share of large United States companies, and Altice Portugal's chief security officer is quoted by name about buying the recovery product.

Pricing Model Nothing paid is priced in public…

Nothing paid is priced in public. No price, package or tier appears on any Semperis page reviewed here, and those pages route a buyer to a demo request or to a partner. Purple Knight is the exception: its own page carries the download.

The one pricing detail on the record is a reporter's. CSO Online wrote that Semperis anticipated offering term and perpetual licensing for its migration product, and that the company did not disclose pricing or a release date for the software-as-a-service version.

One product is stated as free. Semperis calls Purple Knight a free assessment tool and describes Forest Druid as a community tool without naming a price. Semperis also hands partners free assessment tools, so the no-cost surface works as a way in while nothing on the reviewed pages lets a buyer purchase without contact.

Product Delivery & Operations Delivery follows the directory…

Delivery follows the directory. Active Directory Forest Recovery restores to physical or virtual hardware, and CSO Online reported the migration offering shipping as an on-premises deployment with a software-as-a-service version planned.

The cloud shows up as storage and as newer products. Semperis describes configuring the recovery product to store forest backups and configuration in Azure Blob Storage with AES-256 encryption, and Lightning Intelligence is delivered as a cloud posture service rather than installed software.

Operations extend past the software into rehearsal and response. Semperis offers an isolated replica of the production forest for recovery drills with documented results, and its breach preparedness and response team runs assessments, forensic investigations and around-the-clock emergency response. Buyers are being sold a practice, not only a product.

Earning Customers' Trust The attestations are stated and no supporting evidence appears on the probed surfaces. Semperis' federal page records ISO 27001:2013 certification and SOC 2 Type II for its cloud services including Disaster Recovery for Entra Tenant. A probe of trust.semperis.com on 2026-09-04 redirected to a customer community login, and no certificate or audit report was found on any probed surface. The attestations rest on the company's own statement of them. What Semperis does not yet hold, it says so plainly. The same page describes FedRAMP authorization as a 2026 target being pursued with a third-party assessment organization and agency sponsorship, and Common Criteria and a NIST SP 800-171 gap analysis as work under way. For a vendor that markets a federal practice, that is the credential a government buyer has to look past…

The attestations are stated and no supporting evidence appears on the probed surfaces. Semperis' federal page records ISO 27001:2013 certification and SOC 2 Type II for its cloud services including Disaster Recovery for Entra Tenant.

A probe of trust.semperis.com on 2026-09-04 redirected to a customer community login, and no certificate or audit report was found on any probed surface. The attestations rest on the company's own statement of them.

What Semperis does not yet hold, it says so plainly. The same page describes FedRAMP authorization as a 2026 target being pursued with a third-party assessment organization and agency sponsorship, and Common Criteria and a NIST SP 800-171 gap analysis as work under way. For a vendor that markets a federal practice, that is the credential a government buyer has to look past.

Platform Strategy & Ecosystem Positioning The core of Semperis' business is downstream of a platform Microsoft controls. Active Directory and Entra ID are Microsoft products, and Semperis' recovery pitch is written against a Microsoft artifact, the 28-step manual process it says buyers are otherwise stuck with. That argument holds only while the manual process stays manual. Coverage has widened past Microsoft. The platform now spans Okta and Ping alongside Active Directory and Entra ID, and in February 2026 Calcalist reported Semperis acquiring MightyID, a company it describes as working on identity resilience for cloud identity providers, in a deal it puts at roughly $20 million. Calcalist reports the transaction as under way rather than closed. The most substantive partnership runs through a backup vendor. Cohesity announced an offering it calls Cohesity Identity Resilience powered by Semperis, and Semperis supports managing Active Directory backups inside the Cohesity dashboard. That is distribution into an adjacent budget, and it also routes part of the go-to-market through a company that sells its own data protection platform…

The core of Semperis' business is downstream of a platform Microsoft controls. Active Directory and Entra ID are Microsoft products, and Semperis' recovery pitch is written against a Microsoft artifact, the 28-step manual process it says buyers are otherwise stuck with. That argument holds only while the manual process stays manual.

Coverage has widened past Microsoft. The platform now spans Okta and Ping alongside Active Directory and Entra ID, and in February 2026 Calcalist reported Semperis acquiring MightyID, a company it describes as working on identity resilience for cloud identity providers, in a deal it puts at roughly $20 million. Calcalist reports the transaction as under way rather than closed.

The most substantive partnership runs through a backup vendor. Cohesity announced an offering it calls Cohesity Identity Resilience powered by Semperis, and Semperis supports managing Active Directory backups inside the Cohesity dashboard. That is distribution into an adjacent budget, and it also routes part of the go-to-market through a company that sells its own data protection platform.

Team & Execution Capability The three founders are still in the top jobs thirteen years on…

The three founders are still in the top jobs thirteen years on. Calcalist reports Mickey Bresman, Guy Teverovsky and Matan Liberman founding Semperis in 2013 and names Liberman as the one leading the Tel Aviv operation. In an interview with Liberman, the same outlet records Teverovsky arriving from Microsoft disaster-recovery consulting. Help Net Security names the same three founders.

A public-market bench arrived with the 2024 round. TechCrunch reports Jeff Bray joining as chief financial officer, Mike DeGaetano as chief revenue officer and Annabel Lewis as chief legal officer, all with backgrounds at established cyber companies, and quotes Bresman saying the company's next step currently looks like a public offering. Calcalist puts headcount at roughly 600, about 150 of them in Tel Aviv.

The advisory roster is a distribution asset rather than an engineering one. Semperis lists General David Petraeus, a partner at KKR and former director of the CIA, as a strategic advisor working on public-sector identity threat detection and response, which reads as access to government buyers rather than as evidence about the product.

Sources

Company Detail Sources (3)
Id Source Tier Accessed
f1 https://www.semperis.com/identity-resilience-platform/ official 2026-09-04
f2 https://www.calcalistech.com/ctechnews/article/hyp2x3118a press 2026-09-04
f3 https://techcrunch.com/2024/06/20/semperis-a-specialist-in-active-directory-security-now-worth-more-than-1b-raises-125m/ press 2026-09-04
Profile Analysis Sources (16)
Id Source Tier Accessed
s1 Semperis: homepage
“Semperis delivers end-to-end security and resilience across the identity fabric to help you combat the inevitable disruption of an AI-driven world, spanning all major IdPs and supported by a global identity forensics and incident response (IFIR) team.”
official 2026-09-04
s2 Semperis: About us page
“As cybersecurity leaders and Active Directory (AD) experts, we know that identity-first security is the key to operational resilience.”
official 2026-09-04
s3 Semperis: Identity Resilience Platform page
“Semperis protects hybrid identity before, during, and after attack in one purpose-built platform.”
official 2026-09-04
s4 Semperis: Purple Knight product page
“In a 2025 survey of Purple Knight users, respondents reported an average initial security score of 61%—a barely passing grade.”
official 2026-09-04
s5 Semperis: Active Directory Forest Recovery product page
“Unlike traditional system-state or bare-metal recovery approaches, patented, purpose-built ADFR fully automates the AD forest recovery process.”
official 2026-09-04
s6 TechCrunch: report on the June 2024 Semperis growth round
“Its customers include Lenovo, Prime Healthcare, Sanofi, United Airlines, Starbucks, Hertz and many others, covering some 100 million user identities in all.”
press 2026-09-04
s7 Calcalist CTech: report on the June 2024 Semperis round and founding
“Semperis, which is headquartered in Hoboken, New Jersey, was founded in 2013 by CEO Michael Brezman, Chief Technology Officer Guy Teverovsky, and Matan Liberman, who serves as executive vice president of business development and leads the company’s Tel Aviv branch.”
press 2026-09-04
s8 SecurityWeek: report on the 2020 Semperis Series B
“Enterprise identity protection company Semperis on Wednesday announced that it raised $40 million in a Series B funding round, which brings the total raised to date to $54 million.”
press 2026-09-04
s9 Help Net Security: industry-news item on the 2022 Semperis Series C
“Semperis announced it has raised over $200 million in Series C funding led by KKR, with participation from Ten Eleven Ventures, Paladin Capital Group, Atrium Health Strategic Fund, Tech Pioneers Fund, and existing investors including Insight Partners.”
press 2026-09-04
s10 CISA: Semperis Purple Knight service listing
“Purple Knight queries an organization's Active Directory environment and performs a comprehensive set of tests against the most common and effective attack vectors to uncover risky configurations and security vulnerabilities.”
regulatory 2026-09-04
s11 SEC EDGAR: Semperis Ltd. Form D/A primary document
“Semperis Ltd. 7 Jabotinsky St. Ramat Gan L3 ISRAEL”
regulatory 2026-09-04
s12 Calcalist CTech: report on the Semperis acquisition of MightyID
“Semperis serves more than 1,000 organizations, including government agencies and over 25% of the 100 largest U.S. companies.”
press 2026-09-04
s13 CSO Online: article on the Semperis Active Directory migration offering
“The migration system brings together a variety of products from Semperis’ existing armory, including Purple Knight, Forest Druid, Active Directory Forest Recovery (ADFR), and Directory Services Protector (DSP).”
press 2026-09-04
s14 KuppingerCole: Semperis vendor profile
“Its products span posture assessment, anomaly detection, attack path analysis, automated recovery, and professional incident response services for large enterprise and regulated industries.”
research 2026-09-04
s15 Semperis: trust subdomain probe on 2026-09-04, redirects to a customer community login official 2026-09-04
s16 Semperis: federal solutions page with compliance milestones
“Semperis has ISO 27001:2013 certification, which includes rigorous controls, regular internal and external audits, and ongoing assessments to ensure our security practices remain effective and up to date.”
official 2026-09-04
Deep-Dive Sources (16)
Id Source Tier Accessed
s1 Semperis: homepage
“Semperis delivers end-to-end security and resilience across the identity fabric to help you combat the inevitable disruption of an AI-driven world, spanning all major IdPs and supported by a global identity forensics and incident response (IFIR) team.”
official 2026-09-04
s2 Semperis: About us page
“As cybersecurity leaders and Active Directory (AD) experts, we know that identity-first security is the key to operational resilience.”
official 2026-09-04
s3 Semperis: Identity Resilience Platform page
“Semperis protects hybrid identity before, during, and after attack in one purpose-built platform.”
official 2026-09-04
s4 Semperis: Purple Knight product page
“In a 2025 survey of Purple Knight users, respondents reported an average initial security score of 61%—a barely passing grade.”
official 2026-09-04
s5 Semperis: Active Directory Forest Recovery product page
“Unlike traditional system-state or bare-metal recovery approaches, patented, purpose-built ADFR fully automates the AD forest recovery process.”
official 2026-09-04
s6 TechCrunch: report on the June 2024 Semperis growth round
“Its customers include Lenovo, Prime Healthcare, Sanofi, United Airlines, Starbucks, Hertz and many others, covering some 100 million user identities in all.”
press 2026-09-04
s7 Calcalist CTech: report on the June 2024 Semperis round and founding
“Semperis, which is headquartered in Hoboken, New Jersey, was founded in 2013 by CEO Michael Brezman, Chief Technology Officer Guy Teverovsky, and Matan Liberman, who serves as executive vice president of business development and leads the company’s Tel Aviv branch.”
press 2026-09-04
s8 SecurityWeek: report on the 2020 Semperis Series B
“Enterprise identity protection company Semperis on Wednesday announced that it raised $40 million in a Series B funding round, which brings the total raised to date to $54 million.”
press 2026-09-04
s9 Help Net Security: industry-news item on the 2022 Semperis Series C
“Semperis announced it has raised over $200 million in Series C funding led by KKR, with participation from Ten Eleven Ventures, Paladin Capital Group, Atrium Health Strategic Fund, Tech Pioneers Fund, and existing investors including Insight Partners.”
press 2026-09-04
s10 CISA: Semperis Purple Knight service listing
“Purple Knight queries an organization's Active Directory environment and performs a comprehensive set of tests against the most common and effective attack vectors to uncover risky configurations and security vulnerabilities.”
regulatory 2026-09-04
s11 SEC EDGAR: Semperis Ltd. Form D/A primary document
“Semperis Ltd. 7 Jabotinsky St. Ramat Gan L3 ISRAEL”
regulatory 2026-09-04
s12 Calcalist CTech: report on the Semperis acquisition of MightyID
“Semperis serves more than 1,000 organizations, including government agencies and over 25% of the 100 largest U.S. companies.”
press 2026-09-04
s13 CSO Online: article on the Semperis Active Directory migration offering
“The migration system brings together a variety of products from Semperis’ existing armory, including Purple Knight, Forest Druid, Active Directory Forest Recovery (ADFR), and Directory Services Protector (DSP).”
press 2026-09-04
s14 KuppingerCole: Semperis vendor profile
“Its products span posture assessment, anomaly detection, attack path analysis, automated recovery, and professional incident response services for large enterprise and regulated industries.”
research 2026-09-04
s15 Semperis: trust subdomain probe on 2026-09-04, redirects to a customer community login official 2026-09-04
s16 Semperis: federal solutions page with compliance milestones
“Semperis has ISO 27001:2013 certification, which includes rigorous controls, regular internal and external audits, and ongoing assessments to ensure our security practices remain effective and up to date.”
official 2026-09-04

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.