Summary
- Luxembourg-headquartered Osavul has raised €8.5 million in Series A funding led by cybersecurity investor 33N Ventures.
- Its platform combines information, cyber, and physical-risk signals to help organisations assess hostile actors and exposure across assets and supply networks.
- The company plans to expand further into energy, transport, finance, and other critical sectors while continuing government and defence work.
Technology developed around government, defence, and information warfare is moving further into commercial risk management, with Osavul raising €8.5 million to expand its hybrid intelligence platform across critical infrastructure and enterprise markets.
The Series A round was led by 33N Ventures, with Balnord, G+D Ventures, and existing investor 42CAP also participating. Luxembourg-headquartered Osavul says the financing takes its total funding to approximately €12 million.
Its software was initially developed around information operations and hostile campaigns faced by governments and defence organisations, but the platform now combines cyber, information, and physical-risk signals. Energy, transport, finance, aviation, shipping, and other strategically important sectors sit within the company’s commercial expansion plans.
That broader scope reflects how hostile activity can cut across organisational boundaries, because a campaign against an infrastructure operator may involve cyber intrusion, surveillance, information manipulation, sabotage, pressure on employees, or activity involving suppliers rather than one easily categorised incident.
Security teams rarely see the same picture
Large organisations already receive information from endpoint systems, cyber threat feeds, physical security teams, geopolitical analysts, fraud monitoring, supplier-risk processes, government alerts, and open sources. Those streams are often handled by different teams, which can make related events look disconnected until a pattern becomes difficult to ignore.
Osavul’s proposition is to correlate those signals against the organisation’s own exposure, including people, facilities, suppliers, and digital infrastructure. The company describes its Janus platform as combining monitoring, alerts, threat-actor information, and risk modelling so analysts can examine activity across domains rather than reviewing every event in isolation.
Much of the underlying work is probabilistic, which places limits around claims that software can forecast precisely who will attack, when an incident will occur, or which method an adversary will choose. Attribution is difficult even after an attack, while open-source information can be incomplete, deliberately manipulated, or generated by the same actors an intelligence system is trying to track.
Osavul says its assessments are evidence traced and reviewed by analysts, an important distinction where machine learning is being used to support judgements about intent and threat. It also offers deployment inside customer-controlled infrastructure where organisations do not want sensitive internal information processed through a shared external service.
Defence methods move into commercial risk
The company says its technology has been shaped by several years of work around Russia’s invasion of Ukraine and is already used by government, defence, security, and critical infrastructure organisations in more than 10 countries. It is also involved in NATO’s Information Environment Assessment Capability through a consortium led by Brandwatch and Blackbird.AI.
NATO’s programme focuses strongly on monitoring and analysing the information environment, whereas Osavul’s commercial proposition extends into the relationship between information activity, cyber operations, and physical assets. That distinction becomes particularly relevant for energy networks, ports, airports, telecommunications systems, and industrial facilities where digital disruption can have a direct operational consequence.
Supply networks add another dimension because an attacker may target a contractor, logistics provider, employee, smaller technology supplier, or remote facility rather than the central organisation. Traditional perimeter security provides only a partial view when the operational dependency sits elsewhere.
Combining information does not automatically improve security, however, because another platform that produces more alerts can deepen the problem it claims to solve. The useful measure will be whether analysts can identify credible threats earlier, discard weak correlations, and make better operational decisions without spending more time validating machine-generated conclusions.
Osavul plans to use the funding to expand its AI capability, commercial organisation, and geographic reach, while continuing to work with government and defence customers. The company also reports that total contract value increased fourfold during 2025, although it has not disclosed an underlying revenue figure.
The investment arrives as commercial security becomes harder to divide neatly into cyber, physical, reputational, and geopolitical categories. Infrastructure operators increasingly face adversaries capable of moving between those domains, while internal responsibility remains distributed across specialist teams.
Osavul is betting that the resulting coordination problem creates demand for a common intelligence layer. Whether enterprises adopt that model broadly will depend less on the volume of information its systems can collect than on whether combining those signals produces decisions that existing security teams could not reach quickly enough on their own.












