Osavul
AI-powered hybrid-threat intelligence for governments, defense, and critical infrastructure.
Website: https://www.osavul.cloud
Cover Block
Open sources
| Name | Osavul |
| Tagline | AI-powered hybrid-threat intelligence for governments, defense, and critical infrastructure. |
| Headquarters | Kyiv, Ukraine |
| Founded | 2022 |
| Stage | Series A |
| Business Model | SaaS |
| Industry | Security |
| Technology | AI / Machine Learning |
| Geography | Eastern Europe |
| Growth Profile | Venture Scale |
| Founding Team | Co-Founders (2) |
| Funding Label | Series A (total disclosed ~$13,000,000) |
Links
Open sources
- Website: https://www.osavul.cloud
- LinkedIn: https://www.linkedin.com/company/osavul/
- Careers: https://www.osavul.cloud/careers-osavul
What an Investor Needs First
Open sources Osavul is a Ukrainian AI-powered hybrid-threat intelligence company that has secured over $13 million in funding to build a platform for governments and critical infrastructure operators to detect coordinated disinformation, cyberattacks, and physical sabotage before they escalate [Tech.eu, October 2026] [Euronews, September 2024]. Founded in 2022 by Dmytro Plieshakov and Dmytro Bilash, the company originated from a direct request for support from Ukrainian security bodies following Russia's full-scale invasion, giving it a rare, battle-tested wedge into the national security market [The Recursive, May 2023]. Its product analyzes open-source and restricted-access data across social media, news, and messaging platforms to identify connected signals across cognitive, cyber, and physical domains, a synthesis that differentiates it from point-solution competitors [PERPLEXITY SONAR PRO BRIEF]. The founders bring a prior successful exit, having co-founded and sold the AI marketing startup Captain Growth to Perion for up to $3.75 million, which provides a foundation in product development and analytics, though their direct experience in enterprise government sales is a developing track record [Vestbee, October 2026]. Operating on a SaaS model, Osavul has expanded from its initial Ukrainian government deployments to serve customers in 10 countries, including NATO members, as reported in late 2026 [Resilience Media, September 2026]. Over the next 12-18 months, the key watchpoints are the company's ability to convert its Series A capital into scaled commercial contracts beyond its early-adopter government base and to demonstrate that its integrated threat detection model can be operationalized for customers without deep technical teams.
Partially corroborated -- Core company description and founding story corroborated by multiple sources; funding totals and customer counts are reported but with some variance across publications.
Taxonomy Snapshot
| Axis | Classification |
|---|---|
| Stage | Series A |
| Business Model | SaaS |
| Industry / Vertical | Security |
| Technology Type | AI / Machine Learning |
| Geography | Eastern Europe |
| Growth Profile | Venture Scale |
| Founding Team | Co-Founders (2) |
| Funding | ~$13,000,000 (total disclosed) |
Inside the Company
Open sources
Osavul was founded in Kyiv, Ukraine in 2022 by Dmytro Plieshakov and Dmytro Bilash, two entrepreneurs whose previous AI marketing startup, Captain Growth, was sold to Perion for up to $3.75 million [The Recursive, May 2023][Euronews, September 2024]. The company's genesis was a direct response to the information warfare accompanying Russia's full-scale invasion of Ukraine, beginning as a project to support Ukrainian security agencies before formalizing as a commercial venture [Euronews, September 2024].
Its initial product development and deployment were closely tied to the Ukrainian government. By May 2023, the company's software was being used by the Centre for Counteracting Disinformation at Ukraine’s National Security and Defense Council and other domestic security bodies [Mind.ua, May 2023]. This early, operational deployment with a high-stakes customer provided a critical proving ground for its AI-driven threat detection platform.
Key milestones followed a pattern of incremental capital raises aligned with geographic and customer expansion. A $1 million seed round from Ukrainian fund SMRK closed in May 2023 [The Recursive, May 2023]. A $3 million investment led by 42CAP in September 2024 supported growth beyond Ukraine, with the company reporting involvement in projects funded by the European Union and NATO [Euronews, September 2024]. The most recent milestone is a Series A round of approximately €8.5 million ($9-10 million) led by 33N Ventures in October 2026, which brought total disclosed funding to roughly €12 million and was framed as fuel for further international expansion [Tech.eu, October 2026][Kyiv Post, October 2026].
Partially corroborated -- Founding details and funding rounds are corroborated by multiple independent publications, though some financial figures have minor discrepancies across reports.
Under the Hood
Reported and inferred
Osavul’s platform is built to detect coordinated hybrid threats by analyzing signals across cognitive, cyber, and physical domains. The company’s public descriptions frame its core capability as connecting information operations with cyber and physical threats before they escalate, aiming to spot hostile intent in its earliest stages [Resilience Media, October 2026]. The system ingests and analyzes open-source and restricted-access data from social media, news outlets, and messaging platforms to identify disinformation campaigns, bot networks, and psychological operations [The Next Web, October 2026].
On the product surface, the company offers an AI-driven intelligence suite with named solutions. These include Nebula for OSINT and media monitoring, Echo for narrative analysis and tracking, and Janus for threat detection and assessment [Osavul's Solutions | Information Security AI-driven Intelligence Suite, 2026]. The platform is described as a web-based tool that monitors cross-channel information influence operations and automatically detects signals of Coordinated Inauthentic Behavior (CIB) [LinkedIn]. A key technical claim is the successful integration of "hundreds of millions worth of signals" across the three threat domains [Osavul Named a Front-Runner in Gartner's Disinformation..., 2026].
The available evidence points to a SaaS delivery model, though the depth of customization for government clients is not detailed in public sources. Job postings for a Forward Deployed Engineer [Forward Deployed Engineer Job | Join Osavul Now, 2026] and an Account Manager [Account Manager Job at Osavul | Apply Now, 2026] suggest a go-to-market motion that involves significant client-side integration and relationship management, common in the defense and intelligence sector. The technology stack is not explicitly disclosed, but the engineering role’s requirements (inferred from the job title) imply a need for deploying and tailoring the core platform in sensitive, potentially air-gapped environments.
Partially corroborated -- Product claims are sourced from the company's website and press coverage, but technical architecture and performance benchmarks are not independently verified.
Market Research
Open sources The market for hybrid-threat intelligence is being defined by the convergence of distinct, high-stakes security domains under a single analytical lens, a shift driven by the operational tactics of modern state and non-state actors.
No third-party market sizing report specific to hybrid-threat intelligence was identified in the available research. For analogous context, the broader cybersecurity intelligence and threat detection market provides a relevant proxy. According to Gartner, the worldwide security and risk management spending was forecast to exceed $215 billion in 2024, with threat intelligence and management services representing a critical, high-growth segment [Gartner, 2023]. This spending is increasingly directed toward platforms that can correlate signals across information, cyber, and physical domains, a capability gap that Osavul's product directly addresses [Osavul Named a Front-Runner in Gartner's Disinformation..., 2026].
Demand is anchored by several clear, cited tailwinds. The primary driver is the professionalization of information operations, where disinformation campaigns are systematically coordinated with cyber intrusions and kinetic threats [Hybrid Information Operations (InfoOps), 2026]. This creates a need for intelligence that moves beyond siloed monitoring. A second driver is institutional procurement, evidenced by EU and NATO-funded projects for counter-disinformation tools, which create a funded pipeline for government and critical infrastructure customers [Euronews, September 2024]. Finally, the proliferation of generative AI tools is lowering the barrier to creating sophisticated synthetic media, amplifying the scale and believability of influence operations and raising the urgency for automated detection [Vestbee, October 2026].
Key adjacent and substitute markets include standalone cybersecurity threat intelligence platforms, social media monitoring for brand safety, and open-source intelligence (OSINT) tools for investigators. The competitive risk for a hybrid player is that buyers may satisfy their needs through a combination of these point solutions, though this approach often fails to detect the cross-domain correlations that define a hybrid campaign. Regulatory forces are largely enabling, with Western governments and alliances actively seeking technological solutions to foreign information manipulation, though procurement cycles remain long and requirements stringent.
Given the absence of a confirmed TAM for the specific category, the following table summarizes the analogous market context and observed demand signals.
| Market Segment | Cited Context / Signal | Source |
|---|---|---|
| Security & Risk Management Spending | Worldwide spending forecast >$215B (2024) | [Gartner, 2023] |
| Institutional Procurement | Involvement in EU and NATO-funded projects | [Euronews, September 2024] |
| Customer Adoption | Government customers in 10 countries, including NATO | [Resilience Media, September 2026] |
| Analyst Recognition | Named a front-runner in disinformation detection landscape | [Osavul Named a Front-Runner in Gartner's Disinformation..., 2026] |
The analyst takeaway is that the market is nascent but substantiated by powerful, non-cyclical demand drivers. The lack of a discrete TAM figure is less critical than the clear, funded need from sovereign and institutional buyers for tools that can trace hostile intent across the cognitive, cyber, and physical layers, a need amplified by current geopolitical conflicts.
Partially corroborated -- Market sizing relies on analogous reports and inferred demand drivers; specific TAM for hybrid-threat intelligence is not publicly confirmed.
Competition and Substitutes
Reported and inferred Osavul's competitive position is defined by its focus on the intersection of information operations and cyber-physical threats, a niche that sits between traditional cybersecurity and media monitoring vendors.
| Company | Positioning | Stage / Funding | Notable Differentiator | Source |
|---|---|---|---|---|
| Osavul | AI-powered hybrid-threat intelligence for governments and critical infrastructure. | Series A; ~$13M total disclosed funding. | Integrates cognitive, cyber, and physical threat signals; born from Ukrainian wartime defense needs. | [Tech.eu, October 2026], [The Recursive, May 2023] |
| Blackbird.AI | AI-driven narrative and disinformation risk intelligence for enterprises and governments. | Series B; $20M+ total funding. | Focuses on narrative risk and financial market manipulation; strong enterprise traction. | [Crunchbase] |
The table shows a core, named competitor in Blackbird.AI, but the competitive map is more complex. The landscape can be segmented into three broad categories. First, incumbent intelligence platforms like Recorded Future or Mandiant (Google Cloud) offer cyber threat intelligence with some adjacent media monitoring, but their core architecture is not built for the real-time, cross-domain correlation of coordinated inauthentic behavior (CIB) and physical sabotage signals that Osavul emphasizes [Osavul's Solutions, 2026]. Second, challenger AI startups like Blackbird.AI or Graphika compete directly in the disinformation detection and narrative analysis layer, often targeting corporate risk and financial services clients as well as government agencies. Third, adjacent substitutes include specialized OSINT tools used by intelligence analysts and broad social media listening platforms like Brandwatch or Meltwater, which lack the built-in threat detection models and security-focused workflow.
Osavul's defensible edge today appears to be its proven integration in active defense scenarios and its proprietary cross-domain signal processing. The company's software was implemented by Ukraine's Centre for Counteracting Disinformation within a year of its founding, providing a real-world, high-stakes training ground for its models that is difficult for a commercial-only vendor to replicate [Mind.ua, May 2023]. The technical claim of integrating "hundreds of millions worth of signals across three domains: cognitive, cyber, and physical" suggests a data moat built from unique, restricted-access sources and bespoke correlation logic [Osavul Named a Front-Runner in Gartner's Disinformation..., 2026]. This edge is durable if the company continues to secure contracts with defense and intelligence agencies that provide privileged data access and validation feedback loops. It is perishable if competitors successfully partner with similar government entities or if the technical approach to cross-domain analysis becomes a standardized, commoditized feature within larger intelligence platforms.
The company's most significant exposure is in commercial scalability and channel ownership. While it has expanded to serve government customers in 10 countries, its public narrative remains tightly coupled with state-level defense procurement, a sales cycle that is long, relationship-driven, and often non-dilutive of competitors [Resilience Media, September 2026]. A challenger like Blackbird.AI, with a clearer enterprise go-to-market and focus on corporate risk, could build a larger commercial footprint more quickly, achieving scale that later funds a move up-market into Osavul's core government segment. Furthermore, Osavul does not own the underlying data collection channels (social platforms, news feeds); its value is in analysis. A shift in platform APIs or the emergence of a dominant, general-purpose AI threat-detection model from a cloud hyperscaler could disintermediate its analytical layer.
The most plausible 18-month competitive scenario involves market segmentation hardening along customer-type lines. The winner in this scenario is the company that successfully bridges the government and critical infrastructure commercial segment,likely Osavul if it can productize its defense-grade tools for operators of energy grids, transportation networks, and financial markets, leveraging its Series A capital to build that commercial sales function [Tech.eu, October 2026]. The loser is the pure-play vendor that remains confined to a single domain, such as a media monitoring firm that fails to integrate credible cyber threat feeds, or a cyber intelligence firm that treats information operations as a peripheral concern. Osavul's hybrid thesis positions it to avoid that trap, but execution risk in building a dual-track sales motion is high.
Partially corroborated -- Competitor identification and Osavul's positioning are corroborated by multiple sources; competitor funding and detailed landscape analysis rely on single-source corroboration or inference.
Opportunity
Open sources
The clearest path for Osavul is to become the foundational intelligence layer for national security in the digital age, a platform that governments and critical infrastructure operators rely on to see hybrid threats before they escalate into kinetic events.
The headline opportunity is to define and own the emerging category of hybrid-threat intelligence, moving beyond point solutions for disinformation or cyber to become the default system for correlating cognitive, cyber, and physical signals. The company's origin in Ukraine's active defense against Russian information warfare provides a unique, battle-tested wedge [Euronews, September 2024]. Its reported expansion to government customers in 10 countries, including NATO members, suggests this wedge is already translating into a broader value proposition beyond its initial theater [Resilience Media, September 2026]. The outcome is plausible because the threat is systemic; adversaries are already combining narrative manipulation, cyber intrusions, and physical sabotage, creating demand for a unified detection layer that legacy vendors, focused on single domains, are poorly positioned to provide.
Growth scenarios outline concrete paths to scale. The following table details two primary vectors.
| Scenario | What happens | Catalyst | Why it's plausible |
|---|---|---|---|
| NATO Standardization | Osavul's platform becomes a recommended or integrated tool for alliance-wide threat monitoring and early warning. | A formal partnership or procurement framework established through a NATO innovation fund or agency. | The company is already involved in projects funded by the EU and NATO [Euronews, September 2024], and its technology addresses a stated alliance priority on countering hybrid threats. |
| Critical Infrastructure Verticalization | The company expands from government intelligence agencies to become the mandated monitoring provider for energy grids, telecoms, and financial market operators. | A major hybrid attack on Western infrastructure that triggers new regulatory requirements for threat detection. | Osavul's stated mission includes protecting critical infrastructure [PERPLEXITY SONAR PRO BRIEF], and its ability to connect digital chatter with potential physical sabotage aligns directly with operators' risk management needs. |
What compounding looks like is a data and credibility flywheel. Each new government deployment, especially in a different geographic or linguistic region, feeds the AI models with unique patterns of coordinated inauthentic behavior and emerging threat actor tactics. This improves detection accuracy for all customers, which in turn drives further adoption. Evidence of early compounding includes the company's claim to successfully integrate "hundreds of millions worth of signals" across cognitive, cyber, and physical domains [Osavul Named a Front-Runner in Gartner's Disinformation..., 2026]. Furthermore, the shift from a reactive service to a persistent monitoring platform suggests the beginnings of a workflow lock-in; once an agency's analysts are trained on Osavul's interface and alerts, switching costs rise significantly.
The size of the win can be framed by looking at adjacent, publicly-traded cybersecurity and intelligence peers. For instance, Mandiant, prior to its acquisition by Google, was valued at approximately $5.3 billion as a pure-play threat intelligence and incident response firm [Google, September 2022]. CrowdStrike, which expanded from endpoint security into threat intelligence via its Falcon platform, currently commands a market capitalization over $80 billion [Nasdaq, 2026]. While Osavul operates in a more specialized, government-adjacent niche, a successful execution of the NATO standardization scenario could position it as a category-defining asset. In that scenario, a strategic acquisition by a major defense contractor or cloud provider at a valuation reflecting its unique dataset and government contracts is a credible outcome. This is a scenario-based illustration, not a forecast.
Partially corroborated -- Growth scenarios and market comps are based on public reporting of customer traction and known industry dynamics, but specific financial projections and deal terms are not disclosed.
Sources
Open sources
[Tech.eu, October 2026] Hostile threat warning startup Osavul raises €8.5M | https://tech.eu/2026/10/01/hostile-threat-warning-startup-osavul-raises-8-5m/
[Euronews, September 2024] Battling the echo chamber: Osavul’s fight against Russian disinformation | https://www.euronews.com/2024/09/15/battling-the-echo-chamber-osavuls-fight-against-russian-disinformation
[The Recursive, May 2023] War-Born Ukrainian AI Startup OSavul Raises $1M to Combat Disinformation | https://therecursive.com/war-born-ukrainian-ai-startup-osavul-raises-1m-to-to-combat-disinformation/
[PERPLEXITY SONAR PRO BRIEF] | https://www.perplexity.ai
[Vestbee, October 2026] Osavul raises €8.5M Series A to detect hybrid threats | https://www.vestbee.com/insights/articles/osavul-raises-8-5m
[Resilience Media, September 2026] Exclusive: Osavul snaps up $10M to expand its hybrid threat detector tech to more users | https://resiliencemedia.co/osavul-snaps-up-10m-to-expand-its-hybrid-threat-detector-tech-to-more-users/
[Mind.ua, May 2023] $1 million from SMRK: Why the fund invested in AI-startup Osavul | https://mind.ua/en/publications/20257218-1-million-from-smrk-why-the-fund-invested-in-ai-startup-osavul
[Kyiv Post, October 2026] Ukrainian Startup Osavul Raises $10 Million to Expand… | https://www.kyivpost.com/post/85961
[The Next Web, October 2026] Osavul raises €8.5M Series A to expand hybrid threat intelligence | https://thenextweb.com/news/osavul-raises-e8-5m-series-a-to-expand-hybrid-threat-intelligence
[Resilience Media, October 2026] | https://resiliencemedia.co/osavul-snaps-up-10m-to-expand-its-hybrid-threat-detector-tech-to-more-users/
[LinkedIn] Osavul | LinkedIn | https://www.linkedin.com/company/osavul/
[Osavul's Solutions | Information Security AI-driven Intelligence Suite, 2026] | https://www.osavul.cloud
[Osavul Named a Front-Runner in Gartner's Disinformation..., 2026] | https://www.osavul.cloud
[Hybrid Information Operations (InfoOps), 2026] | https://www.osavul.cloud
[Gartner, 2023] | https://www.gartner.com
[Forward Deployed Engineer Job | Join Osavul Now, 2026] Forward Deployed Engineer Job | Join Osavul Now | https://www.osavul.cloud/careers-osavul/forward-deployed-engineer
[Account Manager Job at Osavul | Apply Now, 2026] Account Manager Job at Osavul | Apply Now | https://www.osavul.cloud/careers-osavul/account-manager
[Crunchbase] Blackbird.AI - Crunchbase Company Profile & Funding | https://www.crunchbase.com
[Google, September 2022] Google to Acquire Mandiant | https://blog.google
[Nasdaq, 2026] CrowdStrike Holdings, Inc. (CRWD) Stock Quote | https://www.nasdaq.com
Articles about Osavul
- Osavul's AI Platform Tracks Hybrid Threats Across 10 Governments — The Ukrainian startup, founded by adtech veterans, has raised over $13 million to connect disinformation campaigns with cyber and physical risks.