CoreBastion Security Consulting // Research Intelligence
Video Analytics · Unified Ops · Posture Validation · Physical Security Market · 2026 Edition. 75 vendors tracked across five segments with current market intelligence through Q3 2026. This edition rebuilds the Security Posture Validation segment from five entries to eighteen, split by domain into physical-native, convergent, and cyber-native.
Market Structure
All 75 vendors map to one of five categories based on where they sit in the physical security stack. The first three segments cover detection and management. The fourth covers unified battlefield awareness across every sensor. The fifth covers posture validation and stress-testing of everything built.
Integrated hardware + software + AI. Full-stack vendors owning the camera, server, and analytics layer. Best for greenfield or single-vendor deployments.
Examples: Verkada, Avigilon, Genetec, Axis, Hanwha Vision, Hikvision, i-PRO, Milestone, Bosch, Cisco Meraki, Digital Watchdog, Solink, Brivo (merged Eagle Eye)
Camera-agnostic software overlay. No proprietary hardware. SaaS or cloud-native. Ideal for AI uplift on existing infrastructure without rip-and-replace.
Examples: Ambient AI, ZeroEyes, Hakimo, Scylla, Irisity, Actuate, BriefCam, Omnilert, Airship AI, Spot AI, Rhombus, Coram, IntelliSee, Veesion, Xtract One, Calipsa, Volt AI, Umbo CV, Deep Sentinel, Gorilla Technology, PureTech Systems, AMAROK/Evolon, Sentry AI, promiseQ, Morphean
Foundational platforms, VMS marketplaces, and operational intelligence layers that analytics are built on or feed into. For integrators and large-enterprise custom builds.
Examples: Palantir, Hexagon AB, NVIDIA Metropolis, AWS Kinesis Video Streams, Milestone (VMS layer), Pelco, Alarm.com for Business, ExacqVision, Qognify, AxxonSoft, Dahua Technology
Every connected system becomes a sensor. VMS, access control, IDS, alarms, and environmental inputs feed a single AI reasoning layer. Paul's "Vision Ops" concept: holistic attack vector detection, not siloed alerts.
Examples: Genetec Mission Control, AlertEnterprise, SureView Immix, Everbridge, AxxonSoft, CNL Software IPSecurityCenter, Hakimo AI Operator
The adversarial layer. Scores posture, models component degradation and failure scenarios, and produces defensible gap analysis for boards, auditors, and underwriters. Stress-tests the full stack before an adversary does. Split three ways in this edition by what the platform actually validates: the physical facility, the cyber estate, or both.
Physical: Mistabra, ARES Security AVERT, RhinoCorps Simajin / Vanguard, Sandia Scribe3D / PathTrace, Circadian Risk, RiskWatch
Convergent: Frenos, Filigran OpenAEV
Adjacent: Viakoo, HiveWatch, SiteOwl
Cyber: Picus, Cymulate, SafeBreach, XM Cyber, Pentera, Mandiant Security Validation, CISA SAFE
Full Market Coverage
75 vendors mapped across segment, deployment model, core capabilities, target market, and key differentiator. Updated through Q3 2026. The Security Posture Validation block at the bottom of this table was rebuilt in full for this edition.
| Vendor | Segment | Deploy Model | Core Capabilities | Target Market | Key Differentiator | Tags |
|---|---|---|---|---|---|---|
| Enterprise Platform (13) | ||||||
| Verkada | Enterprise Platform | Hybrid cloud | AI cameras, access control, NLP natural language search, environmental sensors, unified cloud console | Commercial enterprise, mid-market | Zero on-prem server; FedRAMP Moderate authorized May 2026 (DOE sponsor); fastest sales cycle in the market | FedRAMP 2026 |
| Avigilon (Motorola Solutions) | Enterprise Platform | Cloud, On-prem | Appearance search, unusual motion detection, LPR, Alta cloud platform, facial recognition | Enterprise, critical infrastructure, government | Appearance search across days of footage in seconds; Motorola radio and dispatch ecosystem integration | |
| Genetec | Enterprise Platform | Hybrid, On-prem, Cloud | KiwiVision privacy protection, Mission Control PSIM, Omnicast VMS, Synergis access control, AutoVu LPR, Security Center federation | Large enterprise, government, data centers | Strongest VMS ecosystem in North America; privacy-by-design; expanding into unified security operations platform | CoreBastion Preferred |
| Axis Communications | Enterprise Platform | Edge | Onboard ACAP edge analytics, object/people/vehicle detection, LPR, edge AI, thermal imaging | All segments | Open edge AI ecosystem with 1,000+ third-party ACAP apps; acquired FF Group 2026 expanding retail analytics | NDAA FF Group Acq. |
| Hanwha Vision | Enterprise Platform | Edge, Cloud | Object detection, LPR, crowd analytics, Wisenet AI cameras, Ambarella SoC edge processing | Enterprise, government | NDAA-compliant alternative to Chinese OEMs; Ambarella SoC partnership delivering 4x edge inference improvement | NDAA Ambarella 2026 |
| Hikvision | Enterprise Platform | Edge, On-prem | DeepinView AI cameras, behavioral analytics, facial recognition, LPR, thermal | Global enterprise, commercial | Largest global camera install base; lowest cost edge AI at scale; NDAA restricted for U.S. federal use | NDAA Restricted |
| i-PRO (Panasonic spinoff) | Enterprise Platform | Edge, Hybrid | AI open platform cameras, edge analytics, thermal, multi-sensor, NDAA-compliant hardware | Government, critical infrastructure, enterprise | NDAA-compliant Japanese alternative; open AI platform architecture; strong in government and critical infrastructure | NDAA Gov |
| Milestone Systems | Enterprise Platform | On-prem, Hybrid, Cloud | XProtect VMS, Hafnia VLM generative AI plug-in (NVIDIA partnership), open SDK, 10,000+ integrations | Large enterprise, critical infrastructure | Largest open VMS integration ecosystem; Hafnia VLM (2026) enables natural language video search across XProtect archive | Hafnia VLM 2026 |
| Bosch Security Systems | Enterprise Platform | Edge, On-prem | IVA Pro analytics, FLEXIDOME cameras, AI-based person and vehicle detection, deep-learning analytics | Enterprise, critical infrastructure, European government | Deep EU enterprise presence; long heritage in edge analytics; ONVIF compliance and open integration | |
| Cisco Meraki MV | Enterprise Platform | Cloud | Edge AI processing, object detection for people and vehicles, motion metadata, Meraki dashboard integration | Enterprise, multi-site commercial | Native integration with Meraki network stack (Wi-Fi, switches, SD-WAN); unified IT and physical security management | |
| Digital Watchdog (DW) | Enterprise Platform | On-prem, Hybrid | DW Spectrum VMS, MEGApix AI cameras, LPR, analytics, edge processing | Commercial enterprise, mid-market | Strong North American mid-market presence; competitive on total cost of ownership | |
| Brivo (merged Eagle Eye Networks) | Enterprise Platform | Cloud-native | Brivo Security Suite: AI, access control, cloud video surveillance, visitor management, intrusion; Brivo Genius Mobile Agent natural language emergency response | Commercial real estate, multifamily, enterprise | Merged December 2026 to form world's largest AI cloud-native physical security company; 1B+ sq ft secured across 80 countries | Merger Dec 2025 |
| Solink | Enterprise Platform | Cloud, Hybrid | VerifEye AI-assisted GSOC command center; AI Agents for perimeter monitoring and loss prevention; cloud VMS; video alarms; POS and access control integration; 375+ data source connectors; natural language video search | Multi-site commercial, retail, QSR, logistics, enterprise GSOC | $98.2M raised (Goldman Sachs Series C); VerifEye uses VLMs to pre-filter false positives for GSOCs; AI Agents launched February 2026 at Solink Secure Summit; 30,000 customers across 32 countries; strong POS-to-video correlation for loss prevention operations | AI Agents 2026 VerifEye VLM |
| Pure-Play AI (25) | ||||||
| Ambient AI | Pure-Play AI | Cloud, Hybrid | Pulsar VLM: vision-language model with 150+ threat signatures, four-step reasoning trace, false alarm reduction, agentic physical security platform; Securitas Technology global reseller | Fortune 100, data centers, critical infrastructure, hyperscale | Category leader in agentic physical security; FY26 ARR doubled with 140%+ NRR; Pulsar VLM GA November 19, 2025; Securitas global reseller agreement closes enterprise distribution gap | CoreBastion Preferred Pulsar VLM GA |
| ZeroEyes | Pure-Play AI | Cloud | AI gun detection on existing cameras; human verification by trained military veterans before dispatch; multi-threat platform expansion (knives, aggressive behavior) | Schools, government, healthcare, corporate campus | DHS SAFETY Act Full Designation; human-in-the-loop verification reduces false dispatch; only gun detection vendor with that designation | CoreBastion Preferred SAFETY Act |
| Hakimo | Pure-Play AI | Cloud, SaaS | AI Operator: autonomous alarm handling for access control and camera queues; triages and resolves low-risk alarms without human intervention; escalates confirmed events | Data centers, enterprise, GSOC operations | Directly addresses GSOC alert fatigue; $20.5M raised; integrates with Genetec, Lenel, and major ACS platforms; CoreBastion preferred for GSOC-scale alarm management | CoreBastion Preferred |
| Scylla AI | Pure-Play AI | Edge, Cloud | Real-time threat detection: weapons, fight detection, person of interest, perimeter intrusion, crowd analytics; runs on existing cameras | Transportation, government, enterprise | Strong multi-threat detection breadth; camera-agnostic; growing transportation sector deployments | |
| Irisity | Pure-Play AI | On-prem, Cloud, Hybrid | IRIS+ Enterprise: perimeter protection, virtual perimeter, loitering vehicle detection, forensic video search, crowd density up to 50,000 people; built-in anonymization | Airports, critical infrastructure, government, smart city | April 2026: major U.S. airport contract for 1,000 IRIS+ Enterprise AI channels; listed on Nasdaq First North; globally trusted at 3,000+ locations | Airport Contract 2026 |
| Actuate (formerly Aegis AI) | Pure-Play AI | Cloud, Edge | Weapon detection, intrusion detection, tailgating, perimeter analytics on existing cameras | Enterprise, government, education | Camera-agnostic; rapid deployment without hardware replacement; growing government sector presence | |
| BriefCam (Canon) | Pure-Play AI | On-prem, Cloud | Video synopsis, forensic video search, appearance search, facial recognition, crowd analytics | Law enforcement, government, large enterprise | Fastest forensic video search in the market; hours of footage reviewed in minutes; acquired by Canon; strong law enforcement deployment base | |
| Omnilert | Pure-Play AI | Cloud | AI gun detection, emergency mass notification integration, weapon detection on existing cameras | Schools, higher education, healthcare, corporate | DHS SAFETY Act Full Designation (2026); integrated gun detection plus emergency notification in a single workflow | SAFETY Act Full Desig. 2026 |
| Airship AI | Pure-Play AI | Edge, Cloud, On-prem | Outpost AI: edge video analytics, multi-sensor integration, real-time threat alerting; Acuity: data management platform for law enforcement | Law enforcement, government, border security, defense | Edge-first architecture for low-bandwidth and disconnected environments; strong DoD and DHS customer base | Gov / DoD |
| IntelliSee | Pure-Play AI | Cloud, Edge | 11+ detection types: weapons, falls, trespassing, loitering, unauthorized vehicles, crowd formation, slip and fall; overlays on existing cameras | Healthcare, manufacturing, retail, enterprise | Broadest detection type library in the pure-play segment; avoids platform lock-in by working on customer's existing infrastructure | Added Q2 2026 |
| Spot AI | Pure-Play AI | Hybrid (IVR edge) | Intelligent Video Recorder edge device; natural language video search; AI alerts; SOC 2 Type II certified; operational analytics | Retail, logistics, manufacturing, enterprise | On-site IVR minimizes cloud bandwidth; natural language search across camera archives; strong retail and logistics vertical | |
| Rhombus Systems | Pure-Play AI | Cloud | Cloud-managed video, access control, environmental sensors, AI analytics, NLP search via LLM integration, customizable operational analytics | Commercial enterprise, education, multi-site | Honeywell partnership 2026 expands enterprise reach; cloud-first with strong UX; Honeywell distribution accelerates enterprise sales | Honeywell Partner 2026 |
| Coram | Pure-Play AI | Cloud | Open platform cloud VMS; works with any IP camera; AI analytics; no hardware replacement required; Fortune 500 and local business deployments | Commercial, mid-market, enterprise | Zero rip-and-replace; broadest IP camera compatibility in the cloud segment; strong cost-of-migration advantage | |
| Veesion | Pure-Play AI | Edge, Cloud | Gesture recognition AI for shoplifting detection; real-time alerts to loss prevention; integrates with existing cameras | Retail, grocery, pharmacy | Purpose-built for retail loss prevention; gesture-based detection (not just object recognition) reduces false positives in retail environments | |
| Xtract One (formerly Patriot One) | Pure-Play AI | Edge | Frictionless weapons screening; radar and sensor fusion for concealed weapon detection without walk-through metal detectors; ingests at venue throughput rates | Venues, stadiums, arenas, transportation hubs | Eliminating the security checkpoint bottleneck; frictionless screening at full crowd throughput rates; strong venue and stadium deployments | |
| Calipsa (Motorola Solutions) | Pure-Play AI | Cloud | False alarm reduction for remote video monitoring; AI pre-screens camera alerts before human review; integrates with monitoring station workflows | Remote video monitoring centers, alarm receiving centers | Acquired by Motorola Solutions; reduces monitoring center false alarm cost by 80%+; now integrated into Motorola unified stack | Acquired: Motorola |
| Volt AI | Pure-Play AI | Cloud | Automated security monitoring, behavioral analytics, perimeter protection, real-time alerts; connects to existing camera infrastructure | Commercial, enterprise, critical infrastructure | Proactive threat identification focus; emerging player with growing enterprise reference list | |
| Umbo CV | Pure-Play AI | Cloud, Edge | Autonomous video monitoring with AI triage; real-time detection and human escalation for verified events; integrates with monitoring stations | Logistics, commercial real estate, remote sites | Fully autonomous monitoring workflow; designed for unstaffed or minimally staffed sites | |
| Deep Sentinel | Pure-Play AI | Cloud | AI + live human guard hybrid; AI flags events, live guards verify and intervene verbally in real time via cameras and two-way audio | Commercial property, construction sites, high-crime risk sites | Human intervention before police dispatch; documented deterrence effectiveness through verbal challenge | |
| PureTech Systems | Pure-Play AI | On-prem, Hybrid | Geospatial video analytics for critical infrastructure; perimeter protection for substations, oil and gas terminals, water treatment; GIS-based threat visualization | Utilities, substations, oil and gas, water treatment, CNI | Narrowest and deepest focus in the market: geospatial critical infrastructure perimeter analytics; used where GPS-referenced threat visualization is required | Added Q2 2026 CNI Specialist |
| Gorilla Technology | Pure-Play AI | Edge, Cloud, On-prem | Video intelligence platform: facial recognition up to 100,000 biometric profiles, LPR, behavior analytics, AI investigator for post-event forensic search | Smart city, government, enterprise | Strong APAC smart-city footprint; security convergence blending physical and digital; post-event AI investigator for rapid crime-solving | |
| AMAROK / Evolon Technology | Pure-Play AI | Edge, Cloud | AI-powered video monitoring for perimeter security; electric fence integration; remote video verification; Evolon AI analytics (AMAROK 45% investment stake) | Commercial, industrial, logistics, distribution | Perimeter security-as-a-service model; electric fence plus AI monitoring combined; AMAROK strategic investment in Evolon closes the analytics gap | AMAROK/Evolon 2026 |
| Sentry AI | Pure-Play AI | Cloud | AI-powered remote guarding and video monitoring; behavioral analytics; real-time alert escalation; integrates with existing cameras | Commercial, retail, logistics | Remote guarding augmentation; emerging competitor to Hakimo and Deep Sentinel in the autonomous monitoring segment | Added Q2 2026 |
| promiseQ | Pure-Play AI | Cloud, Edge (promiseQube) | Threat Filter: hybrid AI plus human verification for false alarm reduction; edge device (promiseQube) integrates with existing cameras; intrusion detection, behavior analytics, LPR, people counting, safety compliance; 95% false alarm reduction claimed | Monitoring centers, enterprise, European market | Berlin-based competitor to Calipsa in the false alarm reduction category; edge-first architecture differentiates from pure cloud approaches; backed by ExtraVallis and APY Ventures; targets monitoring stations and enterprise security operations | Added Q2 2026 |
| Morphean | Pure-Play AI | Cloud (VSaaS) | Video Surveillance as a Service; cloud CCTV, access control, and business intelligence; works with existing third-party IP cameras; GDPR-compliant EU-hosted data; analytics and reporting dashboards | Mid-market to large enterprise, European organizations, GDPR-sensitive deployments | Swiss-based VSaaS with EU data residency compliance built in; strong position for European organizations where data sovereignty is a procurement requirement; camera-agnostic cloud platform | Added Q2 2026 |
| Infrastructure / Decision Layer (11) | ||||||
| Palantir Technologies | Infrastructure | On-prem, Cloud, Classified | Data fusion across physical, cyber, and operational domains; AIP (AI Platform) for enterprise AI ops; used in defense, law enforcement, and critical infrastructure | Government, defense, large enterprise, CNI | The most powerful decision intelligence platform in existence; few security organizations can operationalize it; highest complexity and cost in the market | Gov / Defense |
| Hexagon AB | Infrastructure | On-prem, Cloud | HxGN OnCall for public safety; GIS-integrated situational awareness; sensor fusion across physical and digital systems; smart facility management | Government, smart city, utilities, enterprise | GIS-native situational awareness; strongest geospatial integration in the commercial security market | |
| NVIDIA Metropolis | Infrastructure | Edge, Cloud | AI video analytics development platform; VIT foundation models; TAO Toolkit for custom model training; Jetson edge AI hardware; Holoscan sensor processing | Platform: ISVs, integrators, OEMs, enterprise | The AI silicon and software foundation that most commercial security analytics run on; not a camera or VMS vendor but powers the ecosystem | |
| AWS Kinesis Video Streams | Infrastructure | Cloud | Video ingestion and processing infrastructure; Rekognition Video AI APIs; scalable storage and analytics pipeline; used as OEM foundation by multiple security vendors | Platform for security software builders; large enterprise self-build | Scales to unlimited camera count; used as hidden infrastructure by many branded security platforms | |
| Milestone Systems (VMS layer) | Infrastructure | On-prem, Hybrid | XProtect as open analytics marketplace; MIP SDK for deep third-party integration; ecosystem of 10,000+ integrations across analytics, access control, sensors | System integrators, enterprise, government | The open VMS most commonly used as the integration platform for third-party AI analytics overlays | |
| Qognify | Infrastructure | On-prem, Hybrid | Cayuga VMS, Situator PSIM; large-scale video management and incident correlation; used at transportation and government installations | Transportation, government, large enterprise | PSIM-integrated VMS; strong in transit and government where multi-system correlation is a baseline requirement | |
| Pelco | Infrastructure | On-prem, Hybrid | VideoXpert VMS, Sarix cameras; open platform; analytics integration marketplace; government and infrastructure specification history | Government, utilities, critical infrastructure | Long specification history in U.S. government and critical infrastructure; open platform enables broad analytics integration | Gov Heritage |
| ExacqVision (Johnson Controls) | Infrastructure | On-prem, Hybrid | Open VMS platform; broad IP camera compatibility; integration with access control and building management; enterprise and government | Enterprise, government, healthcare | Johnson Controls integration gives access to full building management and access control ecosystem; competitive cost of ownership | |
| AxxonSoft | Infrastructure | On-prem, Edge | AxxonNext VMS; AI analytics integration; multi-site management; PSIM capabilities; open SDK | Government, enterprise, smart city | Strong international presence; competitive cost; open architecture supports broad third-party integration | |
| Alarm.com for Business | Infrastructure | Cloud | Cloud-managed video, access control, intrusion, environmental monitoring; unified dealer-delivered platform; AI analytics integration | SMB, mid-market commercial, dealer channel | Largest dealer-delivered cloud security platform; strong SMB to mid-market commercial reach via integrator network | |
| Dahua Technology | Infrastructure | Edge, On-prem | WizSense and WizMind AI camera lines; deep-learning object detection; facial recognition; LPR; behavioral analytics; thermal imaging; MultiVision 2.0 multi-sensor platform; DSS/IVSS VMS; APOLLO 4G solar-powered off-grid AI camera (April 2026) | Global enterprise, commercial, smart city, international government | Second-largest global camera OEM by install base behind Hikvision; NDAA restricted for U.S. federal use alongside Hikvision; lowest cost AI-embedded edge camera at global scale; strong APAC, EU, and LatAm commercial footprint where NDAA restrictions do not apply | NDAA Restricted Added Q2 2026 |
| Unified Ops / PSIM: Vision Ops (7) | ||||||
| Genetec Mission Control | Unified Ops / PSIM | On-prem, Hybrid | Procedure-driven incident management; automated task assignment; escalation timers; unified alarm and video correlation; audit trail and chain of custody | Large enterprise, data centers, government | Native integration with Genetec Security Center; no middleware required; CoreBastion preferred incident management for Genetec deployments | CoreBastion Preferred |
| Hakimo AI Operator | Unified Ops / PSIM | Cloud, SaaS | Autonomous AI alarm handling across access control and camera queues; learns normal patterns; triages alerts; routes verified events to human operators | Data centers, enterprise, GSOC | Directly reduces GSOC headcount requirement; $20.5M raised; proven in multi-site data center deployments | CoreBastion Preferred |
| AlertEnterprise | Unified Ops / PSIM | Cloud, SaaS | Cyber-physical identity convergence; access control meets cyber security; insider threat detection across IT and OT systems; identity governance integration | Critical infrastructure, utilities, enterprise, government | Bridges the physical-cyber identity gap; alerts on access anomalies that cross both domains simultaneously | CNI |
| SureView Immix | Unified Ops / PSIM | On-prem, Cloud | Remote monitoring center platform; alarm management; multi-site VMS aggregation; operator workflow and escalation tools | Remote video monitoring centers, enterprise SOC | Purpose-built for remote monitoring operations; integrates with virtually all major VMS and alarm platforms | |
| Everbridge | Unified Ops / PSIM | Cloud, SaaS | Mass notification, critical event management, threat intelligence, incident response coordination; integrates with physical security systems for unified response | Enterprise, government, healthcare, critical infrastructure | Links physical security incident detection to enterprise-wide emergency communication and response orchestration | |
| CNL Software (IPSecurityCenter) | Unified Ops / PSIM | On-prem, Hybrid | Open PSIM platform; broadest legacy system integration library; correlates video, access, PIDS, fire, and building management under one operator interface | Airports, utilities, government campuses, multi-system environments | Strongest legacy integration library in the PSIM category; handles old and new systems in the same interface | |
| AxxonSoft (Unified Ops) | Unified Ops / PSIM | On-prem, Hybrid | AxxonNext PSIM capabilities; multi-sensor correlation; event-driven automation; integration with access control, fire, and perimeter systems | Government, enterprise, smart city, industrial | Cost-effective PSIM alternative for international and emerging market deployments where Genetec or CNL are cost-prohibitive | |
| Security Posture Validation – Physical Native, Simulation Based (4): output is derived from a model, not asserted by an assessor | ||||||
| Mistabra | Posture Validation | Confidential Preview | Digital twin of the facility plus continuous AI-driven adversarial simulation; Security Readiness Score updated continuously rather than as a point-in-time snapshot; models component degradation and failure scenarios; portfolio-wide site comparison; score tied to underwriting through the Parametrix Lloyd’s-backed program | Data centers, CNI, enterprise, government, REITs and asset owners | The only entry combining continuous cadence, portfolio-scale coverage, a subscription commercial model, and a score wired into insurance underwriting. The simulation method itself is not new; the delivery model is. In confidential preview (mistabra.com) | Physical Native CoreBastion Advisory Board |
| ARES Security (AVERT suite) | Posture Validation | On-prem, licensed, services | 3D digital twin of a site; patented Monte Carlo simulation engine runs thousands of adversary path scenarios; detection, delay, and response modeled together to quantify probability of interruption and neutralization; AVERT for Design, Physical Security, AI, VR, and Virtual Tabletop; ARES Enterprise Security Platform also carries Vidsys CSIM and Mayday Safety | Commercial nuclear, DoD, DoE, utilities, transportation, corporate | The closest true peer on method and the entry most likely to surface in investor diligence. DHS SAFETY Act designated, DoD and DoE accredited, reported in use across roughly two thirds of the North American commercial nuclear fleet. Analyst-configured and engagement-driven rather than continuous SaaS, and priced accordingly | Closest Peer SAFETY Act / DoD / DoE |
| RhinoCorps (Simajin / Vanguard) | Posture Validation | On-prem, licensed, services | Agent-based combat simulation with a detailed human behavior model; analysts author attack plans, defense strategies, and 3D facility and terrain models, then run thousands of autonomous Monte Carlo trials without human intervention; outputs probability of interruption and probability of neutralization; PACRAT integration licensed from PNNL adds blended physical and cyber pathway analysis, including how a cyber compromise degrades the physical protection system | DOE complex, NRC licensee sites, nuclear, international high-security facilities, advanced reactor design | The entry that most directly tests the category claim. Used inside DOE for more than 15 years, named in the Nuclear Power Plant Security Assessment Guide as acceptable for the assessment process, and SAFETY Act approved. Markets an insurance angle already, though via SAFETY Act liability protection rather than premium pricing off a score. Runs unattended once configured; the human gate is model construction and attack plan authoring, sold as a 35-hour analyst course | Closest Peer SAFETY Act / DOE |
| Sandia National Laboratories (Scribe3D, PathTrace, CAS Simulator) | Posture Validation | Licensed to approved partners | Game-engine physical protection system modeling; adversary path analysis producing quickest, most-likely, and least-detected paths; Monte Carlo scenario replay; tabletop, performance test, and force-on-force planning; the EASI and vital area identification lineage underneath most performance-based PPS assessment | Nuclear and radiological facilities, government, universities, IAEA and NNSA training programs | The methodology baseline the entire physical assessment discipline is built on. Licensing, training, and support are free to approved partners, and the tools are in use across 28 countries. Not commercial, not continuous, not portfolio-scale, and not available to a typical enterprise buyer | Methodology Baseline |
| Security Posture Validation – Physical Native, Assessment Based (2): output is asserted by a human assessor, then scored | ||||||
| Circadian Risk | Posture Validation | Cloud SaaS | Physical risk intelligence and assessment platform; inherent risk, control vulnerability, and residual risk scored separately; multi-site portfolio dashboards; Corrective Action Plan remediation tracking; compliance and standards mapping; named data center vertical | Data centers, schools, healthcare, commercial real estate, multi-site enterprise | Competes for the same buyer and the same budget line, but not on the same basis. The score is a function of a human answering questions on a walkthrough, so it moves with the assessor as much as with the facility, and it is only as current as the last visit. Useful for compliance cadence and remediation tracking; it does not tell an operator what an adversary would actually do | Budget Line Competitor |
| RiskWatch | Posture Validation | Cloud SaaS | Framework-mapped assessment with automatic scoring and multi-site rollups; ASIS, FEMA 426, NERC CIP-014, and TAPA libraries built in; physical, cyber, vendor, and 40+ compliance frameworks in a single tenant | Enterprise, government, energy and utilities, healthcare | Competes on compliance defensibility rather than adversarial realism. Wins where an auditor wants framework citations. Worth naming the tradeoff plainly: framework-mapped checklists reward documented controls, not demonstrated performance, and a site can score well while remaining trivially defeatable | |
| Security Posture Validation – Convergent, Adversarial Validation Across Cyber and Physical (2) | ||||||
| Frenos | Posture Validation | Cloud SaaS | Digital twin of the OT network plus SAIRA, an AI reasoning agent that behaves as the adversary; fully simulated penetration tests with no scanning, no added hardware, and no downtime; validates and chains attack paths; continuous posture validation; SAIRA Co-Work persistent agent launched 2026 | Critical infrastructure, utilities, defense, industrial operators | Structurally the same product thesis as Mistabra applied to the OT network rather than the physical facility: build a twin, attack it continuously, output defensible posture. $6.4M raised after a July 2026 seed extension, ARR up more than 10x since the start of 2025 and 215% in H1 2026. The best available commercial proof that this model sells | Structural Analog |
| Filigran OpenAEV | Posture Validation | Open source, Cloud | Adversarial exposure validation across technical systems, human behavior, and physical environments; threat-intelligence-driven scenario generation via OpenCTI; MITRE ATT&CK mapping; crisis and tabletop exercise simulation with team readiness scoring | Government, enterprise, multi-site and multi-jurisdiction organizations | The only cyber-origin AEV platform explicitly claiming physical environments in scope. Deployed by the Swiss Federal Department of Foreign Affairs across 170 sites including embassies and consulates. The most credible encroachment path from cyber into physical validation, and it is free | Encroachment Risk |
| Adjacent – Not Validation Platforms (3): tracked because they hold an input the category depends on, or an encroachment path into it | ||||||
| Viakoo | Posture Validation | Cloud, on-prem agent | Automated discovery, firmware remediation, certificate management, and password rotation across cameras, access control, and IoT devices; treats the physical security device estate as a live attack surface and validates its hygiene continuously | Enterprise, government, data centers, healthcare | Validates the cyber health of the physical security estate, which is the failure mode most physical posture models ignore. Complementary rather than competitive, but it sells into the same room and the same budget conversation | |
| HiveWatch | Posture Validation | Cloud SaaS | Security operations management platform; device health monitoring; alarm noise reduction; AI Operator; operational benchmarking published as The State of Physical Security Operations 2026, measuring perceived readiness against measured program performance | Enterprise corporate security, multi-site GSOC operations | $65M raised. Already owns the operational performance measurement conversation and is publishing benchmark data on the exact gap Mistabra sells against. If HiveWatch extends benchmarking into predictive readiness scoring it becomes the most likely adjacent competitor in the physical segment | Encroachment Risk |
| SiteOwl (ASSA ABLOY) | Posture Validation | Cloud SaaS | Digital twin of the installed security system estate; device-level lifecycle tracking covering design, install, service history, warranty, and location; live shared floorplan designs replacing static drawings | Integrators, system owners, multi-site enterprise and public sector | Acquired by ASSA ABLOY in August 2025. Holds the asset-level digital twin that any physical posture scoring layer needs as an input. Ownership by a major access control OEM makes it either the best integration target in the segment or a future competitor with distribution | Acquired: ASSA ABLOY |
| Security Posture Validation – Cyber Native, Adversarial Exposure Validation (7) | ||||||
| Picus Security | Posture Validation | Cloud, SaaS | Continuous security control validation; breach and attack simulation plus automated penetration testing; attack path and detection rule validation; Picus Swarm agentic validation turning new CVEs and threat intel into automated test activity; MITRE ATT&CK mapped | Enterprise, government, cyber-physical convergence programs | Representative vendor in the March 2026 Gartner Market Guide for Adversarial Exposure Validation. Strongest remediation guidance in the group: vendor-specific instructions on how to close each gap, not just proof that it exists | Gartner AEV 2026 |
| Cymulate | Posture Validation | Cloud, SaaS | Exposure management and continuous control validation; attack surface management; breach and attack simulation; automated red and purple teaming; exposure analytics and risk scoring | Enterprise, financial services, government | Broadest attack surface coverage in the group and strong remediation workflow. Relevant to any organization running converged physical and cyber programs under one CSO | |
| SafeBreach | Posture Validation | Cloud, SaaS | Simulator-based breach and attack simulation running safely in production without agents on every endpoint; large adversary playbook library; risk quantification and board-level posture reporting | Enterprise, financial services, government | Strongest executive risk quantification and board reporting in the group. The reporting model is the one a physical posture platform should study for how a technical score gets consumed by a board | |
| XM Cyber | Posture Validation | Cloud, hybrid | Attack path management across on-prem, cloud, and identity; continuous exposure identification; choke point analysis prioritizing the small number of fixes that break the most paths | Large enterprise, government | Attack path and choke point analysis is the direct cyber analog of adversary path analysis in physical protection. Same intellectual model, different domain, and a useful vocabulary bridge when selling a physical score to a cyber-literate board | |
| Pentera | Posture Validation | Cloud, On-prem | Automated penetration testing that proves exploitability rather than listing theoretical vulnerabilities; validates real reachable risk under production conditions; credential and lateral movement testing | Enterprise, financial services, technology | Proof of exploitability rather than simulation of it. Sets the evidentiary bar buyers increasingly expect: not what could go wrong, but what did go wrong when we actually tried it | |
| Mandiant Security Validation (Google Cloud) | Posture Validation | Cloud, On-prem | Control effectiveness validation using frontline threat intelligence; MITRE ATT&CK emulated attacks; Advanced Environmental Drift Analysis; continuous posture monitoring | Enterprise, government, critical infrastructure | Backed by Mandiant incident response intelligence from active engagements. Highest-fidelity threat emulation in the commercial market | Gov / CNI |
| CISA SAFE | Posture Validation | Government program | CISA Security Assessment Framework for Enterprise; no-cost federal security posture assessment for critical infrastructure operators; gap analysis against NIST CSF and sector-specific standards; access to CISA sector specialists | Critical infrastructure operators, federal agencies | Free federal program and therefore the price anchor every commercial posture vendor is measured against by CNI buyers. Slow, scheduled, and capacity-constrained, which is precisely where a commercial platform wins | Federal Program |
Vendor Deep Dive
The most consequential product launch in physical security AI in 2025. General availability November 19, 2025.
Pulsar VLM is not an analytics overlay. It is a reasoning system trained specifically on physical security threat signatures across 150+ threat categories. Where legacy video analytics detect an object class ("person detected"), Pulsar reasons about the scene: who is present, what they are doing, whether the behavior is anomalous relative to the location and time context, and what threat category applies if any. The output is not a pixel-match alarm. It is a contextualized threat assessment with a four-step reasoning trace the operator can review.
Scene ingestion across all connected camera feeds simultaneously. Raw visual data converted to semantic tokens.
VLM reasoning about what is happening in the scene. Objects, actors, relationships, and temporal context evaluated together.
Threat classification against 150+ signature library. Anomaly scoring relative to learned baseline for that camera location and time of day.
Verified threat routed to operator with full reasoning trace. False positives eliminated before human review. SOC queue receives only confirmed events.
ARR doubled in FY26 with 140%+ net revenue retention, meaning existing customers are expanding deployments faster than Ambient is adding new logos. That metric is the strongest signal of product-market fit in the enterprise SaaS market.
Securitas Technology global reseller agreement closes the distribution gap that kept Ambient a known quantity among practitioners but limited in field sales reach. Securitas has the integrator relationships, the service contracts, and the enterprise security account footprint to carry Pulsar into large-enterprise accounts that Ambient's direct team cannot reach cost-effectively.
CoreBastion assessment: Ambient AI is the preferred AI analytics platform for data center and CNI physical security programs at scale. The VLM approach is structurally superior to rule-based analytics for high-camera-count perimeter and interior monitoring. The Securitas partnership de-risks the integration and support question that previously prevented some enterprise procurement teams from moving forward.
Category Deep Dive · Rebuilt Q3 2026
The prior edition of this report carried five vendors in this segment and described Mistabra as the category creator. A full research pass through Q3 2026 changes that picture. The corrected version is a harder claim to make and a much stronger one to defend.
On the specific combination Mistabra sells, no. Nobody else is running continuous adversarial simulation against a digital twin of a physical facility, across an entire portfolio, on a subscription, with the resulting score wired into insurance underwriting. That combination is genuinely unoccupied.
On the underlying technique, the answer is that it has existed for over a decade and it is accredited. ARES Security has been building 3D digital twins of sites and running thousands of Monte Carlo adversary simulations through its AVERT suite since 2012. AVERT is DHS SAFETY Act designated, DoD and DoE accredited, and reported in use across roughly two thirds of the North American commercial nuclear fleet. Sandia National Laboratories has been doing it longer through Scribe3D, PathTrace, and the EASI lineage that underpins performance-based physical protection assessment worldwide, in 28 countries, licensed free to approved partners.
Any investor who spends an hour on diligence will find both. A category-creator claim that does not survive that hour costs more credibility than it buys.
A second peer, found on the Q3 review: RhinoCorps. Simajin/Vanguard has run agent-based physical security combat simulation inside the DOE complex for over 15 years, is SAFETY Act approved, is named in the Nuclear Power Plant Security Assessment Guide, and through PACRAT (licensed from PNNL) blends physical and cyber pathway analysis in one model. It runs thousands of Monte Carlo trials unattended once configured. It is the single hardest entry for a category-creation claim to get past, and it is less well known than ARES, which makes it more dangerous in diligence rather than less.
The asymmetry to carry into every conversation. ARES has DoD and DoE verification and validation testing plus DHS certification. RhinoCorps has 15 years of DOE program use and NRC guidance recognition. Sandia is the methodology. Everything currently known about Mistabra’s capability comes from Mistabra, in confidential preview, with no published validation. That is a normal position for a preview-stage company and not a criticism, but it means this comparison is claims measured against verified capability. Two rankings exist here: on delivery model Mistabra leads and nothing is close; on demonstrated capability it sits behind four federally validated tools. Lead with the first and be ready for the second.
The distinction that does hold up. AVERT, Vanguard, and the Sandia tools are analyst-operated project instruments. A trained assessor builds the model, defines the design basis threat, runs the study, and delivers a report. That is a consulting engagement with software attached, priced and scheduled accordingly. Mistabra’s claim is a delivery model claim, not a physics claim: continuous rather than episodic, portfolio-wide rather than site-by-site, subscription rather than engagement, operator-run rather than analyst-run, and scored in a form an underwriter will actually price against. Positioned that way the claim survives diligence. Positioned as "nobody has ever simulated an attack on a building" it does not.
The segment only makes sense once it is split by what the platform actually validates. Buyers confuse these constantly, and vendors encourage the confusion.
Validates the built environment: barriers, sensors, access control, camera coverage, guard force posture, and response timelines. Splits again on where the number comes from, which is the distinction that actually matters.
Simulation based: Mistabra · ARES Security AVERT · RhinoCorps Simajin / Vanguard · Sandia Scribe3D / PathTrace
Assessment based: Circadian Risk · RiskWatch
Runs genuine adversarial validation across the cyber and physical boundary. Both build a twin and attack it. Three further entries are tracked as adjacent: Viakoo, HiveWatch, and SiteOwl hold inputs the category depends on or represent encroachment paths, but none of them validate anything adversarially.
Frenos · Filigran OpenAEV
Adjacent: Viakoo · HiveWatch · SiteOwl (ASSA ABLOY)
Validates network, endpoint, identity, and cloud controls. Gartner consolidated breach and attack simulation and automated pen testing into Adversarial Exposure Validation in its March 2026 Market Guide. Mature, funded, and crowded.
Picus · Cymulate · SafeBreach · XM Cyber · Pentera · Mandiant Security Validation · CISA SAFE
Every platform in this segment produces a number. Where the number comes from is the only question worth asking, and most buyers never ask it.
Assessment platforms produce asserted scores. A human walks the site, answers a structured question set, and the platform applies scoring math to those answers. Circadian Risk, RiskWatch, EasySet, and Resolver all work this way. The workflow, the audit trail, and the remediation tracking are real value. The score is not independently reproducible: send two competent assessors to the same facility and you get two different numbers, because the input is judgment. Change nothing about the site and change the assessor, and the posture appears to change.
Simulation platforms produce derived scores. The analyst or operator sets the geometry, sensor placement, delay elements, and response times. The result falls out of the model whether anyone likes it or not. Mistabra, ARES AVERT, and the Sandia tools work this way. Two people running the same model get the same probability of interruption. That is what makes the output defensible in front of an auditor, a board, or an underwriter, and it is why an insurer can price against it.
Practical consequence. Framework-mapped assessment tools reward documented controls rather than demonstrated performance. A site can pass an ASIS or NERC CIP-014 aligned assessment cleanly and still be trivially defeatable, because nothing in the process ever tested whether the control stops an adversary. That gap is the segment’s real opening, and it is a stronger argument than any competitive comparison, because it indicts the status quo rather than a rival product.
Both were carried in an earlier draft of this segment and both fail the test. Naming them here is deliberate: a category boundary that excludes nothing is not a boundary.
Resolver (Kroll). Incident management, investigations, and case management with GRC layered on top. Founded 2000, acquired by Kroll in 2022. Its real strength is chain-of-custody investigation workflow, and its physical security assessment capability is one module inside a corporate security suite. It is backward-looking by design: it documents what happened and manages the response. It never produces a facility posture number, and it does not model an adversary. It competes for corporate security budget, which is worth knowing, but it is not in this category.
EasySet. A physical security assessment report generator. An assessor walks the site with a mobile app, answers guided questions, selects from a prewritten library of vulnerabilities and solutions, and the platform builds a branded PDF. It does produce an Asset Vulnerability Risk Score on a 1 to 100 scale, but the vendor states plainly that the score combines documented vulnerabilities with the assessor’s own risk rating and mitigation priorities. That is assessor judgment with arithmetic applied, and EasySet is candid about it. It is the tool a consultant uses to produce the deliverable, which makes it part of the status quo this category sells against rather than a competitor within it.
"Nobody does what we do" is true and also unfalsifiable, which is why an investor will immediately try to take it apart. Better to take it apart first. Mistabra’s pitch has six components. Every one of them exists somewhere. Nobody holds the bottom four together, and the bottom four are the ones that carry the commercial argument.
| Component | Status | Who else has it | Why it matters |
|---|---|---|---|
| Digital twin of a physical facility | Prior art | ARES AVERT, RhinoCorps Vanguard, Sandia Scribe3D, SiteOwl at the asset level | Table stakes, not a differentiator. Claiming it as novel is the fastest way to lose a technical diligence call |
| Adversarial simulation against that twin | Prior art | ARES AVERT, RhinoCorps Simajin/Vanguard, Sandia Scribe3D and PathTrace, PNNL PACRAT | Accredited and in production for two decades. RhinoCorps has run inside the DOE complex for 15+ years. Concede it up front and pivot to why it never reached the commercial market |
| Continuous, always-on cadence | Unoccupied in physical | Nobody in physical. Frenos does it in OT | Every physical simulation tool runs per study. A finding is accurate the day it lands and decays from there |
| Portfolio-wide, site-versus-site comparison | Unoccupied at depth | Nobody at simulation depth. Circadian Risk does it at assessment depth | The question a CSO and a board actually ask. Per-site modeling cannot answer it at three hundred sites |
| Operator-run, no analyst gate | Narrowly held | Partially contested. Vanguard and AVERT execute simulations unattended; neither builds the model unattended | Narrow the claim to model construction. The gate is authoring the facility model, the design basis threat, and the attack plans, not running the trials |
| Score an underwriter will price | Narrowly held | Partially contested. RhinoCorps markets SAFETY Act liability protection as an insurance benefit. Nobody prices a premium off a continuous physical score. BitSight and SecurityScorecard did that for cyber | Moves the decision out of the security budget and into finance and risk. Still the strongest component, but the wording has to distinguish premium pricing from liability protection |
The generic claim has no answer to this. The unbundled version does, and it is the single most useful paragraph in an investor conversation.
It has not been built because the accredited tools require a trained analyst and a formally defined design basis threat before they produce a number. That requirement caps them at nuclear plants and defense installations that can justify a six-figure engagement per site. Removing the analyst from the loop is the actual product problem, and it only became tractable recently. The insurance linkage is a separate problem that requires a carrier partner willing to price a novel score, which is why almost nobody gets that far.
The caveat worth carrying into the room. This gap is real but it is not a moat. ARES already holds the engine, the accreditation, the reference customers, and the twin library. The only thing between them and this position is a decision to productize AVERT as a subscription. Frenos has now publicly demonstrated that the model sells in a neighboring domain, with ARR up more than tenfold since the start of 2025. Treat the whitespace as a head start measured in quarters, not a defensible position measured in years.
The entries a buyer or an investor is most likely to raise, compared on the dimensions that actually separate them. Assessment platforms are shown as a single column because they differ from each other far less than they differ from everything else in the table.
| Dimension | Mistabra | ARES AVERT | RhinoCorps Vanguard | Sandia Scribe3D / PathTrace | Assessment platforms (Circadian Risk, RiskWatch) | Frenos | Cyber AEV (Picus, Cymulate, et al.) |
|---|---|---|---|---|---|---|---|
| Domain validated | Physical facility | Physical facility | Physical + cyber blended | Physical facility | Physical facility | OT network | IT, cloud, identity |
| Method | Digital twin plus AI adversarial simulation | Digital twin plus Monte Carlo adversary path simulation | Agent-based combat simulation, autonomous Monte Carlo trials | Digital twin plus path analysis and scenario replay | Human walkthrough and questionnaire, scoring applied afterward | Digital twin plus AI reasoning agent | Live control testing and emulated attacks |
| Who operates it | The operator | Trained analyst or ARES services | Trained analyst, 35-hour certification course | Trained analyst, approved partners only | Assessor or consultant | The operator | The security team |
| Cadence | Continuous | Per engagement or per design change | Per study, unattended once configured | Per study | Per assessment visit | Continuous | Continuous |
| Unit of coverage | Portfolio | Site | Site | Site | Portfolio, at visit cadence | Network or site | Enterprise estate |
| Primary output | Security Readiness Score plus prioritized gaps | Probability of interruption, effectiveness metrics, cost-optimized design options | Probability of interruption and neutralization, blended physical-cyber pathways | Path analysis, interruption metrics, tabletop and force-on-force inputs | Inherent, control, and residual risk scores plus corrective action plan and remediation tracking | Validated exploitable attack paths, prioritized | Control effectiveness scores and remediation guidance |
| Commercial model | Subscription | License plus professional services | License plus professional services | Free to approved partners | Subscription | Subscription | Subscription |
| Insurance linkage | Yes, premium priced off a continuous score | No | Partial: SAFETY Act liability protection, not premium pricing | No | No | No | Indirect, via cyber ratings and underwriting questionnaires |
| Independent validation | None published; vendor claims only | DoD and DoE verification and validation testing, DHS certification | DOE program use, NRC guidance recognition | Sandia developed and peer reviewed | Commercial references | Customer-reported ARR growth | Gartner AEV representative vendors |
| Reproducibility | Same inputs, same score | Same inputs, same score | Same inputs, same score | Same inputs, same score | Score moves with the assessor | Same inputs, same score | Same inputs, same result |
| Accreditation and proof | Confidential preview, early deployments | DHS SAFETY Act, DoD and DoE accredited, US nuclear weapons stockpile, Pentagon Force Protection, 65% of US commercial reactors | SAFETY Act approved, 15+ years in the DOE complex, named in NRC assessment guidance | Sandia developed, IAEA and NNSA training, 28 countries | Established commercial install base; scores are assessor-dependent and not independently reproducible | $6.4M raised, ARR up 10x+ since early 2025 | Gartner AEV market category, heavily funded, mature |
Four gaps, none of them technological. All four are delivery model and commercial model gaps, which is where defensible category positions usually come from anyway.
Cadence. Every physical simulation tool on the market runs per study or per engagement. A finding is accurate the day it is delivered and decays from there. Nothing physical-side runs continuously and re-scores itself when a camera fails, a guard post is cut, or a construction phase opens a new path.
Portfolio scale. AVERT and Scribe3D model one site at a time, in depth, expensively. Nothing on the physical side lets an operator with three hundred sites rank all three hundred against each other on the same basis, which is the question a CSO and a board actually ask.
Underwriting linkage. State this one precisely or it breaks. RhinoCorps already markets an insurance benefit: SAFETY Act approval confers liability protection for approved anti-terrorism technology. That caps downside after an incident. It does not price a premium off a score. No physical security score has ever been continuously updated and priced by an underwriter, and Mistabra’s Parametrix arrangement is the first working instance. The claim that holds is "first continuously updated physical readiness score an underwriter prices against," not "first to link physical security to insurance."
Operator-run. Be specific about which analyst task disappears. Vanguard runs unattended once configured, and AVERT automates simulation execution too, so "removes the human from the simulation" is wrong and easily checked. The gate is model construction: building the facility model, defining the design basis threat, and authoring attack plans. RhinoCorps sells a 35-hour analyst certification at $4,990 a seat, which shows exactly where the labor sits. Removing the analyst from model construction is the real product problem and the one AI makes tractable.
Who could take this category, and from which direction.
Lead with the delivery model, not the invention. The strongest version of the pitch concedes the prior art immediately and then explains why it never reached the market: the accredited tools require a trained analyst, a defined design basis threat, and a per-site engagement budget, which caps them at high-consequence facilities that can justify the cost. That is why physical security still buys assessments at roughly $18,000 to $20,000 a site, episodically, covering a fraction of a portfolio.
Then make the redistribution argument. This is not a new budget line. It is an upgrade to spend that already exists, and it frees the human red team budget to concentrate on the small number of sites that genuinely need boots on the ground.
Then close on the insurance channel, because it is the only part of this story that no competitor in any of the three domains currently has. A physical readiness score an underwriter will price is a different kind of asset than a security report, and it moves the buying decision out of the security budget and into finance and risk.
Research basis: vendor primary sources, verified against vendor documentation rather than third-party rankings. Note on sourcing: several widely indexed "top ten physical security software" comparison pages are published by RiskWatch, a vendor competing in this segment. Their factual claims about competitors hold up against primary sources; their rankings should be read as marketing. Also drawn on: Gartner Market Guide for Adversarial Exposure Validation (24 March 2026), Sandia National Laboratories modeling and simulation program documentation, ARES Security product and accreditation disclosures, Frenos funding announcement (28 July 2026), ASSA ABLOY acquisition disclosure (August 2025), HiveWatch State of Physical Security Operations 2026. Mistabra remains in confidential preview; CoreBastion holds an unpaid advisory board position and this assessment is written with that disclosed.
Architecture
Physical security AI does not live in a single product. It operates across six functional layers from edge sensor to posture validation. Understanding which layer a vendor occupies determines whether it competes with or complements your existing stack.
Market Intelligence
Significant vendor developments, acquisitions, product launches, and market movements tracked through Q3 2026.