Lupovis
18 employees on LinkedIn · 2 known investors
Lupovis is a cybersecurity platform that captures real attacker activity and threat intelligence to provide context for security operations teams. The platform helps organizations detect, prioritize, and respond to threats targeting their infrastructure by linking observed attack activity to vulnerabilities, threat actors, and attack techniques.
Also known as Lupovis Limited
Investors · 2
Company profile
researched Aug 2026Lupovis is a cybersecurity company that captures real attacker activity observed in the wild and converts it into contextual intelligence for security operations centre (SOC), cyber threat intelligence (CTI) and vulnerability management teams. Its platform is positioned to show organisations who is targeting them, what parts of their estate are being probed, and what response to take before an incident occurs. Signals are described as spanning the attack lifecycle from scanning and validation through to exploitation attempts, with each signal accompanied by context on the actor, activity, timing and method.
The platform links observed activity to vulnerabilities, threat groups, tactics, techniques and procedures (TTPs) and adversary infrastructure, and filters that activity according to a customer's own assets and targeting so teams can prioritise. Stated use cases include vulnerability intelligence (prioritising actively exploited CVEs rather than relying on CVSS and EPSS scores alone, ahead of KEV alerts), threat-led defence, threat hunting supported by curated SIEM rules mapped to observed attacker activity, SOC efficiency through blocking hostile infrastructure before it reaches the environment, insider threat detection by comparing internal behaviour against attacker tradecraft, and threat-led penetration testing informed by tradecraft seen in the customer's industry.
Earlier company material describes an approach based on deception: deploying decoys in client infrastructure to detect and deter threats early, using AI, manipulation and gamification to draw attackers away from sensitive data and intellectual property while recording the techniques, tactics and procedures they use and passing them to security analysts. The company has framed this as reducing false positives and alert fatigue for SOC analysts and as increasing the level of certainty attackers must operate with.
Founding story
Lupovis was founded in Glasgow by Dr Xavier Bellekens and Professor Ivan Andonovic, both academic members of the Department of Electronic and Electrical Engineering at the University of Strathclyde, who together bring 20 years of experience in cyber security and machine learning. Bellekens serves as chief executive.
Business model
Lupovis sells a security intelligence platform to enterprise and public sector security teams, offering a free entry point alongside a sales-led motion built around booked product demonstrations.
Latest developments
Company materials describe participation in NCSC For Startups, where Lupovis sought to enhance the training of its systems using information and telemetry provided by the NCSC to improve its adversary-luring strategies.
▸Full profile — market position, technology, go-to-market, geography
Market position
Positions itself as a source of definitive, behaviour-backed attacker intelligence, contrasting its use of observed adversary activity with approaches based on inferred patterns or historical indicators.
Emphasises intelligence derived from what attackers actually did rather than predicted behaviour, environment-aware filtering that ties activity to a customer's own assets and targeting, and delivery of vulnerability insight ahead of KEV alerts. Its deception-based collection is framed as inverting the defender's burden, requiring attackers rather than defenders to be right every time.
Technology
The platform is built on the collection of real, observed attacker behaviour rather than inferred patterns or historical indicators. Telemetry from decoys deployed in client infrastructure is used to gather adversary techniques, tactics and procedures, and AI is applied to detect and deter threats and to lure adversaries away from sensitive data and intellectual property. Collected signals are correlated in real time with vulnerabilities, threat groups, TTPs and attacker infrastructure, and are made available to defenders as prioritised insights and curated SIEM rules.
Go-to-market
Direct engagement via the company website through a self-service free tier and 30-minute demonstration walkthroughs delivered by the Lupovis team, alongside participation in the Plexal-run NCSC For Startups programme.
Security operations, cyber threat intelligence and vulnerability management teams, with sector focus on telecommunications, finance, insurance, public sector, defence, healthcare, manufacturing and automotive.
Geography
Founded in Glasgow, Scotland, with links to the University of Strathclyde and to UK programmes run by Plexal and the NCSC.
Compiled by commissioned research from 3 cited public sources — announcements, filings, and press listed under research sources below.
Competitors · 10
by search overlapCompanies competing with Lupovis for the same Google search keywords, organic and paid, via search-intersection analysis.
Timeline · 1
launches, deals, and filingsLupovis was profiled as a member startup of the NCSC For Startups programme delivered by Plexal, seeking to use NCSC information and telemetry to improve its adversary deception and detection capabilities.
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
In the news
▸Research sources · 3
primary sources listed
- Lupovislupovis.io · web
3 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does Lupovis do?
- Glasgow-founded cybersecurity company that captures real attacker activity and turns it into contextual threat intelligence.
- Who are Lupovis's investors?
- Lupovis's investors include Nauta Capital, Volta Ventures.


