Asimily
Exposure management platform for connected device environments spanning IoMT, IoT, OT and IT, with healthcare delivery organisations as its founding and strongest vertical. Founded 2017, headquartered in Sunnyvale. The defining capability is CONTEXTUAL VULNERABILITY PRIORITISATION rather than discovery alone, which addresses the problem that actually defeats hospital security teams: a large hospital may run 10,000 to 25,000 connected medical devices representing 30 to 40 percent of all networked endpoints, and a raw vulnerability list across that fleet is unusable. Asimily evaluates each vulnerability in the context of the specific device's configuration and network environment, and prioritises by likelihood of exploitation and clinical or business impact, so remediation effort goes where risk is real. The company states this is necessary because IoT and IoMT devices exhibit network behaviour unlike conventional IT endpoints, leaving general purpose security tools unable to distinguish genuine risk from false alarms. The platform maintains an extensive knowledge base of connected and standalone medical devices, protocols, vulnerability research and manufacturer capability documents, and extends beyond assessment into orchestrated segmentation and risk mitigation, plus pre-purchase device evaluation so risk can be assessed before procurement. Ranked first in the KLAS 2026 Healthcare IoT Security report with a score of 96.6. Also ranked 13th fastest-growing cybersecurity company on the 2023 Deloitte Technology Fast 500 on reported 773 percent revenue growth, and selected for the US Department of Energy Clean Energy Cybersecurity Accelerator. Integrates with CMMS platforms including MediMizer bidirectionally, enriching its machine learning with medical device context while feeding security incidents into maintenance remediation workflows.
Capability Axes
Deliberate B, and this axis needs care across the whole cybersecurity category because AI language is applied loosely in security marketing. Asimily's machine learning is real and specifically located: contextual vulnerability evaluation against each device's configuration and network environment, exploit likelihood analysis, and behavioural anomaly detection, with the ML explicitly enriched by medical device context through CMMS integration. But the platform's substantive moat is the KNOWLEDGE BASE, described as the most extensive collection of connected and standalone medical device profiles, protocols, vulnerability research and manufacturer capability documents. That is a curated data asset, and device discovery leans on pre-existing device profiles alongside algorithms. Same principle applied to Reveleer's retrieval network and the credentialing lane: where the moat is the proprietary dataset rather than the model, AI Centrality is graded down. Not C, because the prioritisation reasoning is genuinely algorithmic rather than a lookup.
Sits deliberately at the advisory end of a spectrum the category makes explicit. Independent comparison characterises Asimily as a visibility and exposure management leader whose enforcement is delivered through guidance and integration rather than direct architectural isolation, meaning it tells you what to segment rather than segmenting the network itself. The company describes continuously orchestrating segmentation and mitigation actions without disrupting operations, so automation exists but acts through integrated infrastructure rather than unilaterally. That is the appropriate design choice in clinical environments where automated isolation of a misidentified infusion pump is a patient safety event, not merely an outage. Graded B rather than A because the boundary between recommended and automatically enforced action is not precisely stated.
Better than the category norm. The company names its mechanism specifically, evaluating vulnerabilities in the context of each device's configuration and network environment rather than by CVSS score alone, and describes passive monitoring, exploit analysis and the parameter plus device profile approach to discovery. Third party analysis identifies proprietary AI, ML and NLP as the basis for contextual vulnerability evaluation. Graded B rather than A because the prioritisation logic itself is not published in auditable form, and the category editorial for this index specifically warns that AI detection claims should be backed by named detection methodologies rather than marketing language; Asimily is above that bar but not fully transparent.
The best third party validation available in this category, though not clinical evidence in the usual sense. Ranked FIRST in the KLAS 2026 Healthcare IoT Security report with a score of 96.6, which is independent customer-sourced research rather than vendor claim, and is the single most useful comparator in this lane since KLAS surveys actual health system users. Selection for the US Department of Energy Clean Energy Cybersecurity Accelerator is independent technical validation from outside healthcare. Deloitte Technology Fast 500 placement at 13th fastest-growing cybersecurity company reflects commercial traction rather than efficacy. Graded B rather than A because vendor claims such as reducing vulnerabilities 10 times faster with half the resources carry no disclosed methodology, and no published breach-prevention or incident-reduction outcome data exists.
Structurally favourable rather than policy-based. The platform monitors network traffic and device behaviour passively rather than ingesting clinical content, so the data surface is device telemetry, protocol metadata and configuration rather than patient records. Passive monitoring also means no agents installed on medical devices, which matters because agents on regulated devices can invalidate manufacturer support. Graded B rather than A because network traffic in clinical environments can carry PHI in device protocol payloads, notably imaging and monitoring data, and no published statement on how such incidental PHI is handled was located.
No published BAA terms located. The company reports built-in HIPAA compliance reporting as a product capability, but that is a customer compliance feature rather than a statement of the vendor's own posture as a business associate.
No third party attestation such as SOC 2 Type II or ISO 27001 was retrieved at the time of review. This is a more pointed gap than usual: a security vendor without a published security attestation is being asked to meet the standard it exists to enforce, and health system procurement will require it.
Not an FDA regulated product. The platform secures medical devices rather than performing a medical function, so it sits outside Software as a Medical Device. The relevant regulatory surface is different and substantial: HIPAA Security Rule obligations, FDA premarket cybersecurity expectations for device manufacturers which shape what hospitals can patch, and the practical constraint that many clinical devices cannot be modified without voiding manufacturer support, which is precisely why passive monitoring and compensating controls dominate this category.
No governance framework or model evaluation disclosure located. Demographic bias is not the relevant risk class here; the analogous exposure is systematic misclassification of device types or under-detection of vulnerabilities in less common equipment, which would leave specific parts of a fleet silently unprotected. No published false negative or coverage analysis was located.
Strong and correctly targeted at the systems that matter in this category, which are not EHRs. The platform integrates with firewalls, network access control providers, SIEM and notably Computerized Maintenance Management Systems, with the MediMizer integration described as bidirectional: Asimily's machine learning is enriched by medical device context from the CMMS while the CMMS receives real-time security incident data to drive remediation workflows. That CMMS linkage is the important one, because it connects the security team's risk view to the biomedical engineering team that physically maintains the devices, and those two functions are usually disconnected in hospitals. Enforcement is delivered through integration with existing infrastructure rather than by replacing it.
Passive, agentless monitoring means deployment does not require software on clinical devices, which is essential in an environment where installing agents on regulated equipment may void manufacturer support or validation. Cloud platform with recognised cloud architecture. Independent comparison notes faster time to value on device visibility than NAC-based alternatives. Graded B rather than A because no data residency terms or on-premise option were located.
No pricing published and no pricing basis disclosed. Category context makes this consequential: independent analysis reports that enterprise configuration costs for a competing platform in this lane can reach very high figures, so cost variance between vendors is large and undisclosed. Buyers cannot compare cost per device or per site across this category from public information.
Broad across both asset classes and industries while retaining healthcare depth. Covers IoMT, IoT, OT and IT within a single platform, spanning medical, laboratory and general connected device fleets, and serves healthcare systems alongside manufacturing enterprises and financial institutions, with international reach through channel partnerships in Australia and the Nordics. Capability spans the full lifecycle: pre-purchase device evaluation, discovery and classification, vulnerability prioritisation, segmentation orchestration, and forensic incident response. Pre-purchase evaluation is a genuinely differentiated capability, since it moves security assessment upstream of procurement rather than inheriting risk after installation.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Not published
|
Undisclosed. Likely per-device or per-site; enforcement depends on existing network infrastructure so licence is not total cost. | — | — | Third Party Estimated |
No pricing published and no pricing basis disclosed, which is the norm across healthcare cybersecurity but has unusually large consequences in this category. Independent analysis of this lane reports that enterprise configuration costs for at least one competing platform can reach figures in the six digits, indicating very wide cost variance between vendors for what buyers may perceive as comparable capability. A health system cannot compare cost per connected device, per site or per bed across this category from public information. The natural pricing unit is per device monitored or per site, and buyers should establish which, since a large hospital may run 10,000 to 25,000 connected medical devices and per-device pricing scales very differently from a site licence at that fleet size. Two further diligence points specific to this vendor. First, because enforcement is delivered through integration with existing firewall, NAC and SIEM infrastructure rather than by direct isolation, the total cost of a working deployment includes whatever enforcement infrastructure the organisation already has or must acquire, so the platform licence is not the whole spend. Second, the pre-purchase device evaluation capability and the CMMS integration may be licensed separately from core discovery and should be confirmed rather than assumed. The KLAS 2026 Healthcare IoT Security report, in which Asimily ranked first at 96.6, is the most useful independent comparator available for this decision and is worth obtaining.