Exein builds security software that runs inside connected equipment used by manufacturers and infrastructure operators. The company announced a $270 million equity round at a $1.7 billion valuation on September 15, backing international expansion and its push to protect machines that use AI to act in the physical world.
Its Runtime product works at the kernel, the core of an operating system between applications and hardware. Exein says this lets the software inspect activity and block malicious behavior as it attempts to execute. Teams can monitor incidents across a fleet, trace what happened and generate evidence for investigations and compliance reporting from the machines’ operating data.
Equipment suppliers provide a route into those deployments. On Exein’s website, AAEON Europe describes choosing its protection for embedded systems, while railway engineering business DB Systemtechnik describes Exein as a partner protecting connected devices aboard trains. SECO says it integrates Exein with its Clea connected-device platform through a software-as-a-service offering, illustrating how security can reach users through another supplier’s product.
Headline led the financing, with Sofina, Goldman Sachs and other new and existing investors participating. Exein says the equity round closed oversubscribed. Separately, it is expanding its revolving credit facility led by J.P. Morgan, with KfW joining as a lender, to support acquisitions in Europe and the United States.
The existing business gives Exein a base for developing new defenses. According to company figures carried by Tech.eu, its technology spans more than two billion devices, about half its revenue comes from Asia-Pacific, and annual recurring revenue in the first half of 2026 was four times the year-earlier level. Exein is developing a foundation model trained on machine telemetry to power autonomous security agents; the proposed distinction is learning how equipment operates from its own operating history.
That development remains a delivery task: Exein plans its new security architecture by the end of 2026 and its first foundation models in early 2027. The next business test is whether that machine data can become dependable autonomous protection for the equipment makers and operators already integrating its software.