LATEST / COLORTOKENS
23 SEP 2026 · AI-ASSISTED ATTACK CONTAINMENT DEMO PUBLISHED18 AUG 2026 · COMPANY ANNOUNCES REPEATED FORRESTER LEADER DESIGNATION

Company / CybersecurityInside the network / 01

ColorTokens and the Art of Keeping a Breach Small

A compromised machine need not become a compromised company. ColorTokens sells the boundaries that make that distinction possible - and the tools to install them without stopping the business.

The city had more than forty departments. Its network, unfortunately, behaved like one room. In an anonymous case study published by ColorTokens, attackers entered through a single department and moved across the others. Restoring services took weeks. The boundary on the organizational chart had never become a boundary in the network.

The story in four lines
  • The job: restrict where an intruder can go after getting inside.
  • The product: Xshield maps traffic and enforces small, specific security boundaries.
  • The buyers: enterprises with critical applications and a mixture of old and new infrastructure.
  • The catch: a good rule must stop the attacker while letting the business work.

Forty departments, one unwelcome visitor

The city’s problems were familiar: aging systems, accumulated rules and too few security staff. Replacing its unsupported infrastructure would have cost too much. ColorTokens describes a staged deployment: train the staff, let them lead with assistance, then hand over routine operations. The company reports reduced exposure and greater independence for the city’s team.

That account is a vendor’s case study, rather than an independent incident investigation. Still, it supplies a useful question for any executive: when one department is breached, why should the next department become available? Departments keep separate budgets. Their computers might consider separate privileges.

ColorTokens occupies the part of cybersecurity concerned with that second question. Its specialty is enterprise microsegmentation: controlling communications between individual assets or groups of assets, so an initial compromise has fewer places to travel. The company calls the result “breach readiness.” The phrase has the refreshing quality of conceding that a bad day may actually arrive.

The map becomes a set of rules

Founded in 2015 by Nitin Mehta and Rajesh Khazanchi, ColorTokens brings an enterprise-software background to the problem. Mehta is executive chairman. Khazanchi, who became CEO in April 2021, previously led product teams at HP, Oracle and VMware. Those are places where an elegant idea eventually meets an untidy installation.

The flagship Xshield platform starts with assets and their conversations. Which application calls which database? What traffic crosses between workloads, devices and the internet? From that view, a security team can design approved and denied flows, group assets with tags and apply policy templates. The map becomes something the network must obey.

A breach has an itineraryRemove the unnecessary stops.
01 / COMPROMISEDWorkstation
Unapproved traffic×Blocked by policy
02 / CRITICALPatient records
Approved application→Required database access
The intruder gets a smaller guest list. Conceptual illustration of segmentation, not a measured customer result.

NIST’s zero trust architecture describes the underlying principle: network location alone should not grant implicit trust. For a business, that means being inside the network cannot automatically confer the right to talk to everything else inside it. A workstation may need one service. It need not inherit a sightseeing pass to the whole data center.

Xshield’s market position rests partly on the breadth of the estate it can cover. Its materials describe data center servers, cloud workloads, user endpoints, containers and operational technology. Enforcement can use installed agents or agentless methods. The product also offers simulation and testing before a policy begins interfering with live communications. That final detail matters enormously to anyone whose bonus depends on the applications staying up.

The hospital cannot stop for the installation

Consider another ColorTokens account: an unnamed U.S. cancer and research center with more than 10,000 servers and 20,000 endpoints. It had modern applications alongside unsupported systems. Its team wanted to protect Epic and control backup-related exposure, but an earlier attempt with virtual firewalls had proved time-consuming and difficult to maintain.

10,000+servers in an anonymous cancer-center case study
Scale reported by ColorTokens; not the company’s total installed base.

Here the obstacle was implementation and upkeep. The organization needed a way to restrict traffic without substantially changing its network architecture. ColorTokens reports that it achieved the customer’s desired outcome without disruption. It is a useful illustration of the buying motive, rather than proof that every hospital will get the same result.

The broader product logic is straightforward. Some medical and industrial devices cannot readily accept another piece of endpoint software. Gatekeeper, ColorTokens’ agentless enforcement appliance, addresses that constraint. Other machines can use host-based agents. The defense solution brief even discusses Windows 2003 and HP-UX. Corporate infrastructure has a remarkable ability to preserve the past while accounting insists it is building the future.

Public customer stories include Persistent, Virtusa, Livi Bank, California Bioenergy and Estia Health. They span technology services, banking, energy and healthcare. The common thread is a business with valuable systems and complicated connections. ColorTokens sells to the teams responsible for keeping those connections useful without making every connected asset equally reachable.

Rajesh Khazanchi, ColorTokens co-founder and CEO
The man selling smaller disasters. Co-founder and CEO Rajesh Khazanchi brought product experience from HP, Oracle and VMware to ColorTokens.

A moving address is a poor identity

In September 2024, ColorTokens acquired PureID. The acquisition tackled a particular weakness in policy built around infrastructure addresses: cloud workloads change, containers move and users appear in different locations. An IP address is a useful locator. Treating it as a permanent identity asks it to do another job.

ColorTokens said PureID would strengthen identity-based segmentation across cloud, container, operational and user environments. PureID’s PureAUTH passwordless and multifactor authentication platform would continue serving customers. The strategic idea was to anchor rules to reliable identities, with less dependence on changing infrastructure attributes. That is a concrete reason to buy an identity company when your principal business is boundaries.

“Microsegmentation has historically been powerful but operationally complex.”

Rajesh Khazanchi / Xshield AI Agent announcement, March 2026

The next development addressed policy work itself. On March 10, 2026, ColorTokens introduced Xshield AI Agent, an engine for assisting policy design and rollout. The announcement describes plain-language queries, live telemetry and guardrails for refining segmentation policies. Its promise to shorten work from days to minutes is the company’s claim, rather than a stopwatch reading from every customer.

The announcement also reported customer reductions of up to 90% in blast radius and attack surface within 90 days. Those measures describe exposure; they should not be read as a universal 90% reduction in breach probability. A sensible evaluation asks what was measured, which assets were included and whether the rules stayed effective after the environment changed.

The bill includes the work

ColorTokens combines subscription software with services. Xassure covers adoption, managed microsegmentation, monitoring and response. Separate consulting offerings include readiness assessments and implementation. This is a business model suited to a product whose success requires decisions about other people’s applications. Selling the console is only part of getting a useful boundary into production.

A historical cost marker / UK G-Cloud 13£600-£900

Per server, per year for Xshield microsegmentation in a price-list file dated May 2022. Historical procurement pricing, not a current offer.

That public list also offered a lower-priced visualization option without microsegmentation, and described volume variation and multiyear discounts. It makes an instructive distinction: seeing traffic and controlling traffic can be different purchases. A buyer’s budget should also count the internal time needed to identify dependencies, approve changes and maintain policy. Those hours are part of deployment even when they never appear on the vendor’s invoice.

Partners help carry the installation and sales work. Tech Mahindra expanded its collaboration with ColorTokens in December 2024, pairing Xshield with cybersecurity services. In November 2025, Carahsoft became the public-sector distributor for ColorTokens Federal Solutions. The CrowdStrike integration takes another route to adoption: use an existing Falcon agent footprint for visibility and enforcement, reducing the need to install additional endpoint software.

The alternatives include Illumio and Akamai Guardicore Segmentation. ColorTokens’ municipal case study names both as vendors the city considered. Coverage and deployment workflow are reasonable grounds for comparison; no company wins merely by saying “zero trust” more often. In August 2026, ColorTokens announced a repeated Leader designation in Forrester’s microsegmentation evaluation. Analyst recognition helps establish a shortlist. An organization’s own environment still supplies the examination.

Start with the machine you can least afford to lose

The lesson a reader can copy is a sequence. Choose a critical application and identify what it genuinely needs to communicate with. Observe those dependencies, design restrictions, simulate their effects and move into enforcement with the application owner involved. Then keep reviewing the policy. This is an editorial takeaway from the workflow, rather than a claim that one sequence fits every installation.

01ChooseA critical service
02ObserveIts real dependencies
03TestThe proposed boundaries
04EnforceThen review changes

The conditions matter. Missing assets leave missing boundaries. Incomplete dependency maps can turn a well-intended restriction into an outage. Policies that nobody maintains can drift away from the business they were meant to protect. Segmentation also leaves work for patching, identity controls, detection and recovery. Its particular contribution is to reduce reachable paths after something has already gone wrong.

Ask for a demonstration with a deliberately compromised test machine. Which critical assets can it reach? Which connections are blocked? Can the legitimate application still do its job? These questions bring a grand security proposition down to a small, observable transaction. ColorTokens’ proposition lives there: in the connection an attacker wanted, and the rule that declines to provide it.