Oasis Security
by Oasis Security
Discover, secure and govern every non-human identity
Oasis Security is a non-human identity management platform that discovers every service account, API key, token, certificate and AI agent across cloud, SaaS and on-premises estates, assigns each one a human owner, scores its risk, and then orchestrates vaulting, rotation and decommissioning under policy. It is built for identity and security teams whose machine identities already outnumber their staff.
Oasis Security builds an enterprise platform for discovering, securing and governing non-human identities - the service accounts, API keys, tokens and certificates, and increasingly the AI agents, that now outnumber human users in enterprise environments by roughly 82 to 1, a ratio Oasis cites from Palo Alto Networks research. It was founded in 2022 by chief executive Danny Brickman and chief product officer Amit Zimerman, is headquartered in New York, and raised a $120 million Series B led by Craft Ventures on 19 March 2026 with Cyberstarts, Sequoia Capital and Accel participating, bringing total funding to $195 million - the largest single round raised in the non-human identity category. The platform works in three stages. It first inventories non-human identities across AWS, Google Cloud, Azure, SaaS and on-premises systems and enriches each with usage, consumers, resources and privilege context, then uses machine-learning heuristics against CMDB data to auto-assign an owner, which is the step that makes remediation possible at all, since orphaned credentials are precisely the ones nobody dares rotate. It then assesses posture and detects anomalies, credential leaks and unauthorized access through Oasis Scout, its identity threat detection and response module, supported by AuthPrint fingerprinting at the authentication stage. Finally it orchestrates the lifecycle: provisioning, vaulting, safe rotation and decommissioning under policy, with certification campaigns producing audit evidence. Its newer Agentic Access Management layer extends the same model to AI agents using intent-based, just-in-time and ephemeral permissions rather than static roles, alongside AI security posture management for agent configurations. Integrations span HashiCorp Vault, CyberArk, Okta, Ping Identity, Microsoft Active Directory, GitHub, Salesforce, Databricks, Snowflake and OpenAI and Copilot platforms. Oasis reports 5x year-over-year growth in new ARR on a customer base concentrated in the Fortune 500, largely on multi-year contracts, and is SOC 2 Type II compliant and ISO 27001 certified.
The identity or cloud-security team at a large enterprise that has already lost track of its service accounts and is now being asked to let AI agents hold credentials too.
A complete, owner-mapped inventory of every non-human identity, with a safe rotation path for the credentials nobody currently dares touch.
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing, Subscription
- Target Market
- CISOs, Identity and Access Management Teams, Cloud Security Engineers, CIOs, Compliance and Audit Teams
- Deployment
- Cloud-first, Multi-cloud
- Founded
- 2022
- Headquarters
- New York, United States
- Customers
- Customer base concentrated in the Fortune 500, including Citizens Financial and Mars; exact count not disclosed
Key Features
- ✓Automated non-human identity discovery
Inventories service accounts, keys, tokens and certificates across hybrid cloud, SaaS and on-premises estates with usage and privilege context.
- ✓ML-based ownership auto-assignment
Correlates usage patterns against CMDB data to name a human owner for each orphaned credential, making remediation actionable.
- ✓Oasis Scout
Identity threat detection and response for non-human identities, surfacing credential leaks, anomalies and unauthorized access attempts.
- ✓AuthPrint
Fingerprints threat-actor behaviour at the authentication stage against the Oasis NHI Threat Center to cut false positives.
- ✓Agentic Access Management
Grants AI agents intent-based, just-in-time and ephemeral permissions via vaulting, federation and short-lived session identities.
- ✓Lifecycle orchestration and safe rotation
Pre-configured remediation plans drive provisioning, vaulting, rotation and decommissioning without breaking dependent services.
- ✓Certification campaigns
Policy-driven access reviews generate reviewable records of who approved each machine identity, for audit and compliance.
Capabilities
Use Cases
- •Credential sprawl audit before an examination
A bank inventories every service account across three clouds and its SaaS estate ahead of a regulatory review.
- •Rotating credentials nobody owns
Ownership mapping identifies the responsible team, so a decade-old key can finally be rotated or retired safely.
- •Onboarding AI agents without standing privilege
An agent receives time-bound, intent-scoped access rather than a permanent administrative token embedded in configuration.
- •Reducing breach blast radius
Over-privileged non-human identities are surfaced and downscoped before an attacker can chain them into lateral movement.
- •Continuous compliance evidence
Access certification campaigns produce the reviewable approval trail auditors expect for machine identities, not just human accounts.
Ideal For
Best For
- ✓Inventorying service accounts, API keys, tokens and certificates across AWS, Google Cloud, Azure, SaaS and on-premises systems
- ✓Assigning ownership to orphaned credentials so they can finally be rotated or retired
- ✓Granting AI agents scoped, time-bound access instead of long-lived static credentials
- ✓Producing audit and compliance evidence for machine-identity governance and access certification campaigns
- ✓Safe secret rotation in environments where a badly sequenced rotation takes down production
Not Ideal For
- ✗Small teams and startups - pricing is quote-only and the company sells multi-year enterprise contracts to a largely Fortune 500 base
- ✗Organisations looking for human-workforce IAM; Oasis governs machine identities and expects an existing identity provider such as Okta or Microsoft Entra ID alongside it
- ✗Buyers who need published pricing or a self-serve trial, since entry runs through a sales-led demo request and no rate card exists
- ✗Estates with little cloud or SaaS footprint, where the credential sprawl the product solves for has not yet developed
Deployment
Market & Ratings
Customer base concentrated in the Fortune 500, including Citizens Financial and Mars; exact count not disclosed
Market Analysis
Pros
- ✓Ownership auto-assignment solves the actual blocker in machine-identity cleanup - not finding the credentials, but finding who owns them
- ✓One platform spans discovery, posture, threat detection and lifecycle remediation, so teams avoid stitching an inventory tool to a vault to a ticketing workflow
- ✓Broad hybrid coverage across AWS, GCP, Azure, SaaS and on-premises with connectors into Vault, CyberArk, Okta, Ping and Active Directory
- ✓Agentic Access Management is a genuine answer to a live problem: giving AI agents ephemeral, intent-scoped credentials rather than static admin tokens
- ✓Financially the strongest-funded vendor in the category, which matters for a multi-year infrastructure commitment
Cons
- ✗Zero pricing transparency - no plans, no rate card, no trial, and no way to size a deal without engaging sales
- ✗Independent category analysis positions Oasis on established enterprise governance rather than technical novelty, with newer rivals such as Astrix, Clutch and Teleport shipping more distinctive architectures (quad-detection, identity lineage, zero-knowledge, MCP wrapping)
- ✗Practitioner discussion is thin: Hacker News surfaces Oasis mainly through its research team's Azure MFA bypass disclosure, and the NHI security category as a whole draws minimal community discourse, so there is little unfiltered production feedback to check vendor claims against
- ✗No public presence on G2, Capterra, TrustRadius or Trustpilot, so there is no third-party rating or review volume to sanity-check the customer experience
- ✗Astrix's category mindshare fell from 19.0% to 10.2% year over year in one tracker, a reminder that positioning in this market is unstable and today's leader is not a safe multi-year assumption
Pricing
Enterprise
Contact for pricing
- ✓Non-human identity discovery across cloud, SaaS and on-premises
- ✓ML ownership mapping and posture assessment
- ✓Oasis Scout threat detection and AuthPrint fingerprinting
- ✓Agentic Access Management for AI agents
- ✓Lifecycle orchestration: vaulting, rotation and decommissioning
No list pricing is published anywhere on the Oasis site - the pricing page carries only a demo request form, and the sole call to action is to speak with a technical expert. The company states that the majority of its new revenue comes from multi-year enterprise agreements with a customer base concentrated in the Fortune 500, so expect an annual-contract negotiation rather than seat- or usage-based self-serve, with scope more likely driven by the size of the identity estate than by headcount. Budget for a security-platform-sized line item, not a tool.
Security & Compliance
Sources
This page was written from 8 sources, 5 on domains other than oasis.security.
- 1.oasis.security — productvendor
- 2.oasis.security — about usvendor
- 3.oasis.security — pricingvendor
- 4.calcalistech.com — ske4mstcwl
- 5.finance.yahoo.com — oasis security raises 120m series 160000141
- 6.accessnewswire.com — oasis security raises 120m series b to secure the rise of en
- 7.cremit.io — rsac 2026 nhi
- 8.hn.algolia.com — hn.algolia.com
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
OpenAI Daybreak
Vetted-access frontier AI for cyber defenders, with a purpose-built offensive-security model
NVIDIA OpenShell
Open-source, kernel-isolated sandbox runtime for autonomous AI agents
Zenity
Runtime AI agent security that blocks a harmful agent action before it executes
Saviynt Zuma
Identity control plane for AI agents and non-human identities, with runtime authorization
Mentioned In
Oasis Security Raises $120M for AI Agent Access: When Machines Outnumber Humans
Oasis Security raises $120M for AI agent access management. For CISOs managing non-human identities: why agent-to-human ratios demand new identity and access...
March 22, 2026AI SecurityOasis Security's $120M Series B: Securing AI Agent Identities
As enterprises rush to deploy AI agents, Oasis Security raises $120M to secure the explosion of nonhuman identities—now outnumbering employees 144:1. What IT leaders and finance leaders need to know about the fastest-growing attack surface in cloud infrastructure.
March 21, 2026ROILenovo Plus NVIDIA Hybrid AI Cuts Costs 8x With ROI in Six Months
Lenovo Plus NVIDIA Hybrid AI Cuts Costs 8x With ROI in Six Months. For enterprise decision-makers: strategic analysis, cost implications, and implementation ...
March 22, 2026AI SecurityOasis Security $120M Series B: What CFOs Need to Know About AI Agent Cost and Risk
Oasis Security raises $120M for AI agent access management. For CISOs managing non-human identities: why agent-to-human ratios demand new identity and access...
March 20, 2026Data Center CoolingEcolab Pays $4.75B for Liquid Cooling: What CFOs Need to Know About Data Center Infrastructure Bets
Ecolab's $4.75 billion CoolIT acquisition signals liquid cooling's shift from niche to necessity as AI workloads demand thermal infrastructure at scale. Here's the ROI math for enterprise leaders.
March 22, 2026Cloud InfrastructureMicrosoft Loses OpenAI Exclusivity as AWS Pays $50B: What Enterprise AI Buyers Should Do Now
Microsoft Loses OpenAI Exclusivity as AWS Pays $50B. For enterprise decision-makers: strategic analysis, cost implications, and implementation guidance for A...
March 22, 2026Venture CapitalAI Startups Capture 89% of US Venture Capital as Anthropic and Waymo Raise $46B
AI Startups Capture 89% of US Venture Capital as Anthropic and Waymo Raise $46B. For enterprise decision-makers: strategic analysis, cost implications, and i...
March 22, 2026IT ProcurementOpenAI Merges ChatGPT, Codex, and Atlas Into Desktop Super App: What It Means for Enterprise IT Budgets
OpenAI Merges ChatGPT, Codex, and Atlas Into Desktop Super App. For enterprise decision-makers: strategic analysis, cost implications, and implementation gui...
March 22, 2026Enterprise AIOpenAI Doubles Workforce to 8,000: What Enterprise Buyers Should Watch
OpenAI's 77% headcount expansion signals enterprise-first strategy. Technical ambassadors, product consolidation, and faster roadmap velocity.
March 21, 2026AI GovernanceTrump AI Policy Ends 50 State Rules: Enterprise Impact
The White House just released a national AI framework that preempts state laws. Here's what finance leaders and IT leaders need to know about compliance changes, safe harbors, and regulatory timelines.
March 22, 2026ComplianceHow to Red-Team Your AI Agents Before Production
Enterprise AI analysis: How to Red-Team Your AI Agents Before Production. Strategic insights, ROI considerations, and implementation guidance for technical a...
March 16, 2026Enterprise AICresta Knowledge Agent: Why Augmentation Beats Automation for Contact Centers in 2026
Cresta Knowledge Agent uses augmentation over full automation for contact centers. For COOs managing support: productivity gains while maintaining human over...
March 22, 2026