All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Akeyless leads with split-key cryptography that keeps encryption keys split so no single party, including Akeyless, can reconstruct them, and its cryptographic module now carries an independent NIST FIPS 140-3 validation. That zero-knowledge choice closes the trust objection a secrets buyer raises first, and the public record identifies no cross-customer dataset it compounds. So Akeyless competes on engineering depth and certification rather than data scale. Its proven business is conventional secrets management, not the AI-agent pitch on its homepage. It is most defensible where workloads already authenticate through it under regulated controls, and weakest where an incumbent or cloud provider could fold vaultless secrets into a suite buyers already own.
| Description | Akeyless is an identity security platform for AI agents, machines, and humans. It manages secrets, keys, certificates, and machine identities from one policy engine, delivers them with no vault overhead, and secures AI agent actions at runtime. | [f1] |
|---|---|---|
| Founded | 2019 | [f2] |
| HQ | New York, United States | [f3] |
| Funding | $80M total | [f4] |
| Latest funding | Series B ($65M, Nov 2022, led by NGP Capital) | [f4] |
| Deployment | SaaS | [f5] |
| Compliance | FIPS 140-3, ISO 27001, PCI DSS, SOC 2 Type 2 | [f5] |
| Product | What it does |
|---|---|
| Akeyless | Identity security platform for machines and AI agents that issues just-in-time, vaultless secrets and certificates so agents authenticate without hardcoded credentials and act under runtime control. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Akeyless is an identity security platform for machines and AI agents that issues just-in-time, vaultless secrets and certificates so agents authenticate without hardcoded credentials and act under runtime control. It is mapped to the AI Defense Matrix. [f6]
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Akeyless provides secrets management and machine-identity security. This conventional security is mapped to the Cyber Defense Matrix. [f7]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Akeyless names the buyer and the credential-sprawl pain, and KuppingerCole independently frames secrets sprawl, hardcoded credentials, and non-human identity growth as the category problem, but the quantified pain is the vendor's own (the 12 tools across 15 categories and 75 vendors figure Oded Hareven gave), short of independently quantified scale. [s13, s7, s12] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | The public documentation portal details a single control plane spanning authentication, certificate issuance, privileged access, and key management, and the Akeyless cryptographic module integrated into those products now carries an external validation point the prior review lacked: an independent NIST CMVP FIPS 140-3 certificate, with KuppingerCole's evaluation a second outside assessment. [s15, s3, s13] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The enabler is the move of AI agents and non-human identities into production since 2024, which Akeyless reuses its just-in-time engine to serve, layered on the DORA regime that took effect in 2025, but the buyer-side demand evidence stays at the category level (KuppingerCole and Gartner track the market) rather than named Akeyless-specific budget pull. [s7, s13, s5] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Co-founder and President Shai Onn previously founded Fireglass, acquired by Symantec, a prior in-domain security exit CTech corroborates, alongside CEO Oded Hareven's IDF and CA Technologies background and CTO Refael Angel's cryptography work with two submitted patents. A verified prior exit lifts founder credibility above founders without one. [s11, s6, s10] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Cimpress is a named customer that swapped out a rival, independently reported by SiliconANGLE, the Thales CipherTrust OEM embeds Akeyless inside a major vendor's platform, and KuppingerCole names Akeyless an Overall Leader, a verifiable partnership motion plus an independent analyst placement that put traction above the one-or-two-named-customer rung. [s10, s13, s8] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | The $80 million raised by the 2022 Series B and the 2024 Deutsche Bank strategic investment of undisclosed size fund visible shipping, from the unified platform to the agent line, but no revenue, margin, or growth- efficiency figure is disclosed, so output per dollar is unconfirmed and the raise sits at the honest default for a funded private vendor. [s9, s12, s1] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | KuppingerCole names Akeyless an Overall Leader in enterprise secrets management on its own research page, Gartner Peer Insights files it under privileged access and workload identity management, and press places it in secrets management, so buyers and analysts map it to funded budget lines without vendor coaching. It is a co-leader rather than the category definer. [s13, s14, s10] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | The patented split-key architecture and a control plane embedded in how workloads authenticate raise replication cost beyond a quarterly feature, but CyberArk (which owns Venafi's machine-identity business), Thales, and Delinea co-lead the same category, the cloud providers ship native workload identity, and no cross-customer data asset appears in the record. [s1, s13, s8] |
Akeyless sells against credential and secret sprawl, the pain it calls a top cause of breaches. The buyer is the security and DevOps leader accountable for the credentials, certificates, and keys flowing through multi-cloud and hybrid estates, where machine identities far outnumber human ones. Oded Hareven frames the fragmentation concretely, telling Finextra that enterprises run more than 12 tools across 15 categories and 75 vendors for secrets and machine-identity management.
The agent era sharpens the same problem rather than replacing it. Akeyless argues that AI agents run autonomously around the clock across clouds and on-premises systems, so traditional human IAM cannot scale to thousands of ephemeral service instances that spin up and down within seconds. That reframes secrets management as the trust layer an autonomous agent needs before it can authenticate to enterprise systems.
Independent coverage treats the category as established. KuppingerCole's enterprise secrets management research frames secrets sprawl, hardcoded credentials, and non-human identity growth as the market problem, and Gartner Peer Insights tracks workload identity management as a market, third-party evidence that buyers organize budget around the sprawl Akeyless sells against. [s7, s13, s12]
The Akeyless platform unifies several secrets and identity functions on one SaaS control plane rather than a single point tool. Its documentation describes a single cloud-based control plane covering application-to-application authentication, X.509 and SSH certificate issuance, privileged access, encryption and key management, and short-lived credentials, and the platform now folds AI-agent security into the same control plane. The breadth lets a buyer consolidate tools a typical enterprise runs separately.
The architecture is the stated differentiator. Akeyless uses patented Distributed Fragments Cryptography, which splits encryption keys across regions and providers so that, the company says, no single party including Akeyless can access them, paired with hybrid post-quantum encryption. That zero-knowledge design underpins the vaultless SaaS model the company contrasts with self-hosted vaults customers must run and scale themselves.
Public technical depth now has an external validation point it previously lacked. The Akeyless cryptographic module holds an independent NIST CMVP FIPS 140-3 certificate, an accredited-laboratory validation of the cryptography rather than a vendor claim, and KuppingerCole's evaluation of the platform is a second outside assessment alongside the documentation portal a buyer can inspect. [s15, s3, s1]
Akeyless competes on two fronts that share an engine. In conventional secrets management it runs rip-and-replace plays against HashiCorp Vault for enterprises tired of operating self-hosted vaults, and lines up against CyberArk, Thales, Delinea, and the cloud providers' native key and identity services. In the emerging non-human identity space it competes with pure-play startups extending discovery and governance to AI agents.
The company's stated edge is consolidation on patented cryptography, and the market now places it among the leaders. KuppingerCole names Akeyless an Overall Leader in enterprise secrets management alongside BeyondTrust, CyberArk, Delinea, SSH, and Thales, and the Thales CipherTrust OEM shows the underlying technology is strong enough that a security major embeds it. That standing is a genuine differentiator against point tools.
The structural pressure comes from incumbents with the same buyers. CyberArk's purchase of Venafi gave a privileged-access leader a machine-identity portfolio, the cloud providers ship workload identity and key management natively, and Thales is at once Akeyless's largest distribution partner and a category co-leader, so Akeyless must keep proving that a dedicated vaultless platform beats coverage bundled into suites enterprises already pay for. [s13, s8, s1]
Akeyless can point to a named customer that switched from a rival. SiliconANGLE quoted Cimpress's information-security manager saying the platform made it easy to rip and replace the company's existing secrets management solution, an independently reported reference rather than a vendor-curated logo, and Finextra reports Fortune 100 use. The Thales CipherTrust OEM, which embeds an Akeyless-powered vault inside a major vendor's platform, is the clearest partnership proof.
The funding and analyst signals add commercial standing. SecurityWeek reported a 2022 Series B that brought total funding to 80 million dollars led by NGP Capital with Team8 and JVP, Finextra reported a 2024 strategic investment from Deutsche Bank's corporate venture arm, and KuppingerCole's Overall Leader placement is independent recognition a younger vendor cannot manufacture.
What the public record still lacks is agent-era proof. No named customer is cited deploying Akeyless specifically for autonomous AI agents, no current revenue or customer count is disclosed, and the clearest traction evidence belongs to the conventional secrets business rather than the identity-for-AI positioning the homepage now leads with. [s10, s13, s12]
The founding team pairs identity-security operating experience with deep cryptography. Co-founder and CEO Oded Hareven is a veteran of Israel's IDF cyber unit who specializes in identity and access management and held product roles at CA Technologies and at Moovit before its acquisition by Intel, and he is the quoted voice in the company's funding and platform announcements.
The entrepreneurial and technical bench reinforces the pedigree. Co-founder and President Shai Onn previously founded Fireglass, acquired by Symantec, a prior security exit that CTech corroborates and that lifts the team above peers with no founder exit on record, and co-founder and CTO Refael Angel is credited with the company's zero-trust split-key encryption and two submitted patents.
The investor signal adds standing. Akeyless drew NGP Capital, Team8, and JVP across its rounds and later Deutsche Bank, backers with security and enterprise track records, and brought in Mike Christenson, a former New Relic and CA Technologies president, as a board member. What is absent is a sustained public research or publication record of the kind that lifts the strongest teams in this category. [s6, s11, s10]
Akeyless leads its trust story with architecture that limits its own access to customer data. The Distributed Fragments Cryptography design splits key fragments so that, the company states, no single party including Akeyless can reconstruct customer keys. For a tool that holds an enterprise's credentials, that zero-knowledge posture is the core readiness claim a regulated security review opens with.
The compliance posture is unusually deep for a company this size, and now externally verifiable. The Akeyless cryptographic module holds an independent NIST CMVP FIPS 140-3 certificate, and the trust center lists FIPS 140-3, SOC 2 Type II, and ISO 27001 alongside PCI DSS compliance and alignment to the European DORA regulation, a span that lowers the diligence burden for a regulated buyer.
Independent assurance beyond those attestations is lighter. Gartner Peer Insights carries customer reviews across privileged access and workload identity management, and third-party profiling notes Fortune 100 adoption, but the trust center does not publish a downloadable penetration-test report, the next evidence a security team is likely to request before deployment. [s5, s15, s14]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| CyberArk | competes with | Privileged-access leader that acquired Venafi's machine-identity business and co-leads the KuppingerCole enterprise secrets management category, now positioned to bundle secrets, certificate lifecycle, and machine identity against Akeyless's unified platform. | |
| HashiCorp Vault | competes with | The self-hosted secrets manager, now owned by IBM, that Akeyless runs rip-and-replace plays against, its clearest named-customer win. | |
| Aembit | competes with | Workload IAM vendor brokering non-human and AI-agent credentials, sold into the same machine-identity buyer. | |
| Oasis Security | competes with | Non-human identity management platform extending discovery and governance to AI agents, contesting the same identity budget line. | |
| Token Security | competes with | Machine-identity security startup covering discovery, lifecycle, and least-privilege for non-human and agent identities. |
Add analyzed competitors to compare them side by side with Akeyless.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Akeyless is difficult to displace once it becomes the control plane a customer's workloads and AI agents authenticate through. Once policies and rotation depend on it, replacing it means rewiring how workloads authenticate. The engineering is specialized. Split-key cryptography and real-time credential exchange took years of work, now backed by an independent NIST FIPS 140-3 validation of the cryptographic module. Akeyless holds customer secrets, its zero-knowledge design means no party, including Akeyless, can read the secret values, and the public record identifies no cross-customer data asset. Its FIPS, SOC 2, and ISO bars ease procurement but are within reach of larger rivals, no regulation mandates the product class, and customers buy software rather than judgment.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Customers buy a software platform for secrets, certificate, key, and privileged-access management and pay for those capabilities, with a free tier and self-serve onboarding. No managed-judgment service or liability acceptance is part of the offer. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Wiring the control plane into how workloads authenticate, with policies and rotation across clouds, creates meaningful friction once embedded, the cost a rip-and-replace reference implies in reverse. The zero-knowledge design splits the keys beyond Akeyless's reach, so no data gravity or residency lock earns the 3. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 2/3 | FIPS 140-3, SOC 2 Type II, and ISO 27001 plus PCI DSS compliance and DORA alignment ease procurement, and the cryptographic module holds an independent NIST CMVP FIPS 140-3 certificate that goes beyond self-attested commercial audits, but no regulation mandates this product class and the larger vendors KuppingerCole co-names as Overall Leaders have the scale to clear comparable bars, so it stays at 2. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Split-key distributed cryptography, hybrid post-quantum encryption, and real-time just-in-time credential exchange across clouds, Kubernetes, and on-premises systems is security-critical engineering that takes years of specialized expertise, and the independent NIST FIPS 140-3 validation of the cryptographic module corroborates that depth. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | The evidence skews large enterprise, a named Cimpress rip-and-replace and the unnamed Fortune 100 adoption Finextra notes, where procurement slows replacement. A free starter tier and per-client self-serve motion blend the profile downward. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 3/3 | Akeyless is a single control plane that applications, workloads, and AI agents authenticate through to reach systems and data, infrastructure other software depends on to function rather than an end-user application. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The platform holds customer secrets, which is switching friction rather than a data asset, and the zero-knowledge split-key design means no single party including Akeyless can read them, so it forecloses a flywheel on the secret values though not on the access metadata it could aggregate. On the IP branch the cited record credits the chief technology officer with two submitted patents covering the split-key design and establishes neither their grant status nor their claim scope. No named non-public dataset and no cross-customer asset appears in the record. |
Akeyless targets the enterprise drowning in credential and secret sprawl across multi-cloud and hybrid estates, where machine identities far outnumber human ones. The buyer is the security and DevOps leader accountable for the credentials, certificates, and keys flowing through pipelines and production systems, and Oded Hareven sizes the fragmentation for Finextra at more than 12 tools across 15 categories and 75 vendors for secrets and machine-identity management.
The segment skews to the regulated upper enterprise, with a self-serve entry below it. Finextra reports Akeyless is used by Fortune 100 companies, Gartner Peer Insights tracks the product under privileged access management and workload identity management, recognized budget lines buyers already fund, and KuppingerCole frames non-human identity growth as a driver of the market. At the same time the pricing page offers a free starter tier and a per-client SaaS motion, so the addressable set blends a large regulated account with a smaller team that can adopt without a sales call.
The agent era sharpens the same segmentation rather than replacing it. Akeyless argues that AI agents run autonomously around the clock across clouds and on-premises systems, so traditional human IAM cannot scale to thousands of ephemeral service instances, which reframes the secrets buyer as the same leader now accountable for non-human and agent identity.
The platform unifies several secrets and identity functions on one SaaS control plane rather than a single point tool. The documentation describes a single cloud-based control plane covering application-to-application authentication, X.509 and SSH certificate issuance, privileged access, encryption and key management, and short-lived credentials, with AI-agent security folded into the same control plane. The breadth lets a buyer consolidate tools a typical enterprise runs separately.
The architecture is the stated differentiator. Akeyless uses its Distributed Fragments Cryptography design, which splits encryption keys across regions and providers so that, the company says, no single party including Akeyless can access them, paired with hybrid post-quantum encryption. That zero-knowledge design underpins the vaultless SaaS model the company contrasts with self-hosted vaults customers must run and scale themselves.
The AI advantage is engine reuse, not a proprietary model. The same just-in-time credential mechanism that serves applications issues short-lived tokens to AI agents, where an agent requests a minutes-long credential, uses it once, and discards it, so a compromised token has already expired. The durable depth here is distributed cryptography and real-time credential exchange, now corroborated by an independent NIST FIPS 140-3 validation of the cryptographic module, rather than any accumulated data asset.
Go-to-market combines named enterprise references with a self-serve on-ramp. SiliconANGLE reported a customer testimonial in which Cimpress's information-security manager said Akeyless made it easy to rip and replace the company's existing secrets management solution, a named reference a trade outlet published rather than an independently verified deployment. SiliconANGLE also relayed Akeyless's own customer names, such as Wix, Cimpress, Outbrain, and Stash Financial. The Thales CipherTrust OEM, which embeds an Akeyless-powered vault inside a security major's platform, is the strongest partnership proof, and Finextra notes Fortune 100 use.
The investor base and analyst recognition signal commercial standing beyond a typical startup. The 2022 Series B brought total funding to 80 million dollars led by NGP Capital with Team8 and JVP, Finextra reports a 2024 strategic investment from Deutsche Bank's corporate venture arm, and KuppingerCole names Akeyless an Overall Leader in enterprise secrets management alongside BeyondTrust, CyberArk, Delinea, SSH, and Thales, third-party recognition a younger vendor cannot manufacture.
What the public record still lacks is agent-era proof. No named customer is cited deploying Akeyless specifically for autonomous AI agents, no current revenue or customer count is disclosed, and the clearest traction evidence belongs to the conventional secrets business rather than the recent identity-for-AI positioning.
Akeyless publishes a pricing page in a category where most rivals hide one, and the model offers two deployment shapes against a single objection. Pure SaaS is fully cloud-managed for rapid deployment, while Hybrid SaaS adds on-premise gateways and zero-knowledge encryption so a buyer can keep secrets and identity data inside private infrastructure while meeting compliance requirements, letting the customer trade convenience for control.
For Secrets Management the metered unit is the client, not the secret. Akeyless defines clients as human users, applications, or servers that initiate a session, counts multiple instances of one application as a single client, and tracks the distinct total at month end with overage invoiced against an annual quota. Other modules meter their own units, including connectors for multi-vault governance, managed certificates for certificate lifecycle management, transactions and KMIP or TDE applications for encryption and key management, and named users for the password manager. The client unit ties cost to the size of the identity estate under management rather than to seats, which fits the enterprise buyer but offers no forecastable per-unit benchmark to an outside reader.
A free starter tier opens the funnel below the enterprise threshold. Published material stops short of dollar figures for paid tiers, so a smaller team faces a quota-shaped quote that is hard to budget against a fast-growing client count, while a large account folds Akeyless into a negotiated enterprise agreement.
Akeyless delivers as a cloud-native control plane that operates across public cloud, hybrid and multi-cloud, on-premises, and Kubernetes environments. The pure SaaS shape removes infrastructure maintenance entirely, while the hybrid shape places on-premise gateways inside customer boundaries, so the operational burden the customer carries scales with how much control it wants over where secrets live.
The operational core is just-in-time issuance rather than long-lived storage. The platform creates, retrieves, issues, rotates, and enforces policy on secrets, dynamic credentials, certificates, and keys, replacing long-lived credentials with short-lived ones and logging every secret request. That model reduces the standing-credential blast radius a buyer worries about and gives security teams a per-access record.
The heavier operational question is availability in the authentication path. Because Akeyless can sit in the credential-issuance path, a slow or unavailable control plane delays the credentials workloads need to authenticate, so a buyer diligences latency and failover closely. The trust center documents the compliance posture, but the reviewed pages do not publish the explicit uptime and recovery commitments a careful security review will request before deployment.
Akeyless leads its trust story with architecture that limits its own access to customer data. The Distributed Fragments Cryptography design splits key fragments so that, the company states, no single party including Akeyless can reconstruct customer keys, and the hybrid shape lets a buyer keep secrets inside private infrastructure. For a tool that holds an enterprise's credentials, that zero-knowledge posture is the core readiness claim a regulated security review opens with.
The compliance posture is documented and now externally verifiable. The Akeyless cryptographic module holds an independent NIST CMVP FIPS 140-3 certificate, an accredited-laboratory validation rather than a vendor claim, and the trust center lists FIPS 140-3, SOC 2 Type II, and ISO 27001 alongside PCI DSS compliance and alignment to the European DORA regulation, a span that lowers the diligence burden for a regulated buyer.
Independent assurance beyond those attestations is lighter. Gartner Peer Insights carries customer reviews across privileged access and workload identity management, but the trust center does not publish a downloadable penetration-test report, the next evidence a security team is likely to ask for before deployment.
Akeyless positions itself as a single control plane other applications and workloads depend on to authenticate, not a feature inside one cloud's identity service. The documentation frames it as a cloud-based control plane spanning application-to-application authentication, certificate issuance, privileged access, and automated identity workflows across hybrid and multi-cloud environments, so the platform sits underneath the systems that consume its credentials.
The breadth was assembled into one unified offering, and the engine extends outward. The same mechanism that issues short-lived credentials to applications is extended to AI and ML workloads and agents, and the Thales CipherTrust OEM shows the platform is strong enough to run inside a security major's own product rather than only as a standalone service.
Outward ecosystem reach is real but thinly documented in the reviewed pages. The platform integrates across AWS, Azure, GCP, Kubernetes, and on-premises data centers, but no developer marketplace, partner-built integration catalog, or third-party network effect appeared in the pages reviewed, so the platform claim rests on internal consolidation and integration breadth rather than an external builder ecosystem.
The founding team pairs identity-security operating experience with deep cryptography. Co-founder and chief executive Oded Hareven is a veteran of Israel's IDF cyber unit who specializes in identity and access management and held product roles at CA Technologies and at Moovit before its acquisition by Intel, and he is the quoted voice in the company's funding and platform announcements.
The entrepreneurial bench reinforces the pedigree. Co-founder and president Shai Onn previously founded Fireglass, acquired by Symantec, a prior security exit that CTech corroborates and that lifts the team above peers with no founder exit on record, and co-founder and chief technology officer Refael Angel is credited with the company's zero-trust split-key encryption and two submitted patents.
The investor signal adds standing. Akeyless drew NGP Capital, Team8, and JVP across its rounds and later Deutsche Bank, backers with security and enterprise track records, and Mike Christenson, a former New Relic and CA Technologies president, joined as a board member at the Series B. What is absent from the reviewed pages is a sustained public research or publication record of the kind that lifts the strongest teams in this category.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Akeyless: Identity Security for Machines, AI Agents and Humans | official | 2026-07-09 |
| f2 | CTech on the Akeyless Series B (founded 2019) | press | 2026-06-29 |
| f3 | Akeyless unified platform announcement (New York and Tel Aviv) | press | 2026-06-14 |
| f4 | SecurityWeek on Akeyless Series B (total raised 80 million) | press | 2026-06-29 |
| f5 | AI Defense Matrix Catalog entry | other | 2026-06-13 |
| f6 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| f7 | Akeyless platform | official | 2026-06-14 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Akeyless secrets management platform (Distributed Fragments Cryptography, zero-knowledge by design) “Distributed Fragments Cryptography™ (DFC™) splits encryption keys across regions and providers, so no single party, including Akeyless, can access them. Secrets are never exposed, assembled, or held in full.” | official | 2026-06-29 |
| s2 | Akeyless homepage (Identity Security for Machines, AI Agents and Humans) “Trusted by Leading Enterprises, Investors, and Partners” | official | 2026-06-29 |
| s3 | Akeyless docs (single cloud-based control plane, human and machine identities) “Akeyless provides a single cloud-based control plane that supports application-to-application authentication, certificate issuance, privileged access, and automated identity workflows in hybrid and multi-cloud environments.” | official | 2026-06-29 |
| s4 | Akeyless pricing (Pure SaaS or Hybrid SaaS, Clients billing unit) “Clients are human users, applications, or servers that initiate a remote session with Akeyless services. Multiple instances of the same application count as a single client.” | official | 2026-06-29 |
| s5 | Akeyless Trust Center (compliance standards) “Akeyless is proud to maintain world-class compliance and security standards, including FIPS 140-3, SOC 2 Type II, ISO 27001, PCI DSS compliance and DORA.” | official | 2026-06-29 |
| s6 | About Akeyless (leadership Oded Hareven, Shai Onn, Refael Angel) “Refael is a seasoned software engineer with expertise in cryptography. He is the mastermind behind Akeyless’ Zero-Trust encryption technology with 2 submitted patents.” | official | 2026-06-29 |
| s7 | Akeyless blog on securing enterprise AI with unified secrets and NHI management “AI agents operate autonomously, 24/7, often spanning multiple cloud providers and on-premises systems. Traditional human IAM (password resets, manual approval workflows) doesn’t scale to thousands of ephemeral service instances that spin up and down within seconds.” | official | 2026-06-29 |
| s8 | Akeyless: Thales and Akeyless join forces for secrets management (CipherTrust OEM) “I am delighted to announce our partnership with Thales ... to offer the Akeyless Vault Secrets Management solution within the Thales CipherTrust Data Security platform.” | official | 2026-06-29 |
| s9 | SecurityWeek on Akeyless raising 65 million for secrets management “The $65 million Series B investment brings the total raised by Akeyless to $80 million ... led by NGP Capital. Early backers Team8 Capital and Jerusalem Venture Partners (JVP) also invested.” | press | 2026-06-29 |
| s10 | SiliconANGLE on the Akeyless Series B and the Cimpress rip-and-replace (Mike Wheatley) “Daniel Fabbo, senior manager of information security at Cimpress, praised Akeyless ... “This made it easy for us to decide to rip and replace our existing secrets management solution”” | press | 2026-06-29 |
| s11 | CTech on the Akeyless Series B (founded 2019, founders, Fireglass exit; Meir Orbach) “Akeyless was founded in 2019 by Shai Onn, Refael Angel, and Oded Hareven. Onn, the Chairman and President of the company, co-founded Fireglass, which was sold to Symantec in 2018.” | press | 2026-06-29 |
| s12 | Finextra on Deutsche Bank's strategic investment in Akeyless “Deutsche Bank's Corporate Venture Capital (CVC) group has made a strategic investment in identity security firm Akeyless. Terms were not disclosed. ... Used by Fortune 100 companies, the cloud-native SaaS platform manages the lifecycle of all non-human identities and secrets across all environments.” | press | 2026-06-29 |
| s13 | KuppingerCole Leadership Compass: Enterprise Secrets Management (Akeyless named Overall Leader) “Overall Leaders are Akeyless, BeyondTrust, CyberArk, Delinea, SSH, and Thales.” | research | 2026-06-29 |
| s14 | Gartner Peer Insights on the Akeyless Identity Security Platform (market presence) “Market Presence: Privileged Access Management, Workload Identity Management” | research | 2026-06-29 |
| s15 | NIST CMVP Certificate #5227: Akeyless FIPS Cryptographic Module (FIPS 140-3, Active) “Module Name: Akeyless FIPS Cryptographic Module. Standard: FIPS 140-3. Status: Active. The Akeyless FIPS Cryptographic Module is a general-purpose cryptographic library integrated into the Akeyless family of products, providing FIPS 140-3 validated cryptography.” | research | 2026-06-29 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Akeyless secrets management platform (Distributed Fragments Cryptography, zero-knowledge by design) “Distributed Fragments Cryptography™ (DFC™) splits encryption keys across regions and providers, so no single party, including Akeyless, can access them. Secrets are never exposed, assembled, or held in full.” | official | 2026-06-29 |
| s2 | Akeyless homepage (Identity Security for Machines, AI Agents and Humans) “Trusted by Leading Enterprises, Investors, and Partners” | official | 2026-06-29 |
| s3 | Akeyless docs (single cloud-based control plane, human and machine identities) “Akeyless provides a single cloud-based control plane that supports application-to-application authentication, certificate issuance, privileged access, and automated identity workflows in hybrid and multi-cloud environments.” | official | 2026-06-29 |
| s4 | Akeyless pricing (Pure SaaS or Hybrid SaaS, Clients billing unit) “Clients are human users, applications, or servers that initiate a remote session with Akeyless services. Multiple instances of the same application count as a single client.” | official | 2026-06-29 |
| s5 | Akeyless Trust Center (compliance standards) “Akeyless is proud to maintain world-class compliance and security standards, including FIPS 140-3, SOC 2 Type II, ISO 27001, PCI DSS compliance and DORA.” | official | 2026-06-29 |
| s6 | About Akeyless (leadership Oded Hareven, Shai Onn, Refael Angel) “Refael is a seasoned software engineer with expertise in cryptography. He is the mastermind behind Akeyless’ Zero-Trust encryption technology with 2 submitted patents.” | official | 2026-06-29 |
| s7 | Akeyless blog on securing enterprise AI with unified secrets and NHI management “AI agents operate autonomously, 24/7, often spanning multiple cloud providers and on-premises systems. Traditional human IAM (password resets, manual approval workflows) doesn’t scale to thousands of ephemeral service instances that spin up and down within seconds.” | official | 2026-06-29 |
| s8 | Akeyless: Thales and Akeyless join forces for secrets management (CipherTrust OEM) “I am delighted to announce our partnership with Thales ... to offer the Akeyless Vault Secrets Management solution within the Thales CipherTrust Data Security platform.” | official | 2026-06-29 |
| s9 | SecurityWeek on Akeyless raising 65 million for secrets management “The $65 million Series B investment brings the total raised by Akeyless to $80 million ... led by NGP Capital. Early backers Team8 Capital and Jerusalem Venture Partners (JVP) also invested.” | press | 2026-06-29 |
| s10 | SiliconANGLE on the Akeyless Series B and the Cimpress rip-and-replace (Mike Wheatley) “Daniel Fabbo, senior manager of information security at Cimpress, praised Akeyless ... “This made it easy for us to decide to rip and replace our existing secrets management solution”” | press | 2026-06-29 |
| s11 | CTech on the Akeyless Series B (founded 2019, founders, Fireglass exit; Meir Orbach) “Akeyless was founded in 2019 by Shai Onn, Refael Angel, and Oded Hareven. Onn, the Chairman and President of the company, co-founded Fireglass, which was sold to Symantec in 2018.” | press | 2026-06-29 |
| s12 | Finextra on Deutsche Bank's strategic investment in Akeyless (Fortune 100 use) “Deutsche Bank's Corporate Venture Capital (CVC) group has made a strategic investment in identity security firm Akeyless. Terms were not disclosed. ... Used by Fortune 100 companies, the cloud-native SaaS platform manages the lifecycle of all non-human identities and secrets across all environments.” | press | 2026-06-29 |
| s13 | KuppingerCole Leadership Compass: Enterprise Secrets Management (Akeyless named Overall Leader) “Overall Leaders are Akeyless, BeyondTrust, CyberArk, Delinea, SSH, and Thales.” | research | 2026-06-29 |
| s14 | Gartner Peer Insights on the Akeyless Identity Security Platform (market presence) “Market Presence: Privileged Access Management, Workload Identity Management” | research | 2026-06-29 |
| s15 | NIST CMVP Certificate #5227: Akeyless FIPS Cryptographic Module (FIPS 140-3, Active) “Module Name: Akeyless FIPS Cryptographic Module. Standard: FIPS 140-3. Status: Active. The Akeyless FIPS Cryptographic Module is a general-purpose cryptographic library integrated into the Akeyless family of products, providing FIPS 140-3 validated cryptography.” | research | 2026-06-29 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.