All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Curity sells the Curity Identity Server, standards-based software that banks, retailers and telecoms run on their own infrastructure to authorize access for people, applications and now AI agents. Its filed Swedish accounts have moved from a small profit in 2021 to a loss. Revenue grew 0.6% in 2024 at a margin of minus 24.8%, so the company now spends ahead of what it earns. Its named customers run from ICA and Santander to E.ON, and in April 2026 Curity added Access Intelligence to control what AI agents may do while they run. A CSO Online article names Okta, Ping Identity and Microsoft's Entra ID among the platforms moving into that space. The Identity Server carries the broader named production record, and the reviewed sources name one Access Intelligence deployment, at If Insurance.
| Description | Curity is an identity and API security company whose self-hosted Curity Identity Server authenticates and authorizes access for apps, APIs, machines and AI agents on OAuth and OpenID Connect, and adds runtime agent authorization through its Access Intelligence capability. | [f1] |
|---|---|---|
| Founded | 2015 | [f2] |
| HQ | Stockholm, Sweden | [f3] |
| Subsidiaries | CURITY.IO, INC. (United States subsidiary of Curity AB, recorded on Curity AB's Ratsit company record.) | |
| Latest funding | Majority investment from GRO Capital (April 2023, undisclosed) | [f4] |
| Product | What it does |
|---|---|
| Curity Identity Server | Standards-based identity and API security platform on OAuth 2.0, OpenID Connect, FAPI and SCIM that authorizes access for apps, APIs, machines and AI agents, deployed self-hosted. |
| Curity Access Intelligence | Runtime authorization for AI agents and machines, built into the Curity Identity Server, that issues scoped ephemeral tokens and allows, limits or denies every agent API and tool call in real time. |
| Curity Token Intelligence | Token service capabilities inside the Curity Identity Server that design, exchange and constrain OAuth tokens, register clients dynamically and keep access tokens out of the browser. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Curity Access Intelligence issues scoped, ephemeral tokens to AI agents and machines and evaluates every API and tool call against identity, context, policy and risk to allow, limit, or deny it in real time. These capabilities are mapped to the AI Defense Matrix. [f5]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Curity states the problem as deciding what people, applications, machines and AI agents may do across a customer's applications and APIs, and a CSO Online article states that traditional identity tools were never designed to secure anything as complex as agentic AI. The pain is described in category terms rather than quantified for Curity by an independent source, which holds it at the credible-but-unproven level. [s2, s3, s8] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | Curity publishes architecture and feature detail across its product, conformance and pricing pages, and the OpenID Foundation register carries conformance listings for the Identity Server. Those listings record Curity AB as its own certifying party and Curity's conformance page says the product has been self-certified, so the record documents standards engineering without an independent technical evaluation of the product. [s2, s6, s10, s15] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | AI agents reaching production is the enabler, dated by Curity's April 2026 Access Intelligence release and by an April 2026 CSO Online article stating that identity tools were never built for agents that trigger chains of API calls. Buyer-side demand still appears mainly as vendor entry and a single named production deployment, so the timing case is credible rather than independently confirmed. [s5, s8, s3] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Co-founder Jacob Ideskog is chief technology officer and is quoted in a CSO Online article as the company's technical voice, the company page describes founders with long identity and access management careers, and Curity added a chief revenue officer, a chief human resources officer and a board chair who had chaired Auth0 in the phase leading up to its Okta acquisition. No prior in-domain product the founders built appears in the reviewed sources, which keeps the score at verifiable relevant experience. [s4, s8, s18, s19] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Curity publishes customer stories naming ICA, Santander, Skandia, Tele2, E.ON, Arion Banki, Entercard, PagerDuty and If Insurance among its production deployments, and its partner page describes three partner tracks plus a joint Microsoft Azure reference architecture. Filed Swedish accounts recording SEK 71.9m of 2024 revenue corroborate real commercial scale, while no independent customer count or customer-growth figure appears. [s12, s16, s20] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | Filed accounts for Curity AB record revenue growth of 0.6% in 2024 and a profit margin of minus 24.8%, against SEK 45.5m of revenue and SEK 4.9m of EBITDA reported for 2021. GRO Capital's investment amount is undisclosed and shipping stays visible in the April 2026 Access Intelligence release and the Token Intelligence line, so output per capital deployed is unconfirmed rather than shown. [s20, s9, s5, s17] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | Third parties place Curity in recognizable categories: a CSO Online article places it in identity and access management, and GRO Capital describes its offering as a combination of customer identity and access management and API security. Curity now leads with its own access-layer vocabulary, marketing Token Intelligence and Access Intelligence as named capabilities inside the Identity Server, so buyers still need vendor framing to slot it. [s8, s11, s17, s3] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | The Identity Server runs inside customer infrastructure and authorizes access for named production deployments at banks, retailers and telecoms, which is real friction against absorption. A CSO Online article names Okta, Ping Identity and Microsoft's Entra ID as moving into the same agent-security space, and the reviewed sources show no data Curity keeps across customers, so nothing structural stops a platform vendor from matching the agent capability. [s2, s8, s12] |
Curity sells to organizations that treat access to their applications and APIs as core infrastructure. The company states the problem as deciding, for every request, what a person, an application, a machine or an AI agent may do, using open standards rather than proprietary tooling.
An independent article supports the agent half of that problem. A CSO Online piece states that traditional identity and access management tools were never designed to secure anything as complex as agentic AI, and names large cloud platforms moving to fill the gap. The older half, authorizing access for applications and APIs, is established, and Curity says the product is in production across financial services, telecom, healthcare, government and technology.
The buyer is the enterprise that runs the access layer itself. Curity's company page places the product in production across financial services, telecom, healthcare, government and technology, and its customer stories name both the organizations and the people quoted. [s2, s8, s4, s3]
The Curity Identity Server is a standards-based platform for authentication and authorization. It issues and validates OAuth and OpenID Connect tokens, federates identities and controls API access, built on OAuth 2.0, OpenID Connect, FAPI, SAML and SCIM, and it deploys on-premise, in a single cloud, across several clouds or hybrid, with identity data staying where the customer's policies demand.
The platform now presents three surfaces. Access Intelligence, released in April 2026, issues tokens that last only for an interaction, evaluates every request against identity, context, policy and risk, and requires explicit approval before an agent may move money, export data or reach personal information. Token Intelligence covers token design, token exchange, dynamic client registration and sender-constrained tokens. Both are sold inside the Identity Server rather than separately.
Capability evidence is documented rather than independently evaluated. Curity publishes architecture and feature detail plus a conformance page, and the OpenID Foundation register carries Identity Server listings including FAPI 2.0 security profiles, recorded as certified by Curity AB. Curity's own conformance page states that the product has been self-certified. [s2, s3, s5, s17, s6, s10, s8]
Curity competes as a standards-based platform that customers deploy and run themselves. Its own pages put the differentiation in deployment and portability: on-premise, single cloud, multi-cloud or hybrid, with identity data staying where the customer's policies demand and no SaaS dependency.
In agent authorization the field is crowded. A CSO Online article describes a growing list of companies, including Okta, Ping Identity and Microsoft's Entra ID, vying to fill the vacuum, and frames Curity as a smaller competitor arguing that agents cannot be secured with traditional identity tools. Curity's counter is that it already brokers application access and extends the same token model to agents, which that article describes as a self-hosted microservice every agent request must pass through.
Curity leans on its production record. Its company page dates the founding to 2015 in Stockholm and describes a decade building the platform organizations depend on, its customer stories name production deployments, and the conformance record it also points to is its own certification rather than an outside assessment. [s2, s8, s12, s6, s4]
Curity's traction is a long list of named production customers. Its customer stories quote ICA's security operations manager saying not one of its services runs without Curity, and name Santander, Skandia, Tele2, E.ON, Arion Banki, Entercard, PagerDuty and If Insurance. The newest of them is the agent capability itself, where Curity cites If Insurance running its IfGPT assistant on the same OAuth-protected APIs as its mobile app.
Independent records corroborate commercial scale. Curity AB's filed Swedish accounts, published by Ratsit from the annual report lodged with Bolagsverket, put 2024 revenue at SEK 71.9m with growth of 0.6% and a profit margin of minus 24.8%, three years after the SEK 45.5m of revenue and SEK 4.9m of EBITDA an M&A Insights item recorded for 2021.
The motion pairs self-service entry with direct sales and partners. A free Community plan and a 14-day trial give developers a hands-on start, prices sit behind a sales conversation, and the partner page describes three tracks plus a joint Microsoft Azure reference architecture for securing agent and MCP endpoints. [s12, s3, s20, s9, s15, s16]
Curity's founders are identity specialists. The company page describes founders who had spent years working with identity and access management in large organizations, and co-founder Jacob Ideskog serves as chief technology officer and is quoted in a CSO Online article as the company's technical voice.
Ownership and the executive seat changed after the 2023 investment. GRO Capital says it became majority owner in April 2023, partnering with the founding management team; the announcement of that investment quotes co-founder Travis Spencer as chief executive, and GRO's portfolio page now lists Gustaf Sahlman in that role. The reviewed sources do not date the change.
The bench has been rebuilt since. Curity added a chief revenue officer and a chief human resources officer in September 2025, and in March 2026 appointed Monica Enand as chair of the board, saying she had chaired Auth0 during the high-growth phase leading up to its acquisition by Okta in 2021. [s4, s8, s11, s7, s19, s18]
Curity's assurance package is the standard enterprise set. Its company page states SOC 2 Type 2 and ISO 27001 certification, and its conformance page describes the SOC 2 Type 2 as a voluntary cybersecurity attestation and audit.
Standards conformance is published on a third-party register and certified by Curity itself. The OpenID Foundation register lists Identity Server versions with FAPI profiles recorded as certified by Curity AB, and the Foundation publishes its own guidance on how to self-certify. Curity's conformance page states that the product has been self-certified for the basic, implicit, hybrid and configuration protocols of OpenID Connect.
Deployment carries more of the trust argument than the certificates do. Because customers run the software on their own infrastructure, identity data stays where their policies demand, which answers residency requirements directly for the regulated buyers Curity names. [s4, s6, s10, s2, s12]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Okta | competes with | A CSO Online article names Okta among the large cloud platforms moving into AI-agent security, so it competes for the same enterprise identity budget. | |
| Ping Identity | competes with | A CSO Online article names Ping Identity among the platforms moving into AI-agent security, overlapping Curity's customer identity and API access positioning. | N/AWe scored these companies at different scopes, so the totals measure different things. |
| Microsoft | competes with | A CSO Online article names Microsoft's Entra ID among the platforms moving into AI-agent security, so Curity meets it in the same buying decision. | N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product. |
Add analyzed competitors to compare them side by side with Curity.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
press the advantage
Banks, retailers and telecoms run Curity's Identity Server inside their own systems to decide who and what may reach their applications and APIs. The reviewed sources describe that dependence without saying what replacing it would cost. Its compliance credentials are the ordinary kind: SOC 2 Type 2, ISO 27001, and OpenID Foundation listings that record Curity as its own certifying party, so a funded competitor can assemble the same set. The reviewed record evidences no data asset accumulated across its customers. The asset a competitor cannot obtain through ordinary preparation is a United States patent granted to Curity AB in November 2024 for a login and consent method built on OAuth.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Curity delivers standards-based software the customer deploys and configures, sold as a flat annual subscription with a free tier and a 14-day trial, and its partner page shows system integrators operating deployments on customers' behalf. No Curity-run service or accountability layer appears in the offer, so software is the product. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Applications and APIs at named production customers authenticate through the Curity Identity Server, which customers deploy and configure inside their own infrastructure, so leaving means re-pointing each application at a replacement and rebuilding those flows. The cited record documents that mechanism but does not size the migration, and Curity's own pages argue that the standards it builds on keep a customer's architecture portable. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | SOC 2 Type 2, ISO 27001 and the OpenID Foundation conformance listings are all obtainable through ordinary enterprise-market preparation, and the Foundation's register records Curity AB as its own certifying party under a published self-certification programme. The cited record shows no mandate, authorization or audit obligation that would block a funded competitor from replacing the product. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Building a standards-conformant identity server that issues and validates tokens in real time, federates identities and now authorizes each step of an agent's chain of API calls is security-critical distributed-systems engineering on live traffic. The record shows a decade of that engineering and conformance listings for the product on the OpenID Foundation register. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | Many of Curity's named customers are regulated enterprises, including the banks Santander, Arion Banki, Ikano Bank and Entercard, plus Tele2 and E.ON, and its company page says the product is in production across financial services, telecom, healthcare and government. A free developer trial provides entry at the top of the funnel, but the buying customer is the regulated enterprise. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 3/3 | Applications, APIs and now AI agents authenticate and are authorized through the Curity Identity Server rather than around it, and Curity presents it as the access layer other services depend on. That is infrastructure other applications are built on top of. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 2/3 | A United States patent granted in November 2024 and assigned to Curity AB covers a login and consent method built on OAuth with attested clients, and a published international application covers authorizing GraphQL access. That is an evidenced retained asset a competitor cannot obtain through ordinary preparation, while the reviewed record evidences no data asset accumulated across its customers. |
Curity serves regulated enterprises that treat identity and API access as core infrastructure. Its customer stories name Santander, Skandia, Arion Banki, Ikano Bank, Entercard, Tele2, ICA, E.ON, PagerDuty and If Insurance, and the company page says the product is in production across financial services, telecom, healthcare, government and technology.
The newest segment is the same buyer extending into AI agents. Access Intelligence, released in April 2026, targets enterprises wiring agents into APIs they already run, and Curity presents it as an extension of infrastructure the customer already operates rather than a separate system.
Curity's own registration is Swedish. North Data records the operating company at a Stockholm address registered with Bolagsverket, and one customer quote describes offering solutions for 18 European countries. The reviewed sources publish no count of customers by region, so the roster's geographic weighting is not something Curity discloses.
Curity's core capability is standards-based access. The Identity Server issues and validates OAuth and OpenID Connect tokens, federates identities and controls API access, built on OAuth 2.0, OpenID Connect, FAPI, SAML and SCIM, with OpenID Foundation listings recorded as certified by Curity AB.
Access Intelligence applies that engine to AI agents. Curity treats an agent as a special type of application that calls APIs and other agents with OAuth tokens, issues tokens that last only for the interaction, evaluates every request against identity, context, policy and risk, and requires explicit approval before an agent may move money, export data or reach personal information.
The depth is protocol and infrastructure engineering rather than a data or model advantage. The reviewed sources describe no proprietary detection model, and what the record does evidence is a United States patent granted to Curity AB in November 2024 covering a login and consent method built on OAuth with attested clients.
Curity runs a hybrid motion of self-service entry and direct enterprise sales. A 14-day free trial of the Identity Server lets developers evaluate the product without a sales call, alongside paid plans whose prices sit behind a sales conversation.
Founder and executive visibility is real. Co-founder and chief technology officer Jacob Ideskog fronts the public technical argument, quoted in a CSO Online article, and the same argument appears under his byline in Help Net Security, while Gustaf Sahlman leads as chief executive after GRO Capital's 2023 investment.
Distribution combines named customer proof, standards credibility and partners. Curity publishes customer stories with quoted customers, and its partner page describes three tracks covering technology partners, system integrators and value-added resellers, names Ductus operating the Identity Server for ICA Gruppen, and describes a joint Microsoft Azure reference architecture.
Curity publishes plan tiers but not prices. The pricing page lists a free Community edition and paid Standard, Enterprise and Token Handler plans, each a flat annual subscription with unlimited users, while amounts and Enterprise terms sit behind a sales conversation.
The unit of value is the platform rather than the seat. Curity frames the product as consolidating authentication, federation, token services, API access control and user management into one platform, includes Access Intelligence for AI agents in the Standard and Enterprise plans rather than metering agent usage, and says flat-rate licensing keeps pricing predictable as partners, agents and API traffic grow.
Published tiers with a free entry point lower evaluation friction, and the absence of published amounts keeps larger deployments sales-gated. A buyer comparing Curity's agent-authorization cost against a cloud incumbent has to ask for a number.
Curity ships software the customer runs. The Identity Server deploys on-premise, in a single cloud, across several clouds or hybrid, with the company stating that identity data stays where the customer's policies demand and that there is no SaaS dependency.
Access Intelligence follows the same model. A CSO Online article describes it as a self-hosted microservice through which every agent request must pass, and Curity says it is built into the Identity Server and works with any identity provider, API gateway or AI gateway without new systems or architectural changes.
Operations run in the customer's environment, carried out by the customer or by a partner. Curity's partner page names Ductus operating the Identity Server for ICA Gruppen, and its product page lists configuration as code, GitOps workflows, RESTCONF APIs, a scriptable CLI, GraphQL, an admin UI and a DevOps dashboard, with structured logging, metrics export and tracing. Because applications authenticate through Curity, a failure in the deployment can interrupt those access decisions.
Curity carries the standard enterprise assurance set. Its company page states SOC 2 Type 2 and ISO 27001 certification, and its conformance page describes the SOC 2 Type 2 as a voluntary cybersecurity attestation and audit and the ISO/IEC 27001 as a certification.
Standards conformance is published on a third-party register and certified by Curity itself. The OpenID Foundation register lists Identity Server versions with FAPI profiles recorded as certified by Curity AB, and the Foundation publishes its own guidance on how to self-certify. Curity's conformance page states that the product has been self-certified for the basic, implicit, hybrid and configuration protocols of OpenID Connect.
Deployment carries more of the trust argument than the certificates do. Because customers run the software on their own infrastructure, identity data stays where their policies demand, which answers residency requirements directly for the regulated buyers Curity names.
Curity positions the Identity Server as a platform that works alongside the rest of a customer's stack. Access Intelligence is presented as an extension that adds machine and agent controls on top of any identity provider, API gateway or AI gateway the customer already runs, and Curity says it does not replace the existing identity stack.
Standards breadth is the ecosystem strategy. The product is built on OAuth 2.0, OpenID Connect, FAPI, SAML and SCIM, and the conformance page says it supports protocols from bodies including the IETF, the OpenID Foundation and OASIS, which is what lets it sit alongside tools that speak those protocols.
Third-party extension runs through partners rather than a marketplace. The partner page describes three tracks covering technology partners, system integrators and value-added resellers, names Ductus operating the Identity Server for ICA Gruppen, and describes a joint Microsoft Azure reference architecture for securing agent and MCP endpoints. No Curity-operated marketplace of third-party applications appears in the reviewed pages.
Curity's founding team is its most verifiable asset. The company page describes founders who had spent years working with identity and access management in large organizations, and co-founder Jacob Ideskog serves as chief technology officer and is quoted by CSO Online as the company's technical voice.
Ownership and the executive seat changed after the 2023 investment. GRO Capital says it became majority owner in April 2023, partnering with the founding management team; the announcement of that investment quotes co-founder Travis Spencer as chief executive, and GRO's portfolio page now lists Gustaf Sahlman in that role. The reviewed sources do not date the change.
The bench has been rebuilt since. Curity added a chief revenue officer and a chief human resources officer in September 2025, and in March 2026 appointed Monica Enand as chair of the board, saying she had chaired Auth0 during the high-growth phase leading up to its acquisition by Okta in 2021 and had founded and led Zapproved for 15 years.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Curity Identity Server: product overview | official | 2026-08-25 |
| f2 | Curity: about the company | official | 2026-08-25 |
| f3 | North Data: Curity AB register record | regulatory | 2026-08-25 |
| f4 | GRO Capital: Curity portfolio entry | other | 2026-08-25 |
| f5 | Curity Access Intelligence (AI Defense Matrix Catalog) | other | 2026-07-06 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Curity: platform homepage “The access layer your business runs on. Authorization and authentication for APIs, AI agents and humans.” | official | 2026-08-25 |
| s2 | Curity Identity Server: product overview “Secure users, APIs, machines and AI agents with one standards-based platform, deployed where your architecture and data require it.” | official | 2026-08-25 |
| s3 | Curity Access Intelligence: product page “Every request is assessed against identity, context, policy and risk, and can be allowed, limited or denied in real time.” | official | 2026-08-25 |
| s4 | Curity: about the company “Founded in 2015 in Stockholm” | official | 2026-08-25 |
| s5 | Curity: Access Intelligence announcement “We are happy to introduce Access Intelligence , a runtime authorization capability built into the Curity Identity Server that gives enterprises real-time control over what AI agents can access and do.” | official | 2026-08-25 |
| s6 | Curity: standards and conformance page “In particular, the Curity product has been self-certified to comply with the basic, implicit, hybrid and configuration protocols of OpenID Connect.” | official | 2026-08-25 |
| s7 | Curity: GRO investment announcement “Travis Spencer, co-founder and CEO of Curity, says of the investment, “This is an important milestone for Curity, and we are looking forward to working with GRO.” | official | 2026-08-25 |
| s8 | CSO Online: Curity looks to reinvent IAM with runtime authorization for AI agents “While a growing list of companies, including large cloud platforms such as Okta, Ping Identity, and Microsoft’s Entra ID, is vying to fill the vacuum, a smaller competitor, Sweden’s Curity, argues that agents can’t be secured using traditional IAM.” | press | 2026-08-25 |
| s9 | M&A Insights: GRO Capital invests in Curity “In FY21 Curity reported revenues of SEK 45.5m with an EBITDA of SEK 4.9m.” | research | 2026-08-25 |
| s10 | OpenID Foundation: certified OpenID Connect implementations register “Certified by: Curity AB” | research | 2026-08-25 |
| s11 | GRO Capital: Curity portfolio entry “GRO became a majority owner of Curity in April 2023, partnering up with the founding management team to further expand the company’s organizational setup and global footprint, while sustaining the company’s innovative product vision” | other | 2026-08-25 |
| s12 | Curity: customer stories index “There's not a single ICA service that doesn't use Curity in one way or another.
Alexander Salwey
Manager, Security Operations” | official | 2026-08-25 |
| s13 | Help Net Security: contributed article by Curity CTO Jacob Ideskog “Jacob Ideskog, CTO, Curity” | press | 2026-08-25 |
| s14 | Insurance Edge: Curity announcement pickup on Access Intelligence “IfGPT, If Insurance’s generative AI assistant, already serves more than 200,000 customers – running on the same secure APIs that power If’s digital platform, now extended by Access Intelligence.” | press | 2026-08-25 |
| s15 | Curity: plans and pricing page “Every plan is a flat annual subscription with unlimited users.” | official | 2026-08-25 |
| s16 | Curity: partner ecosystem page “Curity works with technology leaders, system integrators and resellers who share our commitment to standards-based, developer-friendly access infrastructure.” | official | 2026-08-25 |
| s17 | Curity Token Intelligence: product page “Token Intelligence is how enterprises open their platform to the world without opening their risk.” | official | 2026-08-25 |
| s18 | Curity: board chair appointment announcement “To support this next phase of growth, Curity is proud to welcome Monica Enand as Chair of the Board.” | official | 2026-08-25 |
| s19 | Curity: executive appointments announcement “Johanna Alvemur joins us as Chief Human Resources Officer (CHRO), bringing deep expertise in building strong, people-centered organizations and fostering cultures of innovation.” | official | 2026-08-25 |
| s20 | Ratsit: Curity AB company record and filed accounts “Curity AB har en tillväxt på 0,6 % jämfört med föregående år. Vinstmarginalen för Curity AB ligger på −24,8 % och placerar bolaget på plats 438 804 i Sverige av 797 046 aktiebolag och i kommunen på plats 83 404 av 172 259 aktiebolag.” | regulatory | 2026-08-25 |
| s21 | Google Patents: US 12,149,612 B2 record “Login and consent methodology that follows rest principles and uses the OAUTH protocol with attested clients” | regulatory | 2026-08-25 |
| s22 | North Data: Curity AB register record “The company shall sell, integrate and develop IT security products within Identity and Access Management and related activities.” | regulatory | 2026-08-25 |
| s23 | Curity: GraphQL access authorization patent announcement “The World Intellectual Property Organization (WIPO) published Curity’s patent application with the number WO2023180364A1 and the title “GraphQL Access Authorization”.” | official | 2026-08-25 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Curity: platform homepage “The access layer your business runs on. Authorization and authentication for APIs, AI agents and humans.” | official | 2026-08-25 |
| s2 | Curity Identity Server: product overview “Secure users, APIs, machines and AI agents with one standards-based platform, deployed where your architecture and data require it.” | official | 2026-08-25 |
| s3 | Curity Access Intelligence: product page “Every request is assessed against identity, context, policy and risk, and can be allowed, limited or denied in real time.” | official | 2026-08-25 |
| s4 | Curity: about the company “Founded in 2015 in Stockholm” | official | 2026-08-25 |
| s5 | Curity: Access Intelligence announcement “We are happy to introduce Access Intelligence , a runtime authorization capability built into the Curity Identity Server that gives enterprises real-time control over what AI agents can access and do.” | official | 2026-08-25 |
| s6 | Curity: standards and conformance page “In particular, the Curity product has been self-certified to comply with the basic, implicit, hybrid and configuration protocols of OpenID Connect.” | official | 2026-08-25 |
| s7 | Curity: GRO investment announcement “Travis Spencer, co-founder and CEO of Curity, says of the investment, “This is an important milestone for Curity, and we are looking forward to working with GRO.” | official | 2026-08-25 |
| s8 | CSO Online: Curity looks to reinvent IAM with runtime authorization for AI agents “While a growing list of companies, including large cloud platforms such as Okta, Ping Identity, and Microsoft’s Entra ID, is vying to fill the vacuum, a smaller competitor, Sweden’s Curity, argues that agents can’t be secured using traditional IAM.” | press | 2026-08-25 |
| s9 | M&A Insights: GRO Capital invests in Curity “In FY21 Curity reported revenues of SEK 45.5m with an EBITDA of SEK 4.9m.” | research | 2026-08-25 |
| s10 | OpenID Foundation: certified OpenID Connect implementations register “Certified by: Curity AB” | research | 2026-08-25 |
| s11 | GRO Capital: Curity portfolio entry “GRO became a majority owner of Curity in April 2023, partnering up with the founding management team to further expand the company’s organizational setup and global footprint, while sustaining the company’s innovative product vision” | other | 2026-08-25 |
| s12 | Curity: customer stories index “There's not a single ICA service that doesn't use Curity in one way or another.
Alexander Salwey
Manager, Security Operations” | official | 2026-08-25 |
| s13 | Help Net Security: contributed article by Curity CTO Jacob Ideskog “Jacob Ideskog, CTO, Curity” | press | 2026-08-25 |
| s14 | Insurance Edge: Curity announcement pickup on Access Intelligence “IfGPT, If Insurance’s generative AI assistant, already serves more than 200,000 customers – running on the same secure APIs that power If’s digital platform, now extended by Access Intelligence.” | press | 2026-08-25 |
| s15 | Curity: plans and pricing page “Every plan is a flat annual subscription with unlimited users.” | official | 2026-08-25 |
| s16 | Curity: partner ecosystem page “Curity works with technology leaders, system integrators and resellers who share our commitment to standards-based, developer-friendly access infrastructure.” | official | 2026-08-25 |
| s17 | Curity Token Intelligence: product page “Token Intelligence is how enterprises open their platform to the world without opening their risk.” | official | 2026-08-25 |
| s18 | Curity: board chair appointment announcement “To support this next phase of growth, Curity is proud to welcome Monica Enand as Chair of the Board.” | official | 2026-08-25 |
| s19 | Curity: executive appointments announcement “Johanna Alvemur joins us as Chief Human Resources Officer (CHRO), bringing deep expertise in building strong, people-centered organizations and fostering cultures of innovation.” | official | 2026-08-25 |
| s20 | Ratsit: Curity AB company record and filed accounts “Curity AB har en tillväxt på 0,6 % jämfört med föregående år. Vinstmarginalen för Curity AB ligger på −24,8 % och placerar bolaget på plats 438 804 i Sverige av 797 046 aktiebolag och i kommunen på plats 83 404 av 172 259 aktiebolag.” | regulatory | 2026-08-25 |
| s21 | Google Patents: US 12,149,612 B2 record “Login and consent methodology that follows rest principles and uses the OAUTH protocol with attested clients” | regulatory | 2026-08-25 |
| s22 | North Data: Curity AB register record “The company shall sell, integrate and develop IT security products within Identity and Access Management and related activities.” | regulatory | 2026-08-25 |
| s23 | Curity: GraphQL access authorization patent announcement “The World Intellectual Property Organization (WIPO) published Curity’s patent application with the number WO2023180364A1 and the title “GraphQL Access Authorization”.” | official | 2026-08-25 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.