IndyKite

Security for AI Identity AccessData Security

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2021
Funding $10.5M
Last updated 2026-09-02

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

IndyKite sells access control applied at the moment of a decision, for people and apps reaching enterprise data and for AI agents acting for someone. Its distinctive piece is a gateway in front of each agent that checks the chain of delegation, from the person who started a task to the last agent in it, before letting a call through. IndyKite documents that gateway down to its deployment layouts and audit format, while its account of what it sells has moved from a Web3 identity layer in 2021 to agentic AI control today. Deutsche Telekom, Rockwell Automation and PACCAR are named customers, though the reviewed sources trace those accounts to IndyKite or its graph database partner. No round appears after an $8 million seed in February 2022, the last financing on the record.

Sourced Details

Description IndyKite sells runtime access control for AI agents and the enterprise data they reach. A knowledge graph holds identities, relationships and context, and a gateway in front of each protected agent checks the user-to-agent delegation chain against a stored workflow before letting a request through. [f1]
Founded 2021 [f2]
HQ San Francisco, California, United States [f3]
Funding $10.5M total [f4]
Latest funding Seed, $8M, February 2022 [f5]

Products

Product What it does
AgentControl Authorization for autonomous AI agents, applied agent-to-agent, model-to-API and model-to-data, with each action traceable back to policy and data provenance.
ContX IQ A runtime API that lets applications query the identity knowledge graph and write to it directly, with policy-based authorization applied at the service itself.
Knowledge-Based Access Control Externalized fine-grained authorization that derives access decisions from graph relationships and context, exposed over AuthZen, OAuth and MCP interfaces.
IndyKite Tags Tagging and classification for unstructured content that detects personal, financial and confidential material and screens prompts before they reach AI systems.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

AgentControl deploys a gateway in front of each protected agent, checks the user-to-agent delegation chain against a workflow stored in the graph, and governs which agents an agentic workflow may invoke. These capabilities are mapped to the AI Defense Matrix. [f6]

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Knowledge-Based Access Control centralizes authorization decisions across applications and APIs and verifies data access at each step, deriving decisions from graph relationships and context rather than static roles. These capabilities are mapped to the Cyber Defense Matrix. [f7]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 28 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 The buyer and the problem are stated precisely: enterprise teams putting AI agents into production, where role-based permissions cannot describe an agent acting on a person's behalf across several systems. The pain is argued by IndyKite and by its graph database partner rather than quantified by an independent source. [s20, s1, s3]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 Public documentation covers the Agent Gateway's request flow, its configuration, four deployment layouts and the schema of the audit record it writes, alongside the Terraform provider and the software development kits its developer resources list. A KuppingerCole Executive View of Knowledge-Based Access Control adds a third-party technical read, although it dates from September 2022 and predates the agent work. [s13, s22, s11, s17]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The enabler is the Agent-to-Agent protocol the gateway implements, which gives agent-to-agent calls a shape an enforcement point can police, and IndyKite launched its AI Control Suite in February 2025. Buyer-side demand stays indirect in the reviewed sources, which carry vendor announcements and partner material rather than independently documented purchasing signals. [s13, s10, s8]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 5/5 Tech.eu reports that Lasse Andresen co-founded ForgeRock, counts ForgeRock among the identity IPOs beside Okta and Ping Identity, and calls him a former Sun Microsystems chief technology officer, a category-level record in this exact market. Biometric Update independently carries the ForgeRock co-founding and Scott McNealy as a formal advisor, and the OpenID Foundation lists Alex Babeanu of IndyKite as an AuthZEN working group chair. [s15, s16, s6, s18]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 Four named enterprise references carry attributed executive quotes, including Rockwell Automation, PACCAR, Deutsche Telekom and Reitan Retail, and Neo4j publishes a customer story describing the Rockwell and PACCAR deployments. The Linux Foundation independently records IndyKite as an Automotive Grade Linux member, but the reviewed sources carry no third-party account of revenue or deployment scale. [s1, s20, s8, s19]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 CB Insights records $10.5 million raised across three rounds with the most recent in February 2022, and the years since carry an acquisition, two product launches and named enterprise wins, so the raise is proportional to the stage and motion with visible shipping. No revenue, margin or growth figure is disclosed, leaving efficiency itself unconfirmed. [s21, s14, s8, s9]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 IndyKite fits externalized fine-grained authorization, the category KuppingerCole placed it in when it reviewed Knowledge-Based Access Control in September 2022, and its agent work sits in a newer market that is still forming. Placement still needs the company's own explanation, since its self-description has moved from a Web3 identity layer in 2021 to an agentic AI control layer, and of the three products announced in February 2025 the current product pages name AgentControl. [s17, s8, s10, s2]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Authorization is adjacent to the identity platforms Tech.eu names among the identity IPOs, ForgeRock, Okta and Ping Identity, and any of them could add delegation-chain checks to an existing identity product. Against that, the graph model and the relationships loaded into it create integration friction, which is friction rather than a moat bundling could not eventually match. [s5, s13, s15, s20]
Business Risks Capital has been quiet since February 2022 while the company runs offices on two continents, so a hiring freeze, an office closure or a distressed round would show the pace was constraint rather than efficiency…
  • Capital has been quiet since February 2022 while the company runs offices on two continents, so a hiring freeze, an office closure or a distressed round would show the pace was constraint rather than efficiency.
  • Every account of the Rockwell Automation, PACCAR and Deutsche Telekom deployments traces to IndyKite or Neo4j, so any of those names leaving the customer page without replacement would leave the traction record thinner than it currently looks.
  • Of the three products announced in February 2025 the current product pages name AgentControl, so another turnover of the lineup within a year would confirm the portfolio changes faster than enterprise buyers can standardize on it.
  • The Agent Gateway assumes agents speak the Agent-to-Agent protocol, so a market that settles on a different agent transport would strand its enforcement point.
  • Okta or Ping Identity shipping delegation-chain checks inside identity products enterprises already own would remove the reason to add a separate enforcement layer.
  • The reviewed record carries one third-party technical assessment, a KuppingerCole Executive View from September 2022 covering the authorization product, so the agent work still has no independent evaluation behind it.
Problem & Market Enterprises putting AI agents into production hit a permission problem their existing tools were not built for…

Enterprises putting AI agents into production hit a permission problem their existing tools were not built for. An agent is not a user with a fixed role. It acts on someone's behalf, calls other agents, and reaches data across systems that were never joined. IndyKite's head of customer and partner experience puts the point bluntly, saying the industry has been trying to make role-based access work since the early 1990s and never got it right for humans.

The buyer is a large enterprise with data spread across systems and a reason to care who touched what. IndyKite's published customer accounts sit in manufacturing and heavy equipment, where the problem it describes is reconciling licences, equipment records and customer records that live in separate systems and cannot be tied back to each other.

The pain itself is argued rather than measured. The reviewed sources carry IndyKite's framing and its graph database partner's, and no independent survey, incident record or market sizing quantifies how many enterprises are stuck where the company says they are. [s20, s1, s6]

Product Capabilities The platform is a graph with three ways to act on it…

The platform is a graph with three ways to act on it. Identities, data assets, relationships such as ownership and delegation, and contextual signals such as purpose and provenance are modelled together, and Knowledge-Based Access Control derives access decisions by walking those relationships instead of matching a role. ContX IQ exposes the same graph as a runtime API that applications can query and write to, with the authorization check applied at the service itself.

AgentControl is the agent-facing product, and its documented artifact is the Indykite Agent Gateway. One instance is deployed per protected agent, it speaks the Agent-to-Agent protocol rather than behaving as a general proxy, and on each call it introspects the caller's token, exchanges it for a delegated token, queries the graph for the workflows that caller may trigger, and checks that the requested sequence of agents matches one the workflow permits. It writes a decision record naming the human subject, the acting agent, the full chain of actors and the reason.

IndyKite Tags covers the content side. It tags unstructured material from SharePoint, OneDrive, Box, Google Workspace, Slack and Confluence, flags personal, health, financial and confidential material, and screens prompts for injection attempts before they reach a model.

The documentation carries the detail an implementer needs. The gateway ships as a container image with four published deployment layouts, a configuration reference and audit formats, and the developer resources list a Terraform provider and software development kits. [s2, s5, s4, s11, s13, s22, s23]

Competitive Positioning IndyKite competes where authorization is pulled out of applications and run as a service, beside vendors such as Cerbos and Axiomatics whose people hold the same standards-body seats…

IndyKite competes where authorization is pulled out of applications and run as a service, beside vendors such as Cerbos and Axiomatics whose people hold the same standards-body seats. Its founder co-founded ForgeRock, which Tech.eu counts among the identity IPOs beside Okta and Ping Identity. Its difference is the substrate. Policies are evaluated by traversing relationship paths in a graph, which is the approach KuppingerCole described in September 2022 when it reviewed Knowledge-Based Access Control and called it progressive.

The company works the standards rather than around them. Its authorization interface advertises AuthZen, OAuth and OpenID, and MCP, the gateway implements the Agent-to-Agent protocol, and the OpenID Foundation lists Alex Babeanu of IndyKite as a chair of its AuthZEN working group beside chairs from Bloomberg, Axiomatics, Cerbos and CrowdStrike. Standards work buys credibility with architects and, by the same token, lowers the cost of leaving for anything built on those interfaces.

The self-description has travelled a long way. The newsroom traces an identity layer for Web3 in October 2021, an identity-powered AI enterprise data platform in February 2024, an AI Control Suite in February 2025, and a runtime control layer for agentic AI today. That 2025 suite announced RagProtect, AgentControl and TrustScore, and of those three the current product pages name AgentControl. A buyer tracking the lineup has had to re-learn what to ask for. [s2, s5, s17, s18, s19, s8, s10]

Go-to-Market & Traction The named customers are large enterprises…

The named customers are large enterprises. Rockwell Automation, PACCAR, Deutsche Telekom and Reitan Retail appear with attributed executive quotes, and Neo4j publishes a customer story describing what IndyKite built at Rockwell Automation, where licensing data, customer records and equipment data had sat in separate systems, and at PACCAR, where the company needed data tied to truck chassis, components, wear and tear and mean time to failure brought together.

Each of those accounts originates with IndyKite or with Neo4j, the graph database vendor IndyKite lists as a subprocessor and partners with. The reviewed sources carry no independent report of a deployment, no revenue figure and no customer count, so the scale behind the names stays unmeasured.

Partnerships are what the reviewed sources document. IndyKite announced an alliance with Enterprise Knowledge in May 2026 and a Neo4j partnership in December 2025, and the Linux Foundation named it an Automotive Grade Linux member in April 2022. The pattern reads as credible enterprise motion, thinly corroborated. [s1, s20, s8, s19, s12]

Team & Credibility Lasse Andresen founded IndyKite in 2021…

Lasse Andresen founded IndyKite in 2021. Tech.eu describes him as a former Sun Microsystems chief technology officer, reports that he co-founded ForgeRock, and counts ForgeRock among the identity IPOs alongside Okta and Ping Identity. Biometric Update independently carries the ForgeRock co-founding, so the strongest claim on his record rests on outside reporting rather than on the company alone.

Scott McNealy, who co-founded Sun Microsystems, is reported by both Tech.eu and Biometric Update as a formal advisor to IndyKite. The 2024 acquisition of 3Edges brought its co-creator Derek Small into the company as head of customer, partner and developer experience, and the OpenID Foundation lists Alex Babeanu of IndyKite among the chairs of its AuthZEN working group.

Below the founder the record thins. The company lists four functional heads by name and role, and the reviewed sources carry no independent account of their backgrounds. [s15, s16, s6, s9, s18]

Trust Readiness IndyKite runs a live trust center listing SOC 2 Type 1 and Type 2, ISO/IEC 27001:2022, GDPR, HIPAA and EU-U.S…

IndyKite runs a live trust center listing SOC 2 Type 1 and Type 2, ISO/IEC 27001:2022, GDPR, HIPAA and EU-U.S. Data Privacy Framework participation, and it publishes the underlying artifacts, including a 2026 ISO/IEC 27001:2022 certificate of registration and SOC 2 Type 2 reports. The controls list names penetration testing and cybersecurity insurance.

The certifications arrived on an ordinary enterprise schedule. The newsroom records a SOC 2 milestone in September 2024, SOC 2 Type 2 in June 2025 and ISO/IEC 27001 in March 2026, which closes a gap KuppingerCole named in September 2022 when it listed certifications in progress among the challenges.

The trust center also discloses the dependency chain, naming Google Cloud Platform as the cloud platform for production services, Neo4j Aura as the hosted graph database, and GitHub for source control. It records a customer-chosen storage location against both the cloud platform and the graph database. [s12, s7, s8, s17]

Competitors Permit.io, Cerbos, Oso, Axiomatics, Aembit, Veza…
Company Relationship Note Compare
Permit.io competes with Competes for the same buyer moving authorization decisions out of application code and into a service.
Cerbos competes with Competes for the same team choosing a policy decision service to sit outside its applications, and the OpenID Foundation lists a Cerbos chair beside an IndyKite chair in the AuthZEN working group. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Oso competes with Competes for the same developer adopting an authorization service rather than writing permission checks by hand. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Axiomatics competes with Competes in externalized authorization for large enterprises, and shares an AuthZEN working group chair seat with IndyKite.
Aembit adjacent Adjacent because it brokers credentials for workloads and agents rather than deciding what an agent may do once it holds them. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Veza adjacent Adjacent because it maps and reviews existing entitlements rather than making the access decision at the moment of the request. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.

Add analyzed competitors to compare them side by side with IndyKite.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 14 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

IndyKite is hard to displace because of where it sits, not because of what it owns. Agents, applications and APIs call it at the moment a decision is made, so leaving means re-pointing every caller and rebuilding the relationship model its policies read from, and the reviewed sources do not size that move. The reviewed record evidences no accumulating asset on IndyKite's side: the graph holds each customer's own data in a storage location that customer chooses, and the record names no patent or private corpus. Its SOC 2 and ISO 27001 certifications are what any funded competitor buys on the way into enterprise sales. Building a real-time graph authorization service is work a well-funded rival can reproduce, and the harder part, reaching enterprise buyers, IndyKite has done.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 IndyKite delivers software the customer configures and runs, a hosted graph plus a gateway image deployed per agent, with the documentation aimed at an implementer. The reviewed sources describe no service layer in which IndyKite accepts accountability for a customer's access decisions.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Leaving means re-pointing every application and agent that calls IndyKite and rebuilding the relationship model its policies read from, which is meaningful friction of the integration and data-history kind. The authorization surface advertises open standards, AuthZen, OAuth, MCP and the Agent-to-Agent protocol, while ContX IQ and the platform APIs are IndyKite's own, and the cited record does not size the migration.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 The certifications on the trust center are SOC 2 Type 1 and Type 2, ISO/IEC 27001:2022, GDPR alignment and HIPAA readiness, which a funded competitor obtains through ordinary enterprise-market preparation. The cited record shows no mandate, authorization or retained liability that blocks a replacement.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 A decision requires introspecting a token, exchanging it for a delegated token, traversing a graph for permitted workflows and matching an actor chain, all inside a call the caller is waiting on. Building a real-time graph authorization service on connected enterprise data is specialized work rather than integration work.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 The cited record names Deutsche Telekom, Rockwell Automation, PACCAR and Reitan Retail as customers, each represented by a named senior executive and, for two of them, a described multi-system deployment across telecommunications, industrial automation, commercial vehicles and retail. On that evidence the buyer is the large regulated enterprise rather than a mid-market team, and all four are attributed to the IndyKite platform rather than to a separate line.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 3/3 ContX IQ is a runtime API applications query for context and write back to, Knowledge-Based Access Control centralizes decisions for apps and APIs, and the gateway sits in the path of agent calls. Other software depends on IndyKite being there when a request is made, which is infrastructure rather than an end-user application.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The cited record identifies customer context and decision traces held in a graph whose storage location the customer chooses, and it evidences no vendor-retained corpus, no patent, no content licence and no cross-customer telemetry.
Strategic Market Segmentation IndyKite aims at large enterprises with data scattered across systems, and its published wins name retail, manufacturing, heavy equipment and telecommunications…

IndyKite aims at large enterprises with data scattered across systems, and its published wins name retail, manufacturing, heavy equipment and telecommunications. Rockwell Automation, PACCAR, Deutsche Telekom and Reitan Retail are the accounts the company puts forward, each represented by a named senior executive.

The segmentation is coherent but narrow in evidence. Every named account in the reviewed sources was surfaced by IndyKite or by its database partner, which is a customer list rather than a market position, and those sources say nothing about deal size, contract length or how many customers sit behind the names.

Geography is split across San Francisco, Calgary, Oslo and Stavanger. Two of the four offices are Norwegian and San Francisco is the headquarters the company gives.

Product Capabilities & AI Advantages The mechanism is specific enough to test…

The mechanism is specific enough to test. The Agent Gateway introspects a caller's token with the customer's identity provider, obtains an actor token for the protected agent, exchanges the two for a delegated token, queries the graph for workflows the caller may trigger, and rejects the call when the requested sequence of agents does not match a permitted chain. Agents are modelled as nodes with owners, skills and tools, and they hold no standing privilege of their own.

That design answers a gap the company describes. An agent calling another agent carries an actor chain, and IndyKite's own head of customer and partner experience argues that role-based access has never worked well even for humans and scales worse when agents can be created by the thousand. Placing the check in a gateway per agent, rather than inside the agent, keeps enforcement outside code the agent's author controls.

The AI in the product is the subject rather than the method. IndyKite Tags does classification work on unstructured content and screens prompts for injection attempts, but the platform's advantage is the graph and the delegation model, not a proprietary model of its own. The reviewed sources describe no model IndyKite trains.

Sales Engagement & Go-to-Market What the reviewed sources document is partnership activity rather than a sales channel…

What the reviewed sources document is partnership activity rather than a sales channel. IndyKite announced an alliance with Enterprise Knowledge in May 2026 to carry agentic delivery into enterprises, a Neo4j partnership in December 2025, and the Linux Foundation named it an Automotive Grade Linux member in April 2022.

The developer surface is real but secondary. The homepage links a documentation site, a sandbox, a forum and software development kits, and the docs carry a Terraform provider, which is the equipment of a self-serve motion. The named accounts are large enterprises, and the reviewed sources do not say how any of them was won.

What the reviewed sources do not show is a repeatable pattern. A short list of named accounts across five years, no disclosed pipeline and no partner-sourced revenue leave the motion described rather than demonstrated.

Pricing Model The reviewed sources carry no pricing…

The reviewed sources carry no pricing. The documentation describes organizations, projects and service accounts without naming a unit of charge.

The absence is consistent with the buyer. The reviewed sources name large enterprise customers and publish no figure, list or otherwise, for what any of them pays.

For a reader, the consequence is that unit economics cannot be assessed from the public record at all. The reviewed sources carry no per-seat, per-decision or per-node figure.

Product Delivery & Operations Delivery is split between a hosted platform and software the customer runs…

Delivery is split between a hosted platform and software the customer runs. The trust center lists Google Cloud Platform as the cloud platform for IndyKite production services and Neo4j Aura as the hosted graph database, and records a customer-chosen storage location against each.

The gateway is the customer's to operate. It ships as a Docker image, runs as a standalone container, under Docker Compose, as a Kubernetes pod or as a sidecar beside the protected agent, and one instance is deployed per agent. That last constraint is the operational cost of the design: an estate of many agents becomes an estate of many gateways to deploy, configure and upgrade.

Prerequisites are ordinary but not trivial. The gateway needs an identity provider supporting token exchange, token introspection and the client credentials grant, plus a workflow modelled in the graph and a ContX IQ query prepared in advance.

Earning Customers' Trust The trust posture is complete for the stage…

The trust posture is complete for the stage. A live trust center lists SOC 2 Type 1 and Type 2, ISO/IEC 27001:2022, GDPR, HIPAA and EU-U.S. Data Privacy Framework participation, and it publishes the certificate of registration and the SOC 2 reports rather than only badges.

The published controls extend past the certificates. Penetration testing, cybersecurity insurance, change management and data classification appear on the controls list, and the subprocessor list names four vendors with the function each performs.

The gap KuppingerCole flagged in September 2022, certifications in progress, has closed. The trust center records that penetration testing is performed, and the reviewed sources carry no report or summary of what it found.

Platform Strategy & Ecosystem Positioning IndyKite advertises open standards on the surfaces buyers integrate against…

IndyKite advertises open standards on the surfaces buyers integrate against. Its authorization service names AuthZen, OAuth and OpenID, and MCP, the gateway implements the Agent-to-Agent protocol, and the OpenID Foundation lists Alex Babeanu of IndyKite as a chair of its AuthZEN working group beside chairs from Bloomberg, Axiomatics, Cerbos and CrowdStrike.

Content integrations are the other half of the ecosystem. IndyKite Tags connects to SharePoint, OneDrive, Box, Google Workspace, Slack and Confluence, pulling content, metadata and permissions.

Standards adherence cuts both ways for durability. A customer that adopted IndyKite through AuthZEN or the Agent-to-Agent protocol keeps those call interfaces if it moves, although the graph model, the workflow definitions, the policies and the ContX IQ queries behind them would still have to be rebuilt.

Team & Execution Capability The founder's record is the strongest asset in the file…

The founder's record is the strongest asset in the file. Tech.eu reports that Lasse Andresen co-founded ForgeRock, counts ForgeRock among the identity IPOs beside Okta and Ping Identity, and describes him as a former Sun Microsystems chief technology officer. Scott McNealy, who co-founded Sun, is reported by both Tech.eu and Biometric Update as a formal advisor.

The 2024 acquisition of 3Edges bought people as much as product. Derek Small, who co-created 3Edges, joined as head of customer, partner and developer experience, and now speaks for the company in its partner material.

Depth below that is undocumented. Four functional heads are listed by name and role, with no independent record of what they built before, and the reviewed sources give no headcount more recent than the roughly sixty staff the press reported in February 2022.

Sources

Company Detail Sources (7)
Id Source Tier Accessed
f1 IndyKite: homepage official 2026-09-02
f2 Biometric Update: report on IndyKite's decentralized ID launch and seed round press 2026-09-02
f3 IndyKite: about us official 2026-09-02
f4 CB Insights: IndyKite funding and financials profile research 2026-09-02
f5 Tech.eu: report on IndyKite's $8 million seed round press 2026-09-02
f6 IndyKite documentation: Agent Gateway overview official 2026-09-02
f7 IndyKite: Knowledge-Based Access Control product page official 2026-09-02
Profile Analysis Sources (23)
Id Source Tier Accessed
s1 IndyKite: homepage
“The runtime control layer for”
official 2026-09-02
s2 IndyKite: platform overview
“IndyKite transforms signals into live enforcement context”
official 2026-09-02
s3 IndyKite: AgentControl product page
“Granular control and dynamic security for AI agents”
official 2026-09-02
s4 IndyKite: ContX IQ product page
“Fetch context-specific data at runtime and update the graph instantly with custom query parameters”
official 2026-09-02
s5 IndyKite: Knowledge-Based Access Control product page
“Fine-grained authorization built for data, AI and dynamic users”
official 2026-09-02
s6 IndyKite: about us
“Headquartered in San Francisco with teams across North America and Europe”
official 2026-09-02
s7 IndyKite: security and privacy page
“Our SOC 2 Type 1 certification demonstrates that our security controls are designed and implemented to protect your data.”
official 2026-09-02
s8 IndyKite: newsroom index
“July 8, 2026 Breakthrough AI wellbeing platform movemove selects IndyKite to power trusted AI”
official 2026-09-02
s9 IndyKite: announcement of the 3Edges acquisition
“IndyKite has today announced the acquisition of the innovative dynamic authorization solution 3Edges.”
official 2026-09-02
s10 IndyKite: announcement of the AI Control Suite launch
“SAN FRANCISCO - February 18, 2025 -”
official 2026-09-02
s11 IndyKite documentation: getting started
“We provide user guides, tutorials, and references to help you learn how to set up, configure, manage, and use the IndyKite platform.”
official 2026-09-02
s12 IndyKite Trust Center: probe of the published trust surface
“Welcome to the IndyKite Trust Center”
official 2026-09-02
s13 IndyKite documentation: Agent Gateway overview
“The Indykite Agent Gateway (IAG) is a standalone service whose goal is to protect a given AI agent. You can deploy instances of the IAG to protect every agent in an agentic workflow, ensuring proper access control and governance across the system.”
official 2026-09-02
s14 Tech.eu: report on IndyKite's $8 million seed round
“Norway/San Francisco-based IndyKite has raised another $8 million in seed funding.”
press 2026-09-02
s15 Tech.eu: report on IndyKite emerging from stealth with a $2.5 million pre-seed round
“Norway/San Francisco-based IndyKite emerges from stealth in conjunction with the announcement of a $2.5 million pre-seed funding round.”
press 2026-09-02
s16 Biometric Update: report on IndyKite's decentralized ID launch and seed round
“launched in October 2021 by ForgeRock co-founder Lasse Andresen with Sun Microsystems co-founder Scott McNealy as a formal advisor, to offer open-source technology based on knowledge graphs has released a new product.”
press 2026-09-02
s17 KuppingerCole: Executive View report on IndyKite Knowledge-Based Access Control
“Executive View September 13, 2022”
research 2026-09-02
s18 OpenID Foundation: AuthZEN Working Group page listing the working group chairs
“Working Group Chairs Julio Auto De Medeiros (Bloomberg) Alex Babeanu (IndyKite) David Brossard (Axiomatics) Alex Olivier (Cerbos) Atul Tulshibagwale (CrowdStrike)”
research 2026-09-02
s19 Linux Foundation: Automotive Grade Linux announces new Bronze members
“announces IndyKite, Marelli and Red Hat as new Bronze members.”
press 2026-09-02
s20 Neo4j: customer story page about IndyKite
“IndyKite's Neo4j-powered context graph helps enterprises like Rockwell Automation and PACCAR connect siloed systems, govern how AI agents access data, and quantify trust at the data level.”
official 2026-09-02
s21 CB Insights: IndyKite funding and financials profile
“IndyKite has raised $10.5M over 3 rounds .”
research 2026-09-02
s22 IndyKite documentation: Agent Gateway deployment
“IndyKite Agent Gateway is delivered as a Docker image.”
official 2026-09-02
s23 IndyKite: IndyKite Tags product page
“Transform unstructured assets into governed, AI-ready inputs through automated tagging, classification, and safety checks.”
official 2026-09-02
Deep-Dive Sources (23)
Id Source Tier Accessed
s1 IndyKite: homepage
“The runtime control layer for”
official 2026-09-02
s2 IndyKite: platform overview
“IndyKite transforms signals into live enforcement context”
official 2026-09-02
s3 IndyKite: AgentControl product page
“Granular control and dynamic security for AI agents”
official 2026-09-02
s4 IndyKite: ContX IQ product page
“Fetch context-specific data at runtime and update the graph instantly with custom query parameters”
official 2026-09-02
s5 IndyKite: Knowledge-Based Access Control product page
“Fine-grained authorization built for data, AI and dynamic users”
official 2026-09-02
s6 IndyKite: about us
“Headquartered in San Francisco with teams across North America and Europe”
official 2026-09-02
s7 IndyKite: security and privacy page
“Our SOC 2 Type 1 certification demonstrates that our security controls are designed and implemented to protect your data.”
official 2026-09-02
s8 IndyKite: newsroom index
“July 8, 2026 Breakthrough AI wellbeing platform movemove selects IndyKite to power trusted AI”
official 2026-09-02
s9 IndyKite: announcement of the 3Edges acquisition
“IndyKite has today announced the acquisition of the innovative dynamic authorization solution 3Edges.”
official 2026-09-02
s10 IndyKite: announcement of the AI Control Suite launch
“SAN FRANCISCO - February 18, 2025 -”
official 2026-09-02
s11 IndyKite documentation: getting started
“We provide user guides, tutorials, and references to help you learn how to set up, configure, manage, and use the IndyKite platform.”
official 2026-09-02
s12 IndyKite Trust Center: probe of the published trust surface
“Welcome to the IndyKite Trust Center”
official 2026-09-02
s13 IndyKite documentation: Agent Gateway overview
“The Indykite Agent Gateway (IAG) is a standalone service whose goal is to protect a given AI agent. You can deploy instances of the IAG to protect every agent in an agentic workflow, ensuring proper access control and governance across the system.”
official 2026-09-02
s14 Tech.eu: report on IndyKite's $8 million seed round
“Norway/San Francisco-based IndyKite has raised another $8 million in seed funding.”
press 2026-09-02
s15 Tech.eu: report on IndyKite emerging from stealth with a $2.5 million pre-seed round
“Norway/San Francisco-based IndyKite emerges from stealth in conjunction with the announcement of a $2.5 million pre-seed funding round.”
press 2026-09-02
s16 Biometric Update: report on IndyKite's decentralized ID launch and seed round
“launched in October 2021 by ForgeRock co-founder Lasse Andresen with Sun Microsystems co-founder Scott McNealy as a formal advisor, to offer open-source technology based on knowledge graphs has released a new product.”
press 2026-09-02
s17 KuppingerCole: Executive View report on IndyKite Knowledge-Based Access Control
“Executive View September 13, 2022”
research 2026-09-02
s18 OpenID Foundation: AuthZEN Working Group page listing the working group chairs
“Working Group Chairs Julio Auto De Medeiros (Bloomberg) Alex Babeanu (IndyKite) David Brossard (Axiomatics) Alex Olivier (Cerbos) Atul Tulshibagwale (CrowdStrike)”
research 2026-09-02
s19 Linux Foundation: Automotive Grade Linux announces new Bronze members
“announces IndyKite, Marelli and Red Hat as new Bronze members.”
press 2026-09-02
s20 Neo4j: customer story page about IndyKite
“IndyKite's Neo4j-powered context graph helps enterprises like Rockwell Automation and PACCAR connect siloed systems, govern how AI agents access data, and quantify trust at the data level.”
official 2026-09-02
s21 CB Insights: IndyKite funding and financials profile
“IndyKite has raised $10.5M over 3 rounds .”
research 2026-09-02
s22 IndyKite documentation: Agent Gateway deployment
“IndyKite Agent Gateway is delivered as a Docker image.”
official 2026-09-02
s23 IndyKite: IndyKite Tags product page
“Transform unstructured assets into governed, AI-ready inputs through automated tagging, classification, and safety checks.”
official 2026-09-02

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.