All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
The capability that wins Oasis its deals is the one any non-human identity rival also ships. GitGuardian ranks Oasis fourth in its 2026 roundup and credits its multi-environment discovery while flagging exposure detection shallower than secret-scanning specialists, so discovery, inventory, and posture are the table that everyone sets. The piece that could make Oasis hard to leave is Agentic Access Management, which issues the ephemeral per-session identities AI agents authenticate through and binds every action to a prompt, intent, policy, and session trail. No public source shows a single named customer routing production agents through that path. Oasis has raised $195 million since 2022 on an entirely anonymous customer base, so the durable layer is a bet, not yet a moat.
| Description | Oasis Security manages the non-human identities and AI agents that operate across a company's cloud and on-prem systems, governing their access to services such as AWS, GitHub, and Salesforce. | [f1] |
|---|---|---|
| Founded | 2022 | [f2] |
| HQ | New York, NY | [f2] |
| Funding | $195M total | [f2] |
| Latest funding | Series B, $120 million, March 2026, led by Craft Ventures | [f2] |
| Deployment | SaaS | [f3] |
| Product | What it does |
|---|---|
| Oasis | Non-human identity management platform that discovers, governs, and enforces least-privilege access for service accounts, secrets, and AI agents across hybrid cloud. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Oasis is a non-human identity management platform that discovers, governs, and enforces least-privilege access for service accounts, secrets, and AI agents across hybrid cloud. It is mapped to the AI Defense Matrix. [f4]
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Oasis inventories conventional non-human identities, assesses posture, rotates secrets, detects identity threats, and provides remediation plans. This line is mapped to the Cyber Defense Matrix. The agentic AI line carries the AI Defense Matrix mapping. [f5]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score |
|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs, demos, and third-party validation. | 3/5 |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 2/5 |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
| Dimension | Score |
|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 3/3 |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Oasis Security: Non Human Identity Management Platform | official | 2026-07-09 |
| f2 | SecurityWeek on the Oasis Series B | press | 2026-06-29 |
| f3 | AI Defense Matrix Catalog entry | other | 2026-06-07 |
| f4 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| f5 | Oasis NHI Security Cloud product overview | official | 2026-06-12 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Oasis Security homepage with customer outcomes “Fortune-50 healthcare provider eliminated a critical exposure, avoiding a $3-5 M HIPAA breach fine. Fortune-500 logistics company cut secret-rotation effort by 35 %.” | official | 2026-06-29 |
| s2 | Oasis non-human identity management platform product overview “Oasis drives Lifecycle Management end-to-end. Provisioning, Ownership Assignment, Vaulting, Posture, Rotation, Decomission.” | official | 2026-06-29 |
| s3 | Oasis Agentic Access Management product page “Issue ephemeral, per-session identities; eliminating standing privileges and minimizing blast radius. AAM links every action to a clear trail: Prompt, Intent, Policy, Session, Action.” | official | 2026-06-29 |
| s4 | Why Oasis differentiators page “Thanks to its policy-based infrastructure-agnostic control plane Oasis automates the NHI lifecycle without compromising developer experience. NHIs represent 20 to 50x more identities growing at 20% YoY.” | official | 2026-06-29 |
| s5 | Oasis about and leadership page “Danny Brickman Co-founder & CEO. Amit Zimerman Co-founder & CPO. Barak Shelef Chief Architect. Yonit Glozshtein VP of Product.” | official | 2026-06-29 |
| s6 | Oasis newsroom listing the Zscaler integration and GuidePoint partnership “Oasis Security Announces Integration with Zscaler to Extend Zero Trust to Non-Human and Agentic Identities. New integration delivers a single control plane for non-human identities and AI agents, combining Oasis' identity governance with inline enforcement across Zscaler's Zero Trust Exchange.” | official | 2026-06-29 |
| s7 | SecurityWeek on the Oasis Series B “raising $120 million in a Series B funding round that brings the total raised by the company to $195 million. The fresh investment round was led by Craft Ventures, with additional support from previous investors Cyberstarts, Sequoia Capital, and Accel.” | press | 2026-06-29 |
| s8 | SiliconANGLE on the Series B (founders and platform mechanics) “Founded in 2022 by Danny Brickman and Ami Timarman, both previous members of Israeli Intelligence Unit 81. The platform includes support for the automated discovery of machine identities, classification based on role and usage and policy-driven governance for credential rotation and access control.” | press | 2026-06-29 |
| s9 | CTech on the Series A extension and valuation “the team has supported a rapidly expanding customer base, including several Fortune 500 companies, with a straightforward solution that delivers immediate value.” | press | 2026-06-29 |
| s10 | CTech on the DeCesare appointment “DeCesare previously served as CEO of Forescout Technologies, which was founded by Israelis and sold in 2020. The appointment comes after a year in which Oasis reported rapid expansion, including a fivefold increase in annual revenue.” | press | 2026-06-29 |
| s11 | SecurityWeek on the Series A extension “$35 million in a Series A extension round that brings the total raised by the company to $75 million” | press | 2026-06-29 |
| s12 | Dark Reading on the Oasis AuthQuake research disclosure “The researchers achieved the bypass, which they dubbed AuthQuake. Oasis informed Microsoft of the issue, which acknowledged its existence in June and fixed it permanently by Oct. 9, the researchers said.” | press | 2026-06-29 |
| s13 | CB Insights profile and ESP placement for Oasis “Founded Year 2022. Stage Series B | Alive. Total Raised $195M. Oasis named as Challenger among 15 other companies, including SailPoint, Saviynt, and HashiCorp.” | research | 2026-06-29 |
| s14 | SEC EDGAR full-text search showing a Form D for an Oasis-named entity “Inflection Ventures Oasis Security Fund I LLC (CIK 0002132124), form D, file_date 2026-06-16, biz_locations Newark, DE, inc_states DE.” | regulatory | 2026-07-02 |
| s15 | GitGuardian: Top 10 Non-Human Identity Security Tools and Platforms for 2026 “4) Oasis Security. Pros: Focused NHI security approach. Strong multi-environment discovery. Cons: Oasis Security's exposure detection features may not be as deep or specialized as dedicated secret-scanning vendors.” | research | 2026-06-29 |
| s16 | Oasis Security homepage footer attestation badges (SOC 2, ISO 27001) “Footer serves SOC2.avif with alt SOC 2 compliance badge and ISO.avif with alt ISO 27001 certification logo, both from the Oasis content domain.” | official | 2026-06-29 |
| s17 | Oasis trust center probe (trust subdomain does not resolve; security and trust paths return 404) “The trust and security subdomains do not resolve and the security, trust, and compliance paths return HTTP 404, so no public trust center or downloadable report is reachable.” | official | 2026-06-29 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Oasis non-human identity management platform product overview “17,000+ non-human identities in our cloud environment and we had no idea. Oasis gave us visibility we simply didn't have before. That alone made it a no-brainer. Head of Identity, Fortune 1000” | official | 2026-06-17 |
| s2 | Oasis Agentic Access Management product page (session provisioning, chain of custody) “Issue ephemeral, per-session identities, eliminating standing privileges and minimizing blast radius. AAM links every action to a clear trail: Prompt, Intent, Policy, Session, Action.” | official | 2026-06-17 |
| s3 | Why Oasis differentiators page (control plane, NHI scale) “Thanks to its policy-based infrastructure-agnostic control plane Oasis automates the NHI lifecycle without compromising developer experience. NHIs represent 20 to 50x more identities growing at 20% YoY.” | official | 2026-06-17 |
| s4 | Oasis about and leadership page “Danny Brickman Co-founder & CEO. Amit Zimerman Co-founder & CPO. Barak Shelef Chief Architect. Yonit Glozshtein VP of Product.” | official | 2026-06-18 |
| s5 | GitGuardian: Top 10 Non-Human Identity Security Tools and Platforms for 2026 “4) Oasis Security. Pros: Focused NHI security approach. Strong multi-environment discovery. Cons: Oasis Security's exposure detection features may not be as deep or specialized as dedicated secret-scanning vendors. Pricing: Enterprise-tier pricing for commercial SaaS.” | research | 2026-06-17 |
| s6 | SecurityWeek on the Oasis Series B (funding and capabilities) “raising $120 million in a Series B funding round that brings the total raised by the company to $195 million. The fresh investment round was led by Craft Ventures, with additional support from previous investors Cyberstarts, Sequoia Capital, and Accel.” | press | 2026-06-17 |
| s7 | SiliconANGLE on the Series B (founders and platform mechanics) “Founded in 2022 by Danny Brickman and Ami Timarman, both previous members of Israeli Intelligence Unit 81. The platform includes support for the automated discovery of machine identities, classification based on role and usage and policy-driven governance for credential rotation and access control.” | press | 2026-06-18 |
| s8 | Oasis Agentic Access Management launch release on PR Newswire “Oasis AAM brings intent-aware control, real-time policy enforcement, and full accountability to the enterprise AI layer, extending Oasis' non-human identity management platform. Backed by leading global investors including Sequoia Capital, Cyberstarts, and Accel.” | press | 2026-06-17 |
| s9 | Oasis homepage footer attestation badges (SOC 2, ISO 27001) “Footer badge images 679b2b742e3af6fc4669f838_SOC2.avif and 679b2b742e3af6fc4669f839_ISO.avif, alt text SOC 2 compliance badge showcasing Oasis Security's adherence to trusted security standards and ISO 27001 certification logo demonstrating Oasis Security's commitment to security standards.” | official | 2026-06-18 |
| s10 | Oasis trust center probe (trust subdomain does not resolve; security and trust paths return 404) “The trust and security subdomains do not resolve and the security, trust, and compliance paths return HTTP 404, so no public trust center or downloadable report is reachable.” | official | 2026-07-02 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Do not republish its content or share access without the operator's permission.