Oasis Security

Security for AI Identity Access

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2022
Funding $195M
Last updated 2026-08-07

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Cyera signed a letter of intent on July 28, 2026 to acquire Oasis for about $1 billion, mostly in cash, and reporting says Oasis will run as an independent unit once the deal closes. What Cyera is buying is machine-identity discovery and lifecycle governance, which GitGuardian places fourth in its 2026 roundup while flagging exposure detection shallower than dedicated secret-scanning vendors, alongside Agentic Access Management, which issues the short-lived per-session identities AI agents authenticate through. An anonymous Fortune 1000 head of identity called that visibility decisive after finding more than 17,000 unmanaged identities. No source in this record names a customer running production agents through the agent-access path.

Sourced Details

Description Oasis Security manages the non-human identities and AI agents that operate across a company's cloud and on-prem systems, governing their access to services such as AWS, GitHub, and Salesforce. [f1]
Founded 2022 [f2]
HQ New York, NY [f2]
Funding $195M total [f2]
Latest funding Series B, $120 million, March 2026, led by Craft Ventures [f2]
Deployment SaaS [f3]

Products

Product What it does
Oasis Non-human identity management platform that discovers, governs, and enforces least-privilege access for service accounts, secrets, and AI agents across hybrid cloud.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Oasis is a non-human identity management platform that discovers, governs, and enforces least-privilege access for service accounts, secrets, and AI agents across hybrid cloud. It is mapped to the AI Defense Matrix. [f4]

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Oasis inventories conventional non-human identities, assesses posture, rotates secrets, detects identity threats, and provides remediation plans. This line is mapped to the Cyber Defense Matrix. The agentic AI line carries the AI Defense Matrix mapping. [f5]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Emerging 24 /40 Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 The buyer is the enterprise identity and security team, and CTech ties the pain to attackers exploiting non-human identities with increasing efficacy (s9), while CB Insights and GitGuardian establish the category rather than quantifying the pain (s13, s15), so the problem is clear but independent quantification is absent. [s4, s9, s13, s15]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 Oasis pages describe the platform in specific functional terms covering discovery, ownership, vaulting, posture, rotation, and decommissioning plus per-session agent credentials (s2, s3), but documentation requires a customer login with no self-service tier or published pricing, and external description beyond vendor pages reduces to GitGuardian's roundup, which flags exposure detection shallower than secret-scanning specialists (s15). [s2, s3, s15]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The enabler is enterprise adoption of agentic AI that created machine and agent identities classic IAM cannot govern, which Oasis answered by shipping Agentic Access Management in November 2025 (s3, s6). Independent demand stays category-level, reducing to analyst category placement at CB Insights and a GitGuardian roundup (s13, s15) rather than named buyer RFP or budget data, matching the same-asset reading at this level. [s3, s6, s13, s15]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 Founders Danny Brickman and Amit Zimerman are publicly identifiable Unit 81 veterans who founded the company in 2022 (s5, s8), but neither shows a prior in-domain exit or a sustained publication record. The April 2026 hire of Michael DeCesare, formerly Forescout CEO and McAfee president (s10), and one widely covered Microsoft MFA disclosure (s12) are verifiable but secondary signals. [s5, s8, s10, s12]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 Customer evidence is entirely anonymous, from a Fortune-50 healthcare provider to a Fortune-500 logistics firm on the homepage (s1), with no named reference customer in any page reviewed, which is weaker than same-asset peers that name at least one customer. Verifiable partnership motion (a GuidePoint reseller agreement and the June 2026 Zscaler integration, s6) and strong investor backing across four rounds (s7) are indirect signals that lift toward but do not reach the higher rung without named customer traction. [s1, s6, s7, s9]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 2/5 The $120 million Series B brings total funding to $195 million (s7) with no disclosed revenue and only company-stated 5x annual-recurring-revenue growth (s10), an outsized raise that outruns verifiable commercial results regardless of the channel program and integrations shipped. [s7, s10, s11]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 4/5 Third parties now place Oasis in an established non-human identity category without vendor coaching, multiply evidenced: CB Insights ranks it a Challenger in machine identity management alongside SailPoint, Saviynt, and HashiCorp (s13), and GitGuardian's tool roundup lists and ranks it (s15). The placement is participant rather than category-defining, so it sits below the top rung. [s13, s15]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Hybrid-environment NHI discovery with lifecycle orchestration is more than a quarterly feature for an identity-provider incumbent, and the company sells multi-year agreements that embed it in customer identity architecture, but Okta and Microsoft are adjacent to the same buyer, Zscaler already operates the enforcement layer Oasis feeds (s6), and no proprietary data flywheel is in evidence. [s6, s13, s15]
Business Risks Okta, Microsoft Entra, or another identity incumbent could ship native non-human identity discovery and agent-access governance, turning the standalone NHI budget line into a platform feature before the category consolidates…
  • Okta, Microsoft Entra, or another identity incumbent could ship native non-human identity discovery and agent-access governance, turning the standalone NHI budget line into a platform feature before the category consolidates.
  • Zscaler could extend its Zero Trust Exchange from enforcing Oasis policies to generating them, absorbing the joint use case the June 2026 integration created.
  • Every traction figure is company-stated and no customer is named, so a growth stall would stay publicly invisible until it surfaced in hiring data or the terms of the next raise.
  • GitGuardian already flags Oasis's exposure detection as shallower than secret-scanning specialists, and RFPs weighted toward leaked-credential detection could route the budget to those rivals.
  • Agentic Access Management bets on per-session agent identities at the access layer, and if enterprises standardize agent authorization on protocol-level controls governed by their existing identity providers, the agent-access layer becomes optional middleware.
Problem & Market Oasis Security targets the machine side of enterprise identity, meaning the service accounts, API keys, tokens, and certificates that applications use to reach critical systems, and now the AI agents joining them…

Oasis Security targets the machine side of enterprise identity, meaning the service accounts, API keys, tokens, and certificates that applications use to reach critical systems, and now the AI agents joining them. The company argues that these identities outnumber human users by 20 to 50 times and grow about 20 percent a year, while classic MFA and conditional access never applied to them, so the controls human accounts get do not reach the machine side.

Corroboration for the problem exists outside the company's marketing. CTech describes attackers exploiting non-human identities with increasing efficacy, CB Insights tracks a machine identity management market that ranks named vendors, and GitGuardian's 2026 roundup treats non-human identity security as an established tool category.

The buyer is the security and identity team in a large enterprise. Oasis says a majority of its customers come from the Fortune 500, and its homepage presents anonymized outcomes for a Fortune-50 healthcare provider and a Fortune-500 logistics firm, the moment those organizations wire AI agents into production faster than their identity programs can govern them. [s1, s4, s9, s13, s15]

Product Capabilities The Oasis platform is an agentless system that connects to cloud and on-premises identity systems, discovers non-human identities, ties each one to an owner, scores posture and risk, and orchestrates lifecycle actions such as provisioning, vaulting, rotation, and decommissioning…

The Oasis platform is an agentless system that connects to cloud and on-premises identity systems, discovers non-human identities, ties each one to an owner, scores posture and risk, and orchestrates lifecycle actions such as provisioning, vaulting, rotation, and decommissioning. SiliconANGLE describes the automated discovery of machine identities, classification by role and usage, and policy-driven governance for credential rotation and access control.

Agentic Access Management, which Oasis shipped in November 2025, extends the platform to AI agents. The documented mechanism is identity-centric. The product issues ephemeral per-session identities instead of standing credentials to shrink blast radius, and links every agent action to a prompt, intent, policy, session, and action trail for accountability, on a control plane the company describes as policy-based and infrastructure-agnostic.

Verification beyond vendor descriptions is thin. Documentation requires a customer login, no self-service tier or published pricing appears on the company site, and the strongest external description is GitGuardian's roundup, which credits the multi-environment discovery while noting that exposure detection runs shallower than dedicated secret-scanning tools. [s2, s3, s4, s8, s15]

Competitive Positioning Oasis occupies the discovery-and-governance wing of the non-human identity category, where it competes most directly with Astrix Security, Entro Security, and Clutch Security, while Aembit approaches the same budget line from runtime credential brokering…

Oasis occupies the discovery-and-governance wing of the non-human identity category, where it competes most directly with Astrix Security, Entro Security, and Clutch Security, while Aembit approaches the same budget line from runtime credential brokering. GitGuardian's 2026 roundup lists those rivals and ranks Oasis fourth, and CB Insights places Oasis as a Challenger in machine identity management alongside SailPoint, Saviynt, and HashiCorp.

Against identity incumbents, Oasis positions itself as the layer legacy IAM does not cover, and its strongest ecosystem proof is the June 2026 Zscaler integration, which pairs Oasis identity governance with inline enforcement in Zscaler's Zero Trust Exchange to give joint customers one control plane from discovery to decommissioning.

The agentic repositioning opens a second competitive front. With Agentic Access Management the company claims the access-management layer for AI agents before that category has settled, and its trademark on the term signals an ambition to name it. If buyers come to treat agent access as an extension of their existing IAM and zero-trust platforms, Oasis will compete with those incumbents rather than fellow startups. [s6, s13, s15]

Go-to-Market & Traction Oasis runs a sales-led enterprise motion aimed at large organizations, with demo-gated evaluation and no self-service tier…

Oasis runs a sales-led enterprise motion aimed at large organizations, with demo-gated evaluation and no self-service tier. The company reports that new annual recurring revenue grew fivefold year over year and that most new revenue comes through multi-year agreements, figures no third party has confirmed.

Channel and ecosystem motion is the verifiable part. Oasis launched a channel program with GuidePoint Security as a reseller, shipped the Zscaler integration in June 2026, and in April 2026 hired Michael DeCesare, a veteran of McAfee, Forescout, Exabeam, and Abnormal, as president running global go-to-market.

Customer evidence stays anonymous. The homepage presents anonymized outcomes for a Fortune-50 healthcare provider and a Fortune-500 logistics firm, and a Cyberstarts partner described a rapidly expanding Fortune 500 customer base in 2024, but no named reference customer appears in any page reviewed. A June 2026 SEC Form D filed by a vehicle named Inflection Ventures Oasis Security Fund I LLC is a regulatory marker of continued investor activity around Oasis, not a customer. [s1, s6, s9, s10, s14]

Team & Credibility Co-founders Danny Brickman, CEO, and Amit Zimerman, CPO, met during service in Unit 81, an Israeli intelligence technology unit, and founded the company in 2022 with offices in New York and Tel Aviv…

Co-founders Danny Brickman, CEO, and Amit Zimerman, CPO, met during service in Unit 81, an Israeli intelligence technology unit, and founded the company in 2022 with offices in New York and Tel Aviv. The public record documents no prior exit for either founder, so public verification depends on the unit's reputation and on who backed and joined the founders.

Those secondary signals are strong. Cyberstarts, Sequoia, Accel, and Craft Ventures funded the company across four rounds, and the executive bench now includes president Michael DeCesare, who previously ran Forescout and Exabeam and served as McAfee's president, alongside chief architect Barak Shelef and VP of product Yonit Glozshtein.

The Oasis research team adds a public technical signal. It disclosed a Microsoft MFA weakness it named AuthQuake in December 2024 that Dark Reading covered, coordinating with Microsoft on the fix. One disclosure is a single data point, but it shows the team invests in public research. [s5, s8, s10, s12]

Trust Readiness The homepage footer serves the company's own SOC 2 and ISO 27001 attestation badges, the AICPA SOC seal and the ISO 27001 seal, both delivered from the Oasis content domain…

The homepage footer serves the company's own SOC 2 and ISO 27001 attestation badges, the AICPA SOC seal and the ISO 27001 seal, both delivered from the Oasis content domain. Those are the table-stakes signals enterprise buyers expect, and they place Oasis level with the category on baseline assurance rather than behind it.

What is missing is the inspectable layer above the badges. In the June 29, 2026 probe, trust.oasis.security and security.oasis.security did not resolve. The security, trust, and compliance paths on www.oasis.security returned HTTP 404. The documentation portal requires a customer login, and no SOC 2 report or ISO certificate appears at any probed URL. For a platform that holds an inventory of every credential and agent identity in a customer's environment, the underlying reports must still be requested privately under a non-disclosure agreement.

Two observable practices reinforce the security posture. SecurityWeek describes the agentless connection model, which limits the footprint customers must deploy, and Oasis handled its AuthQuake disclosure through coordinated reporting, publishing after Microsoft shipped a permanent fix. The remaining gap is one of openness rather than certification, since rivals that publish reports and pricing let a buyer see more before signing. [s11, s12, s16, s17]

Competitors Aembit, Astrix Security, Entro Security, Clutch Security, Okta, Zscaler, Microsoft…
Company Relationship Note Compare
Aembit competes with Approaches the same non-human identity budget line from runtime credential brokering and enforcement, and competes for agentic access with its IAM for Agentic AI line.
Astrix Security competes with Non-human identity discovery and governance rival listed alongside Oasis in GitGuardian's 2026 roundup.
Entro Security competes with Machine identity discovery and lifecycle vendor listed in the same NHI category roundup. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Clutch Security competes with Non-human identity security platform ranked alongside Oasis in GitGuardian's 2026 roundup.
Okta adjacent Human identity-provider incumbent adjacent to the same buyer. Native agent and workload identity features would compress the standalone NHI category. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Zscaler adjacent Integration partner as of June 2026. Its Zero Trust Exchange operates the enforcement layer Oasis feeds, and it could extend into identity governance.
Microsoft adjacent Entra ID administers many of the directories and identities Oasis governs, and agent-identity features there would reach the same buyer first. N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product.

Add analyzed competitors to compare them side by side with Oasis Security.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 13 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Agentic Access Management is the piece that could make Oasis hard to leave, because it issues the short-lived per-session identities AI agents authenticate through, and a customer running production agents on it would rebuild how those agents get access in order to cancel. Discovery appears to drive the public customer proof, and it is a common capability across the non-human identity platforms GitGuardian lists. The cited record documents per-customer inventories but no cross-customer data asset, the self-displayed SOC 2 and ISO 27001 badges are a credibility floor, and the cited record documents software features rather than a delivery layer Oasis operates. Watch whether the identity providers Oasis governs add the same governance natively.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Oasis sells a software platform for discovery, posture, lifecycle, and agent session provisioning that customers configure and run through a demo-led enterprise purchase, and the cited record documents software features, not a managed-service, judgment, or liability-bearing delivery layer.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Discovery baselines, lifecycle and rotation workflows, and the Agentic Access Management session path create meaningful friction once embedded, and the cited record documents no network effect or data-residency constraint that would support a 3, nor does it size what leaving would cost.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Oasis self-displays SOC 2 and ISO 27001 badges on its homepage, the cited record exposes no inspectable trust portal or downloadable report, and it identifies no non-human-identity-specific mandate or vendor-bound authorization, so the badges are table-stakes assurance.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Cross-cloud discovery, classification, posture, credential rotation, anomaly detection, and issuing short-lived per-session identities in the access path is distributed-systems and security engineering that takes years of specialized expertise.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 The buyer is the large-enterprise identity and security team, with a Fortune 1000 head of identity and a Fortune 500 chief information security officer as testimonials, where procurement slows replacement, and every customer reference in the cited record is anonymous.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 3/3 Agentic Access Management issues the short-lived per-session identities AI agents authenticate through on a policy-based infrastructure-agnostic control plane, infrastructure other software depends on to act rather than an end-user application. The discovery line alone would sit at 2, and the cited record offers only an anonymous vendor-published testimonial rather than a named customer whose production agents run on the session-identity path.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The platform holds a per-customer inventory of identities and credentials, which is switching friction rather than a cross-customer data asset, and the cited record names no non-public dataset behind the detection models, so a funded rival could rebuild the capability.
Strategic Market Segmentation Oasis targets the security and identity team in a large enterprise that has lost track of its machine accounts…

Oasis targets the security and identity team in a large enterprise that has lost track of its machine accounts. The company argues that non-human identities outnumber human ones by 20 to 50 times and grow about 20 percent a year, while classic MFA and conditional access never applied to them, so the buyer is the team already accountable for human identity and now inheriting the machine side.

The agentic line sharpens that same buyer rather than opening a new one. Oasis frames AI agents as the next wave of non-human identities and sells Agentic Access Management to the organization wiring agents into production faster than its identity program can govern them. SiliconANGLE reports the platform discovers, classifies, and governs machine identities across enterprise environments to reduce exposure from unmanaged credentials.

The named demand stays anonymous. The product page quotes a Fortune 1000 head of identity who found more than 17,000 unmanaged non-human identities, the agentic page quotes a Fortune 500 chief information security officer, and the homepage lists outcomes for a Fortune 50 healthcare provider and a Fortune 500 logistics company. No source in this record attaches a company name to any of them.

Product Capabilities & AI Advantages The core platform discovers and governs the machine identities a hybrid estate accumulates…

The core platform discovers and governs the machine identities a hybrid estate accumulates. SiliconANGLE describes automated discovery of machine identities, classification by role and usage, policy-driven governance for credential rotation and access control, detection of unused or orphaned identities, least-privilege enforcement, and anomaly monitoring. That is the recognized non-human identity feature set.

Agentic Access Management is where the product moves from observing identities to provisioning them. The launch release documents three mechanisms: intent inference that interprets what an agent is trying to do, a policy engine that validates access decisions and escalates to a human when privilege boundaries are crossed, and just-in-time session identities that provision ephemeral least-privilege credentials for seconds-to-minutes sessions and capture an audit trail of person, prompt, policy, actions, and teardown. The control plane is described as policy-based and infrastructure-agnostic.

The verifiable edge is engineering breadth rather than a unique data asset. GitGuardian credits strong multi-environment discovery while flagging that exposure detection runs shallower than dedicated secret-scanning vendors. The cited record names no non-public training corpus and no third-party accuracy benchmark, so a funded rival could rebuild the capability from the same telemetry.

Sales Engagement & Go-to-Market Oasis runs a sales-led enterprise motion with no published self-service path…

Oasis runs a sales-led enterprise motion with no published self-service path. GitGuardian records enterprise-tier pricing for commercial SaaS, the reviewed product pages route prospects to a demo request, and no rate card or free tier appears in the cited record, the posture of a vendor selling negotiated deals to large security organizations.

Cyera signed a letter of intent on July 28, 2026 to acquire Oasis for about $1 billion, mostly in cash with the remainder in Cyera shares, roughly five times the $195 million Oasis had raised across its disclosed rounds since 2022. The March 2026 Series B that preceded it drew Craft Ventures alongside returning backers Cyberstarts, Sequoia Capital, and Accel.

Disclosed traction below that headline stays thin. SiliconANGLE reports, citing a Bloomberg interview, that business with Fortune 500 companies accounts for the majority of Oasis sales, and the homepage carries customer outcomes without company names. The cited record contains no named reference customer and no revenue figure.

Pricing Model Oasis does not publish pricing, so the charged unit and list price stay private…

Oasis does not publish pricing, so the charged unit and list price stay private. GitGuardian records only enterprise-tier pricing for commercial SaaS, and the reviewed pages route prospects to a demo request, which signals a vendor targeting large negotiated deals rather than self-serve adoption. The absence withholds the budget-anchoring signal some peers publish.

The two product lines suggest two value meters. The core non-human identity platform reads as a subscription scaled to the size of the identity estate under management, while Agentic Access Management reads as a per-agent or per-session access charge, given the ephemeral identities it issues. This is an inference from the delivery mechanics rather than a disclosed model, and the cited record does not state which unit Oasis bills by.

The inferable belief is that buyers pay to govern the machine and agent estate rather than for discrete features. Confirming the billing unit and whether agentic usage is metered separately would require a sales conversation, which the hidden-price posture signals is the intended path.

Product Delivery & Operations Oasis delivers as hosted software, which GitGuardian's roundup records as commercial SaaS priced at the enterprise tier…

Oasis delivers as hosted software, which GitGuardian's roundup records as commercial SaaS priced at the enterprise tier. SiliconANGLE describes the platform integrating with cloud providers, identity systems, and application environments to inventory machine identities and map their relationships to resources and privileges. The product page claims that connection produces a comprehensive inventory within minutes, a vendor assertion no independent source in this record tests.

Lifecycle and governance run continuously once connected. The platform analyzes authentication patterns, credential usage, and permission scopes to build a continuously updated view, then orchestrates rotation, least-privilege enforcement, and anomaly alerting, which gives a security team an operating console for machine-identity risk rather than a one-time scan.

Agentic Access Management changes the operational risk profile. A component that issues the short-lived per-session identities agents authenticate through sits in the access path, where availability and latency affect whether agents can act, and the cited record documents neither service-level commitments nor failure modes, the evidence a careful review requests before routing production agents through it.

Earning Customers' Trust Oasis displays the baseline attestations an enterprise buyer expects…

Oasis displays the baseline attestations an enterprise buyer expects. The homepage footer serves a SOC 2 badge and an ISO 27001 badge from the company content domain, with the badge images carrying SOC 2 and ISO 27001 alt text in the served page. Those place Oasis level with the category on baseline assurance rather than behind it.

What is missing is the inspectable layer above the badges. The trust subdomain does not resolve, and the cited record contains no downloadable SOC 2 report or ISO certificate. For a platform that holds an inventory of the credentials and agent identities in a customer's environment, the cited record does not make the underlying reports inspectable, so a buyer may need to request them from Oasis.

The pending Cyera transaction adds a diligence item rather than removing one. Reporting says Oasis will run as an independent unit once the deal closes, which leaves open where a customer's identity inventory sits and under whose data-handling terms after close. A buyer should resolve retention, residency, and failure-mode terms in a formal review that goes beyond the published seals.

Platform Strategy & Ecosystem Positioning Oasis positions itself as the governance layer legacy identity providers do not cover…

Oasis positions itself as the governance layer legacy identity providers do not cover. It connects with cloud providers, identity systems, and application environments to build a unified view of non-human identities, and the why-Oasis page rests the claim on a policy-based infrastructure-agnostic control plane that automates the lifecycle, so the platform bet is to own that view and the policy engine across a hybrid estate.

Agentic Access Management extends that bet into the access path. By issuing the per-session identities agents authenticate through, Oasis moves from observing identities to provisioning them, which is the sharper platform position because dependent agent workflows would have to be re-plumbed to remove it, though the cited record offers only an anonymous vendor-published testimonial and names no customer whose production agents run on the session-identity path.

The Cyera transaction relocates that bet rather than settling it. Cyera classifies enterprise data, and its stated rationale for buying Oasis is to govern what touches that data from one control point, which pairs the inventory Oasis holds with the data map Cyera holds. The same ground stays contested by the identity systems Oasis integrates with, which reach the same buyer natively.

Team & Execution Capability Oasis rests on two publicly identifiable founders with a documented military intelligence background…

Oasis rests on two publicly identifiable founders with a documented military intelligence background. Reporting on the Cyera transaction names Danny Brickman and Amit Zimerman as the pair who started the company in 2022 and identifies both as alumni of Israeli military intelligence Unit 81, and the launch release names the same two founders. The about page lists Brickman as co-founder and chief executive and Zimerman as co-founder and chief product officer. The cited record documents no prior exit for either founder.

The leadership bench below the founders is now named on the about page, which lists roles across sales, product, research and development, operations, customer success, finance, and technology. Individual prior builds for those leaders do not appear in the cited record, so the page evidences breadth of function rather than depth of track record.

Investors and an acquirer have both priced this team. Craft Ventures led the March 2026 Series B with returning investors Cyberstarts, Sequoia Capital, and Accel, and four months later Cyera signed a letter of intent to buy the company for about $1 billion. That sequence says more about how the market reads this team than any single credential the founders hold.

Sources

Company Detail Sources (5)
Id Source Tier Accessed
f1 Oasis Security: Non Human Identity Management Platform official 2026-07-09
f2 SecurityWeek on the Oasis Series B press 2026-06-29
f3 AI Defense Matrix Catalog entry other 2026-06-07
f4 AI Defense Matrix Catalog mapping other 2026-06-23
f5 Oasis NHI Security Cloud product overview official 2026-06-12
Profile Analysis Sources (17)
Id Source Tier Accessed
s1 Oasis Security homepage with customer outcomes
“Fortune-50 healthcare provider eliminated a critical exposure, avoiding a $3-5 M HIPAA breach fine. Fortune-500 logistics company cut secret-rotation effort by 35 %.”
official 2026-06-29
s2 Oasis non-human identity management platform product overview
“Oasis drives Lifecycle Management end-to-end. Provisioning, Ownership Assignment, Vaulting, Posture, Rotation, Decomission.”
official 2026-06-29
s3 Oasis Agentic Access Management product page
“Issue ephemeral, per-session identities; eliminating standing privileges and minimizing blast radius. AAM links every action to a clear trail: Prompt, Intent, Policy, Session, Action.”
official 2026-06-29
s4 Why Oasis differentiators page
“Thanks to its policy-based infrastructure-agnostic control plane Oasis automates the NHI lifecycle without compromising developer experience. NHIs represent 20 to 50x more identities growing at 20% YoY.”
official 2026-06-29
s5 Oasis about and leadership page
“Danny Brickman Co-founder & CEO. Amit Zimerman Co-founder & CPO. Barak Shelef Chief Architect. Yonit Glozshtein VP of Product.”
official 2026-06-29
s6 Oasis newsroom listing the Zscaler integration and GuidePoint partnership
“Oasis Security Announces Integration with Zscaler to Extend Zero Trust to Non-Human and Agentic Identities. New integration delivers a single control plane for non-human identities and AI agents, combining Oasis' identity governance with inline enforcement across Zscaler's Zero Trust Exchange.”
official 2026-06-29
s7 SecurityWeek on the Oasis Series B
“raising $120 million in a Series B funding round that brings the total raised by the company to $195 million. The fresh investment round was led by Craft Ventures, with additional support from previous investors Cyberstarts, Sequoia Capital, and Accel.”
press 2026-06-29
s8 SiliconANGLE on the Series B (founders and platform mechanics)
“Founded in 2022 by Danny Brickman and Ami Timarman, both previous members of Israeli Intelligence Unit 81. The platform includes support for the automated discovery of machine identities, classification based on role and usage and policy-driven governance for credential rotation and access control.”
press 2026-06-29
s9 CTech on the Series A extension and valuation
“the team has supported a rapidly expanding customer base, including several Fortune 500 companies, with a straightforward solution that delivers immediate value.”
press 2026-06-29
s10 CTech on the DeCesare appointment
“DeCesare previously served as CEO of Forescout Technologies, which was founded by Israelis and sold in 2020. The appointment comes after a year in which Oasis reported rapid expansion, including a fivefold increase in annual revenue.”
press 2026-06-29
s11 SecurityWeek on the Series A extension
“$35 million in a Series A extension round that brings the total raised by the company to $75 million”
press 2026-06-29
s12 Dark Reading on the Oasis AuthQuake research disclosure
“The researchers achieved the bypass, which they dubbed AuthQuake. Oasis informed Microsoft of the issue, which acknowledged its existence in June and fixed it permanently by Oct. 9, the researchers said.”
press 2026-06-29
s13 CB Insights profile and ESP placement for Oasis
“Founded Year 2022. Stage Series B | Alive. Total Raised $195M. Oasis named as Challenger among 15 other companies, including SailPoint, Saviynt, and HashiCorp.”
research 2026-06-29
s14 SEC EDGAR full-text search showing a Form D for an Oasis-named entity
“Inflection Ventures Oasis Security Fund I LLC (CIK 0002132124), form D, file_date 2026-06-16, biz_locations Newark, DE, inc_states DE.”
regulatory 2026-07-02
s15 GitGuardian: Top 10 Non-Human Identity Security Tools and Platforms for 2026
“4) Oasis Security. Pros: Focused NHI security approach. Strong multi-environment discovery. Cons: Oasis Security's exposure detection features may not be as deep or specialized as dedicated secret-scanning vendors.”
research 2026-06-29
s16 Oasis Security homepage footer attestation badges (SOC 2, ISO 27001)
“Footer serves SOC2.avif with alt SOC 2 compliance badge and ISO.avif with alt ISO 27001 certification logo, both from the Oasis content domain.”
official 2026-06-29
s17 Oasis trust center probe (trust subdomain does not resolve; security and trust paths return 404)
“The trust and security subdomains do not resolve and the security, trust, and compliance paths return HTTP 404, so no public trust center or downloadable report is reachable.”
official 2026-06-29
Deep-Dive Sources (12)
Id Source Tier Accessed
s1 Oasis NHI Security Cloud product overview
“We came out of that meeting and it was like: this is a bigger issue for us than we ever thought. 17,000+ non-human identities in our cloud environment and we had no idea. Oasis gave us visibility we simply didn’t have before. That alone made it a no-brainer.”
official 2026-08-07
s2 Oasis Agentic Access Management product page (session identities, chain of custody)
“Each request runs on a short-lived, least-privilege identity. No standing privilege, no long-lived tokens, no hard-coded secrets, reducing blast radius.”
official 2026-08-07
s3 Why Oasis differentiators page (control plane, NHI scale)
“Thanks to its policy-based infrastructure-agnostic control plane Oasis automates the NHI lifecycle without compromising developer experience.”
official 2026-08-07
s4 Oasis about and leadership page
“Oasis leverages advanced AI-based analytics to automatically discover NHIs, assess their risk, and identify their owners throughout the environment.”
official 2026-08-07
s5 GitGuardian: Top 10 Non-Human Identity Security Tools and Platforms for 2026
“Oasis Security's exposure detection features may not be as deep or specialized as dedicated secret-scanning vendors. So, potential customers might prefer other options.”
research 2026-08-07
s6 SecurityWeek on the Oasis Series B (funding and investors)
“raising $120 million in a Series B funding round that brings the total raised by the company to $195 million. The fresh investment round was led by Craft Ventures, with additional support from previous investors Cyberstarts, Sequoia Capital, and Accel.”
press 2026-08-07
s7 SiliconANGLE on the Series B (platform mechanics)
“The platform includes support for the automated discovery of machine identities, classification based on role and usage and policy-driven governance for credential rotation and access control.”
press 2026-08-07
s8 Oasis Agentic Access Management launch release on PR Newswire
“Just-in-Time (JIT) Session Identities: Automatically provisions ephemeral, least-privilege credentials for seconds-to-minutes sessions, eliminates standing secrets, and captures full audit trails of person, prompt, policy, actions, and teardown.”
press 2026-08-07
s9 Oasis homepage (attestation badges, customer outcome claims)
“ISO 27001 certification logo demonstrating Oasis Security’s commitment to security standards”
official 2026-08-07
s10 Oasis trust center probe (trust subdomain does not resolve)
“The trust subdomain does not resolve, so no public trust center or downloadable attestation report is reachable at this address.”
official 2026-08-07
s11 TechCrunch on Cyera signing a letter of intent to acquire Oasis Security
“Data security company Cyera, which recently raised $600 million at a $12 billion valuation, announced Tuesday that it signed a letter of intent to acquire Oasis Security for approximately $1 billion in a deal expected to be paid mostly in cash, with the remainder in Cyera shares.”
press 2026-08-07
s12 SiliconANGLE on the Cyera agreement to buy Oasis Security
“Globes reported that the two have signed a letter of intent and that Oasis will run as an independent unit inside Cyera once the deal closes.”
press 2026-08-07

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.