Oso

Security for AI Identity AccessDeveloper Tools also known as Oso Security, Inc.

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2018
Last updated 2026-08-09

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Oso spent seven years building developer authorization. Its Oso Cloud service and Polar policy language let engineering teams at Duolingo, Intercom, and Productboard decide who can do what inside an application. Its agent line now documents enforcement, not only watching: rules that block a tool call, hold it for user or security approval, and apply centrally at the network level. Oso Cloud has the longer public record, and its Polar policies and authorization checks are integrated into customer applications. Replacing that takes work, though the record does not size it. The agent product is thinner ground, because its mechanism is documented interception and a rule builder, and the record does not establish that identity or cloud platforms match it. Watch who adopts the enforcement.

Sourced Details

Description Oso is an authorization company. Its Oso Cloud service and Polar policy language give developers fine-grained access control for applications, and its Oso for Agents line discovers and monitors the AI agents employees run and enforces policies that block or hold their tool calls. [f1]
Founded 2018 [f2]
HQ New York, NY [f2]
Latest funding Series B, $15 million, June 2023, led by Felicis Ventures [f3]

Products

Product What it does
Oso Cloud Centralized authorization service built on the Polar policy language, providing fine-grained access control (RBAC, ReBAC, ABAC) to applications through APIs and SDKs.
Oso for Agents Discovers AI agents across endpoints and browsers, monitors agent sessions, alerts on sensitive data, and enforces policies that block a tool call or hold it for approval.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Oso for Agents discovers AI agents across endpoints and browsers, monitors agent sessions through an edge proxy, and alerts on unsanctioned usage and sensitive data. These capabilities are mapped to the AI Defense Matrix. [f4]

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Oso Cloud enforces fine-grained authorization for applications, deciding which actions each user or service may perform against an application's resources. It is mapped to the Cyber Defense Matrix. [f5]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 26 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Authorization is a clearly defined problem, and The New Stack notes that broken access control tops OWASP's Top 10 web application security risks (s8), which grounds it independently. The agent version of the problem is quantified mainly by Oso's own research with Cyera, which reports 96 percent of enterprise permissions going unused (s15), so the agent-specific pain is vendor-measured rather than independently established (s3). [s8, s15, s3]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 Oso Cloud rests on the purpose-built Polar language and a documented engine applications call over HTTP or an SDK (s2), the open-source library that built its following had been downloaded millions of times by Neray's account to TechCrunch (s7), and The New Stack covered the authorization approach independently (s8). The agent line documents enforcement and the interception that carries it (s16, s17), but no third party has published an evaluation of that product. [s2, s7, s8, s16, s17]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The enabler is the rise of AI coding agents holding real access to systems, which The New Stack documented in July 2025 as a new authorization risk (s8) and which Oso answers with a product that now blocks or holds agent tool calls centrally (s3, s16). Buyer-side demand is still indirect, evidenced by Oso's own research with Cyera rather than by independent measurement (s15). [s8, s3, s16, s15]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 Co-founders Graham Neray and Samuel Scott appear on the SEC Form D and in press since 2021 (s12, s6), Neray is chief executive with Nick Kucharski as chief technology officer and a named bench across sales, marketing, and operations (s5), and Oso publishes an Authorization Academy (s1). The cited sources document no prior founder exit and report a small team (s7), keeping this at verifiable experience rather than a category-defining record. [s12, s6, s5, s1, s7]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 Oso's homepage carries a customer logo wall naming Verizon, Visa, Duolingo, and Productboard, plus signed endorsements from leaders at Roblox and Brex (s1), and TechCrunch reported product-led growth with Oso Cloud's recurring revenue rising 20 percent month over month in 2023 (s7). No third party reports revenue scale, and every published agent plan routes through a demo booking (s4), which holds this below the top rung. [s1, s7, s4]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 Oso raised an $8.2 million Series A led by Sequoia in 2021 and a $15 million Series B led by Felicis in 2023, which TechCrunch put at over $25 million raised in total (s6, s7). The capital pairs with a lean team and an inbound motion, but efficiency itself is unconfirmed because Oso discloses no revenue and its one growth figure dates to 2023 (s7). [s6, s7]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Authorization as a service is a category buyers can place, but the field has not consolidated, with several competing policy languages and managed services (s13). Oso's second line, securing the AI agents employees run, sits in a category still being named, and Oso sells it through a demo booking and a meeting with the chief executive (s3, s4). [s13, s3, s4]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 The Polar policies a customer writes and the API calls into Oso Cloud create friction, but identity providers and cloud vendors already ship competing fine-grained authorization, including AWS Verified Permissions and Auth0 and Okta's FGA (s13), so the core value is being matched by adjacent platforms rather than protected by a structural barrier. The agent enforcement is newer, and the cited record does not show those platforms offering the same central blocking of agent tool calls (s16). [s13, s16, s2]
Business Risks AWS, Okta, or another platform the buyer already owns could make fine-grained authorization a native feature, turning Oso's standalone engine into a checkbox before the field consolidates…
  • AWS, Okta, or another platform the buyer already owns could make fine-grained authorization a native feature, turning Oso's standalone engine into a checkbox before the field consolidates.
  • Oso's agent enforcement is documented but unproven in the public record, so a buyer has no independent account of how blocking and approval holds behave against real agent traffic.
  • Oso's traction figures are vendor-stated and dated to 2023, so a growth stall would stay invisible in the public record until it surfaced in hiring or the terms of a next raise.
  • The open-source library that built Oso's following is now deprecated, so the developer mindshare it generated could erode if paid Oso Cloud does not carry that community forward.
  • Sitting between employee agents and the models they call puts Oso in the live path, where added latency or a block that fires wrongly becomes a production problem rather than a missed alert.
  • If enterprises standardize agent controls on the identity providers they already own, Oso's per-agent layer could become optional middleware.
Problem & Market Oso sells authorization, the layer that decides what a logged-in user or service is allowed to do inside an application…

Oso sells authorization, the layer that decides what a logged-in user or service is allowed to do inside an application. The company separates this from authentication, the login step that identity providers like Okta already handle, and argues that developers have long been forced to build fine-grained access control by hand. The New Stack notes that broken access control tops OWASP's Top 10 web application security risks, which grounds the problem independently of Oso's marketing.

Oso now frames the same problem around AI agents, which take on the access a person holds and act on it far faster than a person can. Its own research with Cyera, the Least Privilege Report 2026, is the headline evidence, reporting that 96 percent of enterprise permissions go unused. That figure is vendor research rather than an independent measurement, so the agent-specific pain is asserted more than it is independently quantified. Neray's argument to The New Stack is sharper than the statistic: companies accept a degree of over-permissioning because a human has a finite limit on the time and resources available to do damage, and an agent does not.

The buyer has historically been the engineering leader who owns an application's access model, which fits Oso's developer-first, inbound motion. The agent framing widens that to the security team now accountable for the AI agents employees run, and Oso's account of why it turned to them is that seven years of building permissions for humans showed why those models fail for agents. What Oso offers that team is no longer observation alone but rules that block an agent's tool call or hold it for approval. [s8, s15, s5, s3]

Product Capabilities Oso Cloud is a centralized authorization service built on Polar, a logic programming language Oso created for expressing permission systems, running over SQLite…

Oso Cloud is a centralized authorization service built on Polar, a logic programming language Oso created for expressing permission systems, running over SQLite. Polar can model role-based, relationship-based, and attribute-based access control, and applications query Oso Cloud over HTTP or an SDK to get back a boolean, a list, or logic to run against their own database. Oso backs the engine with extensive public documentation and an open-source library that first built its following, which Neray told TechCrunch had been downloaded millions of times. That library is now deprecated, though Oso says it will keep providing support and critical bug fixes.

Oso for Agents extends the company into securing the AI coding agents employees run on their own devices, and it covers both watching them and stopping them. Oso inventories the agents running across endpoints and browsers, captures every prompt, completion, and tool call in a session, and alerts on unsanctioned agents or sensitive data. Its policy documentation then defines what happens next: a rule can alert the team, block the call outright, or hold it until the end user or the security team approves it, enforced centrally at the network level.

The mechanism behind that enforcement is documented as well. Oso sits between the agents and the models they talk to, installing process hooks distributed through the buyer's device management, routing agents that accept a custom model endpoint through its own proxy, and capturing web-based agents with a browser extension. One limit is stated plainly. When a rule matches content in a tool's response, the call has already run, so blocking redacts the response rather than preventing the action.

External validation is strongest for the core authorization work and thinnest for the agent line. The New Stack covered Oso's fine-grained authorization approach and its automated-least-privilege argument for AI. An independent comparison of authorization policy languages documents a crowded field, with managed services from AWS's Cedar, Auth0 and Okta's OpenFGA, and Cerbos, the same market Oso's Polar sells into, and that comparison does not mention Oso at all. A third-party catalog lists Oso as an active SaaS product and describes its agent discovery, monitoring, and alerting, but no third party in the cited record has evaluated the enforcement Oso documents. [s2, s7, s14, s3, s16, s17, s8, s13, s9]

Competitive Positioning Oso competes in fine-grained application authorization, a field that has not settled on a standard…

Oso competes in fine-grained application authorization, a field that has not settled on a standard. An independent comparison documents several purpose-built policy languages and managed services, including AWS's Cedar and Verified Permissions, Auth0 and Okta's OpenFGA, and Cerbos. Oso's differentiation is the Polar language and a hosted engine that answers authorization questions against a customer's own data.

Identity providers and cloud vendors are adjacent competitors. AWS Verified Permissions and Okta's FGA have shipped fine-grained authorization to the same developers Oso sells to. Oso's counter is its dedicated Polar language and hosted engine.

The move into agent security opens a second front against many of the same players, because governing what an agent may do is ground the identity providers and cloud vendors that already ship authorization can also occupy. What Oso has that the cited comparison does not attribute to them is a documented way to stop an agent mid-action, blocking a tool call or holding it for approval from a central point in the network. Oso's bet is that a company already governing human and service access will want one place to govern agents too, which keeps its core relevant as buying shifts toward agents. [s13, s3, s16, s1]

Go-to-Market & Traction Oso shows real customer traction for its core product…

Oso shows real customer traction for its core product. Its homepage carries a logo wall naming Verizon, Visa, Duolingo, PagerDuty, Productboard, and others, and it publishes signed endorsements from the infrastructure lead at Roblox and the chief information security officer at Brex. The motion has been product-led and inbound. Neray told TechCrunch in 2023 that the company grew without outbound sales and had no salespeople at the time, and that Oso Cloud's recurring revenue was rising 20 percent month over month.

The agent product is sold differently. Its published plans run from a free Developer tier for three users to a Growth tier at $15 per user per month for twenty-five, then to a custom Enterprise tier that adds data residency, on-premises deployment, and around-the-clock support. Every one of those tiers routes through a demo booking, and the documentation says access is arranged by meeting the chief executive, so the published prices set expectations rather than close a sale. Pricing counts humans who invoke agents, not agents, with no cap on the agents behind one user.

Oso raised an $8.2 million Series A led by Sequoia in 2021 and a $15 million Series B led by Felicis in 2023, which TechCrunch reported as over $25 million raised in total, a figure Neray said meant no other authorization company had raised more at that point. On that capital and a small team, Oso grew through inbound demand and its open-source following, though it discloses no revenue and the one growth figure it has shared dates to 2023, so capital efficiency stays unconfirmed. Independent records corroborate the company's footing: TechCrunch covered both rounds, and Oso Security Inc. filed a Form D with the SEC for an earlier raise, a regulatory record listing founders Graham Neray and Samuel Scott and a 2018 incorporation in Delaware. [s1, s7, s4, s3, s6, s12]

Team & Credibility Oso rests on two publicly identifiable co-founders…

Oso rests on two publicly identifiable co-founders. TechCrunch identifies Graham Neray and Samuel Scott as co-founders, the company's SEC Form D lists both as executive officers and directors alongside a 2018 incorporation, and Neray is chief executive today. Leadership has changed below him: TechCrunch identified Scott as chief technology officer in 2021, and the company now lists Nick Kucharski in that role. The record documents no prior exit, so what they have built at Oso since 2018 is the main evidence of their ability.

The team has built a body of authorization content. Oso publishes an Authorization Academy of technical guides on application authorization, and Neray argues the case in the technical press that permissions built for humans break once an agent inherits them. That publication record is a real but modest signal, one educational resource rather than a category-defining reputation.

The company has been small, which is part of the story. TechCrunch reported nine employees in 2021 and 13 in 2023, a lean headcount for a company with Oso's customer list. The about page now names a bench beyond the founders covering sales, marketing, operations, and a founding engineer, so the leadership surface is wider than it was, though public detail on those backgrounds is thin. [s12, s6, s5, s1, s7, s8]

Trust Readiness Oso publishes the baseline assurance an enterprise buyer expects…

Oso publishes the baseline assurance an enterprise buyer expects. The company announced SOC 2 certification in a 2023 post, and its security page states that Oso is SOC 2 certified, describes encryption of customer data in transit and on disk, and says production releases go through peer review. Both statements come from Oso's own pages rather than from a published report.

Access to the underlying documents is indirect. The security page points buyers to a Vanta-hosted trust center for compliance reports and policies rather than publishing them on the page itself, and the cited page does not state the trust center's access terms. That matters more here than for a passive tool. Oso Cloud sits on an application's authorization path, and the agent product records every prompt and tool call and can block or redact them, so confirming data-handling terms and failure behavior belongs in the evaluation rather than after it. [s10, s11, s2, s16, s17]

Competitors Okta, Amazon Web Services, Cerbos…
Company Relationship Note Compare
Okta adjacent Identity incumbent adjacent to the same developers. Its Auth0 and Okta FGA, built on OpenFGA, ship fine-grained authorization natively. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Amazon Web Services adjacent Ships Cedar and AWS Verified Permissions, a managed fine-grained authorization service reaching the same developers Oso sells to. N/AAmazon Web Services is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product.
Cerbos competes with Authorization vendor offering a competing policy language and a managed hub in the same fine-grained authorization field.

Add analyzed competitors to compare them side by side with Oso.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 13 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Oso's closest thing to durability is the authorization its customers build around Oso Cloud. They write rules in the Polar language and thread access checks through their code, so leaving means re-implementing authorization, friction the record documents without sizing. The agent line now documents enforcement, blocking tool calls and holding them for user or security approval centrally at the network level, which puts Oso in the live path rather than beside it. The mechanism is still documented interception and a rule builder a funded rival could rebuild. Polar's language and behavior are public, an earlier engine shipped as open source, the record names no proprietary dataset, and its SOC 2 is table stakes.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Oso delivers a hosted software product that customers configure and integrate, an authorization service and an agent product priced per user whose enforcement is a feature the buyer configures, and the sources show no human-operated managed security service or liability-bearing accountability layer.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 The cited record documents authorization rules written in the Polar language and access checks threaded through the customer's own application code, so a departing customer re-implements those checks against another engine. The agent line adds endpoint hooks, a proxy, and a browser extension, which are deployment steps rather than rewrites. The cited record documents the mechanism but does not size the exit, so the documented case is meaningful friction, not a genuinely expensive migration.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Oso states a SOC 2 certification, table stakes for enterprise sale, with no regulatory mandate or certification that raises a barrier rivals cannot clear.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Fine-grained authorization across distributed applications is hard engineering, and Oso's homepage claims under 10ms p90 latency on the critical path, which is why Oso built a purpose-built logic language and a dedicated evaluation engine, and the agent line adds inline interception that must decide whether to block or hold a call while the agent waits.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 Oso grew bottom-up with engineering teams through the product-led, inbound motion TechCrunch reported for Oso Cloud, and its agent product publishes a free Developer tier while routing every published plan through a demo booking and its documentation through a meeting with the chief executive. What the cited record documents is a mixed motion, part self-serve entry and part sales-led conversation.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 3/3 Oso Cloud sits on the critical authorization path, answering the access questions applications delegate to it, so removing it breaks an application's ability to answer who can do what. The agent line now sits between an employee's agent and the model it calls, where a rule can block or hold the tool calls that agent makes.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 Polar is documented and the open-source library that carried an earlier engine is public, now deprecated (s14), Oso Cloud's language and APIs are documented (s2), and no named non-public dataset compounds an advantage, so a funded rival could reproduce the assets.
Strategic Market Segmentation Oso sells to the team that owns an application's access model…

Oso sells to the team that owns an application's access model. Historically that is the engineering leader who must decide what each user or service can do inside the product, which fits the product-led, inbound motion Oso's chief executive described to TechCrunch in 2023, when Oso Cloud's revenue was growing without outbound sales. The current pricing page publishes a free Developer tier capped at three users, but that page prices Oso for Agents rather than Oso Cloud, so it evidences the agent line's entry motion and not the historical developer one. The company positions authorization as distinct from the login step identity providers handle.

The agent line points at the security team inheriting AI agents. Oso argues that access models built for humans do not fit agents, which take on broad human-scale permissions and act at machine speed, so the buyer becomes whoever is accountable for the agents employees run. That buyer is now offered enforcement rather than observation alone, and the documentation routes access through a meeting with the chief executive, so the agent motion reaches its buyer through a conversation rather than a signup.

Product Capabilities & AI Advantages The core capability is a hosted authorization engine driven by a purpose-built language…

The core capability is a hosted authorization engine driven by a purpose-built language. Applications send an authorization question to Oso Cloud over HTTP or an SDK, and the service evaluates it against policies written in Polar and customer-provided authorization facts, returning an allow-or-deny decision or a filtered list. Polar can express role-based, relationship-based, and attribute-based models.

The agent capability now spans observation and enforcement. Oso for Agents inventories agents across endpoints, browsers, and network traffic, captures every prompt, completion, and tool call in a session, and alerts on unsanctioned agents or sensitive content. Its policy documentation defines rules that match an actor, an operation, and a resource, then respond by alerting, blocking the call outright, or holding it for user or security approval, applied centrally at the network level. One documented limit is worth naming: when a rule matches content in a tool's response, the call has already run, so blocking redacts the response instead of preventing the action.

The engineering is real but reproducible. The New Stack covered Oso's fine-grained authorization approach, and the field it competes in already holds several purpose-built languages and managed services, from AWS's Cedar to Auth0 and Okta's OpenFGA and Cerbos. Polar's language and Oso Cloud's APIs are publicly documented, a now-deprecated open-source library carried an earlier engine, and the agent line's own mechanism is documented interception plus a condition-and-response rule builder, so the record shows no unique asset a rival would have to license, though rebuilding either service would take real work.

Sales Engagement & Go-to-Market Oso built its growth on a product-led, inbound motion…

Oso built its growth on a product-led, inbound motion. Neray told TechCrunch in 2023 that the company grew without outbound sales and that Oso Cloud's recurring revenue was rising 20 percent month over month, and that motion produced named reference customers, including Duolingo, Intercom, and Productboard. The agent product runs on a different motion, because every published plan calls for booking a demo and the documentation says access is arranged by meeting the chief executive.

Pricing is per user, defined as a human who invokes agents, with no limit on the agents each user runs. The published plans start at a free Developer tier capped at three users, rise to a Growth tier at fifteen dollars per user per month capped at twenty-five, and reach a custom Enterprise tier, which keeps the entry price low while pushing any real deployment into a negotiation.

The verifiable traction is the named customers and the funding history, not independently reported scale. TechCrunch covered the 2021 Series A and the 2023 round, Oso Security Inc. filed a Form D with the SEC, and the homepage now carries agent-era endorsements from leaders at Roblox and Brex alongside its earlier developer testimonials. The cited coverage still relays company-provided growth figures rather than independently verified revenue or customer counts.

Pricing Model The Oso for Agents pricing page charges per user and publishes a free Developer tier, while Oso Cloud's pricing model is not published there…

The Oso for Agents pricing page charges per user and publishes a free Developer tier, while Oso Cloud's pricing model is not published there. It defines a user as a human who invokes agents, with no limit on the number of agents per user, which signals that Oso wants to price by the people directing agents rather than by agent volume.

The tiers gate capability as well as headcount. The free Developer tier carries the audit trail and default alerts for three users, the Growth tier at fifteen dollars per user adds leak and risky-tool detection for twenty-five, and Enterprise adds SIEM export, data residency, on-premises deployment, and a custom user count. Every tier routes through a demo booking, so the published numbers set expectations rather than close a sale. The per-user meter also raises a question every agent-era vendor faces, because usage driven by many agents under one human user may not track the value delivered.

Product Delivery & Operations Oso Cloud is delivered as a hosted service on the application's authorization path…

Oso Cloud is delivered as a hosted service on the application's authorization path. Applications call its APIs to answer authorization questions, so availability and latency are core to the product, and the documentation also describes local and hybrid deployment options that keep decisions closer to the application.

Oso for Agents sits between agents and the models they call. It captures traffic through process hooks pushed to endpoints by mobile device management, a network proxy for agents that accept a custom model endpoint, and a browser extension for web-based agents, and it attributes each session to a user, a group synced from an identity provider, and a device correlated with the buyer's endpoint detection inventory. Because a policy can block a call or hold it pending approval, adoption puts Oso in the live path of employee agent traffic rather than beside it, which raises what a buyer should ask about latency and failure behavior and raises what the product can change.

Earning Customers' Trust Oso publishes the baseline assurance enterprise buyers expect…

Oso publishes the baseline assurance enterprise buyers expect. It announced SOC 2 certification in 2023, and its security page states that Oso is SOC 2 certified and describes customer data isolation, encryption in transit and at rest, enforced two-factor authentication, and peer-reviewed production change control.

Access to the underlying documents is indirect. The security page points buyers to a Vanta-hosted trust center for compliance reports and policies, and that trust center failed to load during the fetch recorded here, which leaves self-service access unconfirmed in this record rather than ruled out. A buyer should retry the trust center and, if it still does not load, ask Oso for the SOC 2 report directly. For a service on the authorization path that, in the agent line, records prompts and tool calls and can block or redact them, confirming data-handling terms matters before adoption.

Platform Strategy & Ecosystem Positioning Oso's platform bet is to be the one place a company expresses authorization…

Oso's platform bet is to be the one place a company expresses authorization. Oso Cloud centralizes access logic that would otherwise scatter across services, and the pitch is that engineering and security teams manage one policy engine rather than many hand-built checks.

The agent line extends the pitch to non-human callers, and it now enforces rather than only reports. The two lines remain separate in the fetched record, because the agent product's rules are built from actor, operation, and resource conditions rather than written in Polar, and the documentation does not say the agent product runs on the Oso Cloud engine, so the shared-engine thesis is positioning rather than documented architecture.

The exposure is that identity providers and cloud vendors offer competing managed authorization services and policy engines, from AWS's Cedar-based Verified Permissions to Okta's FGA. The comparison this record cites treats those engines as alternatives that differ in syntax, performance, formal verification support, and tooling rather than as drop-in equivalents, so the competitive question is which model fits a given application.

Team & Execution Capability Oso rests on two identifiable co-founders…

Oso rests on two identifiable co-founders. TechCrunch identifies Graham Neray and Samuel Scott as co-founders, the company's SEC Form D lists both and a 2018 incorporation, and Neray is chief executive today. TechCrunch identified Scott as chief technology officer in 2021, and the company now lists Nick Kucharski in that role. The record documents no prior exit.

The team publishes technical content and was small at its last reported counts. TechCrunch reported nine employees in 2021 and 13 in 2023, and Oso maintains an Authorization Academy of guides on application authorization. That lean headcount fits the capital-efficient read, and the about page now names a bench beyond the founders that covers sales, marketing, operations, and a founding engineer, though public detail on their backgrounds is thin.

Sources

Company Detail Sources (5)
Id Source Tier Accessed
f1 Oso for Agents overview documentation official 2026-08-06
f2 TechCrunch: Oso announces $8.2M Series A press 2026-07-04
f3 TechCrunch: Oso sees huge opportunity in simplifying authorization press 2026-07-04
f4 Oso (AI Defense Matrix Catalog) other 2026-07-04
f5 Oso Cloud documentation official 2026-07-04
Profile Analysis Sources (17)
Id Source Tier Accessed
s1 Oso homepage with customer logos and testimonials
“Visibility and controls to secure agents. Logos: Verizon, Visa, Duolingo, PagerDuty, Productboard, Webflow, Wayfair, Brex. Jared Rosoff, VP of Infra, Roblox. Mark Hillick, CISO, Brex. Your employees ignore 96% of their permissions. Authorization Academy.”
official 2026-08-06
s2 Oso Cloud documentation
“Oso Cloud is a centralized authorization service built on Polar, our logic programming language designed for expressing permission systems, and SQLite. RBAC, ReBAC, ABAC. you call our APIs via HTTP or SDKs. a boolean, list, or logic to execute against your database.”
official 2026-08-06
s3 Oso for Agents overview documentation
“Oso captures every prompt, completion, and tool call. Define policies that govern what agents are allowed to do. Block tool calls, require user or security approval, and alert your team - combine these however you need, enforced centrally at the network level. Meet with our CEO to get access.”
official 2026-08-06
s4 Oso for Agents pricing page
“Developer $0 user/mo, 3 users. Growth $15 user/mo, 25 users. Enterprise Custom, Custom # users. Book a demo. Data residency agreement, Cloud or on-prem deployment, 24/7 support. A user is a human invoking agents. There's no limit to the number of agents associated with a single user.”
official 2026-08-06
s5 Oso About Us page with leadership
“Seven years building permissions for humans taught us how and why those models fail for agents. Leadership Team: Graham Neray CEO & Founder, Nick Kucharski CTO, Jerome Deloziere Head of Sales, Meghan Gill Head of Marketing, Marci Teichman Head of Operations, Gabe Jackson Founding Engineer.”
official 2026-08-06
s6 TechCrunch: Oso announces $8.2M Series A
“$8.2 million Series A led by Sequoia. the company, which launched in 2018, has nine employees with plans to triple that over the next 18 months. Neray and co-founder and CTO Sam Scott. created an open-source library for developers to make it easier to build authorization in their applications.”
press 2026-08-06
s7 TechCrunch: Oso Series B, product-led growth
“the open source product, which Neray says has been downloaded millions of times. ARR from that product growing 20% month over month. a $15 million round led by Felicis. over $25 million. just 13 employees so far. we're not doing outbound [sales and marketing]. We don't currently have salespeople.”
press 2026-08-06
s8 The New Stack: Oso Focuses on Fine-Grained Authorization To Thwart AI Risks
“Jul 24th, 2025. Oso advocates the idea of automated least privilege. Broken access control tops the list on OWASP's Top 10 web application security risks. we accept a certain amount of over-permissioning. there's this finite limit on your time or resources as a human to do bad or stupid things.”
press 2026-08-06
s9 Oso (AI Defense Matrix Catalog)
“Discovers shadow AI agents across endpoints and browsers, monitors agent sessions through an edge proxy, and alerts on unsanctioned usage and sensitive data. Deployment: SaaS. Status: Active.”
other 2026-08-06
s10 Oso: Announcing SOC 2 Certification and Fallback
“October 19, 2023. SOC 2 certification declares in concrete terms that you can trust us to be responsible stewards of your data. Oso Fallback is a read-only instance of your Oso Cloud data that you run on your own infrastructure.”
official 2026-08-06
s11 Oso security page (SOC 2 and trust center link)
“Oso is SOC 2 certified. Access our live trust center to review compliance reports, security policies, and monitoring practices powered by Vanta. We use encryption to protect customer data in transit to Oso Cloud and on all disks where data is at rest. We require peer review.”
official 2026-08-06
s12 SEC EDGAR: Oso Security Inc. Form D (CIK 0001775888, signed 2019-05-10)
“entityName Oso Security Inc. previousName Keesh, Inc. jurisdictionOfInc DELAWARE. yearOfInc value 2018. Related persons Graham Neray and Samuel Scott, each Executive Officer and Director. totalAmountSold 2743999. industryGroupType Other Technology. signatureDate 2019-05-10.”
regulatory 2026-08-06
s13 sph.sh: Cedar vs Rego vs OpenFGA policy language comparison
“Cedar is a declarative policy language developed by Amazon. Managed services: Cedar with AWS Verified Permissions, Rego with Open Policy Agent, OpenFGA DSL with Auth0/Okta FGA, Cerbos YAML/CEL with Cerbos Hub. Open source: Cedar SDK, OPA, OpenFGA, Cerbos PDP.”
research 2026-08-06
s14 GitHub: osohq/oso open-source library (deprecated)
“Deprecated: See README. We have deprecated the legacy Oso open source library. we are not end-of-lifing (EOL) the library and we'll continue to provide support and critical bug fixes.”
official 2026-08-06
s15 Oso Least Privilege Report 2026 (Oso x Cyera)
“Least Privilege Report 2026 [Oso x Cyera]. 96% of Enterprise Permissions Go Unused. New research analyzing 2.4 million workers and 3.6 billion permissions.”
official 2026-08-06
s16 Oso for Agents policies documentation
“Block: prevents the call. Require user approval: pause until the end user allows or denies it. Require security approval: block until your security team grants a one-time exception. the call has already run by the time it's scanned, so Block instead redacts the response.”
official 2026-08-06
s17 Oso for Agents architecture documentation
“Oso sits between AI agents and the models they talk to. Oso installs hooks that intercept requests at the agent process level, through your MDM. Agents supporting custom LLM base URLs route traffic through agents.osohq.cloud. The Oso browser extension captures session content.”
official 2026-08-06
Deep-Dive Sources (16)
Id Source Tier Accessed
s1 Oso homepage with customer logos and testimonials
“Visibility and controls to secure agents. Logos: Verizon, Webflow, Wayfair, Visa, Duolingo, PagerDuty, Brex, Oyster, Honeycomb, Productboard, Auditboard, Mastra, Chief. Testimonials: Jared Rosoff, VP of Infra, Roblox. Mark Hillick, CISO, Brex. Brian Scanlan, Engineer, Intercom.”
official 2026-08-06
s2 Oso Cloud documentation
“Oso Cloud is a centralized authorization service built on Polar, our logic programming language designed for expressing permission systems. Polar can express any model, including RBAC, ReBAC, ABAC. When you need to answer an authorization question, you call our APIs via HTTP or SDKs.”
official 2026-08-06
s3 Oso for Agents overview documentation
“Define policies that govern what agents are allowed to do. Block tool calls, require user or security approval, and alert your team - combine these however you need, enforced centrally at the network level. Enabling: Meet with our CEO to get access.”
official 2026-08-06
s4 Oso for Agents pricing page
“Oso for Agents Plans to meet you where you are. Developer $0 user/mo, Book a demo, 3 users. Growth $15 user/mo, Book a demo, 25 users. Enterprise Custom, Book a demo, Custom # users. A user is a human invoking agents. There's no limit to the number of agents associated with a single user.”
official 2026-08-06
s5 Oso About Us page with leadership
“Seven years building permissions for humans taught us how and why those models fail for agents. Leadership Team: Graham Neray CEO & Founder, Nick Kucharski CTO, Jerome Deloziere Head of Sales, Meghan Gill Head of Marketing, Marci Teichman Head of Operations, Gabe Jackson Founding Engineer.”
official 2026-08-06
s6 TechCrunch: Oso announces $8.2M Series A
“the company, which launched in 2018, has nine employees with plans to triple that over the next 18 months. Neray and co-founder and CTO Sam Scott are thinking carefully about how to build a diverse, inclusive and equitable company as they grow.”
press 2026-08-06
s7 TechCrunch: Oso Series B, product-led growth
“the company added Oso Cloud last year with ARR from that product growing 20% month over month. He says they are doing this without any outbound sales to this point. today the company announced a $15 million round led by Felicis. keeping the company lean with just 13 employees so far.”
press 2026-08-06
s8 The New Stack: Oso Focuses on Fine-Grained Authorization To Thwart AI Risks
“Oso advocates the idea of automated least privilege. Confining the LLM's permissions to a user's permissions is one way to scope down access. Broken access control tops the list on OWASP's Top 10 web application security risks.”
press 2026-08-06
s9 Oso (AI Defense Matrix Catalog)
“Discovers shadow AI agents across endpoints and browsers, monitors agent sessions through an edge proxy, and alerts on unsanctioned usage and sensitive data. Deployment: SaaS. Status: Active.”
other 2026-08-06
s10 Oso: Announcing SOC 2 Certification and Fallback
“Today, we're making two announcements that demonstrate our commitment to your trust: SOC 2 certification and Fallback. Oso's SOC 2 certification declares in concrete terms that you can trust us to be responsible stewards of your data. Published: October 19, 2023.”
official 2026-08-06
s11 Oso security page (SOC 2 and trust center link)
“Oso is SOC 2 certified. Access our live trust center to review compliance reports, security policies, and monitoring practices powered by Vanta. We use encryption to protect customer data in transit to Oso Cloud and on all disks where data is at rest.”
official 2026-08-06
s12 SEC EDGAR: Oso Security Inc. Form D (CIK 0001775888, filed 2019)
“entityName Oso Security Inc. previousName Keesh, Inc. jurisdictionOfInc DELAWARE. yearOfInc value 2018. Related persons: Graham Neray, Samuel Scott. totalOfferingAmount 2744000. totalAmountSold 2743999. industryGroupType Other Technology.”
regulatory 2026-08-06
s13 sph.sh: Cedar vs Rego vs OpenFGA policy language comparison
“A deep comparison of Cedar, Rego, OpenFGA DSL, and Cerbos YAML/CEL policy languages: syntax, performance, formal verification, tooling, and TypeScript integration. Cedar is a declarative policy language developed by Amazon and used by AWS Verified Permissions.”
research 2026-08-06
s14 GitHub: osohq/oso open-source library (deprecated)
“GitHub - osohq/oso: Deprecated: See README.”
official 2026-08-06
s15 Oso for Agents policies documentation
“Policies let you control what agents can do. Enforce - restrict the matching call. Block - prevent the call from proceeding. Require user approval - pause until the end user allows or denies it. Require security approval - block until your security team grants a one-time exception.”
official 2026-08-06
s16 Oso for Agents architecture documentation
“Oso sits between AI agents and the models they talk to. By intercepting that traffic - through a combination of hooks, a browser extension, and a network proxy - Oso can see what agents are doing, who is running them, and what data is flowing in and out.”
official 2026-08-06

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.