Service accounts, API keys, OAuth tokens, workload identities, and AI agents now outnumber your people by 45 to 1, and they are the attack surface behind Salesloft/Drift, Snowflake, Storm-0558, and Shai-Hulud. This is the neutral reference for understanding and governing them.
Free to read. Editorially independent. No vendor pays to be profiled.
Four ways in. Every one is free, runs in your browser, and gives you something you can act on, no signup to use them.
Every page either teaches a concept, translates a framework, or dissects a breach. No product funnels. No vendor paywalls. One conversion action on every page: run a free assessment or open the tools.
Definitional pages written to be the neutral reference on NHI, cited, not a sales funnel. What is a non-human identity? What distinguishes it from machine identity and workload identity? How does the lifecycle work? A-Z glossary. Built to be cited, not to sell software.
Browse the library →OWASP NHI Top 10 with a working self-audit. SPIFFE and SPIRE explained without the vendor spin. The IETF WIMSE working group's draft architecture, read and summarised. CSA's program guide. NIS2, DORA, and EU AI Act cross-mapped to NHI controls.
See the frameworks →Every anchor NHI breach, broken down to the attack chain, the root-cause NHI, the timeline, and the specific control that would have prevented it. Salesloft/Drift. Snowflake. Microsoft Storm-0558. Shai-Hulud 2.0. Okta Support. CircleCI. Codecov. Fewer cases, more depth.
Study the breaches →Two hubs that aren't the core pillars, but are where the SEO is wide open and the buyer pain is growing fastest: agentic AI identity, and vendor-neutral buyer guidance.
The fastest-growing NHI category with the thinnest existing coverage. Microsoft Entra Agent ID. SailPoint Agent Identity Security. Model Context Protocol governance. Delegation patterns. Human-in-the-loop controls. This is where enterprise pain is growing fastest and reference-quality writing is thinnest.
Enter the hub →Profiles of Astrix, Oasis, Entro, CyberArk, HashiCorp Vault, and GitGuardian, without paid placement, without "strategic partner" footers, with a clear editorial policy and last-reviewed date on every profile. Compare head-to-head. More vendors added as we review them.
Open the vendor hub →Most organisations sit between stages 1 and 3. That's the honest starting point. The interactive assessment takes about 4 minutes, scores you across 12 control areas, and emails a per-area breakdown with the three highest-leverage remediations for your stage.
| Stage | What it looks like | Typical blast radius of a breach |
|---|---|---|
| 1 · Ad hoc | No inventory. Secrets in code. No offboarding. NHIs created freely without ownership. | Full tenant compromise; months of attacker dwell time |
| 2 · Reactive | Spreadsheet inventory. Some secret scanning. Rotation only after exposure. | Widespread lateral movement through forgotten service accounts |
| 3 · Defined | Centralised secret store. Policy documented. Reviews run annually. Coverage uneven. | Contained to one integration; detection still slow |
| 4 · Managed | Automated rotation. Behavioural monitoring. OAuth review. Continuous evidence. | Detected and revoked within hours; minimal data loss |
| 5 · Optimised | Short-lived credentials as default. Workload identity federation. NHIDR + SOAR. | Identity itself is not reusable; attacks fail by design |
Three tools designed to give you an answer in the browser, not to gate you behind a form. Optional email if you want the full written report.
Score your programme across 12 control areas against a 5-stage model. Get a stage diagnosis and the three highest-leverage next steps.
Walk through all ten OWASP NHI risks and mark Pass / Partial / Fail. Get a coverage percentage and remediation guide.
Test your controls against Salesloft/Drift, Snowflake, Storm-0558, and four more real attack patterns.
Most NHI reference sites list 15+ "strategic partners" in their footer. That is their business model. Ours is different. We are funded by a weekly newsletter sponsored by one partner per issue, disclosed at the top of every email, and by selective affiliate links on specific vendor profile pages, always marked and always next to non-affiliate alternatives. No vendor pays to be profiled here. No vendor reviews or edits our writing. No vendor gets a better placement.
Three free interactive tools for CISOs, IAM directors, cloud security leads, and DevSecOps engineers: a 12-question maturity assessment, the OWASP NHI Top 10 self-audit, and a breach-readiness score. Get your result on-screen, then unlock the full written report by email.
A non-human identity (NHI) is any digital identity that represents a software entity rather than a person, service accounts, API keys, OAuth tokens, cloud IAM roles, Kubernetes service accounts, certificates, SSH keys, workload identities, SaaS-to-SaaS integrations, and the rapidly growing category of AI agents and MCP servers. Full definition here.
Partially. "Machine identity" (Gartner, Venafi, CyberArk's preferred framing) centres on the machine or certificate as the identity-bearing unit. "Non-human identity" (NHIMG, Astrix, Oasis, most newer vendors) is a broader umbrella that includes SaaS-to-SaaS connections, OAuth apps, and AI agents. We use NHI as the umbrella term and break down the distinction here.
HumanAudit Inc., a Delaware C-Corp. We also publish euaiactchecklist.com and iso42001toolkit.com, which are commercial toolkit products. This site is editorially independent, no vendor pays to be profiled. When you need audit-ready documentation or hands-on help, our commercial toolkits and advisory calls are linked where relevant. More on who we are.
No. No vendor pays to be profiled, reviewed, compared, or mentioned on any content page. Newsletter issues may be sponsored by a single partner per week, disclosed at the top of the email. Certain vendor profile pages include affiliate links that are clearly marked and never affect editorial placement. Editorial policy in full.
No. Everything on this site is educational and informational. For compliance decisions affecting your organisation under NIS2, DORA, HIPAA, PCI DSS, or the EU AI Act, consult qualified legal counsel. See the Terms of Use.
From our team at HumanAudit
This hub is free and vendor-neutral. When you need audit-ready documentation, our two commercial sister sites publish the templates compliance and security teams attach to their audit files.