The vendor-neutral reference hub

Non-human identity governance, without the vendor pitch.

Service accounts, API keys, OAuth tokens, workload identities, and AI agents now outnumber your people by 45 to 1, and they are the attack surface behind Salesloft/Drift, Snowflake, Storm-0558, and Shai-Hulud. This is the neutral reference for understanding and governing them.

Free to read. Editorially independent. No vendor pays to be profiled.

45×
Non-human identities outnumber humans in the modern enterprise (Rubrik Zero Labs, 2024)
700+
Organisations impacted by the Salesloft/Drift OAuth supply-chain breach (Aug 2025)
1,195
Organisations with secrets exfiltrated in the Shai-Hulud 2.0 npm supply-chain worm (Entro Security analysis, Nov 2025)
65%
Organisations with AI agents reported at least one AI-agent-related security incident in the past 12 months (CSA, April 2026)
Start here

What you can do today.

Four ways in. Every one is free, runs in your browser, and gives you something you can act on, no signup to use them.

How this hub is organised

Three pillars. One clear job.

Every page either teaches a concept, translates a framework, or dissects a breach. No product funnels. No vendor paywalls. One conversion action on every page: run a free assessment or open the tools.

Two support hubs

Where the market is moving next.

Two hubs that aren't the core pillars, but are where the SEO is wide open and the buyer pain is growing fastest: agentic AI identity, and vendor-neutral buyer guidance.

The 5-stage NHI maturity model

Where is your programme today?

Most organisations sit between stages 1 and 3. That's the honest starting point. The interactive assessment takes about 4 minutes, scores you across 12 control areas, and emails a per-area breakdown with the three highest-leverage remediations for your stage.

Run the assessment →
Stage What it looks like Typical blast radius of a breach
1 · Ad hocNo inventory. Secrets in code. No offboarding. NHIs created freely without ownership.Full tenant compromise; months of attacker dwell time
2 · ReactiveSpreadsheet inventory. Some secret scanning. Rotation only after exposure.Widespread lateral movement through forgotten service accounts
3 · DefinedCentralised secret store. Policy documented. Reviews run annually. Coverage uneven.Contained to one integration; detection still slow
4 · ManagedAutomated rotation. Behavioural monitoring. OAuth review. Continuous evidence.Detected and revoked within hours; minimal data loss
5 · OptimisedShort-lived credentials as default. Workload identity federation. NHIDR + SOAR.Identity itself is not reusable; attacks fail by design
Interactive tools

Do the work, right here, no signup.

Three tools designed to give you an answer in the browser, not to gate you behind a form. Optional email if you want the full written report.

All tools →
The neutrality commitment

Why this site can be neutral when others can't.

Most NHI reference sites list 15+ "strategic partners" in their footer. That is their business model. Ours is different. We are funded by a weekly newsletter sponsored by one partner per issue, disclosed at the top of every email, and by selective affiliate links on specific vendor profile pages, always marked and always next to non-affiliate alternatives. No vendor pays to be profiled here. No vendor reviews or edits our writing. No vendor gets a better placement.

Assess your programme

Score your NHI programme in the browser.

Three free interactive tools for CISOs, IAM directors, cloud security leads, and DevSecOps engineers: a 12-question maturity assessment, the OWASP NHI Top 10 self-audit, and a breach-readiness score. Get your result on-screen, then unlock the full written report by email.

Open the tools →

Common questions

Frequently asked

What is non-human identity?

A non-human identity (NHI) is any digital identity that represents a software entity rather than a person, service accounts, API keys, OAuth tokens, cloud IAM roles, Kubernetes service accounts, certificates, SSH keys, workload identities, SaaS-to-SaaS integrations, and the rapidly growing category of AI agents and MCP servers. Full definition here.

Is this the same as machine identity management?

Partially. "Machine identity" (Gartner, Venafi, CyberArk's preferred framing) centres on the machine or certificate as the identity-bearing unit. "Non-human identity" (NHIMG, Astrix, Oasis, most newer vendors) is a broader umbrella that includes SaaS-to-SaaS connections, OAuth apps, and AI agents. We use NHI as the umbrella term and break down the distinction here.

Who publishes this site?

HumanAudit Inc., a Delaware C-Corp. We also publish euaiactchecklist.com and iso42001toolkit.com, which are commercial toolkit products. This site is editorially independent, no vendor pays to be profiled. When you need audit-ready documentation or hands-on help, our commercial toolkits and advisory calls are linked where relevant. More on who we are.

Do vendors pay to appear here?

No. No vendor pays to be profiled, reviewed, compared, or mentioned on any content page. Newsletter issues may be sponsored by a single partner per week, disclosed at the top of the email. Certain vendor profile pages include affiliate links that are clearly marked and never affect editorial placement. Editorial policy in full.

Is this legal advice?

No. Everything on this site is educational and informational. For compliance decisions affecting your organisation under NIS2, DORA, HIPAA, PCI DSS, or the EU AI Act, consult qualified legal counsel. See the Terms of Use.

From our team at HumanAudit

From understanding NHI risk to documented compliance

This hub is free and vendor-neutral. When you need audit-ready documentation, our two commercial sister sites publish the templates compliance and security teams attach to their audit files.

EU AI Act compliance toolkit → 58-point checklist, Annex III classifier, FRIA & technical-documentation templates. From $149 · euaiactchecklist.com ISO 42001 documentation toolkit → The 22 core AIMS documents, Microsoft SSPA & EU AI Act crosswalks. From $199 · iso42001toolkit.com Talk to a practitioner → Governing NHI or AI-agent identity at scale and want a second opinion? Book a free 20-minute call with an Oxford-certified AI governance practitioner.