The vendor-neutral reference hub

Non-human identity governance, without the vendor pitch.

Service accounts, API keys, OAuth tokens, workload identities, and AI agents now outnumber your people by 45 to 1, and they are the attack surface behind Salesloft/Drift, Snowflake, Storm-0558, and Shai-Hulud. This is the neutral reference for understanding and governing them.

Free to read. Editorially independent. No vendor pays to be profiled.

New and recently updated

Why this matters

The identities nobody is watching.

Service accounts, API keys, OAuth grants, workload credentials and AI agents outnumber your people by a wide margin, and almost none of them are covered by the joiner-mover-leaver process that governs everyone else.

45×
Non-human identities outnumber humans in the modern enterprise (Rubrik Zero Labs, 2024)
700+
Organisations impacted by the Salesloft/Drift OAuth supply-chain breach (Aug 2025)
1,195
Organisations with secrets exfiltrated in the Shai-Hulud 2.0 npm supply-chain worm (Entro Security analysis, Nov 2025)
65%
Organisations with AI agents reported at least one AI-agent-related security incident in the past 12 months (CSA, April 2026)
The neutrality commitment

Why this site can be neutral when others can't.

Most NHI reference sites list 15+ "strategic partners" in their footer. That is their business model. Ours is different. We are funded by HumanAudit Inc. consulting and ISO/IEC 42001 documentation products, and we take no vendor money.

Common questions

Frequently asked

What is non-human identity?

A non-human identity (NHI) is any digital identity that represents a software entity rather than a person, service accounts, API keys, OAuth tokens, cloud IAM roles, Kubernetes service accounts, certificates, SSH keys, workload identities, SaaS-to-SaaS integrations, and the rapidly growing category of AI agents and MCP servers. Full definition here.

Is this the same as machine identity management?

Partially. "Machine identity" (Gartner, Venafi, CyberArk's preferred framing) centres on the machine or certificate as the identity-bearing unit. "Non-human identity" (NHIMG, Astrix, Oasis, most newer vendors) is a broader umbrella that includes SaaS-to-SaaS connections, OAuth apps, and AI agents. We use NHI as the umbrella term and break down the distinction here.

Who publishes this site?

HumanAudit Inc., a Delaware C-Corp. We also publish euaiactchecklist.com and iso42001toolkit.com, which are commercial toolkit products. This site is editorially independent, no vendor pays to be profiled. When you need audit-ready documentation or hands-on help, our commercial toolkits and advisory calls are linked where relevant. More on who we are.

Do vendors pay to appear here?

No. No vendor pays to be profiled, reviewed, compared, or mentioned on any content page. We carry no affiliate links of any kind. No vendor on this site has paid us anything, and none can. Editorial policy in full.

Is this legal advice?

No. Everything on this site is educational and informational. For compliance decisions affecting your organisation under NIS2, DORA, HIPAA, PCI DSS, or the EU AI Act, consult qualified legal counsel. See the Terms of Use.