By HumanAudit Inc. editorial teamLast reviewed 5 August 2026
VerifiedLast reviewed 5 August 2026 by the HumanAudit Inc. editorial team.Corrections logEditorial policy
On this page
  1. Why we built this
  2. Who we are
  3. How we work
  4. How we make money
  5. Who we read and learn from
  6. Get in touch

How this site is funded

This publication is funded entirely by HumanAudit Inc., through consulting engagements and ISO/IEC 42001 documentation products. We carry no advertising, no sponsored content, no affiliate links and no paid vendor placement of any kind, and we do not operate a newsletter or collect email addresses. That funding model is the reason vendor coverage can say what it says: no vendor on this site has paid us anything, and none can.

Why we built this

In 2025, non-human identities became the leading root cause of enterprise breaches. Salesloft/Drift. Snowflake. Microsoft Storm-0558. Shai-Hulud 2.0. Not one of them was a phishing-a-user problem. Every one was a service-account, OAuth-token, or workload-identity problem. The market responded with a wave of vendor pitches. The search results filled with product pages that answered every question the same way: "and here is how our platform helps."

The reference material lagged badly. The one serious neutral community site, the Non-Human Identity Management Group (NHIMG), does excellent practitioner work but is explicit in its own footer that vendor pages on the site are written by paid strategic partners. OWASP's NHI Top 10 is sponsored by a single vendor. The Cloud Security Alliance produces authoritative surveys but only two or three a year. Individual vendors produce glossaries that stop at their own product boundary.

There was no reference. No single place where a security leader could read the complete, honest story of what non-human identity is, what it isn't, which frameworks matter, which vendors are credible for which use cases, and which breaches actually prove the category exists. That is the gap this site fills.

Who we are

NHI Governance is published by HumanAudit Inc., a Delaware C-Corp headquartered in the United States. HumanAudit publishes three sites in the security and compliance space:

  • euaiactchecklist.com, commercial toolkits and templates for EU AI Act (Regulation EU 2024/1689) compliance.
  • iso42001toolkit.com, commercial toolkits and templates for ISO/IEC 42001 AI management systems.
  • nhigovernance.com, this site. A free, vendor-neutral reference hub for non-human identity governance.

The first two sites are commercial products, we sell documentation toolkits to compliance teams and consultancies. This site is deliberately different. It is not a product. It is the reference resource we believe the NHI category needs.

How we work

Every definitional and framework page is written against primary sources: OWASP working group drafts, IETF RFCs and internet-drafts, NIST publications, CSA research, vendor documentation, and post-incident forensics from Google/Mandiant, Microsoft, Wiz, and Unit 42. Every page carries a visible "last reviewed" date. Definitional and framework pages are reviewed at least quarterly; breach case studies are re-reviewed whenever new forensic detail surfaces.

We cite outbound. An article that links only to other pages on our own site is a content-marketing tactic, not a reference. The goal is to help the reader go deeper, which often means sending them to OWASP, CSA, SPIFFE.io, or the primary vendor documentation. We link to competitors and critics without hedging.

We take a position where there is a genuine industry debate. On "non-human identity" versus "machine identity," for example, we explain the argument on both sides, then state our view and the reasoning. The reader can disagree, and we are happy to be disagreed with. But we will not punt on questions where punting is a form of selling a fog to everyone.

How we make money

One way, and it is stated plainly because a reader is entitled to know who pays for what they are reading.

This publication is funded entirely by HumanAudit Inc., through consulting engagements and ISO/IEC 42001 documentation products. Nothing on this site is funded by anyone we write about.

We carry no advertising, no sponsored content, no affiliate or referral links, and no paid vendor placement of any kind. We do not operate a newsletter and we collect no email addresses. No vendor profiled on this site has paid us anything, and under this model none can.

We do not take money to profile a vendor, to review one favourably, or to omit one from a comparison. Every vendor profile is researched and written by our editorial team from publicly available sources, plus direct documentation access where we can obtain it. Vendors are welcome to request a factual correction and we publish corrections with date-stamped change logs, but they do not get editorial sign-off.

The commercial relationship runs the other way round from the usual arrangement: the consulting and product work pays for the reference, and the reference is worth reading precisely because it owes nothing to the vendors in it.

Who we read and learn from

This site would not exist without the work of a number of practitioners, researchers, and organisations who were on NHI early. Credit is owed to:

If you believe we have missed citing someone whose work we have drawn on, write to us and we will fix it.

Get in touch

Reach us at hello@nhigovernance.com. For legal, licensing, or partnership enquiries with HumanAudit Inc. directly, email truth@humanaudit.ai.

We are not a consultancy. We do not sell advisory hours. If you need paid NHI advisory work, we will recommend practitioners and firms we trust, without taking a referral fee.