How this site is funded
This publication is funded entirely by HumanAudit Inc., through consulting engagements and ISO/IEC 42001 documentation products. We carry no advertising, no sponsored content, no affiliate links and no paid vendor placement of any kind, and we do not operate a newsletter or collect email addresses. That funding model is the reason vendor coverage can say what it says: no vendor on this site has paid us anything, and none can.
Why we built this
In 2025, non-human identities became the leading root cause of enterprise breaches. Salesloft/Drift. Snowflake. Microsoft Storm-0558. Shai-Hulud 2.0. Not one of them was a phishing-a-user problem. Every one was a service-account, OAuth-token, or workload-identity problem. The market responded with a wave of vendor pitches. The search results filled with product pages that answered every question the same way: "and here is how our platform helps."
The reference material lagged badly. The one serious neutral community site, the Non-Human Identity Management Group (NHIMG), does excellent practitioner work but is explicit in its own footer that vendor pages on the site are written by paid strategic partners. OWASP's NHI Top 10 is sponsored by a single vendor. The Cloud Security Alliance produces authoritative surveys but only two or three a year. Individual vendors produce glossaries that stop at their own product boundary.
There was no reference. No single place where a security leader could read the complete, honest story of what non-human identity is, what it isn't, which frameworks matter, which vendors are credible for which use cases, and which breaches actually prove the category exists. That is the gap this site fills.
Who we are
NHI Governance is published by HumanAudit Inc., a Delaware C-Corp headquartered in the United States. HumanAudit publishes three sites in the security and compliance space:
- euaiactchecklist.com, commercial toolkits and templates for EU AI Act (Regulation EU 2024/1689) compliance.
- iso42001toolkit.com, commercial toolkits and templates for ISO/IEC 42001 AI management systems.
- nhigovernance.com, this site. A free, vendor-neutral reference hub for non-human identity governance.
The first two sites are commercial products, we sell documentation toolkits to compliance teams and consultancies. This site is deliberately different. It is not a product. It is the reference resource we believe the NHI category needs.
How we work
Every definitional and framework page is written against primary sources: OWASP working group drafts, IETF RFCs and internet-drafts, NIST publications, CSA research, vendor documentation, and post-incident forensics from Google/Mandiant, Microsoft, Wiz, and Unit 42. Every page carries a visible "last reviewed" date. Definitional and framework pages are reviewed at least quarterly; breach case studies are re-reviewed whenever new forensic detail surfaces.
We cite outbound. An article that links only to other pages on our own site is a content-marketing tactic, not a reference. The goal is to help the reader go deeper, which often means sending them to OWASP, CSA, SPIFFE.io, or the primary vendor documentation. We link to competitors and critics without hedging.
We take a position where there is a genuine industry debate. On "non-human identity" versus "machine identity," for example, we explain the argument on both sides, then state our view and the reasoning. The reader can disagree, and we are happy to be disagreed with. But we will not punt on questions where punting is a form of selling a fog to everyone.
How we make money
One way, and it is stated plainly because a reader is entitled to know who pays for what they are reading.
This publication is funded entirely by HumanAudit Inc., through consulting engagements and ISO/IEC 42001 documentation products. Nothing on this site is funded by anyone we write about.
We carry no advertising, no sponsored content, no affiliate or referral links, and no paid vendor placement of any kind. We do not operate a newsletter and we collect no email addresses. No vendor profiled on this site has paid us anything, and under this model none can.
We do not take money to profile a vendor, to review one favourably, or to omit one from a comparison. Every vendor profile is researched and written by our editorial team from publicly available sources, plus direct documentation access where we can obtain it. Vendors are welcome to request a factual correction and we publish corrections with date-stamped change logs, but they do not get editorial sign-off.
The commercial relationship runs the other way round from the usual arrangement: the consulting and product work pays for the reference, and the reference is worth reading precisely because it owes nothing to the vendors in it.
Who we read and learn from
This site would not exist without the work of a number of practitioners, researchers, and organisations who were on NHI early. Credit is owed to:
- Lalit Choda and the Non-Human Identity Management Group, for building the practitioner community and documenting 52+ NHI breaches in chronological detail.
- The OWASP NHI Top 10 working group, for producing the canonical risk taxonomy, and to Astrix for co-sponsoring its development.
- The SPIFFE community and the IETF WIMSE working group, for the open standards underneath workload identity.
- The Cloud Security Alliance, for the annual state-of-NHI surveys that anchor industry data.
- The Identity Defined Security Alliance and NHIcon organisers, for the nonprofit space where vendor-neutral discussion happens.
- Individual analysts and practitioners, including Francis Odum's Software Analyst Cybersecurity Research and Pieter Kasselman's IETF work on workload identity, and many others whose writing and talks we learn from and cite.
If you believe we have missed citing someone whose work we have drawn on, write to us and we will fix it.
Get in touch
Reach us at hello@nhigovernance.com. For legal, licensing, or partnership enquiries with HumanAudit Inc. directly, email truth@humanaudit.ai.
We are not a consultancy. We do not sell advisory hours. If you need paid NHI advisory work, we will recommend practitioners and firms we trust, without taking a referral fee.