By HumanAudit Inc. editorial teamLast reviewed 5 August 2026

The pure-play NHI category consolidated between May and July 2026

All three leading independent NHI platforms have been acquired or are under signed agreement. Any vendor shortlist built before May 2026 is out of date.

  • Astrix → Cisco. Intent announced 4 May 2026, reported completed. Reported ~$400M.
  • Entro → SailPoint. Completed 29 June 2026. Reported ~$200M.
  • Oasis → Cyera. Letter of intent signed 28 July 2026. Reported ~$1B. Not closed.

Verified 5 August 2026 against acquirer announcements and contemporaneous trade reporting.

Editorial independence. NHI Governance does not accept paid vendor placement, affiliate-for-placement, or sponsored write-ups. Profiles are produced from public information, vendor documentation, primary-source briefings we request on our terms, and the editorial desk's own evaluation. We carry no affiliate relationships at all, so there are none to disclose. See our editorial policy.

How to read this page

The NHI vendor category is still consolidating. The shape of the market as of April 2026 is:

  • NHI security platforms (new-generation): Astrix, Oasis, Entro. Discovery-first, posture management, integration-dense. Fast-growing, VC-backed, M&A-active.
  • Identity security incumbents (absorbing NHI): CyberArk (now part of Palo Alto Networks post-February 2026 close), Silverfort (absorbed Rezonate late 2024). Came from PAM; now positioning as NHI.
  • Secrets management (the older layer): HashiCorp Vault (now part of IBM), CyberArk Conjur, AWS Secrets Manager, Azure Key Vault. Foundational; being complemented by discovery/posture tools rather than replaced.
  • Secrets detection (the GitOps layer): GitGuardian, Spectral (Check Point), truffleHog (open-source + Truffle Security). Focused on secrets sprawl in code and CI/CD.
  • Workload identity (the open-source foundation): SPIFFE/SPIRE (CNCF graduated), HashiCorp Boundary, open ecosystem.

The 2025 to 2026 M&A wave

The NHI space has been actively consolidating:

  • Palo Alto Networks + CyberArk ($25B, closed February 11, 2026). Largest cybersecurity deal ever. Folds CyberArk's PAM and Venafi (which CyberArk acquired in 2024 for $1.54B) machine-identity capabilities into the PANW Cortex platform.
  • IBM + HashiCorp ($6.4B, closed 2025). Vault and Terraform join Red Hat within IBM.
  • CyberArk + Venafi ($1.54B, closed 2024). Gave CyberArk a certificate/machine-identity footprint before the PANW deal.
  • Silverfort + Rezonate (November 2024). Expanded Silverfort's identity protection to cloud-NHI discovery.
  • Cisco / Astrix (acquired by Cisco, reported ~$400M), Entro (acquired by SailPoint, completed 29 June 2026, reported ~$200M), and Oasis (Cyera letter of intent, 28 July 2026, reported ~$1B). Reporting only; treat as unconfirmed until principals disclose.

This wave is substantially changing the competitive map. Category-defining startups from 2022 to 2024 are becoming platform lines within larger vendors; pricing, roadmap control, and field-level independence all shift as a result. We track this on an ongoing basis.

Capability comparison (the category map)

VendorPrimary strengthCategoryNotable
Astrix SecurityNHI discovery + posture across SaaSNHI platform$85M funded; reporting suggests Cisco acquisition at ~$350M (unconfirmed)
Oasis SecurityNHI lifecycle + remediation workflowsNHI platform$190M+ total funding incl. $120M Series C March 2026
Entro SecuritySecrets-aware NHI postureNHI platformSecrets-detection heritage, merged into NHI platform
CyberArk (PANW)PAM + machine identity (Venafi)Identity incumbentAcquired by Palo Alto Networks; integrating into Cortex
HashiCorp Vault (IBM)Foundational secrets storage + dynamic secretsSecrets managementIBM acquisition closed Feb 2025; continues as the most widely-deployed enterprise secrets platform
GitGuardianSecrets sprawl detection in code and CI/CDSecrets detectionPublic post-mortem contributions on major breaches (Shai-Hulud, Codecov)

Selection guidance

A brief, unbranded decision frame:

  • If your primary problem is "I don't know what NHIs exist in my SaaS estate", start with an NHI discovery/posture platform (Astrix, Oasis, Entro). Their differentiators are in integration coverage and remediation UX.
  • If your primary problem is "secrets are everywhere in our codebase and CI", start with a secrets detection layer (GitGuardian et al.). Pair with a vault for mitigation.
  • If your primary problem is "we have no centralised secrets storage", start with a secrets manager (HashiCorp Vault, CyberArk Conjur, cloud-native). Platform choice here has long-lived implications; choose deliberately.
  • If your primary problem is PAM for service accounts, this is CyberArk's (now PANW) home turf, with BeyondTrust, Delinea, and others in the conversation.
  • If your primary problem is workload identity architecture, SPIFFE/SPIRE. Open-source, CNCF graduated, the foundation that commercial NHI platforms build upon.

More often than not, a mature program combines two or three of these layers. The architectural question is which one is primary in your stack, the discovery plane vs. the credential-issuance plane vs. the code-scanning plane, and what data flow you build between them.

Vendor profile

Astrix Security

NHI discovery & posture across SaaS and cloud.

Read →
Vendor profile

Oasis Security

NHI lifecycle + automated remediation workflows.

Read →
Vendor profile

Entro Security

Secrets-aware NHI posture management.

Read →
Vendor profile

CyberArk (PANW)

PAM + Venafi machine identity, now inside Palo Alto Networks.

Read →
Vendor profile

HashiCorp Vault (IBM)

The foundational secrets platform, inside IBM.

Read →
Vendor profile

GitGuardian

Secrets sprawl detection across code and CI/CD.

Read →

Frequently asked questions

Which vendors lead in non-human and AI agent identity?

The category consolidated between May and July 2026 and there are no longer three independent leaders. Astrix was acquired by Cisco, Entro by SailPoint, and Oasis is under a signed letter of intent from Cyera. Capability now sits inside larger platforms, so the leadership question has become which platform you want governing identity rather than which point tool scores highest. Our consolidation tracker records every transaction with dates and status.

How do NHI vendors compare on discovery, risk scoring and remediation?

Meaningful comparison on those axes requires testing against your own estate, because every platform claims all three and the differences are in depth and in which integrations are production-grade. What we can compare accurately is ownership and origin discipline: Astrix came from SaaS security, Entro from secrets detection, Oasis from lifecycle workflow, CyberArk from privileged access, Vault from secrets storage, GitGuardian from source-code scanning. Origin predicts six-month deployment experience better than any feature grid.

Do you rank or score NHI vendors?

No. We take no vendor money, run no product bake-offs, and do not publish capability rankings we cannot independently verify. We publish ownership status, origin discipline, and the evaluation questions that genuinely discriminate, and we state what we do not know.

Is there a list of NHI cybersecurity vendors?

Our vendor section profiles the six platforms most often shortlisted, each with current ownership and origin. It is deliberately not exhaustive: a long list of names with one-line descriptions helps nobody make a decision, and it decays faster than we could maintain it. For decisions, the comparison page and the RFP question bank are more useful than a directory.

Assess your own NHI programme.

Run the free maturity assessment or the OWASP NHI Top 10 self-audit, get your score in the browser, and unlock the full written report.