By HumanAudit Inc. editorial teamLast reviewed 5 August 2026
VerifiedLast reviewed 5 August 2026 by the HumanAudit Inc. editorial team.Corrections logEditorial policy
On this page
  1. At a glance
  2. What they do
  3. Differentiators
  4. Where the category context matters
  5. Practical notes
  6. When Astrix makes sense
  7. What we don't know

Ownership change. Cisco

Astrix Security has been acquired by Cisco. Cisco announced its intent to acquire on 4 May 2026 and has since reported completion; Calcalist reported a price of approximately $400M. Astrix capabilities are being integrated into Cisco Identity Intelligence, Duo, and Secure Access. Evaluate Astrix as a Cisco platform component, not as an independent vendor. Reviewed 5 August 2026.

At a glance

Founded2021
FoundersAlon Jackson (CEO), Idan Gour (CTO)
HeadquartersNew York, NY / Tel Aviv
CategoryNHI security platform (discovery + posture)
Reported funding$85M cumulative; $45M Series B (December 2024) led by Menlo Ventures via the Anthology Fund (Menlo's Anthropic partnership), with Workday Ventures, Bessemer Venture Partners, CRV, and F2 Venture Capital
OwnershipAcquired by Cisco. Intent announced 4 May 2026; reported completed. Calcalist reported approximately $400M.
Position in categoryDiscovery-first NHI platform, strong SaaS integration coverage

What they do

Astrix connects (read-only by default) to a customer's SaaS, cloud, and development-platform estate and builds an inventory of the non-human identities operating across it, OAuth tokens, service accounts, API keys, webhooks, connected apps, workflow automations. It then continuously evaluates each NHI against posture criteria (overprivilege, staleness, exposure, suspicious activity) and surfaces prioritised remediation work.

The product's shape in practice is three capability bands:

  • Inventory. Connect to Salesforce, Google Workspace, Microsoft 365, GitHub, Okta, AWS, and so on. Ingest what NHIs exist and how they're used.
  • Posture. For each NHI, evaluate: is it overprivileged for its actual usage? is it stale (no recent activity)? is it owned by a departed employee? is it exposed to third-party vendors that have been breached?
  • Remediation. Workflow tooling, ticket creation, approval flows, automated revocation where scope permits.

Differentiators

  • Breadth of SaaS integration. Deep coverage of the connected-app / OAuth-third-party surface where traditional IAM tools are blind.
  • Research output. Astrix's research team has published notably on NHI-relevant incidents including supply-chain and OAuth-token compromises. This tends to signal depth of understanding, not just product breadth.
  • Early AI-agent posture attention. Among the first NHI platforms to treat AI-agent identities as a distinct class.

Where the category context matters

Astrix competes most directly with Oasis Security and Entro Security for the "NHI platform" slot in enterprise RFPs. Each has slightly different origin stories (Astrix: SaaS-security heritage; Oasis: lifecycle-workflow heritage; Entro: secrets-detection heritage) and the products reflect those starting points. Integration coverage, remediation UX, and policy flexibility are the dimensions most customers evaluate on.

The Cisco acquisition changes Astrix's field-level posture materially. At a reported ~$400M this was the first major NHI-category exit to a platform vendor, and it opened a consolidation window: SailPoint completed its acquisition of Entro Security on 29 June 2026, and Cyera signed a letter of intent to acquire Oasis Security for approximately $1B on 28 July 2026. Enterprise buyers standardising on Cisco security may now get Astrix capability under an existing platform relationship; buyers committed to vendor-independent tooling should weigh Cisco lock-in as a real evaluation criterion.

Practical notes

  • Deployment is agent-less for SaaS (OAuth-based); cloud connectors use read-only IAM roles.
  • Time-to-first-inventory is measured in hours for mid-sized estates, days for enterprise-complex ones.
  • Remediation depth depends materially on which integrations are in scope, broad discovery coverage doesn't always imply automated remediation in every platform.
  • Pricing is enterprise-negotiated; expect six-figure ACVs for meaningful deployments.

When Astrix makes sense

Astrix is a reasonable shortlist candidate when the driver is:

  • "We don't know what NHIs we have in our SaaS estate and we need to find out."
  • "Our SOC is seeing OAuth-token-abuse incidents and we need discovery + posture."
  • "We're starting an NHI program and need a platform to anchor it."

Less obvious fit when the driver is:

  • "We need a secrets manager", that's a different primitive (Vault, Conjur, cloud-native).
  • "We need secrets detection in code", the dedicated secrets-detection tools are purpose-built for that.
  • "We need PAM for privileged service accounts", PAM incumbents have depth here.

What we don't know

  • Exact customer count and ARR, not publicly disclosed.
  • Final integration roadmap into Cisco Identity Intelligence, Duo and Secure Access, and the future of standalone Astrix contracts. Not disclosed.

Assess your own NHI programme.

Run the free maturity assessment or the OWASP NHI Top 10 self-audit, get your score in the browser, and unlock the full written report.