Read this before the table
This comparison covers the ownership and category position of each vendor, not a feature scorecard. We do not run product bake-offs, we take no vendor money, and we do not publish capability rankings we cannot independently verify. What we can tell you accurately is who owns what, what each product was originally built to do, and which evaluation questions actually discriminate between them. See our editorial policy.
The comparison
| Vendor | Ownership (Aug 2026) | Origin discipline | Strongest when the driver is | Weaker fit when |
|---|---|---|---|---|
| Astrix | Cisco (reported ~$400M, reported completed) | SaaS and third-party app security | "We don't know what NHIs exist across our SaaS estate". OAuth grants, connected apps, third-party integrations | You need secrets management or PAM depth, or you are deliberately avoiding Cisco platform consolidation |
| Entro | SailPoint (completed 29 June 2026, reported ~$200M) | Secrets detection and telemetry | Secrets sprawl in code, CI/CD, and pipelines, and you want credential-level lineage feeding governance | You are not a SailPoint customer and do not intend to become one |
| Oasis | Cyera LOI (28 July 2026, ~$1B reported, not closed) | Lifecycle and workflow | Ownership attribution, rotation, and decommissioning workflow rather than dashboards | You need contractual certainty in the next two quarters, given the pending transaction |
| CyberArk | Palo Alto Networks | Privileged access management | Privileged service accounts, existing PAM estate, regulated environments needing mature controls | The problem is SaaS-to-SaaS OAuth sprawl, which is not PAM's native shape |
| HashiCorp Vault | IBM | Secrets storage and dynamic credentials | You need a secrets engine and dynamic credential issuance as infrastructure | You expected discovery and posture. Vault is a primitive, not a governance platform |
| GitGuardian | Independent | Secrets detection in code | Hard-coded credentials in repositories and developer workflow remediation | You need lifecycle governance across cloud and SaaS, not source-code scanning |
Ownership verified 5 August 2026. See the consolidation tracker for transaction detail and sources.
The comparison most buyers are running is the wrong one
Feature matrices are the default artefact in security procurement and they are close to useless in this category, for three reasons.
First, every platform claims every capability. Discovery, posture, lifecycle, remediation, secrets, and agents appear on all six vendors' marketing. The differences are in depth and in which integrations are actually production-grade, and neither is visible from a datasheet.
Second, origin discipline predicts real behaviour better than feature lists. A product built from secrets detection outward has genuinely deep credential telemetry and shallower SaaS-integration coverage. One built from SaaS security outward has the inverse. Those starting points persist for years after the marketing converges, and the origin column above will tell you more about a six-month deployment experience than any capability grid.
Third, and now dominant: the ownership question outranks the product question. After the 2026 consolidation, choosing an NHI tool is largely choosing a platform relationship. The relevant question is not "which product scores higher" but "which platform do we want governing identity in five years, and does this decision commit us to it?"
Nine questions that actually discriminate
Ask these in a proof of concept, against your own data, not in a demo:
- Run discovery on our real estate. What percentage of the NHIs we already know about does it find? Then, more importantly: what did it find that we did not know about? That second number is the product.
- Show us ownership attribution on identities where the creating employee has left. This is the hardest problem in the category and the one most often demoed with clean data.
- What happens when you recommend a revocation and we accept it? Automated remediation depth varies enormously and is frequently narrower than discovery coverage implies.
- Which of your integrations are read-only discovery and which support write remediation? Ask per-integration, not in aggregate.
- Can you produce evidence an auditor accepts? Ask for an actual export, not a dashboard screenshot.
- How do you treat an AI agent differently from a service account? If the answer is "it's just another NHI," the agent capability is a label.
- What is your delegation-chain model? If the product cannot represent "this agent acted for this human under this consent," it cannot answer the question auditors will ask. See our agent identity standards map.
- Post-acquisition: is this separately purchasable, on what terms, for how long? Get it in writing.
- What does this not do that we will discover in month six? The quality of the answer to this question is the strongest single signal about the vendor you will get.
The option the matrix leaves out
For a meaningful number of organisations, the correct first move is not to buy any of these. If you have no NHI inventory, no ownership model, and no rotation policy, a platform will hand you a very well-organised list of problems you are not yet structured to fix, at six-figure annual cost.
The sequence that works: establish the inventory and ownership model using cloud-native and existing tooling, define what good looks like for your highest-risk identity classes, then buy the platform to scale a process that already exists. Buying first inverts that and is the most common way NHI programmes stall. Our maturity assessment will tell you in about ten minutes which side of that line you are on.
Frequently asked questions
What is the best NHI security vendor?
There is no single best vendor, and after the 2026 consolidation the question has changed shape. Astrix is now part of Cisco, Entro part of SailPoint, and Oasis is under a signed letter of intent from Cyera. Because each is now attached to a platform, the decision is largely about which platform you want governing identity, combined with origin discipline: Astrix came from SaaS security, Entro from secrets detection, Oasis from lifecycle workflow, CyberArk from privileged access, Vault from secrets storage, and GitGuardian from source-code scanning.
Do you rank or score NHI vendors?
No. We do not run product bake-offs, we take no vendor money, and we do not publish capability rankings we cannot independently verify. We publish ownership status, origin discipline, and the evaluation questions that genuinely discriminate between products, and we tell you what we do not know.
Should we buy an NHI platform before building an inventory?
Usually not. If you have no inventory, no ownership model, and no rotation policy, a platform will produce a well-organised list of problems you are not yet structured to fix, at six-figure annual cost. The sequence that works is inventory and ownership first using existing tooling, then buy a platform to scale a process that already exists.
How do I evaluate an NHI platform's AI agent capability?
Ask how it treats an AI agent differently from a service account, and ask for its delegation-chain model. If the product cannot represent the fact that a specific agent acted for a specific human under a specific consent, it cannot answer the question auditors are beginning to ask, and the agent capability is a label rather than a feature.
Is GitGuardian a competitor to Astrix or Oasis?
Only partially. GitGuardian's origin is secrets detection in source code, which addresses one specific surface: credentials committed to repositories. The broader NHI platforms address discovery and lifecycle across cloud and SaaS estates. Organisations frequently run both, and treating them as substitutes usually means one of the two problems is not being addressed.
Building an NHI vendor shortlist right now?
The category consolidated in 90 days. If your shortlist predates May 2026 it contains companies that no longer exist independently. A 20-minute call with HumanAudit will tell you what has changed for your specific evaluation, at no cost.