By HumanAudit Inc. editorial teamLast reviewed 5 August 2026
VerifiedLast reviewed 5 August 2026 by the HumanAudit Inc. editorial team.Corrections logEditorial policy
On this page
  1. At a glance
  2. What they do
  3. Differentiators
  4. Where the category context matters
  5. Practical notes
  6. When Oasis makes sense
  7. What we don't know

Ownership change. Cyera (pending)

On 28 July 2026 Cyera signed a letter of intent to acquire Oasis Security for approximately $1B. This is a signed letter of intent, not a closed transaction, and terms have not been formally disclosed. Buyers in an active evaluation should ask Oasis directly about contract continuity and roadmap. Reviewed 5 August 2026.

At a glance

Founded2022
FoundersDanny Brickman (CEO), Amit Zimerman (CPO)
HeadquartersNew York, NY / Tel Aviv
CategoryNHI security platform (lifecycle + posture)
Reported funding~$195M cumulative; $120M Series B (March 2026) led by Craft Ventures, with Sequoia Capital, Accel, and Cyberstarts
OwnershipCyera signed a letter of intent to acquire Oasis on 28 July 2026 for approximately $1B, reported as mostly cash. Signed LOI, not yet closed.
Position in categoryLifecycle-workflow to first NHI platform; enterprise-scale posture

What they do

Oasis discovers NHIs across cloud (AWS, Azure, GCP), SaaS, identity providers, and development platforms, and organises them into a lifecycle model: who owns this identity, what does it do, when was it created, when does it expire, when was its credential last rotated, and when should it be decommissioned. The workflow surface, ownership assignment, rotation orchestration, retirement approvals, is the product's centre of gravity.

In practical product shape this comes out as four capability bands:

  • Discovery. Inventory across cloud IAM, SaaS OAuth, CI/CD, IdP, and code.
  • Context. Resolve each NHI to an owning human or team, link to the application or workload it serves, surface its privilege scope.
  • Posture. Evaluate overprivilege, staleness, long-lived secrets, third-party exposure, and configuration drift.
  • Lifecycle actions. Rotation orchestration, approval workflows, decommissioning with change-management integration.

Differentiators

  • Lifecycle framing. Oasis talks about NHI as a lifecycle problem (joiner-mover-leaver for machines) rather than purely a posture problem. The product reflects that orientation.
  • Enterprise depth. Integration coverage and multi-cloud scale are positioned at regulated-enterprise and financial-services buyers.
  • Policy flexibility. Custom policies, ownership rules, and workflow routing are first-class, which matters for organisations with idiosyncratic identity governance practices.

Where the category context matters

Oasis competes most directly with Astrix Security and Entro Security in "NHI platform" RFPs. Each vendor's origin story leaks into its product shape: Astrix foregrounds SaaS connected-app discovery, Entro foregrounds secrets telemetry, Oasis foregrounds lifecycle workflow. For buyers with an existing SOC and strong SaaS tooling, the lifecycle-and-ownership angle tends to be the differentiator that lands.

The March 2026 Series B is notable not just for size but for signal: a $120M growth round at that scale, with Craft Ventures leading new money in, implies investor confidence that NHI governance remains a standalone category rather than something folding into a broader IAM platform in the near term.

Practical notes

  • Deployment is agent-less; cloud connectors use read-only IAM; rotation actions require scoped write permissions the customer grants explicitly.
  • Time to useful inventory is typically days for enterprise-scale environments with complex multi-cloud.
  • Ownership attribution, mapping an NHI to an accountable human, is one of the harder problems and a place where buyers should validate behaviour on their own data during POC.
  • Pricing is enterprise-negotiated; expect six-figure ACVs for meaningful deployments.

When Oasis makes sense

Oasis is a reasonable shortlist candidate when the driver is:

  • "We have tens of thousands of NHIs and no systematic lifecycle, we don't know who owns what, we don't rotate, we don't retire."
  • "We need a platform to underpin an NHI governance programme, not just a discovery tool."
  • "We're a regulated enterprise with multi-cloud and the audit questions are getting sharper."

Less obvious fit when the driver is:

  • "We need secrets detection in source code and CI logs", dedicated secrets-detection tooling is purpose-built.
  • "We need a secrets manager", that's a different primitive.
  • "We need agent identity for LLM-driven workflows specifically", the AI-agent identity category is still adjacent, though converging.

What we don't know

  • Customer count and ARR, not publicly disclosed.
  • Whether the Cyera letter of intent converts to a closed transaction, and on what final terms. Signed 28 July 2026; not closed as of 5 August 2026.
  • Post-acquisition product roadmap and whether Oasis remains separately purchasable.

Assess your own NHI programme.

Run the free maturity assessment or the OWASP NHI Top 10 self-audit, get your score in the browser, and unlock the full written report.