Startup Diligence
Diligence report Cybersecurity Series B 2026-07-10

Oasis Security

Agentic Access Governance: Pricing a New Control Layer for Non-Human Identities

Oasis Security looks strategically important in a fast-growing identity category, but the current public file supports continued diligence more than outright conviction because valuation-relevant operating metrics remain undisclosed.

Cover facts

Last raised 01
$120M Series B [CO010]
Total raised 02
195 USD millions [CO011]
Valuation 03
700 USD millions [CO012]
Founded 04
2022 [CO001]
Customer mix 05
Fortune 500 majority [CO013]
Headcount 06
142 [CO017]

Company profile

Oasis Security is a New York- and Israel-linked cybersecurity company focused on one of the most important identity shifts in modern enterprise infrastructure: the rise of non-human identities and AI agents. Its platform combines discovery, ownership mapping, posture management, secret rotation, provisioning, and agentic-access controls to help enterprises govern machine identities and AI agents across cloud, SaaS, on-prem, and developer-tool environments. Founded in 2022 by Danny Brickman and Amit Zimerman, Oasis has moved quickly from stealth to a $120M Series B, built a Fortune-500-heavy customer narrative, and expanded its positioning from NHI lifecycle management to broader agentic-access governance. The strategic story is strong, but the company remains private and materially under-disclosed on financial metrics that would let investors validate the implied valuation with confidence.

Website
www.oasis.security
Founded
2022-01-01
Founders
Danny Brickman, Amit Zimerman
Founding location
Tel Aviv, Israel
Headquarters
Tel Aviv, Israel & New York, USA
Product
Oasis sells a software platform for discovering, governing, and securing non-human identities and AI agents. Core functions include identity inventory, context and ownership mapping, posture and anomaly analysis, lifecycle governance, secret rotation, provisioning, and just-in-time / policy- driven controls for agentic access.
Customers
Large enterprises—especially regulated or operationally complex organizations in financial services, healthcare, manufacturing, logistics, insurance, and AI-platform ecosystems—served through direct enterprise sales and partner-assisted procurement routes.
Business model
Custom-priced enterprise SaaS sold through negotiated subscription agreements, multi-year enterprise contracts, and partner / marketplace routes.
Stage
Series B
Funding status
$120M Series B in March 2026; public reporting places total raised at ~$195M and the best- supported valuation mark at roughly $700M post-money.
[CO001, CO002, CO010, CO011, CO012, CO013, CO017, CO032]

Executive summary

Top strengths

  • Strong strategic alignment with the rise of AI agents and non-human identity governance
  • Fast funding progression to a $120M Series B backed by top-tier cybersecurity and software investors
  • Fortune-500-heavy customer narrative with real deployment depth in healthcare, financial services, industrial, and large-enterprise environments
  • Product breadth now spans discovery, posture, rotation, provisioning, and agentic-access control rather than a single-point feature
  • Strategic scarcity is improving as larger vendors fund or acquire adjacent machine-identity assets

Top risks

  • ARR, margin, burn, retention, and concentration data are still undisclosed, making the valuation difficult to underwrite
  • The company is selling into a market whose standards and procurement expectations are still catching up to agentic-AI security needs
  • Execution depends on partner ecosystems and trust conversion, not only on product quality
  • The implied valuation premium can compress quickly if Oasis fails to validate strong recurring-revenue quality
  • Strategic-process noise, including the reported Cyera talks, can distract execution without guaranteeing upside

Open gaps

  • Current ARR and quarterly ARR bridge
  • Gross margin, burn, runway, and capital-efficiency metrics
  • NRR / GRR, churn, and renewal behavior by segment
  • Top-customer, partner, and vertical concentration
  • Cap-table terms, preferences, venture debt, and any secondary activity
  • Referenceable customer proofs tied to expansion, not just initial deployments

Contents

Chapter 01

01Company Overview

1.1 Identity, product scope, and founding context

Oasis Security is best understood as a post-stealth infrastructure-security company selling governance for non-human identities rather than a narrow secrets utility. Across its homepage, about page, product page, and founding blog, the company describes a platform that discovers machine identities, maps ownership and usage context, and orchestrates lifecycle controls such as monitoring, certification, remediation, and decommissioning. The product language is deliberately broad: Oasis says it spans IaaS, SaaS, PaaS, and on-prem environments and names endpoints as diverse as AWS, Azure, BigQuery, GitHub, ChatGPT, Salesforce, Office 365, and Copilot. That breadth matters because it implies the company wants to sit above fragmented vaults and point tools as an identity-governance layer. The official origin story also gives Oasis a distinct narrative: Danny Brickman says the company began in a modest room in Tel Aviv with teammates from Israeli cyber operations, while independent reporting identifies Brickman and Amit Zimerman as the founding pair. The result is a company with visibly Israeli technical roots but a commercial narrative now anchored in U.S. enterprise identity security.[CO001, CO002, CO003, CO004, CO005, CO006]

Snapshot KPI table
MetricValue / statusDateConfidenceGap / caveat
Founded20222022HighMultiple 2024-2026 sources agree on the founding year
Commercial headquartersNew York2026MediumSupported by Tech Company News and BankInfoSecurity, but the company website does not publish a corporate-address page
Technical / origin footprintTel Aviv roots; Israel hiring plus U.S. hiring2024-2026MediumOfficial founding blog and Globes point to Israel roots, but no formal two-office roster is public
Latest disclosed round$120M Series B led by Craft Ventures2026-03-19HighRound details are corroborated by company and independent press
Total disclosed funding$195M2026-03-19HighConsistent across official and independent 2026 reporting
Best-supported valuation estimate~$700M post money2026-03MediumValue is reported by market sources, not formally disclosed by the company
Customer mixMajority of client base from Fortune 5002026MediumCompany claim; exact customer count is undisclosed
Named public customersChipotle; JLL; Mercury Financial2024-01MediumOnly a small set of customer names surfaced publicly
ARR signal5x YoY growth in new ARR2026MediumGrowth rate disclosed, ARR dollars not disclosed
Headcount signal45 in Jan 2024; 142 in Mar 20262024-2026MediumLater figure comes from one independent article rather than company disclosure
Governance disclosureFounders plus president are public; full board is not2026HighNo full board roster or committees located
M&A contextCyera acquisition talks reported; no formal announcement2026-07-06LowAdverse strategic context may change quickly and is unconfirmed by company filing or release

Rows intentionally distinguish disclosed values, market estimates, and undisclosed items so later chapters can reuse the snapshot without treating estimates as company-confirmed facts.

[CO001, CO011, CO012, CO013, CO014, CO016]
FO002: Company snapshot logic

Oasis links machine-identity discovery and governance to AI-agent adoption, enterprise buying, and ecosystem integrations.

[CO004, CO005, CO006, CO013, CO020, CO023]

1.2 Funding history, investor map, and governance signals

Oasis has moved unusually fast through private financing milestones. It emerged publicly in January 2024 with a previously closed $35 million Series A and $40 million total funding, then returned in May 2024 with a $35 million extension that management and press sources said doubled the prior valuation and lifted cumulative funding to $75 million. The most important financing event is the March 2026 Series B: Oasis announced $120 million led by Craft Ventures with existing backers Cyberstarts, Sequoia Capital, and Accel, bringing total funding to $195 million. Independent reporting from Globes and Tech Company News places the post-money valuation around $700 million, which is materially below the $1.2 billion figure in the user-supplied background and therefore the better-supported current value anchor. Governance disclosure remains thinner than funding disclosure. Public sources clearly identify the founders and the April 2026 addition of Michael DeCesare as president, but they do not surface a full board roster, committee structure, or cap-table detail. That makes investor pedigree a strength, but governance transparency an unresolved diligence item.[CO001, CO002, CO007, CO008, CO009, CO010]

Leadership and founder table
PersonRoleBackgroundFunctional coverage / relevanceKey-person dependency
Danny BrickmanCo-founder and CEOPublicly described as an ex-IDF cyber R&D leader with seven-plus years of military cyber experienceFounding vision, category evangelism, enterprise credibility, and external face of product strategyHigh
Amit ZimermanCo-founder and CPONamed in multiple funding reports as co-founder and chief product officerOwns product strategy and technical translation of the NHI problem setHigh
Michael DeCesarePresident (appointed Apr 2026)Career cybersecurity GTM operator; joined after the Series B to run sales, marketing, alliances, and customer successProfessionalizes go-to-market and channel scale-up after founder-led early salesMedium
Founding team / IDF cyber peersInformal technical founding cohortOfficial founding blog points to a broader Tel Aviv cyber-operations nucleus around the foundersSupports the claim that the company has a deep practitioner DNA even if only two founders are publicly namedMedium

Coverage is partial because no reviewed source published a formal executive or board roster beyond the founders and the 2026 president hire.

[CO002, CO003, CO019, CO034]
Stakeholder or investor map
StakeholderRoleControl / economic importanceEvidenceDiligence ask
Craft VenturesSeries B lead investorLead 2026 capital provider and likely major board-influence holder after the largest disclosed roundSeries B press release and follow-on coverageConfirm ownership, liquidation preference, and board rights
CyberstartsRepeat investorExisting investor that participated again in Series B, signaling sustained sponsor convictionSeries B press releaseConfirm cumulative ownership and any governance rights
Sequoia CapitalSeries A and extension backer; Series B participantTop-tier sponsor that participated across multiple roundsTechCrunch, CTech, Access Newswire, Series B pressConfirm whether Sequoia maintains formal board or observer rights
AccelSeries A lead group, extension co-lead, Series B participantLong-duration investor across every disclosed financing stageCTech, Access Newswire, Series B pressConfirm stake size and ownership concentration
Maple CapitalSeries A participantNamed in the initial stealth-exit financing onlyTechCrunch and CTechConfirm whether the fund retained pro-rata rights in later rounds
GuidePoint SecurityStrategic reseller partnerNot an equity investor, but a potentially important channel multiplier in North AmericaPR Newswire channel launch; GPSEC agendaRequest sourced pipeline and conversion metrics from the channel motion
CrowdStrike and Wiz ecosystem partnersIntegration distribution nodesMarketplace / integration visibility can influence deal velocity even without direct economic ownershipMarketplace and integration pagesClarify attach rates, joint customers, and sourcing contribution

This map blends equity stakeholders and commercially strategic partners because public cap-table disclosure is sparse and partner leverage is already part of the current growth narrative.

[CO008, CO009, CO010, CO020, CO023, CO024]

1.3 Traction signals, partner validation, and category timing

Traction evidence is real but still selective. The strongest company claim is that a majority of Oasis's client base comes from the Fortune 500 and that new ARR grew fivefold year over year heading into the Series B. That is directionally impressive, especially when paired with management's claim that most new ARR is driven by multi-year enterprise agreements. Independent public customer proof is shallower: TechCrunch named Chipotle, JLL, and Mercury Financial as early users, while Gartner Peer Insights showed a 5.0 rating from a single banking review in early 2026. Partner surfaces strengthen the adoption story. CrowdStrike's marketplace listing and Wiz's integration page both describe Oasis as an active ecosystem participant rather than a conceptual integration. Just as important, third-party category signals show that the market window is real. NIST launched an AI Agent Standards Initiative in 2026, Palo Alto Networks said machine identities hit 109-to-1 versus humans, and CyberArk framed the machine-identity problem as a breach and outage vector. Oasis is therefore not selling into a synthetic category; it is selling into a problem that large security vendors and standards bodies also describe as urgent.[CO013, CO014, CO015, CO016, CO020, CO021]

FO003: Snapshot KPIs

Publicly disclosed metrics are strong on funding and growth direction but weak on customer count, ARR dollars, and governance detail.

[CO012, CO013, CO014, CO016, CO017, CO018]

1.4 Milestones, disclosure gaps, and adverse context

The milestone record from public sources is coherent enough to support an overview chapter, but it still leaves obvious gaps. The company moved from a stealth exit in January 2024 to a Series A extension in May 2024, formal channel-program launch in April 2025, Series B in March 2026, and executive expansion in April 2026. Those are the milestones of a company trying to turn an early product wedge into a scaled enterprise platform. The missing pieces are just as important. No reviewed source published a precise customer count, exact ARR dollars, board roster, or audited financials. Even the most discussed valuation figure is only a market estimate, not a disclosed board-sanctioned number. The clearest adverse-context item is a July 2026 Globes report that Cyera was in advanced talks to acquire Oasis for up to $1 billion, but without a formal announcement. That does not disprove the $700 million financing benchmark; it does indicate that strategic- option narratives around Oasis were already shifting by the run date. Investors should therefore treat the company as well-funded and clearly relevant, but still materially under-disclosed on the metrics that would let later chapters underwrite a price-sensitive view.[CO011, CO012, CO017, CO018, CO020, CO021]

Milestone table
DateEventTypeAmount / statusParticipantsImplication
2022Company foundedfoundingFoundedDanny Brickman; Amit ZimermanEstablishes the company as a 2022-vintage startup rather than a 2023 birth
2024-01Stealth exit and Series A announcementfinancing$35M Series A; $40M total funding thenSequoia; Accel; Cyberstarts; Maple; angelsValidated early customer traction before public launch
2024-05Series A extensionfinancing$35M extension; $75M total fundingAccel; Cyberstarts; SequoiaDoubled prior valuation and funded additional hiring
2025-04Channel program launchedpartnershipProgram live; GuidePoint named as resellerOasis; GuidePoint SecuritySignals a move from founder-led sales toward leveraged distribution
2025-05GuidePoint GPSEC sessiongovernancePublic conference placementGuidePoint; OasisShows NHI thought-leadership in channel events before Series B
2026-03-19Series B announcedfinancing$120M; $195M total fundingCraft Ventures; Cyberstarts; Sequoia; AccelCreates the capital base for broader GTM and agentic-AI expansion
2026-04-23President appointedgovernanceMichael DeCesare joinsOasisAdds a professional GTM leader after rapid ARR growth
2026-07-06Cyera acquisition talks reportedadverseReported only; not formally announcedCyera; OasisIntroduces strategic-option noise and a possible valuation reset near $1B

The chronology uses only dated events surfaced in reviewed public sources and keeps the July 2026 M&A rumor separate from completed financing facts.

[CO001, CO007, CO009, CO010, CO019, CO020]
FO001: Company milestone timeline

Public milestones show a rapid path from stealth exit to channel scale-up, Series B financing, and strategic-option speculation.

[CO001, CO007, CO009, CO010, CO019, CO020]

1.5 Exhibits

Chapter 02

02Market Analysis

2.1 Market boundary, included spend, and status-quo substitutes

The fastest way to misunderstand Oasis's market is to treat it as a rebranded secrets manager. Public sources instead define a broader problem set: NHIs now include application and service identities, API and OAuth tokens, machine and device identities, cryptographic identities, bots, workloads, and increasingly AI agents. That means the relevant spend boundary includes discovery, posture, ownership assignment, lifecycle governance, and runtime authorization for automated actors. It also means the status quo is fragmented. Some buyers try to solve parts of the problem with vaults or identity stores such as HashiCorp Vault; others lean on cloud-native IAM, SPIFFE-style workload identity, or manual CMDB ownership processes. Those substitutes can address credential issuance or low-level workload identity, but they do not by themselves create enterprise- wide governance over every machine identity and delegated AI action. The NHI market is therefore best viewed as a convergence layer sitting between traditional IAM/PAM, secrets management, platform engineering, and AI- governance workflows.[CM001, CM002, CM003, CM021, CM023, CM027]

Market definition table
Segment / categoryIncluded spendExcluded spendBuyer / payerRelevance to Oasis
Dedicated NHI governanceDiscovery, ownership, posture, lifecycle, remediation, policy orchestration for machine and AI identitiesHuman workforce IAM and pure user SSOCISO / IAM / platform-security sponsorsDirect target category
Vault / secrets managementSecret storage, issuance, rotation, identity-store plumbingFull business governance of every NHI and AI actionPlatform engineering / DevSecOpsStatus-quo substitute and integration point
Workload identity frameworksCryptographic workload identity for infrastructure and servicesBusiness-owner mapping, compliance workflows, cross-SaaS governancePlatform engineering / infrastructure teamsFoundational substitute, not full governance layer
Cloud-native IAMCloud permissions, roles, service principals within one hyperscalerCross-cloud, SaaS, and AI-agent lifecycle governanceCloud center of excellenceAdjacent incumbent
Agent identity / developer access platformsSession-scoped agent credentials and MCP-style identity boundariesBroad NHI posture and enterprise-wide ownership inventoryDeveloper tools / platform teamsEmerging adjacent spend

The boundary is intentionally drawn around governance and lifecycle control, not every product that can hold or mint a credential.

[CM001, CM002, CM003, CM027, CM028, CM029]

2.2 Sizing lenses, identity segmentation, and regional shape

Public market sizing for NHI governance is directionally strong but not numerically clean. Mordor Intelligence sizes the narrower NHI security segment at $8.22 billion in 2026 and $22.94 billion by 2031, while Research and Markets and its Yahoo Finance distribution partner place the broader NHI access-management category at $12.2 billion in 2026 and $38.8 billion by 2036. The spread is not noise; it reflects different boundaries. The broader estimate includes solution and services layers across identity types, deployment modes, organization sizes, and verticals, while the narrower estimate is closer to the security-control subset. Regional shape is clearer than precise SAM: North America currently leads, Asia-Pacific is forecast to grow fastest, and large enterprises dominate present demand. Identity-type segmentation is also explicit in the broader forecast: application and service identities, API and OAuth token identities, machine and device identities, cryptographic identities, and AI-agent identities are already first-class subsegments. The correct takeaway is that the market is real, large, and expanding quickly, but a clean Oasis-specific SOM is not public.[CM004, CM005, CM006, CM007, CM008, CM009]

TAM / SAM / SOM or sizing lens table
Publisher / lensYear / horizonGeographyValueGrowth / CAGRMethodology / limitation
Mordor Intelligence: NHI security market2026 / 2031Global$8.22B in 2026; $22.94B by 203122.78% CAGRNarrower security lens; useful for governance/control spend but not a published Oasis-specific SAM
Research and Markets / Yahoo: NHI access management2026 / 2036Global$12.2B in 2026; $38.8B by 203612.2% CAGRBroader access-management envelope including solutions and services across identity types
Regional lens from Yahoo / R&M2026Global by regionNorth America largest; Asia-Pacific fastest growthn/aQualitative regional hierarchy rather than a discrete submarket dollar table
Identity-type lens from Research and Markets2026-2036GlobalApplication/service; API/OAuth; machine/device; cryptographic; AI agent identitiesn/aSegmentation lens helps framing but does not by itself produce a clean SOM
Oasis-relevant serviceable slice2026North America + regulated enterprise priorityNot publicly isolatedn/aRequires management assumptions on attach rate, vertical focus, and buyer conversion

Market numbers are preserved as separate lenses because the public sources use different boundaries and forecast horizons; the final row is intentionally left non-numeric to avoid invented SOM precision.

[CM004, CM005, CM006, CM007, CM008, CM009]
FM001: Market sizing lens

Public market sources support a three-layer view: broad NHI access management, narrower NHI security, and a still-unpublished Oasis-like serviceable slice.

[CM001, CM004, CM006, CM007, CM033, CM037]
FM002: Market estimate range

Published estimates are best treated as a bounded range because the sources use different category definitions and forecast horizons.

[CM004, CM005, CM006, CM011, CM014]

2.3 Buyers, vertical use cases, and how adoption actually starts

Buyer structure matters because this category rarely belongs to one team. The product narratives of Oasis, Saviynt, Delinea, GitGuardian, Aembit, and HashiCorp all imply a shared-control model: IAM/PAM leaders care about identity governance, cloud and platform teams care about workload access patterns, and regulated business owners care about auditability and resilience. Oasis's own solution pages make the point concrete. The AI page emphasizes restricting AI agents to approved model suppliers and enforcing least privilege; the finance page ties the pain to PCI DSS 4.0, SOC 2, and digital-operations continuity; the healthcare page ties it to patient privacy, HIPAA/GDPR-style obligations, and uninterrupted care. Across the market, adoption typically begins with discovery and inventory, then moves into owner attribution and risk labeling, then lifecycle policy, and only later into runtime authorization or secretless enforcement. That sequence is a useful reminder that many buyers will first land on visibility and posture before they trust a vendor with inline access control.[CM015, CM021, CM022, CM025, CM026, CM029]

Segment / buyer map
SegmentBuyerUserPayer / budget ownerWorkflow triggerAdoption trigger
AI-agent governanceIAM or platform-security leadSecurity engineers; AI platform teamsShared between security and platform budgetsAI agents begin accessing enterprise data or toolsNeed to restrict delegated permissions and prove auditability
Regulated financial servicesCISO / IAM / compliance sponsorCloud-security and app teamsSecurity + compliance budgetsPCI DSS / SOC 2 evidence or toxic combinations in core workflowsAudit pressure plus resilience concerns
Healthcare / patient-data environmentsSecurity + privacy leaderInfra, app, and operations teamsSecurity + privacy budgetsRisk of patient-data leakage or care interruption from overprivileged service identitiesNeed for HIPAA/GDPR-style evidence and uninterrupted operations
Platform engineering / DevSecOpsPlatform engineering leaderDevelopers and SREsPlatform / infra budgetSecrets sprawl, token leakage, or service-account ownership gapsDesire for automation and short-lived access
Multi-cloud enterprise securityIAM / cloud-security directorCloud and identity ops teamsShared security budgetCross-cloud role sprawl and SaaS-to-cloud identity chainsNeed for unified visibility across fragmented tools

Budget ownership is shown as shared or split because public vendor materials imply multi-stakeholder buying rather than a single universal payer.

[CM030, CM031, CM032, CM033, CM034, CM038]
FM003: Buyer urgency / ownership map

Buyer ownership is split, and urgency is highest where compliance, AI-agent exposure, and platform sprawl intersect.

[CM030, CM031, CM032, CM033, CM035, CM036]

2.4 Growth drivers, adoption constraints, and the standards gap

The strongest growth driver is simple arithmetic: machine identities and AI agents are proliferating faster than human IAM systems were built to handle. Palo Alto says the machine-to-human ratio reached 109-to-1 in 2026 and continues to rise, while Axis Intelligence highlights both secrets sprawl and long-lived credential exposure. On top of that, NIST has now launched an AI Agent Standards Initiative, and vendors across the market are translating that into product narratives around open protocols, least privilege, and governance. But the same sources also reveal why market conversion will not be frictionless. OWASP-style maturity work shows a large adoption-to-protection gap; Cloud Security Alliance says enforceable controls do not yet exist; ITECS argues shadow AI is already outpacing visibility; and Delinea warns that AI agents often carry persistent, broadly privileged access. In practice, buyers are pulled forward by urgency and compliance, but held back by fragmented tooling, unclear ownership, and the operational burden of replacing entrenched vault or cloud-IAM patterns. That combination supports a fast-growing market with real friction rather than a straight-line land grab.[CM011, CM012, CM013, CM014, CM016, CM017]

Growth drivers and constraints table
Driver / constraintDirectionTimingImplicationDiligence ask
Machine identities rising from 82:1 to 109:1DriverCurrentProblem volume is compounding faster than human IAM headcount can respondAsk buyers how many service identities they inventory today and how fast the count is growing
99% AI-agent adoption with 40% already touching organizational dataDriverCurrentAgentic access is moving from future problem to present procurement triggerValidate whether access governance is now part of AI rollout checkpoints
Zero trust, open protocols, and emerging standards workDriverNear-termStandards activity legitimizes the category and expands budget conversationsCheck whether standards help or delay enterprise buying criteria
Secrets sprawl and long-lived valid credentialsDriverCurrentCredential leakage gives buyers a concrete operational pain pointQuantify how many incidents or audit findings map to NHI gaps
Shadow AI and immature controlsConstraintCurrentUnsanctioned use expands demand but also makes scoping and ownership harderAsk whether buyers can even produce a reliable AI-agent inventory
Fragmented tooling and substitute incumbentsConstraintCurrentVaults, cloud IAM, and workload identity tools can delay a dedicated platform purchaseIdentify what incumbent budget or tool Oasis-like products actually displace

Rows intentionally mix positive demand drivers and negative adoption frictions because the market is expanding quickly but not frictionlessly.

[CM011, CM012, CM013, CM016, CM017, CM018]
FM004: Adoption path from visibility to runtime control

Most buyers progress in stages from inventory to ownership to lifecycle policy before adopting session-scoped runtime controls.

[CM003, CM022, CM025, CM026, CM027, CM028]

2.5 Exhibits

Chapter 03

03Competitors

3.1 Landscape: direct peers, suite incumbents, adjacents, and substitutes

The competitive map around Oasis is crowded, but not flat. One cluster is the direct NHI and agentic-identity pure plays: Oasis itself, Entro, Aembit, and until its June 2026 Cisco absorption, Astrix. A second cluster is the suite incumbents: CyberArk, Saviynt, and Delinea, all of which approach the problem from broader identity- security or machine-identity platforms. A third cluster is runtime and infrastructure control: HashiCorp Vault, SPIFFE/SPIRE, and newer developer-first identity entrants such as WorkOS. These are not always direct displacement threats, but they are legitimate substitutes for specific buyer use cases. The key implication is that Oasis is rarely fighting a single category. In some deals it will be compared with lifecycle-governance peers; in others it will be asked why a buyer cannot extend an incumbent vault, PAM, or workload identity framework instead. That multi-category competition increases both buyer education burden and the importance of clear category ownership.[CP001, CP010, CP018, CP020, CP027, CP028]

Competitor profile table
Vendor / clusterRoleCore anglePublic signalStrategic implication
OasisDirect peer / category shaperHybrid NHI lifecycle governance plus agentic access narrativeCrowdStrike and Wiz integrations; sparse but positive reviewsStrong story if buyers want a unifying control plane
AembitRuntime-control adjacentSecretless, short-lived access for workloads and agentic AIHomepage centers runtime access and developer productivityThreatens Oasis when runtime control is the priority
EntroDirect peerDiscovery, classification, observability, remediation across code-to-cloud surfacesHomepage emphasizes AI agents and NHI observabilityCompetes closely on visibility plus remediation narrative
Astrix / CiscoDirect peer being absorbed into platformAI-agent and NHI security capabilities moving under CiscoStandalone sales ended June 30, 2026Consolidation can amplify distribution but reduce buyer choice
CyberArkSuite incumbentMachine identity visibility, automation, and lifecycle protectionState report anchors breach/outage urgency and installed-base logicDangerous in accounts that already trust CyberArk
SaviyntSuite incumbentGovernance-first NHI posture and remediation inside a broader identity cloudISPM launch and Wiz partnershipThreatens Oasis in governance-led accounts
DelineaSuite incumbentContinuous discovery plus privileged-access hygiene for NHIs and AI agentsDiscovery and secure-AI-agent messagingCan commoditize inventory and posture features

Profiles mix direct peers and adjacent incumbents because real procurement often compares Oasis against whichever identity, cloud, or access vendor already has internal sponsor support.

[CP001, CP004, CP005, CP006, CP007, CP011]
FP001: Competitive positioning map

The field spans suite breadth on one axis and runtime/access depth on the other, with Oasis positioned between broad governance suites and runtime-first adjacents.

[CP001, CP004, CP007, CP009, CP012, CP020]

3.2 Profiles: who owns lifecycle breadth versus runtime depth

The strongest profile contrast is between lifecycle-breadth vendors and runtime-depth vendors. Oasis, Entro, and Saviynt all emphasize discovery, contextual ownership, posture, and remediation. CyberArk competes with scale and lifecycle breadth for machine identities, but from a broader enterprise identity base and with certificate and secrets heritage. Delinea also pushes continuous discovery and privileged-access hygiene. By contrast, Aembit and HashiCorp are more explicit about short-lived or dynamic access patterns: Aembit sells secretless, policy-based runtime access for agentic AI and workloads, while HashiCorp validates OAuth-based AI-agent authentication and dynamic secrets. SPIFFE is even more infrastructure-native, offering a cryptographic workload identity control plane without the business-governance wrapper. These differences matter because buyers do not all value the same layer. A security leader worried about overprivileged orphaned identities may favor lifecycle governance; a platform team focused on eliminating static secrets may prefer runtime plumbing first.[CP002, CP003, CP004, CP005, CP007, CP009]

Feature / capability matrix
CapabilityOasisCyberArkSaviyntDelineaAembitEntro / Astrix
Discovery / inventory breadthYes; core narrative across hybrid systemsYes; machine identity observabilityYes; continuous discovery and postureYes; continuous discovery / inventoryNot primary storyYes; discovery and classification front and center
Lifecycle governance / remediationYes; provisioning, monitoring, decommissioning, remediationYes; lifecycle protection and automationYes; risk insights and automated remediationYes; governance and privileged hygienePartial; access-oriented controlsYes; remediation explicitly marketed
Runtime short-lived / secretless accessImplied via agentic access, not the clearest homepage wedgeNot core public wedge in reviewed pagesNot core public wedge in reviewed pagesNot core public wedge in reviewed pagesYes; secretless short-lived access is centralLess explicit in reviewed public materials
AI-agent-specific framingYes; agentic access message is prominentIndirect, via machine identities and AI-system securityYes; broader identity types include AI agentsYes; AI agents called out directlyYes; IAM for agentic AIYes; AI agent and NHI framing are explicit
Infrastructure-native primitivesIntegrates broadly but not a low-level primitive itselfSecrets / certificates / workload heritageSuite-led governance layerSuite-led governance layerAccess plane for workloadsDiscovery-led overlay, now Cisco-bound for Astrix
Distribution leverage visible publiclyCrowdStrike and Wiz partner surfacesInstalled-base and report authoritySuite brand plus ecosystem narrativeSuite brand and security-report postureRuntime niche positioningCisco pull for Astrix; direct branding for Entro

The matrix is qualitative because public pages emphasize capabilities and positioning rather than consistent, benchmarked performance metrics.

[CP002, CP003, CP004, CP005, CP007, CP009]
Pricing / packaging comparison
VendorPublic pricing posturePackaging clueProcurement implicationConfidence
OasisNo reviewed public list pricingEnterprise platform and partner-led motionRequires sales process or partner engagement for real comparisonMedium
CyberArkNo reviewed public list pricingEnterprise suite / machine identity platformBudget fit must be inferred from scope and installed-base leverageMedium
SaviyntNo reviewed public list pricingIdentity cloud / NHI module narrativeLikely sold into broader identity-cloud budgetsMedium
DelineaNo reviewed public list pricingIdentity security and discovery-led suite motionPricing comparison likely happens only inside enterprise processMedium
AembitNo reviewed public list pricingRuntime access / workload IAM motionCould be framed as infrastructure spend rather than broad governance spendMedium
Entro / AstrixNo reviewed public list pricingPure-play NHI / AI-agent security narrativePure-play value must be justified against incumbent bundlesMedium

This table intentionally captures pricing opacity rather than inventing package details; the absence of public price cards is itself a meaningful competitive fact for enterprise procurement.

[CP035, CP036, CP037]
FP002: Product maturity / capability map

The most durable differentiation is shifting from simple discovery toward the combination of lifecycle orchestration, runtime control, and distribution.

[CP027, CP028, CP029, CP031, CP033, CP034]

3.3 Distribution power, proof points, and switching dynamics

Distribution power is emerging as a decisive differentiator. Oasis has visible partner surfaces with CrowdStrike and Wiz, and both integrations tell a helpful story: the platform is not only finding identities, but also pulling in endpoint or cloud context and tying that to governed remediation. That is a more mature commercial signal than a standalone homepage claim. At the same time, Oasis's public proof remains thinner than its partner story. Gartner shows only one visible review, while SourceForge and Slashdot provide product- directory summaries rather than enterprise-grade reference depth. That asymmetry matters in head-to-head sales cycles. Switching costs also appear additive rather than fully replacement-oriented. Buyers can keep Vault, SPIFFE, cloud IAM, or other workload primitives and still add a governance layer on top. This makes the market structurally multi-home, which lowers outright rip-and-replace friction but raises the bar for proving why Oasis should become the unifying control plane rather than just another dashboard.[CP017, CP021, CP022, CP023, CP024, CP025]

FP003: Moat / readiness KPIs

Public signals suggest Oasis has real ecosystem momentum, but reference depth and pricing transparency still lag the product narrative.

[CP006, CP021, CP024, CP032, CP037]

3.4 Moat durability, consolidation, and commoditization risk

Oasis's moat is credible but not yet unassailable. The best version of the case is that it unifies inventory, contextual ownership, lifecycle action, and an agentic-access narrative in one market-facing platform. The weaker version is that many of those pieces are being added across the ecosystem: Saviynt and Delinea are deepening discovery and posture; CyberArk already owns a large machine-identity budget anchor; HashiCorp and Aembit attack static credentials through runtime patterns; and Astrix's absorption into Cisco shows that larger platforms want this capability set. The category may therefore commoditize from both ends — discovery and posture from suites, runtime access from infrastructure vendors. Public pricing opacity makes it harder to see who is cheapest, but that probably increases, rather than decreases, the role of distribution, deployment model, and reference depth in buying decisions. The result is a market where Oasis can still win, but only if it keeps moving from point capabilities to a visibly integrated control plane.[CP006, CP008, CP013, CP019, CP031, CP033]

Moat durability / competitive risk register
Risk or moat factorWho pressures itEvidenceImplication for OasisDiligence ask
Unified lifecycle governance storySuite incumbentsSaviynt, Delinea, and CyberArk all market discovery plus lifecycle breadthOasis must show integration depth, not just category vocabularyRequest proof that customers consolidate tools rather than add dashboards
Runtime access differentiationAembit / HashiCorp / WorkOS adjacentsShort-lived, secretless, or session-scoped access is a strong adjacent wedgeOasis cannot let runtime access become someone else's durable control planeClarify how often Oasis wins when runtime controls dominate
Distribution and platform pullCisco, CrowdStrike, Wiz, incumbent suitesAstrix joined Cisco; Oasis shows partner surfaces; suites have installed basesChannel and ecosystem leverage may matter as much as featuresQuantify sourced pipeline, attach rates, and reseller influence
Public proof depthGartner / directories reveal thin visible review volumeOne Gartner review plus directory descriptions are weaker than many enterprise buyers preferReference scarcity could slow later-stage procurementRequest customer references by vertical and deployment stage
Multi-homing / additive adoptionVaults, SPIFFE, cloud IAMBuyers can keep primitives while adding governance layersCategory may be additive, lowering rip-and-replace friction but also lock-inAsk whether Oasis displaces budgets or merely layers onto them
Consolidation and commoditizationCisco / suites / inventory expansionAstrix consolidation and broader suite feature expansion compress independent surface areaDiscovery-only narratives may commoditize faster than integrated control planesTrack whether Oasis can defend against bundling on breadth and execution

Rows focus on strategic durability rather than raw product checklists, because the real question is whether Oasis can remain control-plane-relevant as adjacent layers consolidate.

[CP006, CP017, CP019, CP030, CP031, CP032]

3.5 Exhibits

Chapter 04

04Financials

4.1 Revenue Model, Procurement, and Contract Stack

The best public evidence says Oasis sells recurring enterprise software, not project-based consulting. Its July 2025 SaaS subscription agreement is tied to an order and then layered with a public DPA and SLA, while AWS Marketplace routes buyers to custom private offers instead of fixed catalog pricing. That combination is the classic posture of an enterprise SaaS vendor that negotiates terms per customer and expects ongoing service delivery. The contract stack also shows that Oasis is already operating in procurement environments where privacy, uptime, and support commitments matter, which tends to correlate with annual or multi-year subscription selling rather than discretionary tooling purchases. The product surface behind that revenue model is broad enough to support expansion. Oasis does not only inventory non-human identities; it packages provisioning, ownership assignment, attestation, rotation, posture management, and decommissioning as lifecycle capabilities. The provisioning launch is especially relevant financially because it extends the product into workflow triggers such as Terraform, ServiceNow, and generic APIs, and into cloud and vault ecosystems including AWS, Azure, GCP, HashiCorp, CyberArk, and Azure Key Vault. That makes revenue quality more likely to come from platform embedment than from isolated point-feature adoption. Pricing transparency, however, remains weak. AWS Marketplace confirms buyers can request a private offer, but there is no public list price, seat metric, or asset-based tiering schedule that would let an outsider infer ACV. The result is that Oasis can be described as a custom-priced, enterprise-subscription software business with partner- assisted procurement, but not yet as a business whose realized price architecture is publicly visible.[CI001, CI002, CI003, CI004, CI007, CI008]

Revenue Streams Table
StreamMechanismUnitCurrent StatusRevenue QualityDiligence Ask
Platform subscriptionRecurring software access under order-backed SaaS agreementPer customer subscription termConfirmed by public contract stack; pricing undisclosedHigh if multi-year and stickyRequest ARR by cohort, term length, and renewal mix
Lifecycle governance add-onsProvisioning, ownership, rotation, attestation, decommissioning workflowsPer module / feature bundleCapabilities publicly marketed; attach rate undisclosedMedium to high; likely expansion leverRequest attach rates and module-level upsell data
Partner / marketplace procurementAWS Marketplace, CrowdStrike Marketplace, GuidePoint, Wiz-linked ecosystemPer negotiated contract / private offerConfirmed procurement routes; economics undisclosedMedium; improves reach but may compress realized marginRequest partner-discount schedules and channel share of ARR
Regulated-industry workflowsFinancial-services and other compliance-sensitive use casesPer enterprise deploymentBuyer need validated; realized pricing undisclosedMedium; may improve ACV and retentionRequest ACV by vertical and compliance use case
Support / service obligationsSLA-backed support and onboarding around the platformEmbedded in subscription or separate servicesSupport commitments are public; separate services revenue not disclosedUnknown; could compress gross marginRequest services mix, support cost, and onboarding effort per account

Rows describe public revenue mechanisms and analyst-inferred monetization levers. Oasis does not disclose revenue contribution by stream.

[CI001, CI003, CI013, CI016, CI019, CI036]
Pricing / Monetization Table
ElementPublic EvidenceList vs. Realized PricingUnknownsImplication
AWS Marketplace offerCustom pricing via private offerNo list price shownNo seat, identity, or asset metric disclosedSuggests negotiated enterprise pricing, not commodity SaaS
Direct SaaS subscriptionOrder-linked contract with renewal languageRealized pricing unknownDiscount bands, term lengths, minimums unknownContracts likely customized by customer size and complexity
Channel-led salesGuidePoint and partner program indicate reseller motionPartner economics unknownReseller margin, MDF, and co-sell splits unknownCould accelerate growth while lowering net realization
Marketplace / ecosystem integrationsCrowdStrike and Wiz routes improve procurement relevancePricing hidden behind enterprise negotiationBundled vs. standalone economics unknownIntegrations may improve win rate more than immediate price realization
Vertical compliance valueFinance page positions PCI DSS / SOC 2 / GDPR workflowsValue-based pricing plausible; no proof publicVertical ACV premium unprovenCould support premium pricing if validated in customer data

Public evidence supports negotiated pricing and partner-assisted procurement, but not realized ASP or discounting.

[CI007, CI014, CI016, CI017, CI036]
FI001: Revenue Model Bridge

Public documents point to a negotiated enterprise SaaS motion layered through contracts and partner-assisted procurement.

[CI001, CI003, CI013, CI019]

4.2 Delivery Model, Cost Structure, and Unit-Economics Signals

Oasis has not published unit economics, but its public architecture points to where the cost base likely sits. The Outpost pattern keeps sensitive identity operations inside the customer perimeter while the central platform handles control logic, metadata, lifecycle automation, and analysis. That setup suggests a software- heavy model whose marginal delivery burden should be dominated by engineering, cloud analytics, customer support, and partner enablement rather than by hardware, inventory, or large working-capital swings. The secret-rotation and governance pages reinforce that reading because they frame risk remediation as an automated recurring control, not as a manually staffed professional service. The strongest public production proof in this chapter is the financial-services case study. Oasis describes fast Azure AD deployment, auto- discovery, risk posture analysis, stale-account cleanup, and automated identity rotation for a private-credit customer. Even though the case study is company-authored and does not disclose contract value, it is still useful because it shows the platform can enter regulated customer workflows where compliance and credential hygiene are economically important. The finance-solution page further links the buyer case to PCI DSS 4.0, SOC 2, and GDPR-sensitive environments, which implies that the company is targeting use cases where budget owners often care about risk reduction, auditability, and operational resilience rather than only developer convenience. Still, the public record stops short of underwriting metrics. There is no disclosed ACV, gross margin, CAC, NRR, or services mix. The only defensible conclusion is qualitative: Oasis appears structurally capable of software-like margins, but no outsider can yet measure how much support, services, or channel discounting compresses those margins in practice.[CI005, CI006, CI012, CI014, CI015, CI018]

Unit Economics Table
MetricPublic Value / StatusConfidenceWhy It MattersDiligence Ask
ARRNot publicly disclosedLowCore denominator for valuation and sales efficiencyRequest current ARR and last 8 quarters by segment
Revenue growthCompany-reported fivefold ARR growth in prior year via GlobesLowSignals momentum but not auditable without base valueRequest audited or board-reported ARR bridge
Gross marginNot publicly disclosed; software-like margin potential inferredLowDetermines payback and operating leverageRequest gross margin bridge separating platform, support, services, and partner discounts
NRR / GRRNot publicly disclosedLowNeeded to evaluate expansion durabilityRequest NRR, GRR, cohort retention, and module expansion data
CAC / paybackNot publicly disclosedLowNeeded to test whether growth is capital efficientRequest S&M spend, CAC by channel, and payback at gross margin
Services burdenSupport/SLA obligations are public; scale of services work is notMediumServices can drag on margins if onboarding is labor intensiveRequest implementation hours, support tickets, and professional-services revenue share

This table intentionally distinguishes observable facts from non-public metrics that remain diligence blockers.

[CI005, CI006, CI023, CI026, CI037]
FI002: Unit Economics Bridge

The public record supports a qualitative, not quantitative, picture of Oasis unit economics.

[CI010, CI015, CI017, CI020, CI037]
FI003: Financial Estimate Range

Only the financing stack is directly disclosed; all other financial ranges remain unknown or narrative-backed.

[CI021, CI022, CI033]

4.3 Capital Adequacy, Funding Context, and Missing Runway Inputs

Oasis clearly has capital to keep investing, but public sources do not reveal enough to convert that fact into a runway model. The March 2026 Series B brought in $120 million, and contemporaneous reporting from Newswire, Globes, and SiliconANGLE framed the round around the security problem created by enterprise AI agents and non- human identities. Globes additionally reported total capital raised of $195 million, a roughly $700 million valuation according to market sources, a fivefold ARR increase, and a customer base composed mostly of Fortune 500 companies. Even if those traction figures are company-supplied rather than audited, they are directionally important: Oasis is not financing itself from a position of obscurity. What remains hidden is the balance- sheet side of the story. Public materials reviewed here do not disclose cash on hand after the Series B, monthly burn, gross margin, or net revenue retention, and no debt facility or credit line surfaced in the chapter evidence. GuidePoint’s OASIS+ positioning shows federal go-to-market intent, and the channel program plus marketplace listings show an expanding partner motion, but none of that translates into a quantified revenue split between direct, federal, or partner-led business. The right conclusion is therefore asymmetric. Oasis looks well funded for near-term product and go-to-market expansion, especially relative to the early age of the company, but the evidence is still too incomplete to estimate remaining runway or the next-round trigger with confidence. A diligence team would need monthly financial statements, ARR history, and concentration data before taking a hard view on capital adequacy.[CI016, CI017, CI021, CI022, CI023, CI024]

Capital Adequacy Table
ItemPublic Value / StatusConfidenceWhy It MattersDiligence Ask
Latest round2026 Series B raised $120MHighFresh external capital extends operating runwayConfirm close-date cash received and any escrow or tranched conditions
Total raised~$195M reported by GlobesMediumShows cumulative capital support since foundingReconcile cap table and total primary capital raised
Valuation context~$700M valuation reported by market sourcesMediumSets expectations for growth and next-round proof burdenConfirm post-money, preferences, and option pool impact
Debt / project financeNo public debt facility identifiedMediumAbsence of debt reduces fixed financial obligationsConfirm whether venture debt, lines, or SAFEs exist
RunwayCannot be estimated confidently from public dataLowBurn and cash balance are missingProvide monthly burn, cash balance, and board runway forecast

Funding is well evidenced; runway is not. Public evidence should not be mistaken for a complete liquidity view.

[CI021, CI022, CI024, CI025, CI038]
FI004: Capital Intensity / Cash-Flow Map

Public evidence suggests a software-led cost base but leaves major quantitative holes around burn and margin.

[CI018, CI025, CI037, CI038]

4.4 Peer Benchmarks for Revenue Quality and Capital Intensity

Because Oasis is private, public identity and security vendors provide the only clean recurring-revenue benchmarks. Okta, SailPoint, Rubrik, and CyberArk all reported billion-dollar subscription or ARR scale in 2026-period disclosures, and both Okta and SailPoint also have current SEC filing trails that confirm the market treats identity security as a recurring software category. These companies are not direct product matches for Oasis, but they do establish the economic language that investors and acquirers use for identity businesses: subscription revenue, ARR, SaaS ARR, RPO, and large-customer recurring cohorts. Those peers also show why Oasis’s missing disclosures matter. If management can substantiate strong ARR growth, healthy retention, and software-like gross margin, then the company can plausibly be framed against a premium identity-security revenue model rather than against services or infrastructure resellers. If not, the same lack of transparency can become a discount factor. In that sense, the comparable set is helpful not because it yields a precise multiple for Oasis today, but because it defines the proof burden Oasis would need to satisfy in a financing or acquisition process. Analyst valuation research sharpens the point. Windsor Drake’s Q2 2026 IAM report places mainstream public IAM near 6.0x NTM revenue while non-human and AI-agent identity platforms can clear a 15x-30x range. Finro’s warning that mature public cyber comps can mislead on AI-native private companies is directionally fair, but it also cuts both ways: without hard ARR and margin evidence from Oasis, the premium part of that range is aspirational rather than underwritten.[CI028, CI029, CI030, CI031, CI032, CI033]

4.5 Financial Verdict and Diligence Blockers

The financially attractive interpretation of Oasis is straightforward. It appears to be a contract-backed, custom-priced enterprise SaaS company selling into a painful and expanding identity problem, with enough product depth to support expansion and enough fresh capital to keep pressing the market. The public peer set shows that identity-security winners can become very large recurring-revenue businesses, and Oasis’s partner footprint suggests it is trying to scale through both direct enterprise relationships and distribution channels. The problem is that the public evidence stops at narrative quality and fundraising quality. There is no auditable public view of ARR, revenue mix, gross margin, burn, NRR, CAC, or concentration. Even pricing is opaque beyond the fact that it is quote-based. As a result, Oasis’s financial chapter should be read as structurally favorable but not yet underwritable from public information alone. For diligence, that means the gating items are specific and unavoidable: a quarterly ARR bridge, segment and channel mix, gross margin by component, burn and runway materials, and concentration data for top customers and partners. If management can produce those quickly and the numbers are consistent with the growth narrative, the financial posture strengthens materially. If not, the absence of disclosure itself becomes a risk factor because valuation expectations are already being influenced by premium-category narratives around non-human identity and agentic access.[CI026, CI033, CI034, CI035, CI036, CI038]

Public Financial Gaps Table
Missing MetricImpactWhy It MattersExact Diligence Path
Current ARR and quarterly historyMaterialNeeded for valuation, growth, and capital planningRequest quarterly ARR bridge for 8 quarters with new / expansion / churn components
Gross margin and COGS splitMaterialNeeded to judge software quality and paybackRequest gross margin by platform, support, services, and partner discounting
Burn, cash balance, and runwayMaterialNeeded to assess financing dependencyRequest monthly P&L, balance sheet, and board runway deck
Federal / channel / top-customer concentrationMaterialNeeded to assess durability and downside riskRequest top-10 customers by ARR, federal/commercial split, and channel contribution
Pricing realization and discountingHighNeeded to connect narrative demand to revenue qualityRequest price book, sample MSAs/order forms, and realized discount analysis

These are the minimum private data requests required before an investor can underwrite Oasis on economics rather than narrative.

[CI026, CI027, CI035]

4.6 Exhibits

Chapter 05

05Product & Technology

5.1 Product Definition and Module Map

Oasis no longer presents itself as only a non-human identity inventory vendor. The public product story now has two connected layers. First is the legacy NHI management platform covering governance, posture, and secret rotation across service accounts, applications, roles, keys, and other machine identities. Second is Agentic Access Management, which extends those controls to AI agents that reason and act across enterprise systems. The core product promise is not merely “discover the identities” but “convert every machine or agent action into a governed identity workflow” through provisioning, ownership, approval, policy enforcement, rotation, and decommissioning. That module map is unusually coherent for a young category. Oasis’s governance page concentrates on secure provisioning, ownership assignment, privilege control, rotation, attestation, and decommissioning. The posture-management page adds analytics for compromise attempts, toxic combinations, policy violations, and anomalies. The secret-rotation page then translates those insights into operational action by structuring discovery, observation, policy management, safe rotation, and lifecycle cleanup. For AI agents, AAM adds intent analysis, short-lived session identities, and chain-of-custody logs tying prompts to actions. Taken together, Oasis is building a control plane for who or what can act, why they can act, how long that access lasts, and how the action is audited after the fact.[CE001, CE002, CE003, CE004, CE005, CE015]

Product Module / Asset Matrix
ModulePrimary UserCurrent Public StatusDifferentiationDiligence Gap
Agentic Access ManagementIdentity / security teams managing AI agentsPublicly launchedIntent-aware control plus JIT identities and audit trailsNeed production benchmarks and deployment counts
GovernanceIdentity / IAM administratorsPublic solution pageOwnership, attestation, privilege controls, decommissioningNeed workflow depth and admin-scale evidence
Posture ManagementSecurity operations / cloud securityPublic solution pageAI analytics for anomalies, toxic combinations, and prioritizationNeed false-positive and remediation-rate data
Secret RotationSecurity + platform engineeringPublic solution pageAutomated rotation and lifecycle cleanup rather than manual scriptsNeed rotation-success metrics across environments
NHI Provisioning / OutpostPlatform / DevSecOps teamsPublicly described in blogs and solution pagesCloud- and vault-agnostic provisioning with in-perimeter executionNeed customer references and architecture depth

Status is based on public product and blog surfaces rather than customer-count disclosures.

[CE001, CE011, CE015, CE016, CE017, CE036]
Workflow / Use-Case Table
User JobCurrent WorkflowOasis SolutionMeasurable Benefit ClaimedLimitation
Govern AI-agent actionsAgent decides to act across enterprise toolsIntent analysis, policy enforcement, JIT identity, audit chainReduced standing privilege and clearer accountabilityNo public efficacy benchmark
Discover shadow AI and unmanaged agentsSecurity teams inspect endpoints, SaaS, and cloud for emerging usageAI-solution visibility and metadata analysisEarlier discovery of unauthorized tools and NHIsCoverage depth by environment is not published
Provision machine identities securelyDevelopers or app owners request new identityTerraform / ServiceNow / API / UI approval workflow with automated creationFaster provisioning with policy from day oneNo public cycle-time metrics
Prioritize risky identitiesTeams triage posture issues manuallyPosture analytics detect compromise attempts and toxic combinationsHigher prioritization accuracy is impliedNo public precision / recall data
Rotate or retire secrets safelyTeams rotate or decommission credentials after risk or policy triggersDiscover-observe-manage lifecycle with safe rotation and cleanupLower exposure from stale credentialsNo public success-rate data by connector

Benefits are company-claimed unless explicitly described as production case-study outcomes.

[CE002, CE003, CE007, CE012, CE016, CE017]
FE001: Product Architecture Map

Oasis’s public product story layers governance, analytics, provisioning, and agentic runtime control on top of enterprise identity estates.

[CE001, CE011, CE015, CE016, CE017, CE033]

5.2 Architecture and Deployment Model

The public architecture pattern is that of a governance control plane layered across heterogeneous identity environments. Oasis documents provisioning workflows that can start in Terraform, ServiceNow, a generic API trigger, or the Oasis UI. It also supports both credential-based and federated identities, which matters because it allows buyers to choose between directly managed secrets and trust-based access patterns such as managed identities, IAM roles, and OIDC. This is not the footprint of a narrow secrets vault; it is a product trying to sit above multiple identity primitives and orchestrate lifecycle controls around them. Oasis Outpost is the most important architectural clue. Outpost is described as a collector container that lives inside the customer’s cloud perimeter so that privileged identity operations, secret generation, and secret storage stay local. Oasis itself exchanges control messages and metadata rather than becoming a backdoor into the customer environment. That design supports enterprise acceptance because it reduces the trust leap customers must take when automating sensitive machine credentials. It also suggests Oasis is optimizing for governance and orchestration rather than for owning every enforcement point directly. The case study in financial services adds practical deployment evidence. Oasis describes rapid Azure AD integration, auto-discovery, posture analysis, stale-account cleanup, and automated identity rotation. Even though the case study is company- authored, it demonstrates that the product is meant to be installed into live enterprise identity estates rather than offered as a conceptual roadmap-only platform.[CE006, CE007, CE008, CE011, CE012, CE013]

Technology / Operating Architecture Table
Layer / ComponentRoleDependencyRisk
Policy engineEvaluates intent and access against governance rulesAccurate context and policy definitionsPolicy drift or ambiguous intent interpretation
JIT session identity serviceIssues short-lived least-privilege credentialsUnderlying identity providers and session plumbingFailed issuance or poor scoping could block workflows
Outpost collectorExecutes privileged identity operations inside customer perimeterCustomer cloud / container environmentOperational overhead and deployment friction
Provisioning connectorsIntegrate Terraform, ServiceNow, APIs, UI-triggered workflowsThird-party APIs and workflow systemsConnector fragility if APIs change
Analytics / posture layerDetects anomalies, toxic combinations, and risk posture issuesTelemetry quality and data normalizationFalse positives or blind spots if telemetry incomplete
Integration fabricBrings in Wiz, Zscaler, Cursor, marketplaces, and other ecosystemsPartner products and commercial relationshipsStrategic dependence on partner roadmaps

This table reflects the operating pattern publicly described across Oasis pages and ecosystem announcements.

[CE002, CE003, CE012, CE014, CE019, CE020]
FE002: Customer Workflow / Operating Flow

The public workflow begins with discovery and request intake, then moves through policy, provisioning, execution, and audit.

[CE003, CE006, CE012, CE013, CE018]
FE003: Critical Dependency Map

Oasis’s architecture depends on identity sources, workflow systems, enforcement partners, and operator context.

[CE012, CE014, CE019, CE020, CE033, CE035]

5.3 Integration Ecosystem and Operator Workflow

Oasis’s operator workflow depends heavily on integrations rather than on a closed-stack assumption. The Wiz integration enriches Oasis with issues and data-security posture findings so identity actions can be prioritized by blast radius. The Zscaler partnership pairs identity governance with inline enforcement for machine-to-machine and agentic traffic. The Cursor partnership shows how the model extends up-stack into the agentic IDE, where agents run commands, call MCP tools, and interact with internal systems. Finally, the CrowdStrike marketplace motion and AI Access Partnership Program show that Oasis wants to be embedded inside broader enterprise AI and security buying journeys, not merely sold as a standalone dashboard. This ecosystem posture is strategically important. It allows Oasis to capture context from cloud exposure platforms, influence execution in zero-trust enforcement layers, and plug directly into developer and AI-agent workflows. That breadth may expand distribution and stickiness, but it also means the product’s value is partly dependent on maintaining interoperability across third-party systems whose own APIs and product strategies will evolve. In technical terms, Oasis appears to be building the identity-governance layer that normalizes signals from many systems and turns them into bounded, auditable access decisions.[CE009, CE010, CE019, CE020, CE021, CE033]

FE004: Product Maturity / Capability Map

Public evidence is strongest on workflow breadth and ecosystem reach, weaker on externally benchmarked performance proof.

[CE018, CE019, CE020, CE032, CE036]

5.4 Trust, Standards, and Technical Maturity

Oasis’s trust story has three pillars: auditability, standards alignment, and technical credibility. Auditability comes from the AAM claim that each agent action is logged from prompt to action through a chain- of-custody record. Standards alignment comes from the AAM Framework launch and the broader NIST AI Agent Standards Initiative, which together show that the company is trying to anchor its narrative in a maturing external governance conversation rather than in product marketing alone. Technical credibility is reinforced by the OpenClaw disclosure, where Oasis researchers publicly detailed an agent-takeover chain and said the upstream team shipped a fix within 24 hours. At the same time, the standards environment is still early. NIST’s initiative is oriented around secure interoperability and open protocols, not a mature checklist buyers can simply adopt today. That creates an opening for Oasis to shape best practices, but it also means many of its governance claims are ahead of stable third-party certification norms. Public materials further highlight developer-signal through recruiting and engineering culture, yet they do not surface the kind of deep public API or package ecosystem that would make technical adoption easy to independently inspect. So the current technical-maturity signal is strong on narrative coherence and growing ecosystem relevance, but lighter on public benchmarks and open implementation proof.[CE022, CE023, CE024, CE025, CE026, CE027]

Trust / Quality / Compliance Table
Control / SignalStatusScopeEvidence QualityGap
Prompt-to-action audit chainPublicly describedAAM agent sessionsMedium — company product page and launch PRNo sample audit artifact or schema published
AAM FrameworkPublicly launchedAgentic-access governance model and maturity assessmentMedium — PR-backed but still company-ledNo independent adoption data
NIST standards alignmentRelevant external initiativeSecure interoperability / open protocols for AI agentsHigh for existence, low for implementation specificityStandards still emergent
Research capabilityPublic OpenClaw disclosureAI-agent threat analysisMedium — company-authored but concrete incident narrativeNeed broader repeatability of research output
Developer signalCareers and AI-native engineering writingHiring and engineering cultureMedium — real signal but indirectNo public SDK/package ecosystem surfaced

This table captures trust and maturity signals, not a substitute for formal certification review.

[CE022, CE023, CE025, CE028, CE032]

5.5 Roadmap Direction and Product Risks

The public roadmap is visible in the release chronology even without a formal product roadmap file. Oasis began with NHI lifecycle management, then added more explicit provisioning and governance workflows, and by late 2025 to mid-2026 had clearly pivoted into agentic access management, ecosystem partnerships, and a practitioner-built governance framework. That is a credible expansion path because AI agents inherit the same underlying identity problems as service accounts and workload identities, only with higher autonomy and faster decision loops. The main technical risks are equally clear. First, the company is making high-value claims about intent analysis, policy enforcement, and lifecycle automation without publicly released benchmark data, throughput metrics, or efficacy comparisons. Second, the architecture depends on continued cooperation from cloud, vault, IDE, and security-platform partners. Third, developer-signal is present mostly through recruiting and thought leadership rather than a visible open-source or SDK footprint. None of these risks breaks the product thesis, but they do mean that buyer diligence should move quickly from “the story sounds right” to “show the implementation detail, deployment evidence, and performance data.”[CE029, CE030, CE031, CE032, CE033, CE034]

Roadmap / Release / Development-Stage Table
Date / StageFeature or MilestoneStatusImplicationSource
2025-10AAM Framework launch with SequoiaPublic launchMoves Oasis into governance-framework territory for agentic AIPR Newswire framework
2025-11Agentic Access Management launchPublic launchExtends Oasis from NHI lifecycle into AI-agent runtime controlPR Newswire AAM
2026-01Gartner AI TRISM mentionPublic market-validation signalSuggests external market attention to the categoryOasis Gartner blog
2026-06Cursor governed-access announcementPublic integration launchShows product fit inside agentic developer workflowsOasis Cursor blog
2026-06Wiz Integration Network announcementPublic integration launchLinks identity governance to cloud exposure and DSPM findingsOasis Wiz blog
2026-06Zscaler and CrowdStrike ecosystem pushesPublic partnership launchesBroadens enforcement and procurement surfacesOasis partner blogs

Public roadmap signals show direction and sequencing but not full GA maturity details or adoption counts.

[CE021, CE022, CE024, CE033, CE036]

5.6 Exhibits

Chapter 06

06Customers

6.1 Customer Base Segmentation and Vertical Mix

Oasis’s public customer story is clearly enterprise-first and heavily skewed toward regulated or operationally complex environments. The broadest signal comes from its own about page, which says leading organizations across many industries use the product. More specific signals come from Newswire and Globes, which say Oasis serves dozens of Fortune 500 companies and that a majority of the client base comes from the Fortune 500. The vertical pages and case-study surfaces point most strongly to healthcare, financial services, logistics, insurance, manufacturing, and large consumer brands. Those are precisely the environments where machine identities proliferate fastest, operational downtime is expensive, and audit pressure is real. The interesting nuance is that Oasis sells into both end-user enterprises and partner-facing ecosystems. The AI Access Partnership page pitches enterprise AI vendors who want governance out of the box, not only the final enterprise buyer. GuidePoint, CrowdStrike Marketplace, and Wiz extend the route to market further, showing that customer access may come through procurement vehicles and partner workflows as much as through direct sales. This broadens acquisition paths but makes it harder to see the exact composition of the installed base from public evidence alone. The end result is a customer map with strong top-end enterprise bias, decent vertical richness, and weak denominator transparency. Public materials make it plausible that Oasis is landing with large complex buyers, but they do not disclose how many customers exist in each segment or which segments dominate recurring revenue.[CU001, CU008, CU009, CU010, CU018, CU027]

Customer Segmentation Table
SegmentPublic ProofPrimary Use CaseEvidence QualityStrategic ValueKey Gap
Fortune 500 / large enterpriseNewswire and Globes say dozens / majority Fortune 500; home page shows F50/F500/F300/F200 examplesGovern NHI and AI-agent access in complex environmentsMediumHigh — validates enterprise relevanceNo disclosed customer count or ARR by segment
Financial servicesPrivate-credit Azure case; Antares whitepaper; finance solution page; targeted Bank of America ABM pageVisibility, rotation, lifecycle governance, complianceMediumHigh — regulated buyer with strong budget logicNamed production references still limited
HealthcareHealthcare-provider case; healthcare solution page; Fortune-50 outcome claimAudit readiness, visibility, uninterrupted care operationsMediumHigh — compliance-driven stickiness potentialOutcome claims are company-authored
Industrial / manufacturingIndustrial Azure webinar; F200 manufacturing M&A compliance claimClassify NHIs, remediate excessive privilege, compliance across acquired envsMediumMedium to high — complex hybrid estatesNamed customer absent in webinar
Logistics / insurance / CPGHome-page outcome claims onlyOperational resilience and rotation efficiencyLow to mediumMedium — shows breadth beyond finance/healthcareMostly anonymous and lightly detailed
Partner-facing AI vendorsAI Access Partnership ProgramEmbed governance into AI products for enterprise salesMediumMedium — expands route-to-market beyond direct buyersPipeline signal, not deployment proof

The segmentation view mixes named customers, anonymous case studies, and company-claimed outcome examples.

[CU001, CU008, CU009, CU010, CU018, CU032]
FU001: Customer Journey Map

Oasis’s strongest public journey starts with high-complexity identity pain and moves into governed lifecycle automation.

[CU002, CU011, CU018, CU024, CU025, CU038]

6.2 Named Customer Proofs and Case-Study Depth

The richest public customer evidence is mostly company-authored, but it is not empty marketing fluff. Oasis has surfaced detailed deployment narratives in multiple sectors. A private-credit firm in financial services is described using Oasis in Azure AD for visibility, tailored security policies, stale-account cleanup, and automated identity rotation. A healthcare-provider case study is more data-rich still: the environment reportedly had 8,500 human identities, more than 100,000 NHIs, over 50,000 certificates, and around 10,000 service accounts, all being managed by an 18-person security team and roughly 50-person IT-operations team. An industrial-company webinar adds an Azure remediation and compliance narrative. Two named public references stand out. Mars appears in a dedicated April 2026 case-study resource focused on hyper-fragmented cloud identity visibility. Antares appears in the financial-services whitepaper as a user that streamlined lifecycle management and reduced manual work. These named references are stronger procurement-grade proof than anonymous vertical cases, though they still lack contract details, deployment length, or expansion history. By contrast, the Bank of America account page should be treated as account-based marketing, not as evidence of a live deployment. The core diligence takeaway is that Oasis has real use-case depth and at least some named public proof, but the public evidence remains unevenly distributed. Named customer proof exists, yet many of the most operationally informative case studies still remain anonymous.[CU002, CU011, CU012, CU013, CU014, CU015]

Named Customer Proof Table
Customer / ReferenceSegmentDeployment / Use CaseProduction vs PilotOutcome / EvidenceLimitation
MarsGlobal consumer brand / manufacturingHyper-fragmented cloud environment; visibility into service accounts and API keysAppears production-oriented case studyDedicated April 2026 case-study resourceContract scope, duration, and expansion unknown
AntaresFinancial servicesLifecycle management and manual-effort reductionAppears production-oriented whitepaper referenceNamed in financial-services whitepaperNo quantitative before/after metrics beyond qualitative benefit
Private credit firm (unnamed)Financial servicesAzure AD visibility, stale-account cleanup, automated identity rotationAppears production-oriented case studyOperational steps and CISO quotes includedCustomer name withheld
Healthcare provider (unnamed)HealthcareVisibility across 100,000+ NHIs in hybrid cloudAppears production-oriented case studyDetailed environment and team-size metricsCustomer name withheld
Industrial company (unnamed)Industrial / manufacturingAzure NHI discovery, privilege remediation, compliance improvementLikely production or late-stage deploymentWebinar describes concrete workflow problems and remediationCustomer name withheld
Bank of America pageFinancial-services ABM targetEnterprise-specific marketing pageNot proofShows Oasis targets very large banking estatesShould not be counted as a live-customer reference

This enumeration is intentionally partial and separates proof from non-proof.

[CU011, CU012, CU013, CU014, CU015, CU016]
FU003: Customer Proof Matrix

Public customer proof is strongest on operational detail inside company-authored cases and weakest on independent retention visibility.

[CU017, CU020, CU023, CU030, CU035, CU038]

6.3 Adoption Signals, Review Surfaces, and Independent Customer Voice

Public adoption signals are strongest when Oasis speaks about enterprise outcomes and weakest when outside review platforms are examined. On the positive side, the home page lists multiple enterprise results: a Fortune-50 healthcare provider avoiding an estimated HIPAA fine, a Fortune-500 logistics buyer cutting secret- rotation effort by 35%, an insurance customer containing an outage impacting half of production workloads, and a manufacturing customer enforcing M&A compliance on newly acquired environments. The product page adds a Fortune 1000 quote about discovering 17,000-plus non-human identities in a cloud environment. Those signals are meaningful because they imply the product has been used inside live operational settings. The independent- customer-voice layer is much thinner. Gartner Peer Insights shows a 4.6 out of 5 rating from 20 ratings on the captured page, which is directionally positive. But that is still a relatively small sample for a company claiming dozens or more large-enterprise deployments. SourceForge and Slashdot provide product listings, yet the captured SourceForge page shows an overall 0.0/5 and both long-tail review sites offer very limited review substance. That does not prove customer dissatisfaction, but it does mean the public review surface is shallow outside Gartner. Investors should therefore separate two truths. First, Oasis likely has real enterprise adoption. Second, independent public voice remains too sparse to say much about broad satisfaction, ease of deployment, or renewal behavior at scale.[CU003, CU004, CU005, CU006, CU007, CU020]

Customer Growth / Adoption Trajectory Table
Public SignalValue / ObservationDateConfidenceImplicationMissing Denominator
Fortune 500 presenceDozens of Fortune 500 customers2026-03-19MediumLarge-enterprise traction appears realTotal customer count unknown
Fortune 500 mixMajority of client base reportedly from Fortune 5002026-03-19MediumInstalled base may be concentrated in large accountsNo breakdown by ARR or logo count
Multi-year enterprise agreementsMost new ARR reportedly driven by multi-year agreements2026-03-19MediumPositive durability signalNo renewal or retention data
Healthcare provider complexity>100,000 NHIs, 50,000+ certificates, ~10,000 service accounts2026-04-22MediumShows product used in large, messy estatesSingle case, anonymous customer
Fortune 1000 quote17,000+ NHIs in cloud environmentcurrent on captured product pageMediumConfirms visibility pain point and enterprise scaleSingle quote, unnamed customer
Review sample4.6 / 5 from 20 Gartner ratings2026 captureMediumSome positive independent voice existsSample too small for cohort-level inference

This table records public adoption signals, not audited company KPIs.

[CU002, CU008, CU009, CU020, CU024]
Retention / Repeat Usage / Satisfaction Table
Metric / SignalPublic ValueSegment / SurfaceConfidenceWhy It Matters
Gartner rating4.6 / 5 from 20 ratingsIndependent review surfaceMediumBest available independent satisfaction signal
Multi-year enterprise agreementsMost new ARR reportedly multi-yearLarge enterpriseMediumSuggests some durability and procurement commitment
Ongoing lifecycle workflowsCase studies emphasize ongoing governance, rotation, ownership, and postureFinancial services / healthcare / industrialMediumImplies repeat usage rather than one-time audit
Independent review depthThin outside Gartner; SourceForge/Slashdot shallowLong-tail public review surfacesMediumLimits confidence in broad satisfaction conclusions
Retention statisticsNo public NRR / GRR / churnAll segmentsHighMajor diligence blocker for customer durability

Public durability evidence is mostly qualitative.

[CU020, CU021, CU022, CU023, CU024, CU025]
Independent Customer-Proof Quality Table
SurfaceWhat It ShowsEvidence StrengthMain Limitation
Gartner Peer Insights4.6 rating from 20 ratingsMediumSmall sample, limited qualitative detail in capture
SourceForgeProduct presence but 0.0/5 captured on pageLow / adverseMay reflect shallow coverage more than poor product quality
SlashdotProduct listing and category presenceLowVery limited outcome specificity
GuidePoint / partner procurementSales route into federal and enterprise accountsMediumDoes not prove end-customer adoption
Company-authored case studiesOperational depth across verticalsMedium to highPotential selection bias and limited referenceability

This table distinguishes public proof quality from customer count or retention.

[CU017, CU020, CU021, CU022, CU023, CU035]
FU002: Adoption / Deployment Funnel

The public deployment path is evidence-rich on enterprise need and use-case depth, but not on conversion math or retained cohorts.

[CU006, CU019, CU024, CU026, CU031]

6.4 Retention, Expansion, and Concentration Risks

The public record provides only one direct durability signal: Newswire said most new ARR is driven by multi- year enterprise agreements. That is a useful clue because multi-year contracts generally indicate some stickiness and customer commitment. The case studies also describe ongoing governance work rather than one- time assessments, which supports a recurring-usage interpretation. But the public evidence stops there. No NRR, GRR, churn, cohort, renewal-rate, or contract-length distribution is available, and no public customer count makes it possible to turn named proof into a credible penetration or concentration model. Concentration risk is the largest unresolved customer question. If Oasis truly serves dozens of Fortune 500 companies yet remains early in total count, then a small number of very large accounts could influence revenue heavily. The public record also does not reveal how much business arrives through GuidePoint, CrowdStrike Marketplace, Wiz- driven workflows, or the broader partner channel. Those routes are clearly important for acquisition and procurement access, but they could also concentrate bargaining power or distort deployment ownership if overused. The right diligence posture is cautious optimism. Oasis’s public customer evidence is strong on workflow relevance and deployment anecdotes, but weak on retention math and concentration visibility. That means customer quality cannot be fully underwritten without internal cohort and segment data.[CU024, CU025, CU026, CU027, CU028, CU036]

Expansion and Concentration Risk Table
Expansion Driver / RiskPublic EvidenceImpactConfidenceDiligence Path
Land-and-expand through lifecycle modulesCase studies describe governance, rotation, posture, and provisioning workflowsCould increase stickiness and ACV over timeMediumRequest module attach rates and expansion by cohort
Partner-assisted procurementGuidePoint, CrowdStrike Marketplace, Wiz, channel programCould widen access but shift bargaining power to partnersMediumRequest partner-attributed ARR and pipeline share
Large-enterprise concentrationDozens / majority Fortune 500 claimsCould make revenue dependent on a small set of accountsLow to mediumRequest top-10 customers by ARR and logo count
Federal / regulated concentrationGuidePoint OASIS+ and vertical pages show strong regulated pushCan strengthen durability but also raise procurement frictionLow to mediumRequest revenue split by vertical and by federal route
POV-to-production conversion uncertaintySome high-profile home-page proof is explicitly a POVCan overstate production traction if not convertedMediumRequest POV conversion rate and time-to-production

Concentration analysis is constrained by the lack of customer-count and ARR concentration data.

[CU024, CU027, CU028, CU031, CU036, CU037]

6.5 Exhibits

Chapter 07

07Risks

7.1 Risk Stack Overview and Severity Ranking

Oasis is addressing a real problem, but it is doing so in a threat environment moving faster than standards, buyer education, and public proof. The external context is unusually harsh. NIST’s AI Agent Standards Initiative is still at the stage of industry-led protocols and gap analysis rather than enforceable controls, while the Cloud Security Alliance says enterprises already need practical governance now. At the same time, machine identities vastly outnumber humans, AI agents are proliferating, and multiple recent incidents show how fragile the surrounding toolchain can be when trust boundaries are weak. That creates a distinctive risk profile. Oasis is not primarily exposed to a single catastrophic regulatory ban or a single hardware dependency. Instead, its biggest risks stack on top of each other: selling ahead of settled standards, relying on multiple partner ecosystems, proving control quality without much public benchmark evidence, and serving demanding regulated buyers whose procurement cycles are long and security-review burden is high. The product thesis may be right while the execution bar keeps rising. The implication for investors is that the most important risks are not abstract. They are monitorable: whether enterprise security reviews shorten, whether integrations remain stable, whether public proof matures beyond research and narrative, and whether management can turn category urgency into trusted large-scale deployment without strategic distraction.[CR001, CR002, CR022, CR024, CR037, CR039]

FR001: Risk Heatmap

Oasis’s top risks cluster around trust conversion, ecosystem fragility, and proof lag rather than a single fatal compliance event.

[CR001, CR007, CR026, CR028, CR029, CR042]

7.2 Regulatory, Legal, and Trust Risk

Oasis is selling into environments where compliance and trust burden are high, but the external standards layer is not yet mature. NIST is building agentic-AI standards around secure interoperability and open protocols, while CSA explicitly argues that enterprises are operating before agent-specific controls are settled. This mismatch is risky: Oasis can benefit from urgency, but it can also find itself repeatedly educating buyers and defending category assumptions that standards bodies have not fully codified. The company’s own public contract stack partly mitigates this and partly shifts risk back to customers. The DPA references GDPR, UK GDPR, and Israeli privacy law, while the SaaS agreement makes customers responsible for legal bases and permissions around their data. The SLA gives a 99.9 percent uptime commitment, but remedies are constrained to service credits capped at 20 percent of subscription value. In other words, Oasis has baseline enterprise paperwork, yet customers still shoulder meaningful compliance and outage risk in practice. This means legal and regulatory risk is less about immediate enforcement against Oasis and more about trust conversion. Buyers in healthcare, finance, and AI governance will expect a rapidly improving proof stack: clearer standards alignment, better external validation, and evidence that public legal language maps to reliable operational control.[CR003, CR004, CR005, CR006, CR007, CR033]

Regulatory / Legal Risk Register
Rule / Contract RiskJurisdiction / SurfaceStatusLikelihoodSeverityMitigationResidual ExposureDiligence Path
Agentic-AI standards immaturityU.S. / global standardsNIST initiative underway; no settled control setHighHighUse NIST and practitioner frameworks; show control mappingHighRequest standards roadmap and customer control-mapping examples
Cross-border privacy obligationsGDPR / UK GDPR / Israel privacy lawExplicitly referenced in DPAMediumHighContractual DPA and customer legal-basis obligationsMediumRequest privacy architecture and DPA negotiation history
Customer legal-basis burdenSaaS agreement / DPAShifted materially to customerMediumMediumDocumented in contract stackMediumReview redlines and largest-customer legal objections
Limited downtime remedyPublic SLAService credits only, capped at 20%MediumMediumAvailability commitment plus support-response targetsMediumRequest uptime history and major-incident record
Regulated-buyer trust burdenHealthcare / finance / AI governance buyersHigh expectations; proof stack incompleteHighHighExpand external validation and audit artifactsHighRequest certification status, audit reports, and benchmark studies

Severity reflects underwriting impact, not legal certainty of enforcement.

[CR001, CR002, CR003, CR004, CR005, CR006]

7.3 Operational, Technical, and Security Risk

The strongest evidence in the file is that the underlying problem space is dangerous. Oasis’s own research and incident analyses document a string of agentic and NHI failures: OpenClaw takeover from a visited website, Claude prompt-injection data exfiltration, shared agent-identity ambiguity in Claude Tag, localhost hijack in Cline, silent folder-open execution in Cursor, one-click VS Code MCP compromise, malicious MCP package exfiltration, weak-default-credential failure in McHire, and older but still highly relevant breaches at Change Healthcare, Cloudflare, and Cisco. Taken together, these are not edge cases. They show a pattern of repeated access-boundary failure across AI and machine-identity systems. That pattern is a commercial opportunity for Oasis but also a product risk. If buyers conclude that agentic systems are too unsafe to deploy broadly, demand can pause. If buyers do deploy aggressively, the burden shifts to vendors like Oasis to prove their controls actually reduce the risk. External threat summaries from OWASP, CyberArk, Palo Alto, Delinea, and related sources reinforce that governance gaps, over-privilege, weak offboarding, secret leakage, and immature AI controls are all common. Public evidence does not yet show Oasis publishing the kind of third- party efficacy benchmarks that would decisively answer that challenge. Operationally, the deployment model is safer than pure central custody because customer-side execution and local control boundaries matter. But that also means implementation quality, connector resilience, and customer-operational maturity become part of the product-risk equation, not something Oasis can abstract away entirely.[CR008, CR009, CR010, CR011, CR012, CR013]

Operational / Quality / Security Risk Register
Failure ModeLikelihoodSeverityMitigation MaturityResidual ExposureUnresolved Gap
Prompt injection / tool misuseHighHighMedium — Oasis research and product thesis address itHighNeed external efficacy proof against these attacks
Shared or ambiguous agent identitiesMediumHighLow to mediumHighNeed stronger buyer proof that AAM resolves shared-identity risk
Localhost / IDE / MCP agent compromiseHighHighLow to mediumHighEcosystem remains volatile and fast-moving
Secret leakage / unrotated credentialsHighHighMediumMedium to highNeed customer success evidence and connector-level metrics
Supply-chain / package abuse in agentic workflowsMediumHighLow to mediumHighNeed dependency monitoring and connector hardening proof
Operational outage or degraded serviceMediumMediumMedium — SLA existsMediumNeed uptime history and postmortem visibility

This table groups recurrent technical risks visible across Oasis research and external incident reports.

[CR008, CR009, CR010, CR011, CR012, CR013]
FR002: Risk Transmission Map

Agentic-access failures travel quickly from technical control gaps into customer, financial, and strategic outcomes.

[CR009, CR014, CR016, CR017, CR037, CR041]

7.4 Partner, Customer, and Model Risk

Oasis’s route to market is part of its moat and part of its risk stack. The AI Access Partnership Program openly pitches buyers and partners on bypassing lengthy security reviews. The public ecosystem also spans GuidePoint’s OASIS+ route, the channel program, Wiz, Zscaler, and other surrounding platforms. These dependencies help Oasis reach customers and integrate into enterprise security workflows, but they also mean platform stability, distribution leverage, and even some buyer trust are partially borrowed from partners. Customer risk is similarly double-edged. Large regulated enterprises can be sticky once won, yet they are slow to procure, expensive to support, and often concentrated. Public materials suggest Fortune-500-oriented traction and meaningful customer outcomes, but they still do not quantify retention, concentration, or partner-attributed ARR. That missing visibility matters because it becomes much harder to tell whether large logos represent a durable base or a small set of demanding accounts with outsized leverage. Financial-model risk is therefore mostly an information risk today. The March 2026 Series B reduced immediate funding anxiety, and multi-year-agreement language is helpful, but burn, runway, and concentration remain undisclosed. Finro’s warning about valuation-compression risk under weak public comps is a useful reminder that great category narratives do not eliminate financing discipline.[CR026, CR027, CR028, CR030, CR031, CR038]

Partner / Dependency Risk Register
DependencyCounterpartyRoleConcentrationFailure ScenarioSeverityMitigationResidual Exposure
Procurement / federal routeGuidePointAccess to OASIS+ and partner-led enterprise dealsUnknownPartner deprioritizes Oasis or contract route underperformsMediumDiversify direct routes and partnersMedium
Cloud exposure contextWizEnriches risk prioritization and remediation contextUnknownIntegration breaks or strategic alignment weakensMediumMaintain independent value and alternative contextsMedium
Inline enforcementZscalerComplements governance with network / zero-trust enforcementUnknownEnforcement-layer dependency narrows solution portabilityMediumKeep governance layer vendor-agnosticMedium
Channel expansionPartner programScales awareness and enterprise reachUnknownChannel conflict or weak enablement slows growthMediumMeasure partner productivity and fallback to direct motionMedium
AI-platform partnershipsAI Access Partnership participantsDistribution into AI-vendor ecosystemsUnknownSecurity-review promises fail to materialize in production winsHighTrack conversion from partner interest to live deploymentsHigh

Concentration is unknown because public sources do not quantify partner-attributed ARR or deployments.

[CR007, CR026, CR027, CR038]
People / Execution Risk Register
Role / FunctionDependency or GapLikelihoodSeverityMitigationDiligence Path
Security engineeringMust ship faster than threat surface expandsMediumHighKeep research-driven feedback loop tightReview secure-SDLC and vuln-response metrics
Product / standards strategySelling ahead of settled norms requires heavy educationHighMediumMap product claims to NIST / practitioner frameworksRequest standards and product roadmap review
Partner managementEcosystem breadth increases coordination loadMediumMediumDedicated partner enablement and fallback planningRequest top integrations by usage and support burden
Go-to-market trust motionLengthy security reviews can stall pipelineHighHighBuild repeatable proof stack and procurement playbooksRequest win/loss data tied to security-review outcomes
Leadership focusStrategic rumor or process noise can distract teamsMediumMediumClear internal communication and customer messagingAsk about M&A contingency and retention planning

Execution risk is meaningful because Oasis competes in a fast-moving, trust-intensive market.

[CR007, CR029, CR032, CR038, CR039]
FR003: Dependency Map

Oasis depends on standards bodies, partner ecosystems, and customer-operated control boundaries to make the category work in practice.

[CR001, CR025, CR026, CR027, CR039]

7.5 Mitigations, Monitoring, and Kill Criteria

The encouraging part of the Oasis risk stack is that most of it can be tested early. Several of the top risks are not binary unknowables. Management can show evidence that enterprise security reviews are speeding up, that customer retention is healthy, that partner concentration is moderate, that public proof is expanding, and that vulnerability-response discipline is rigorous. If Oasis can move those needles, the risk case weakens materially because the company’s market relevance is already credible. The kill criteria are equally concrete. If public incidents keep showing the ecosystem is fragile while Oasis cannot provide benchmark evidence of control efficacy, buyer trust may stall. If partner dependence rises without fallback options, distribution resilience weakens. If strategic noise around potential M&A begins to distract teams or customers, execution risk rises. And if financial disclosure stays thin even as valuation expectations rise, investors should assume model risk is being carried forward rather than solved. In short, Oasis’s risk profile is best understood as manageable but front-loaded. The company must prove discipline, trust, and resilience faster than the agentic-access threat surface expands around it.[CR029, CR032, CR037, CR038, CR039, CR042]

Mitigation and Kill Criteria Table
RiskMonitorable TriggerThreshold / EventAction Implication
Trust proof lagNo new external validationNo benchmark / audit artifact progress over next 2 quartersDowngrade conviction; require direct evidence before underwriting
Partner dependencyOne partner dominates new pipeline>35% of new ARR attributed to a single partner routeTreat as concentration risk and re-cut valuation
Security-review frictionEnterprise reviews stay slowWin/loss data shows security review as top reason for slippageAssume category adoption curve slower than plan
Operational reliabilityMeaningful outage without transparent responseCustomer-visible incident plus weak postmortem disciplineReassess product-operating maturity
Strategic distractionM&A noise disrupts executionElevated employee churn, customer hesitation, or roadmap slipIncrease execution-risk discount
Model opacityFinancial / retention metrics remain undisclosedNo cohort, burn, or concentration disclosure in diligenceMove to research-more / avoid price-taking

These are investment kill criteria, not generic security best practices.

[CR028, CR029, CR030, CR035, CR038, CR042]

7.6 Exhibits

Chapter 08

08Valuation

8.1 Investment Thesis and Anti-Thesis

The public bull case for Oasis is compelling. The company sits in a category whose importance is rising quickly as AI agents and non-human identities proliferate across enterprise systems. Oasis has a visible Series B, recognizable investors, enterprise-oriented customer references, and a product story that positions it as the access-governance layer for the agentic enterprise. Strategic scarcity is real: category peers are being funded, large security vendors are consolidating adjacent machine-identity assets, and industry research now treats non-human and AI-agent identity as a first-order security control problem. The anti-thesis is equally important. Oasis has not publicly disclosed the operating metrics needed to justify a premium valuation. ARR, gross margin, retention, burn, and concentration are missing. Public category excitement therefore does not translate directly into underwriting confidence. Investors can believe the problem is real and still conclude that the price cannot be judged with enough precision yet. That tension matters because valuation here is narrative-sensitive. Oasis may in fact deserve a premium mark if growth quality is as strong as the company and reporters imply. But until the denominator is disclosed, the public file is best read as strategically promising rather than valuation-complete.[CV004, CV005, CV006, CV007, CV009, CV024]

Recommendation Summary Table
RecommendationConfidenceRisk RatingValuation StanceDecision Implication
research-moreMediumHighSpeculative but plausibleStay engaged, but do not underwrite the public mark without private metrics
Why not buyN/AN/APrice sensitivity is too highARR, retention, margin, and concentration remain undisclosed
Why not avoid entirelyN/AN/ACategory upside is realStrategic scarcity and enterprise traction justify continued diligence

This table is price-sensitive, not a generic quality score.

[CV032, CV033, CV034, CV042]
Thesis / Anti-Thesis Table
ArgumentWhat Would Change the View
Oasis sits in a strategically important category as AI agents and NHIs proliferateShow weak ARR quality or stalled enterprise conversion and the thesis softens
Enterprise traction and multi-year-agreement language imply serious buyer interestProvide customer-count and cohort data to strengthen the case
Strategic M&A and peer funding suggest exit optionalityIf M&A rumors fade and public comps compress, upside shrinks
Missing ARR, margin, and retention data make the current mark hard to underwriteDisclose ARR, NRR, gross margin, and burn to unlock a firmer valuation call
Distribution optionality through partners could accelerate adoptionShow partner concentration or weak conversion and the benefit turns into a risk

Thesis and anti-thesis both depend on evidence quality, not only on category narrative.

[CV006, CV007, CV024, CV025, CV038, CV039]
FV001: Recommendation Logic

The recommendation flows from strong category upside through missing economics to a research-more stance.

[CV004, CV005, CV009, CV032, CV042]

8.2 Financing Context and Entry Discipline

The most reliable public price anchor is the March 2026 financing. Newswire, Globes, SiliconANGLE, Access Newswire, and TechCompanyNews all support the $120 million Series B. Globes adds the most useful valuation detail by reporting that market sources believed Oasis was worth about $700 million and that total capital raised reached $195 million. That is the public financing mark of record. July 2026 introduced a second but weaker valuation signal: Globes reported advanced talks to sell Oasis to Cyera for up to $1 billion, mostly cash with a small amount of stock. Investors should not treat that as a closed-market mark. It is better interpreted as evidence that larger security players or private platforms could view Oasis as strategically relevant. The rumor increases upside optionality, but it also raises the risk of over-reading an unconfirmed process. Entry discipline should therefore remain tight. The last funded mark around $700 million is credible. The rumored strategic ceiling near $1 billion is interesting. But without cap-table detail, preferences, or unit-economics disclosure, a disciplined investor should not underwrite to the high case by default.[CV001, CV002, CV003, CV008, CV026, CV027]

FV002: Valuation Sensitivity

Oasis valuation is most sensitive to proof of revenue quality, strategic demand, and multiple discipline.

[CV003, CV010, CV011, CV027, CV028]

8.3 Comparable Framework and Market Sentiment

The right comparable framework is recurring-revenue identity security, not generic services or infrastructure software. Okta, SailPoint, Rubrik, and CyberArk all discuss their businesses through subscription revenue or ARR. Their filings and official results reinforce that investors value identity platforms on recurring-revenue quality, retention, and expansion. Those companies are much larger and not directly comparable to Oasis on product scope, but they do establish the language of the category. Analyst valuation work adds the second layer. Windsor Drake’s Q2 2026 IAM report pegs mainstream public IAM around 6.0x NTM revenue while stating that non-human and AI-agent identity platforms can clear roughly 15x to 30x in private rounds. Finro argues that using mature public cyber comps against private AI-native companies can badly mislead. Multiples.vc shows that the broader cyber tape has also improved meaningfully in 2026. Strategic consolidation reinforces the point: Astrix’s sale to Cisco and CyberArk’s machine-identity consolidation around Venafi show that large platforms are still buying into this control layer. The catch is that Oasis has not disclosed ARR. So while the comparable set says what kind of company Oasis might become, it cannot yet say what multiple Oasis truly deserves today.[CV010, CV011, CV012, CV013, CV014, CV015]

Comparable Valuation Table
ComparableMetricMultiple / Valuation / StatusRelevanceLimitation
OktaFY2026 subscription revenue $2.855BPublic recurring-revenue identity leaderShows how the market values identity at scaleMuch broader workforce-identity scope than Oasis
SailPointFY2026 ARR $1.125B; SaaS ARR $746MPublic / recently re-listed identity-security peerUseful ARR-centric identity compLarger and more mature than Oasis
RubrikFY2026 subscription ARR $1.46BHigh-growth security SaaS compUseful recurring-revenue and growth benchmarkNot an identity-native vendor
CyberArk2025 total ARR $1.44B; subscription ARR $1.267BIdentity / machine-identity incumbentStrong strategic comp for machine identityBroader PAM and incumbent scale
Astrix / CiscoStrategic deal, 2026Signals M&A appetite for NHI / agentic identity controlsStrategic validation for the categoryDeal terms not fully public in this file
GitGuardian2026 $50M Series CPrivate adjacent NHI / AI-agent security funding signalValidates investor appetite for the segmentFunding round is not a direct valuation multiple

The table is a valuation lens, not a claim that Oasis should trade exactly like any one comparable.

[CV014, CV015, CV017, CV018, CV019, CV020]
FV003: Valuation / Return Range

Public evidence supports a wide range because the mark is visible but the denominator is not.

[CV003, CV010, CV011, CV026, CV027, CV028]

8.4 Scenario Analysis and Recommendation

The base-case decision is to anchor near the last defensible public financing mark and refuse to extrapolate too far beyond it. That means treating roughly $700 million as the current public benchmark, not because it is certainly correct but because it is the best-supported mark. The bull case can credibly approach $1.0 billion if the Cyera interest proves directionally right or if management can validate premium ARR growth and retention quality. The bear case falls to the mid-hundreds of millions if the market reverts to public-IAM discipline before Oasis supplies the metrics needed to justify premium private-category framing. Given that setup, the most defensible recommendation is research-more. Oasis looks like a company worth staying close to, not a company that can be bought confidently on public evidence alone. Confidence is medium because the category tailwinds and financing mark are real, but the operating evidence is incomplete. Risk rating remains high because disclosure, dependence, and proof questions are still material. This is a company that may be good and may even be strategically scarce. The issue is that the public file still does not show enough to know whether the current implied price is attractive, merely fair, or already stretched.[CV026, CV027, CV028, CV032, CV033, CV034]

Bull / Base / Bear Scenario Table
ScenarioCore AssumptionsValuation / Return LogicKey RisksProbability Signal
BullOasis substantiates strong ARR quality, keeps premium category positioning, and strategic buyer interest proves real$900M-$1.0B+ range becomes credible through strategic scarcity or premium revenue multiple supportDisclosure gap closes too slowly; rumors do not convert to realityPossible but requires new evidence
BaseLast public mark remains best anchor and category momentum continues without major negative surprise~$700M remains fair reference point until fresher metrics arriveUnderwriting remains incompleteMost defensible current case
BearPublic-comp discipline tightens and Oasis cannot prove premium ARR, retention, or concentration quality$450M-$550M downside if premium narrative weakensValuation compression and partner / buyer frictionPlausible if disclosure stays thin
Status-quo holdInvestor stays engaged without pricing convictionNo action until ARR, NRR, and margin are disclosedOpportunity cost if momentum acceleratesRational near-term posture
Strategic takeoutM&A process or strategic scarcity drives premium beyond last roundDepends more on buyer synergies than on public compsUnconfirmed process; integration and retention riskLow visibility but real optionality

Valuation ranges are estimated scenario anchors derived from public financing and comp context, not from disclosed Oasis ARR.

[CV003, CV008, CV024, CV026, CV027, CV028]
Thesis-Break and Kill Triggers Table
TriggerThresholdTransmission to ThesisAction Implication
ARR quality disappointsManagement cannot substantiate strong ARR growth, retention, or gross marginPremium-category valuation logic weakens immediatelyRe-cut valuation downward or walk away
Strategic interest evaporatesCyera-style interest proves illusory and no buyer appetite remainsBull-case ceiling compressesAnchor to base/bear only
Partner concentration risesOne route or partner dominates pipeline / ARRDistribution optionality turns into dependency riskApply concentration discount
Public proof lagsNo meaningful improvement in external validation or customer metricsTrust and diligence burden stay too highKeep recommendation at research-more
Comp compression returnsPublic IAM and cyber multiples roll over materiallyNarrative premium narrowsTighten entry discipline and downside range

These are price-sensitive kill criteria tied to valuation, not generic product issues.

[CV025, CV029, CV030, CV037, CV042]
Final Diligence Asks Table
TopicMissing EvidenceWhy It MattersOwner / Diligence Path
ARR and revenue qualityCurrent ARR, segment mix, NRR / GRR, quarterly bridgeCore denominator for valuation and confidenceManagement / data room
Gross margin and burnGross margin bridge, COGS split, monthly burn, runwayNeeded to assess capital adequacy and downsideFinance diligence
Customer concentrationTop-10 customers, partner attribution, federal/commercial splitDetermines durability and bargaining riskRevenue operations / CFO
Cap table and preferencesPreferences, debt, secondaries, option poolEntry price depends on more than headline valuationLegal / financing diligence
M&A process statusReality of strategic interest and impact on team/customersAvoid overpricing on rumor aloneBoard / management discussion
Referenceable proofNamed customers, expansion cases, deployment maturityConverts narrative premium into trustable proofCustomer diligence / calls

Without these asks, the valuation call cannot move beyond research-more.

[CV009, CV031, CV032, CV036, CV042]
FV004: Investment KPIs

The KPI view highlights the visible marks and the hidden denominator driving the recommendation.

[CV001, CV002, CV003, CV008, CV032]

8.5 Exhibits

Disclaimer

This report is based on public sources as of 2026-07-10 and is not investment advice. Important financial, contractual, customer, legal, and technical details remain private and should be verified directly with management and primary documents before any investment decision.

Evidence index

Claims
IDStatementConfidenceSources
CO001 Oasis Security was founded in 2022. High SO011, SO014, SO015
CO002 The publicly identified founders are Danny Brickman, who serves as CEO, and Amit Zimerman, who serves as CPO. High SO011, SO013, SO014
CO003 Oasis's origin story is tied to Israeli cyber-service experience and a founding team that says the company began in Tel Aviv. Medium SO004, SO007
CO004 Oasis positions itself as a purpose-built platform for discovering, governing, and securing non-human identities across hybrid cloud environments. High SO001, SO002, SO003
CO005 The product description centers on inventory, contextual ownership mapping, and lifecycle management rather than vault-only secrets storage. High SO003, SO002
CO006 Oasis says its platform spans IaaS, SaaS, PaaS, and on-prem environments, including AWS, Azure, BigQuery, GitHub, ChatGPT, Salesforce, Office 365, and Copilot. Medium SO001
CO007 The company emerged from stealth in January 2024 with a previously closed $35 million Series A round and $40 million total funding to date. High SO007, SO008
CO008 The January 2024 Series A round was led by Sequoia Capital, Accel, Cyberstarts, and Maple Capital, with angels including Guy Podjarny and Michael Fey also participating. High SO007, SO008
CO009 Oasis announced a $35 million Series A extension in May 2024 that brought total funding to $75 million and doubled the prior Series A valuation. High SO009, SO010, SO011
CO010 Oasis announced a $120 million Series B round on March 19, 2026 led by Craft Ventures with existing investors Cyberstarts, Sequoia Capital, and Accel participating. High SO006, SO012, SO014
CO011 Public sources consistently place Oasis's lifetime capital raised at $195 million after the Series B round. High SO006, SO014, SO015
CO012 Independent market reporting estimated the Series B post-money valuation at roughly $700 million rather than the $1.2 billion figure in the prompt. Medium SO013, SO014
CO013 Oasis says it serves large enterprises and that a majority of its client base comes from the Fortune 500. Medium SO006, SO013
CO014 The company says new ARR grew fivefold year over year in the run-up to its March 2026 financing. Medium SO006, SO016, SO013
CO015 Oasis says most of its new ARR is driven by multi-year enterprise agreements, implying an enterprise-sales motion rather than low-touch self-serve adoption. Medium SO006
CO016 TechCrunch identified Chipotle, JLL, and Mercury Financial as early users while Oasis was still in stealth. Medium SO007
CO017 BankInfoSecurity reported that Oasis employed 142 people in March 2026. Medium SO015
CO018 Calcalist reported a headcount of 45 employees at the January 2024 Series A announcement, showing rapid post-stealth hiring if the 2026 headcount estimate is directionally correct. Medium SO008, SO015
CO019 Oasis appointed Michael DeCesare as president in April 2026 to run the global go-to-market organization spanning sales, marketing, alliances, and customer success. High SO005, SO016, SO017
CO020 The company launched a formal channel program in April 2025 and named GuidePoint Security as a strategic reseller partner in North America. High SO018, SO005
CO021 Oasis said the channel program generated millions of dollars in pipeline and dozens of deal registrations in less than one year. Medium SO018
CO022 Gartner Peer Insights showed Oasis at 5.0 out of 5 from a single banking-sector review as of February 2026, which is positive but too sparse to treat as broad market proof. Medium SO019
CO023 CrowdStrike's marketplace listing says Oasis correlates endpoint telemetry with identity context across service accounts, service principals, API keys, OAuth tokens, machine identities, DevOps tools, and AI agents. Medium SO020
CO024 Wiz's integration page says Oasis ingests Wiz Issues and DSPM findings so identity teams can add blast-radius context and lifecycle remediation to cloud findings. Medium SO021
CO025 GuidePoint placed Oasis on the 2025 GPSEC agenda for a session titled “Beyond IAM: Why Non-Human Identity is the Missing Layer,” indicating channel-led thought-leadership before the 2026 Series B. Medium SO022
CO026 NIST launched an AI Agent Standards Initiative in February 2026, strengthening the timing argument for agent-governance platforms such as Oasis. Medium SO023
CO027 Palo Alto Networks said machine identities reached 109-to-1 versus humans in 2026, up from 82-to-1 a year earlier, which supports Oasis's view that the problem set is growing faster than human IAM can absorb. Medium SO024
CO028 CyberArk reported that machine identities outnumber humans by more than 80-to-1 and framed fragmented identity security as a material breach and outage risk, underscoring the urgency of the category Oasis sells into. Medium SO025
CO029 Oasis repeatedly describes itself as the first solution purpose-built for non-human identity visibility, security, and governance. Medium SO002, SO004
CO030 The about page says leading organizations across a wide range of industries already use Oasis, even though the company discloses only a small number of named customer references publicly. Medium SO002, SO007
CO031 Oasis says it uses AI-based analytics, heuristics, and certification workflows to identify owners and resolve gaps in NHI accountability. Medium SO002, SO003
CO032 The company frames agentic access as a new layer because traditional IAM cannot govern AI agents and machine identities at the speed and scale of modern enterprise automation. Medium SO001, SO006
CO033 Globes said the May 2024 Series A extension would fund additional hiring across Israel and the United States. Medium SO011
CO034 BankInfoSecurity described CEO Danny Brickman as an ex-IDF cyber R&D leader with more than seven years of military service. Medium SO015
CO035 A July 2026 Globes report said Cyera was in advanced talks to acquire Oasis for up to $1 billion, but the article also said the companies had not formally announced a deal. Low SO026
CO036 Tech Company News described Oasis as headquartered in New York. Medium SO013
CO037 The stealth-emergence blog says Oasis began in a modest room in Tel Aviv, supporting a dual U.S.-commercial and Israel-R&D identity even though the public website does not publish a formal two-office roster. Medium SO004, SO011
CO038 No reviewed source published a precise customer count, ARR dollar figure, board roster, or audited financial statement for Oasis as of 2026-07-10. High SO005, SO006, SO019
CM001 The non-human identity market boundary includes application and service identities, API and OAuth tokens, machine and device identities, cryptographic identities, and AI agent identities. High SM003, SM011, SM018
CM002 The category is broader than secrets management alone because vendors now package discovery, posture, lifecycle governance, and runtime authorization around NHIs. Medium SM015, SM016, SM020, SM021
CM003 Status-quo substitutes include vaults and identity stores such as HashiCorp Vault, workload identity frameworks such as SPIFFE, cloud-native IAM, and manual ownership processes. Medium SM021, SM022, SM024
CM004 Mordor Intelligence sized the NHI security market at $8.22 billion in 2026. Medium SM001
CM005 Mordor Intelligence projects the NHI security market to reach $22.94 billion by 2031, a 22.78% CAGR from 2026. Medium SM001
CM006 Research and Markets and Yahoo Finance place the broader NHI access-management market at $12.2 billion in 2026 and $38.8 billion by 2036, implying a slower but larger envelope than the narrower NHI-security lens. High SM002, SM003
CM007 The gap between the $8.22 billion and $12.2 billion 2026 estimates is best explained by different market boundaries rather than a direct contradiction. Medium SM001, SM002, SM003
CM008 North America is described as the largest 2026 market while Asia-Pacific is expected to grow fastest. Medium SM002, SM003
CM009 Large enterprises and cloud-based deployments lead the current market share in the broader NHI access-management forecast. Medium SM002, SM003
CM010 Research and Markets explicitly breaks the market into solutions and services across identity types, deployment modes, organization sizes, and verticals. Medium SM003
CM011 Palo Alto Networks said machine identities reached 109-to-1 versus humans in 2026, up from 82-to-1 a year earlier. High SM004, SM005
CM012 Palo Alto Networks also said 77% of organizations expect the machine-to-human identity ratio to keep climbing. Medium SM004
CM013 According to Palo Alto's 2026 landscape reporting, 99% of organizations have adopted AI agents and 40% of those agents already have access to organizational data. Medium SM004
CM014 Axis Intelligence highlighted how vendor methodologies still diverge widely, citing 2025-2026 ratios from 45-to-1 to 144-to-1 and a composite around 79-to-1. Medium SM005
CM015 Axis Intelligence said GitGuardian found 28.65 million new hardcoded secrets exposed on public GitHub in 2025, with AI-service leaks up 81.5% year over year. Medium SM005
CM016 Axis Intelligence also said 64% of secrets confirmed valid in 2022 remained exploitable as of January 2026. Medium SM005
CM017 NIST's 2026 AI Agent Standards Initiative is organized around interoperability, security, and open protocols for autonomous agents. High SM006, SM007
CM018 Cloud Security Alliance noted that no enforceable, agent-specific security controls exist yet and substantive standards will take time to emerge. Medium SM008, SM006
CM019 The OWASP maturity article says 83% of organizations plan to deploy agentic AI, yet only 29% believe they can adequately protect it. Low SM009
CM020 ITECS argued that 68% of employees already use AI tools without IT approval, creating a Shadow AI visibility gap. Low SM010
CM021 Saviynt argues that NHIs are broader than machine identities alone and also include bots, workloads, and AI agents. Medium SM015, SM018
CM022 Saviynt's ISPM positioning centers on continuous discovery, real-time inventory, risk insights, and automated remediation for NHIs. Medium SM016
CM023 Delinea defines NHIs to include applications, services, scripts, devices, APIs, bots, and AI agents. Medium SM018
CM024 Delinea warns that NHIs and AI agents often carry persistent, broadly privileged access with weak ownership and review discipline. Medium SM020
CM025 Aembit positions short-lived, secretless access as the buyer answer for agentic AI and workload identity use cases. Medium SM023
CM026 HashiCorp's validated AI-agent pattern uses OAuth token exchange and dynamic secrets, showing that engineering-centric buyers are moving away from static credentials. Medium SM021
CM027 HashiCorp's identity engine treats an entity as a client with multiple aliases and audit-linked actions, illustrating the identity-store foundation many teams use before buying a broader governance layer. Medium SM022
CM028 SPIFFE and SPIRE provide a uniform cryptographic identity control plane for workloads across heterogeneous infrastructure. Medium SM024
CM029 WorkOS's March 2026 release added agent-oriented features such as Pipes MCP and session-scoped identity boundaries, showing that agent identity is spreading into developer-access platforms. Medium SM025
CM030 Oasis's AI solution page frames the buyer need as restricting AI agents to approved model suppliers, enforcing least privilege, and monitoring delegated permissions. Medium SM026
CM031 Oasis's finance page ties the problem to PCI DSS 4.0, SOC 2, GDPR, and resilience of core financial workflows. Medium SM027
CM032 Oasis's healthcare page ties the problem to HIPAA/GDPR-style privacy risk, audit readiness, and uninterrupted care operations. Medium SM028
CM033 The core buyer set appears to span IAM/PAM leaders, cloud and platform security teams, and regulated application owners rather than a single budget owner. Medium SM015, SM016, SM026, SM027, SM028
CM034 Across competing solution narratives, the practical adoption path starts with discovery and inventory, then owner attribution, then lifecycle policy, and finally runtime access control or secretless enforcement. Medium SM016, SM019, SM023
CM035 The main growth drivers are AI-agent adoption, cloud-native sprawl, zero-trust programs, certificate/secret lifecycle pressure, and rising audit expectations. Medium SM002, SM004, SM006, SM015, SM016
CM036 The main adoption constraints are immature standards, shadow AI, unclear ownership, fragmented tooling, and the integration burden of replacing entrenched vault or IAM workflows. Medium SM008, SM010, SM020, SM022, SM024
CM037 Public sources do not isolate a clean agentic-access SAM or SOM, so market sizing must be treated as overlapping lenses rather than a precise bottom-up forecast. High SM001, SM002, SM003, SM008
CM038 The addressable spend is not purely security budget: it also touches developer productivity, platform operations, and compliance programs. Medium SM023, SM025, SM027, SM028
CP001 The competitive landscape splits into direct NHI lifecycle-governance platforms, runtime/workload access controls, broad identity suites, and infrastructure-level substitutes. High SP003, SP004, SP006, SP008, SP010, SP019
CP002 Oasis positions itself as a hybrid-platform vendor spanning IaaS, SaaS, PaaS, and on-prem environments rather than a single-system access tool. Medium SP001
CP003 Oasis's core product story is inventory, contextual ownership, and lifecycle management for NHIs. Medium SP002
CP004 Aembit positions itself around secretless, policy-based, short-lived access for agentic AI and workloads. Medium SP003
CP005 Entro positions itself around discovery, classification, observability, and remediation across clouds, code, CI/CD, on-prem, and collaboration tools. Medium SP004
CP006 Astrix says it is now part of Cisco and ended standalone sales of new licenses effective June 30, 2026. Medium SP005
CP007 CyberArk markets machine identity security around comprehensive visibility, advanced automation, and lifecycle protection for secrets, certificates, and workload identities. Medium SP006
CP008 CyberArk's state report says 50% of organizations reported breaches linked to compromised machine identities and 72% had at least one certificate-related outage in the past year. Medium SP007
CP009 HashiCorp's competitive angle is dynamic secrets and OAuth-based AI-agent authentication rather than broad posture management. Medium SP008
CP010 HashiCorp's identity engine centers on entities, aliases, and audit-linked actions, illustrating an engineering-centric identity store rather than a business-governance console. Medium SP009
CP011 Saviynt argues NHIs are broader than machine identities alone and include workloads, bots, accounts, and AI agents. Medium SP010
CP012 Saviynt's posture-management message emphasizes continuous discovery, risk insights, and automated remediation for NHIs. Medium SP011
CP013 Saviynt also uses the Wiz Integration Network to pitch unified cross-cloud identity visibility and least-privilege context. Medium SP012
CP014 Delinea defines NHIs as applications, services, scripts, devices, APIs, bots, and AI agents. Medium SP013
CP015 Delinea warns that NHIs and AI agents often carry persistent, broadly privileged access that would be unacceptable for humans. Medium SP014
CP016 Delinea treats continuous discovery and identity inventory as the foundational step in identity security. Medium SP015
CP017 GitGuardian's 2024 strategy update says layered NHI security requires integrations across five secrets-management platforms including HashiCorp Vault and CyberArk. Medium SP016
CP018 GitGuardian's 2026 tooling taxonomy divides the market into secrets detection, NHI lifecycle/governance platforms, machine identity and certificate management, and vault/authorization extensions. Medium SP017
CP019 GitGuardian's OWASP commentary highlights improper offboarding, secret leakage, overprivileged NHIs, and insecure authentication as central buyer fears. Medium SP018
CP020 SPIFFE and SPIRE provide a uniform cryptographic workload-identity control plane, making them powerful substitutes for infrastructure teams but not a full enterprise governance suite. Medium SP019
CP021 WorkOS's March 2026 release added Pipes MCP and session-scoped agent boundaries, signaling an adjacent developer-first entrant into agent identity control. Medium SP020
CP022 Oasis's CrowdStrike marketplace listing emphasizes endpoint-correlated identity context plus governed remediation such as rotating credentials and revoking tokens. Medium SP021
CP023 Oasis's Wiz integration emphasizes blast-radius-aware prioritization and lifecycle actions such as hygiene, attestation, safe key rotation, and decommissioning. Medium SP022
CP024 Gartner Peer Insights gives Oasis visible but very thin public review proof: one 5.0 review and a visible “top alternatives” frame rather than broad review volume. Medium SP023
CP025 SourceForge describes Oasis as the first enterprise platform purpose-built to secure the complete lifecycle of NHIs for companies seeking this outcome. Medium SP024
CP026 Slashdot likewise describes Oasis around end-to-end NHI lifecycle protection rather than narrow secret storage. Medium SP025
CP027 Direct NHI pure plays such as Oasis, Entro, Aembit, and historically Astrix compete on modern AI-agent and machine-identity narratives more than legacy PAM rhetoric. Medium SP003, SP004, SP005, SP001
CP028 Broad identity suites such as CyberArk, Saviynt, and Delinea compete through larger installed bases and wider identity portfolios. High SP006, SP010, SP013
CP029 Runtime-control vendors and infrastructure substitutes win when buyers prioritize short-lived access, developer velocity, or workload-native plumbing over enterprise posture inventory. Medium SP003, SP008, SP019, SP020
CP030 The market is likely to stay multi-vendor because buyers can keep vaults, workload identity frameworks, and cloud IAM while adding a governance layer on top. Medium SP008, SP009, SP019, SP022
CP031 Consolidation is already visible: Astrix is being absorbed into Cisco, suggesting platform vendors value AI-agent/NHI controls but also reducing independent-choice surface for buyers. Medium SP005
CP032 Marketplace and integration surfaces matter competitively because they reinforce distribution and technical context rather than only feature lists. Medium SP021, SP022, SP012
CP033 Oasis's moat is more about unified lifecycle governance and agentic-access messaging than about owning the lowest-level secret store or workload identity primitive. Medium SP001, SP002, SP021, SP022
CP034 Discovery-only positions face commoditization pressure because suite vendors are rapidly adding inventory and posture features. Medium SP011, SP015, SP017
CP035 Pricing is still largely opaque across the public enterprise pages reviewed, which preserves sales-led procurement friction and weakens simple product-to-product price comparison. High SP001, SP003, SP006, SP010, SP013
CP036 Because public pricing is sparse, buyers are more likely to compare vendors on control-plane depth, integration fit, and deployment model than on a posted per-seat list price. Medium SP001, SP003, SP008, SP022
CP037 Oasis currently has stronger public partner visibility than public pricing transparency. Medium SP021, SP022, SP023
CP038 The category remains early enough that no single vendor publicly demonstrates undisputed control over discovery, lifecycle, runtime access, and distribution simultaneously. High SP003, SP004, SP006, SP008, SP010, SP013, SP021
CI001 Oasis sells its platform through a SaaS subscription agreement tied to an order form rather than a public self-serve plan. High SI001, SI004
CI002 The subscription agreement auto-renews for successive terms unless either party gives at least 60 days notice of non-renewal. Medium SI001
CI003 Oasis publishes a contract stack that includes a SaaS agreement, a DPA, and an SLA, which is typical of an enterprise software vendor selling recurring service. High SI001, SI002, SI003
CI004 The DPA expressly references GDPR, UK GDPR, and Israeli privacy law, signaling that Oasis expects to process regulated customer data across multiple jurisdictions. Medium SI002
CI005 Oasis commits to a 99.9% monthly uptime service level in its public SLA. Medium SI003
CI006 The same SLA targets an initial response within three business hours for severity-1 incidents and five business hours for severity-2 incidents. Medium SI003
CI007 AWS Marketplace lists Oasis with custom pricing and directs buyers to request a private offer rather than showing a public list price. Medium SI004
CI008 Oasis positions itself as a unified NHI management platform spanning visibility, security, and governance across hybrid cloud environments. Medium SI005
CI009 Oasis NHI Provisioning supports Azure, GCP, AWS, on-prem environments, and third-party vaults including HashiCorp, Azure Key Vault, and CyberArk. High SI006, SI009
CI010 Provisioning can be initiated from Terraform, ServiceNow, a generic API trigger, or the Oasis UI. Medium SI006
CI011 Provisioning supports both credential-based identities and federated identities such as managed identities, IAM roles, and OIDC-linked trust relationships. Medium SI006
CI012 Oasis Outpost keeps privileged identity operations, secret generation, and storage inside the customer perimeter while Oasis only exchanges control messages and metadata. Medium SI006
CI013 Oasis governance materials package provisioning, ownership assignment, privilege controls, rotation, attestation, and decommissioning as productized lifecycle features. High SI008, SI009
CI014 The finance solution page frames Oasis as a compliance and least-privilege workflow product for PCI DSS 4.0, SOC 2, and GDPR-sensitive buyers. Medium SI010
CI015 The financial-services case study describes rapid Azure AD deployment, auto-discovery of NHIs, posture analysis, disabling stale accounts, and automated identity rotation. Medium SI007
CI016 Indirect procurement is available through AWS Marketplace, CrowdStrike Marketplace, Wiz integrations, and GuidePoint’s federal contracting motion. High SI004, SI016, SI017, SI018
CI017 Oasis said its 2025 channel program was intended to make channel a key source of growth and launched with GuidePoint as a reseller partner. High SI015, SI016
CI018 The careers page shows Oasis is still recruiting builders and operators, consistent with ongoing post-Series-B investment in engineering and go-to-market capacity. Low SI011
CI019 The public contract and marketplace materials collectively indicate a recurring software model, not a one-off project services business. High SI001, SI003, SI004
CI020 Secret rotation is presented as an automated ongoing control rather than as a manual consulting workflow, supporting software-like gross-margin potential over time. Medium SI008, SI009
CI021 Oasis announced a $120 million Series B in March 2026 led by Craft Ventures with Accel, Cyberstarts, and Sequoia participating. High SI012, SI013, SI014
CI022 Globes reported that Oasis had raised $195 million in total and that market sources believed the Series B valued the company at about $700 million. Medium SI013
CI023 Globes also reported that Oasis said ARR increased fivefold over the prior year and that most customers were Fortune 500 companies. Medium SI013
CI024 The March 2026 funding coverage framed the round around securing enterprise AI agents, implying the new capital was intended for category expansion rather than emergency refinancing. High SI012, SI014
CI025 No public debt facility, credit line, or project-finance obligation was identified in the financial evidence reviewed for this chapter. Medium SI001, SI012, SI013, SI015
CI026 Public sources reviewed for this chapter do not disclose Oasis ARR, revenue, gross margin, burn rate, cash balance, or NRR in enough detail for underwriting. Medium SI004, SI012, SI013, SI015, SI018
CI027 Federal revenue concentration cannot be quantified publicly even though GuidePoint’s OASIS+ contract shows federal-channel intent through 2030. Medium SI015, SI016
CI028 Okta reported $2.855 billion of FY2026 subscription revenue and 15% growth in remaining performance obligations, illustrating the recurring-revenue model of scaled identity vendors. High SI019, SI023
CI029 SailPoint reported FY2026 ARR of $1.125 billion and SaaS ARR of $746 million, showing strong market value for durable identity-security subscriptions. High SI020, SI024
CI030 Rubrik reported $1.46 billion of subscription ARR and 2,805 customers above $100K subscription ARR in fiscal 2026. Medium SI021
CI031 CyberArk ended 2025 with $1.44 billion of total ARR and $1.267 billion of subscription ARR, confirming that privileged and machine-identity leaders already monetize at billion-dollar recurring scale. High SI022, SI027
CI032 These peer disclosures support using recurring-revenue logic rather than services multiples when framing Oasis, even though Oasis itself does not disclose ARR. Medium SI019, SI020, SI021, SI022
CI033 Windsor Drake’s Q2 2026 IAM report put public IAM valuations near 6.0x NTM revenue while non-human and AI-agent identity platforms cleared roughly 15x to 30x revenue. Medium SI025
CI034 Finro warned that mature public cybersecurity comps can materially understate private AI-native cybersecurity valuations, which is an adverse signal against simplistic public-comp benchmarking. Medium SI026
CI035 The combination of custom quote pricing, no public ARR disclosure, and no public burn disclosure means Oasis cannot be underwritten from public evidence alone. Medium SI004, SI013, SI026
CI036 Oasis’s contract stack and marketplace footprint imply annual or multi-year subscription revenue with partner-assisted procurement, but realized pricing and discounting remain opaque. Medium SI001, SI004, SI015, SI016
CI037 The likely cost base is software R&D, cloud analytics, support, and partner enablement rather than hardware or working capital, but public sources do not quantify the split. Medium SI006, SI011, SI015, SI018
CI038 Public evidence is strong enough to conclude Oasis is well funded for near-term growth, but not strong enough to estimate remaining runway with confidence. Medium SI012, SI013, SI026
CE001 Oasis Agentic Access Management is positioned as a purpose-built governance layer for AI agents across their lifecycle. High SE001, SE024
CE002 AAM evaluates agent intent in real time and applies policy before the action reaches enterprise data or systems. High SE001, SE024
CE003 AAM grants short-lived least-privilege session identities instead of standing access or long-lived secrets. High SE001, SE002, SE024
CE004 Oasis describes a full chain-of-custody for agent actions linking prompt, intent, policy, session, and action. Medium SE001
CE005 The AAM launch blog says actions such as reviewing pull requests, modifying production records, and triggering workflows are converted into time-bound least-privilege sessions. Medium SE002
CE006 Visibility is treated as the first operational step for AI governance: teams must discover agents, understand what identities they use, what data they access, and who is accountable. Medium SE005
CE007 The AI solution page says Oasis can detect AI adoption across endpoints, SaaS, and cloud while surfacing unauthorized tools and unmanaged NHIs. Medium SE012
CE008 The same AI page frames control around least privilege, identity-based controls, provisioning, rotation, and automated enforcement. Medium SE012
CE009 Cursor agents are described as executing commands, calling MCP tools, and interacting with internal systems, which is why Oasis pairs intent-based access with audit trails. Medium SE004
CE010 The AI Access Partnership Program promises built-in governance, admin visibility, audit-ready reporting, and co-selling access to Fortune 500 demand. Medium SE003
CE011 Oasis NHI Provisioning supports AWS, Azure, GCP, on-prem environments, and vault integrations such as HashiCorp, Azure Key Vault, and CyberArk. High SE009, SE011
CE012 Provisioning can start through Terraform, ServiceNow, a generic API trigger, or the Oasis UI. Medium SE009
CE013 Provisioning supports both credential-based identities and federated identities, including managed identities, IAM roles, and OIDC-linked trust relationships. Medium SE009
CE014 Oasis Outpost is deployed inside the customer perimeter so secret generation and storage stay local while Oasis exchanges control messages and metadata. Medium SE009
CE015 Governance features are packaged around secure provisioning, ownership assignment, attestation, privilege controls, rotation, and decommissioning. High SE009, SE021
CE016 The posture-management page says Oasis uses AI-based analytics to detect compromise attempts, policy violations, misconfigurations, toxic combinations, and anomalies. Medium SE010
CE017 The secret-rotation page organizes the workflow around discovery, observation, policy management, safe rotation, and decommissioning of secrets. Medium SE011
CE018 The financial-services case study describes rapid Azure AD deployment, auto-discovery, risk-posture insights, stale-account disablement, and automated identity rotation. Medium SE013
CE019 The Wiz integration enriches Oasis with Wiz Issues and DSPM findings so teams can correlate privilege, sensitive-data context, and usage before lifecycle actions. High SE014, SE028
CE020 The Zscaler partnership positions Oasis as the identity-governance layer while Zscaler provides inline enforcement for machine-to-machine and agentic traffic. Medium SE015
CE021 The CrowdStrike marketplace partnership is presented as part of a wider shift toward unified next-generation identity protection. High SE016, SE029
CE022 The AAM Framework launch says Oasis and Sequoia created a seven-pillar, practitioner-built governance framework plus a free maturity assessment. Medium SE025
CE023 NIST’s AI Agent Standards Initiative is designed around secure interoperability and open protocols, which means the external standards environment is still being defined in 2026. Medium SE023
CE024 Oasis said Gartner named it in a January 2026 report on top-funded startups in AI TRISM and agentic AI. Medium SE017
CE025 Oasis researchers disclosed a vulnerability chain in OpenClaw that allowed full agent takeover from a visited website and said the upstream team fixed it within 24 hours. Medium SE007
CE026 Oasis’s LLM and MCP risk post says over 90% of Fortune 500 companies use LLM tools, thousands of MCP servers are published online, and the MCP repository has been forked more than 4,000 times. Medium SE006
CE027 The RPA-to-agents post argues that adaptive AI agents introduce more access-governance complexity than rule-based automation. Medium SE008
CE028 The careers page describes Oasis as a team of builders tackling NHI security at scale, and the AI-native engineering post signals an engineering culture centered on rapid AI-assisted development. Medium SE018, SE019
CE029 HashiCorp’s validated pattern for AI-agent identity uses OAuth token exchange and dynamic secrets, offering an external technical analogue to Oasis’s short-lived credential model. Medium SE020
CE030 GitGuardian’s NHI governance concepts emphasize discovery, ownership, and lifecycle control, which lines up with the way Oasis packages its product modules. Medium SE021, SE009
CE031 SPIFFE provides a cryptographic workload-identity control plane, whereas Oasis’s public materials emphasize broader governance, lifecycle, and enterprise workflow controls across heterogeneous systems. Medium SE022, SE009, SE012
CE032 Public Oasis materials show availability commitments in the SLA but do not publish benchmarked false-positive, throughput, or efficacy metrics for AAM or posture analytics. Medium SE001, SE010
CE033 The partner stack suggests Oasis deliberately avoids being a closed stack: it integrates with cloud, ticketing, vault, exposure-management, inline-enforcement, IDE, and marketplace ecosystems. Medium SE003, SE004, SE014, SE015, SE016
CE034 The AI Access Partnership Program indicates Oasis wants to embed governed execution patterns into third-party AI platforms, not only secure existing non-human identities after the fact. Medium SE003, SE004
CE035 The documented control-plane pattern suggests Oasis is primarily a governance and orchestration layer rather than a network-inline proxy or a standalone vault. Medium SE009, SE014, SE015, SE020
CE036 Across 2025-2026 public releases, Oasis expanded from NHI lifecycle management into agentic access governance through AAM, the partnership program, the framework, and ecosystem integrations. High SE002, SE003, SE024, SE025
CU001 Oasis says leading organizations across a wide range of industries use its platform. Medium SU001
CU002 The product page includes a Fortune 1000 Head of Identity quote describing 17,000-plus NHIs in the customer’s cloud environment and saying Oasis visibility made the problem a no-brainer. Medium SU002
CU003 The home page says a Fortune-50 healthcare provider eliminated a critical exposure and avoided an estimated $3-5 million HIPAA breach fine. High SU003, SU013
CU004 The same home page says a Fortune-500 logistics company cut secret-rotation effort by 35 percent. Medium SU003
CU005 Oasis also says an F500 insurance customer capped an outage affecting 50 percent of production workloads. Medium SU003
CU006 Oasis says an F300 consumer packaged goods customer reduced attack surface by 60 percent in days during a proof of value. Medium SU003
CU007 The home page further claims an F200 manufacturing customer enforced M&A compliance on newly acquired environments. Medium SU003
CU008 Newswire said Oasis serves dozens of Fortune 500 companies. High SU022, SU023
CU009 Globes reported that a majority of Oasis’s client base comes from the Fortune 500. Medium SU023
CU010 The AI Access Partnership page says Fortune 500 customers are actively looking for vetted secure AI solutions through the Oasis enterprise network. Medium SU014
CU011 A private-credit financial-services customer deployed Oasis into Azure AD and used it for visibility, tailored security policies, stale-account cleanup, and automated identity rotation. High SU004, SU012
CU012 The healthcare-provider case study describes an environment with 8,500 human identities, more than 100,000 NHIs, over 50,000 certificates, and about 10,000 service accounts. High SU005, SU013
CU013 The same healthcare case says an 18-person security team and roughly 50 IT-operations staff were trying to manage that identity sprawl across cloud and on-prem systems. Medium SU005
CU014 The Mars case study says Mars used Oasis to secure a hyper-fragmented cloud environment and achieve instant visibility into service accounts and API keys. Medium SU006
CU015 An industrial-company webinar says the buyer used Oasis to uncover and classify NHIs across Azure, remediate excessive privilege, and improve continuous compliance. Medium SU007
CU016 A financial-services whitepaper says Oasis helped Antares streamline NHI lifecycle management, minimize manual effort, and take a more proactive security posture. High SU009, SU010
CU017 The leading-organizations webinar and other resource pages show that Oasis’s customer-proof surface is richer in detailed vertical case studies than in a simple named-customer roster. Medium SU008, SU004, SU005, SU006
CU018 Public customer evidence skews toward regulated or operationally complex enterprise environments such as financial services, healthcare, industrial Azure estates, logistics, insurance, manufacturing, and large consumer brands. Medium SU003, SU004, SU005, SU007, SU009, SU012, SU013
CU019 The product and home pages imply production use cases, not merely conceptual pilots, because the quoted outcomes concern exposure removal, outage mitigation, lifecycle automation, and compliance work. Medium SU002, SU003
CU020 Gartner Peer Insights shows Oasis Security at 4.6 out of 5 from 20 ratings on the captured 2026 page. Medium SU015
CU021 SourceForge lists Oasis but shows an overall 0.0 out of 5 and thin review depth on the captured page, which is an adverse signal about long-tail public review coverage rather than necessarily about product quality. Medium SU016
CU022 Slashdot also lists Oasis, but the captured page provides little usable review depth or customer-outcome specificity. Medium SU017
CU023 Independent public customer-voice evidence is therefore materially thinner than Oasis’s company-authored case-study surface. Medium SU015, SU016, SU017
CU024 Newswire said most new ARR is driven by multi-year enterprise agreements, which is a positive durability signal even though contract counts and renewal cohorts are undisclosed. Medium SU022
CU025 Public sources reviewed for this chapter do not disclose customer count, NRR, GRR, churn, contract length distribution, or top-customer concentration. Medium SU015, SU022, SU023
CU026 The case studies emphasize ongoing lifecycle governance and policy enforcement, which suggests recurring usage rather than one-time audit work. Medium SU004, SU005, SU006, SU007, SU009
CU027 GuidePoint’s OASIS+ contract and the 2025 channel-program announcement show an active partner-led route to federal and enterprise procurement. High SU018, SU019
CU028 The CrowdStrike Marketplace and Wiz integration pages add additional procurement and workflow surfaces that can support expansion even when direct customer references are sparse. High SU020, SU021
CU029 The Bank of America page is an account-targeted marketing page and should not be treated as proof that Bank of America is a live customer. Medium SU011
CU030 The strongest named public customer references surfaced in this chapter are Mars and Antares; other operationally rich examples remain anonymous by vertical. Medium SU006, SU009, SU004, SU005, SU007
CU031 The home-page proof point for the F300 CPG customer is explicitly described as a proof of value, so it should not be treated as full production-retention evidence. Medium SU003
CU032 The financial-services whitepaper and solution page show Oasis tailoring its customer story to institutions worried about PCI DSS 4.0, SOC 2, GDPR, and operational resilience. Medium SU010, SU012
CU033 The healthcare solution page similarly ties Oasis to patient-privacy, HIPAA/GDPR-style compliance, audit readiness, and uninterrupted care operations. Medium SU013
CU034 The AI Access Partnership page suggests enterprise AI-platform vendors are themselves a partner-facing customer segment for Oasis, not only end-user enterprises. Medium SU014
CU035 The Noname Security CISO podcast and ISMG interview show practitioner awareness and ecosystem education, but they are not substitutes for deployment proof or retention data. Medium SU024, SU025, SU026
CU036 Public evidence does not reveal what share of revenue comes from the top ten customers, from the federal segment, or from partner-led customers. Medium SU018, SU019, SU022, SU023
CU037 If dozens of Fortune 500 customers are real but still concentrated in a small number of large accounts, concentration risk could be material; the public record is too thin to resolve that risk. Medium SU022, SU023
CU038 The best-supported public conclusion is that Oasis has genuine enterprise traction and meaningful use-case depth, but its public proof is much stronger on deployment anecdotes than on broad retention or satisfaction statistics. Medium SU003, SU015, SU022, SU023
CR001 NIST’s AI Agent Standards Initiative is a 2026 standards effort around secure interoperability and open protocols rather than a mature, enforceable control regime. High SR004, SR005
CR002 CSA’s 2026 governance-gap note says substantive agent-specific standards are still pending and enterprises are operating ahead of clear controls. High SR005, SR004
CR003 Oasis’s DPA expressly references GDPR, UK GDPR, and Israeli privacy law, confirming that customer deployments can create cross-jurisdiction privacy obligations. Medium SR001
CR004 The SaaS agreement makes customers responsible for having the necessary legal basis and permissions for customer data processed through the service. High SR002, SR001
CR005 Oasis’s public SLA offers 99.9 percent monthly uptime but limits the customer remedy to service credits rather than broader damages. Medium SR003
CR006 Maximum service credits are capped at 20 percent of the amount due during the applicable subscription term. Medium SR003
CR007 The AI Access Partnership page explicitly promises to bypass lengthy security reviews, which is evidence that procurement and trust review friction is a real go-to-market risk in this category. Medium SR023
CR008 OpenClaw showed that a developer visiting an ordinary website could lose full control of an AI agent if browser and local-agent trust boundaries are poorly designed. Medium SR012
CR009 The Claude.ai prompt-injection chain described by Oasis turned untrusted content into data exfiltration and tool-misuse risk. Medium SR013
CR010 Claude Tag demonstrates a governance risk where an agent acts under its own shared identity rather than under the identity of each human participant in a channel. Medium SR014
CR011 Oasis reported a critical CVSS 9.7 localhost WebSocket hijack in Cline that could exfiltrate workspace data and inject agent commands. Medium SR015
CR012 Oasis reported that Cursor could execute code on folder open because Workspace Trust was off by default. Medium SR016
CR013 Oasis reported that a single click on a crafted VS Code MCP install dialog could enable full code execution or reroute tool calls through an attacker account. Medium SR017
CR014 The MCP breach write-up shows how a malicious package in an AI workflow can quietly exfiltrate sensitive email traffic at scale. Medium SR018
CR015 The McHire breach write-up shows that default credentials plus IDOR flaws can expose tens of millions of applicant records in AI-assisted systems. Medium SR019
CR016 The Change Healthcare breach analysis points to compromised credentials and missing MFA as a catastrophic failure mode for non-human or privileged access. Medium SR020
CR017 The Cloudflare breach analysis highlights how one unrotated token and a few service accounts can preserve attacker access even after a major incident is discovered. Medium SR021
CR018 The Cisco breach analysis ties public DevHub exposure, hard-coded credentials, tokens, and keys directly to enterprise data leakage risk. Medium SR022
CR019 GitGuardian’s OWASP NHI Top 10 summary names secret leakage, improper offboarding, overprivileged NHIs, and insecure authentication as recurring failure modes. Medium SR006
CR020 CyberArk’s state report says organizations increasingly recognize machine-identity security as essential, but preparedness remains uneven. Medium SR007
CR021 Delinea argues that AI is now embedded across workflows faster than governance and identity protections are maturing. Medium SR008
CR022 Palo Alto said machine identities reached 109 to 1 versus humans in 2026, magnifying the blast radius of identity-governance failures. Medium SR009
CR023 The ShareuHack OWASP summary argues that many organizations intend to deploy agentic AI before they can adequately protect it. Low SR010
CR024 Oasis’s own LLM-and-MCP risk post says LLMs are used by over 90 percent of Fortune 500 companies and that thousands of MCP servers are already available, which expands attack surface faster than governance can standardize. Medium SR011
CR025 Oasis’s perimeter-execution and Outpost-style design reduces direct secret custody by the vendor but creates dependency on customer-side deployment correctness. Medium SR002, SR003, SR024
CR026 The public product story depends on partner ecosystems such as Wiz, Zscaler, GuidePoint, and the channel program, creating integration and distribution dependency risk. Medium SR024, SR025, SR026, SR027
CR027 GuidePoint’s OASIS+ route shows federal procurement ambition, but it also means Oasis depends on partner and contract-vehicle access for some government sales. High SR027, SR026
CR028 The 2026 Series B and reports of multi-year enterprise agreements reduce immediate financing panic, but public sources still do not expose burn, cash, or runway. Medium SR028, SR030
CR029 The July 2026 Globes report of advanced acquisition talks with Cyera up to $1 billion introduces strategic-distraction and process-risk even if the deal never closes. Medium SR029
CR030 Finro’s warning about misread cybersecurity multiples is an adverse reminder that financing expectations can compress quickly if public comparables stay weak. Medium SR030
CR031 The home page’s customer-outcome claims suggest large regulated deployments, but they do not provide the retention or concentration detail needed to judge revenue durability risk. Medium SR032, SR028
CR032 The AI-native engineering post implies Oasis is moving quickly with AI-assisted development, which can increase execution speed but also raises process-discipline risk if security foundations lag. Medium SR031
CR033 The combination of healthcare, financial-services, and AI-governance positioning means Oasis faces high buyer expectations on privacy, auditability, and policy enforcement. Medium SR001, SR023, SR032
CR034 Service-credit-only remedies and customer-controlled data/legal obligations shift significant operational and compliance burden back to the customer. High SR001, SR002, SR003
CR035 Public materials do not surface downloadable audit reports, third-party efficacy studies, or broad public benchmark data for AAM and posture analytics. Medium SR023, SR032
CR036 Oasis’s strongest public technical credibility comes from vulnerability research and incident analysis, not from public operational metrics or certification detail. Medium SR012, SR013, SR015, SR016, SR017
CR037 Machine-identity governance failures now transmit into customer risk, operational outages, privacy violations, and financing outcomes rather than staying isolated as a narrow security problem. Medium SR006, SR007, SR022, SR030
CR038 Procurement friction is itself a thesis-break risk because Oasis is selling a new category into buyers already burdened by lengthy security reviews and evolving AI governance expectations. High SR023, SR026
CR039 Public evidence does not show a mature external standards shield yet, so Oasis bears the risk of selling ahead of customer comfort and ahead of settled regulation. High SR004, SR005, SR023
CR040 Large-enterprise and regulated-industry focus can be a moat, but it also concentrates Oasis in slower, more demanding procurement cycles where deployment and renewal proof must be stronger. Medium SR028, SR032
CR041 The repeated breach examples across Cloudflare, Change Healthcare, Cisco, McHire, and AI coding tools support a high-likelihood environment for NHI and agentic-access incidents. Medium SR015, SR016, SR017, SR019, SR020, SR021, SR022
CR042 The overall risk verdict is not that Oasis lacks product-market relevance, but that the company must prove implementation discipline, partner resilience, and buyer trust faster than the threat surface is expanding. Medium SR005, SR023, SR026, SR030, SR032
CV001 Oasis announced a $120 million Series B in March 2026. High SV001, SV002, SV026, SV027, SV028
CV002 Globes reported that Oasis had raised $195 million in total by March 2026. High SV002, SV001
CV003 Globes reported that market sources believed the Series B valued Oasis at about $700 million. Medium SV002
CV004 Newswire said new ARR grew 5x year over year and that most new ARR came from multi-year enterprise agreements. Medium SV001
CV005 Newswire also said Oasis serves dozens of Fortune 500 companies, while Globes said a majority of the client base comes from the Fortune 500. High SV001, SV002
CV006 The home and product pages show Oasis positioning itself as the access-management layer for AI agents and NHIs across major enterprise systems, which supports the strategic-upside thesis. Medium SV004, SV005, SV006
CV007 The AI Access Partnership page suggests large enterprises are actively seeking vetted agentic-security controls, adding demand optionality beyond direct Oasis sales. Medium SV008
CV008 The July 2026 Globes report of advanced talks to sell Oasis to Cyera for up to $1 billion is unconfirmed but does indicate strategic interest around the asset. Medium SV003
CV009 Public evidence still does not disclose Oasis ARR, gross margin, burn, or retention, which prevents clean revenue-multiple underwriting. Medium SV001, SV002, SV019
CV010 Windsor Drake’s Q2 2026 IAM report places mainstream public IAM around 6.0x NTM revenue. Medium SV016, SV017
CV011 The same Windsor analysis says non-human and AI-agent identity platforms clear roughly 15x to 30x revenue in private rounds. Medium SV016, SV017
CV012 Finro argues that mature public cybersecurity comps can materially understate private AI-native cybersecurity valuations. Medium SV019, SV018
CV013 Multiples.vc reported the weighted market-cap performance of its cybersecurity index at +74.6 percent as of July 9, 2026. Medium SV020
CV014 Astrix announced it was joining Cisco, which validates ongoing strategic-buyer appetite for NHI and AI-agent security assets. Medium SV021
CV015 GitGuardian raised a $50 million Series C in February 2026 to expand in secrets and AI-agent security, showing investors are still funding adjacent NHI platforms. Medium SV022
CV016 CyberArk said machine identities outnumber humans by more than 80 to 1 and that security concerns are a major blocker to agentic-AI adoption. High SV023, SV024
CV017 Okta reported $2.855 billion of FY2026 subscription revenue. High SV009, SV013
CV018 SailPoint reported FY2026 ARR of $1.125 billion and SaaS ARR of $746 million. High SV010, SV014
CV019 Rubrik reported fiscal-2026 subscription ARR of $1.46 billion. High SV011, SV015
CV020 CyberArk ended 2025 with $1.44 billion of total ARR and $1.267 billion of subscription ARR. Medium SV012
CV021 The Okta, SailPoint, and Rubrik SEC filings confirm that the relevant public comp set is valued and discussed through recurring-revenue language, not project-services language. High SV013, SV014, SV015
CV022 CyberArk’s Venafi integration and Astrix’s sale to Cisco show that machine-identity capabilities are being consolidated into larger security platforms. High SV021, SV025
CV023 Oasis’s customer-proof surface includes named enterprise references such as Mars, which strengthens the upside case but does not solve retention opacity. Medium SV030, SV005
CV024 The bull thesis is that Oasis becomes a control layer for enterprise agentic access while strategic buyers and growth investors keep paying premium identity-security multiples. Medium SV006, SV007, SV011, SV016, SV021
CV025 The anti-thesis is that market excitement about AI agents outruns real buyer conversion and that missing ARR, margin, and retention proof prevent premium-multiple support. Medium SV019, SV020, SV001, SV002
CV026 A sensible base case anchors near the best-supported public financing mark of about $700 million until fresher operating metrics emerge. Medium SV002
CV027 A credible bull case reaches roughly $1.0 billion if strategic interest proves real or if Oasis can substantiate premium-category ARR and retention. Medium SV003, SV016, SV021
CV028 A reasonable bear case falls toward the mid-hundreds of millions if investors revert to public-IAM comp discipline before Oasis discloses premium-quality metrics. Medium SV016, SV019, SV020
CV029 Public comp data supports valuing identity-security businesses on recurring revenue quality, but Oasis does not yet disclose the denominator needed to apply that framework. Medium SV017, SV018, SV021
CV030 The March 2026 Series B and peer-funding environment suggest Oasis is not under forced-financing pressure in the immediate term. Medium SV001, SV022
CV031 However, the cap table, liquidation preferences, and any venture debt remain undisclosed publicly. Medium SV001, SV002
CV032 Because the current public evidence is rich on category momentum but poor on unit economics, the most defensible recommendation is research-more rather than buy. Medium SV001, SV002, SV019, SV020
CV033 Confidence in that recommendation is medium: the last financing mark is visible, but the operating evidence needed to accept or reject it is incomplete. Medium SV002, SV003, SV019
CV034 Risk rating should remain high because standards, partner dependence, disclosure gaps, and proof burdens all remain material. Medium SV007, SV008, SV019, SV020
CV035 Exit-readiness upside exists because larger security platforms are already consolidating machine-identity and adjacent identity-security assets. Medium SV021, SV025
CV036 Exit-readiness is constrained by Oasis’s private-data opacity: a buyer or late-stage investor would still need ARR, retention, and concentration proof. Medium SV001, SV002, SV019
CV037 The price sensitivity is high: if Oasis can prove strong ARR quality, premium-category framing becomes more credible; if not, the last mark looks harder to defend. Medium SV002, SV016, SV019
CV038 The channel program and partnership surfaces increase distribution optionality, which could support a higher outcome if adoption keeps broadening. Medium SV008, SV029
CV039 The same channel and ecosystem breadth can also obscure where real customer ownership, conversion, and pricing power sit. Medium SV008, SV029
CV040 Series-B coverage consistently frames Oasis as a new category leader in agentic access and non-human identity management. High SV001, SV026, SV028
CV041 Oasis’s home page outcome claims imply substantial enterprise value creation, but those claims are company-authored and therefore insufficient to close the valuation debate on their own. Medium SV004, SV005
CV042 The best public case for upside is strategic scarcity in a growing category; the best public case for caution is that valuation has run ahead of disclosed operating proof. Medium SV016, SV019, SV021, SV022, SV023
Sources
IDPublisherTitleQuote
SO001 Oasis Security Non Human Identity Management Platform | OASIS Security
SO002 Oasis Security non-human identity management | About oasis
SO003 Oasis Security Non-Human Identity Management Platform
SO004 Oasis Security Oasis Security Emerges from Stealth: CEO's Perspective Oasis began as a dream in a modest room in Tel-Aviv.
SO005 Oasis Security Newsroom
SO006 Oasis Security via Newswire Oasis Security Raises $120M Series B to Secure the Rise of Enterprise AI Agents Oasis has seen strong enterprise adoption, with new annual recurring revenue (ARR) growing 5x year over year.
SO007 TechCrunch Oasis Security leaves stealth with $40M to lock down the wild west of non-human identity management The fast-casual food chain Chipotle, property firm JLL and Mercury Financial are among its early users.
SO008 CTech Oasis Security raises $35 million Series A to resolve non-human identity security challenge
SO009 ACCESS Newswire Oasis Secures $35M Series A Extension to Automate Non-Human Identity Security
SO010 Built In NYC Oasis Security Raises $35M Series A Extension Round
SO011 Globes Oasis Security raises $35m, doubles valuation
SO012 SiliconANGLE Oasis Security raises $120M to secure nonhuman identities across AI and cloud environments
SO013 Tech Company News Oasis Security Raises $120 Million In Series B Funding Round Oasis Security raised $120 million in a Series B round led by Craft Ventures, bringing its total funding to $195 million and valuing the company at approximately $700 million post money.
SO014 Globes Israeli co Oasis Security raises $120m
SO015 BankInfoSecurity Oasis Raises $120M Series B to Safeguard Agentic Identities Oasis Security, founded in 2022, employs 142 people and has raised $195 million.
SO016 Digital IT News Michael DeCesare Named President of Oasis Security
SO017 CRN Oasis Aims For Partner Push To Enable ‘Next Wave’ Of Identity Security: President Michael DeCesare
SO018 PR Newswire Oasis Security Launches Channel Program to Accelerate Growth and Make Non-Human Identity Management Mainstream
SO019 Gartner Peer Insights Oasis Security Reviews & Ratings 2026 | Gartner Peer Insights 5.0 (1 Rating) ... SVP IAM ... 3B - 10B USD, Banking.
SO020 CrowdStrike Marketplace Oasis NHI Security Cloud
SO021 Wiz Oasis Security integration | Wiz
SO022 GuidePoint Security 2025 GPSEC St. Louis Agenda
SO023 NIST AI Agent Standards Initiative
SO024 Palo Alto Networks How to Assess Maturity When Machine Identities Outnumber Humans 109:1
SO025 CyberArk Machine Identities Outnumber Humans by More Than 80 to 1: New Report Exposes the Exponential Threats of Fragmented Identity Security
SO026 Globes Cyera in advanced talks to buy Oasis Security for $1b The companies have yet to make a formal announcement about the signing of a deal.
SM001 Mordor Intelligence Non-Human Identity (NHI) Security Market Size, Share & 2031 Growth Trends Report
SM002 Yahoo Finance / Research and Markets Non-Human Identity Access Management Market Global Forecast Report 2026-2036: Opportunities in Adoption of Zero Trust Architecture, Cloud-native Applications, and Regulatory Compliance Requirements
SM003 Research and Markets Non-Human Identity Access Management Market by Offering, Identity Type, Deployment Mode, Organization Size, and Vertical - Global Forecast to 2036
SM004 Palo Alto Networks How to Assess Maturity When Machine Identities Outnumber Humans 109:1
SM005 Axis Intelligence Machine Identity Statistics 2026: Non-Human Identity Ratios, Secrets Sprawl, and Certificate Lifecycle Data
SM006 NIST AI Agent Standards Initiative
SM007 Cloud Security Alliance NIST AI Agent Standards: Enterprise Governance Implications
SM008 Cloud Security Alliance The AI Agent Governance Gap: What CISOs Need Now
SM009 ShareuHack OWASP Agentic AI Security Maturity Framework 2026: Where Does Your Agent Stand?
SM010 ITECS Agentic AI Governance Framework 2026 | Shadow AI Guide
SM011 GitGuardian Core concepts | GitGuardian documentation
SM012 GitGuardian Non Human Identities Lifecycle Management: Best Practices
SM013 GitGuardian GitGuardian Launches Comprehensive Non-Human Identities Security Strategy
SM014 GitGuardian Non-Human Identity Security in the Age of AI
SM015 Saviynt Non-Human Identity Management | Non-Human Identities (NHI) Security
SM016 Saviynt Non-Human Identity Security with Identity Security Posture Management | ISPM Solution for NHI | Saviynt
SM017 Saviynt Saviynt & Wiz: Unified Non-Human Identity Security
SM018 Delinea What are Non-Human Identities (NHIs)?
SM019 Delinea The Importance of Continuous Discovery in Identity Security
SM020 Delinea How to Secure Non-Human Identities and AI Agents
SM021 HashiCorp Developer Secure AI agent authentication using HashiCorp Vault dynamic secrets | HashiCorp Developer
SM022 HashiCorp Developer Identity secrets engine | Vault | HashiCorp Developer
SM023 Aembit Aembit | Agentic AI and Workload Identity & Access Management
SM024 SPIFFE Secure Production Identity Framework for Everyone
SM025 WorkOS March Updates — WorkOS
SM026 Oasis Security AI
SM027 Oasis Security Finance
SM028 Oasis Security Healthcare
SP001 Oasis Security Non Human Identity Management Platform | OASIS Security
SP002 Oasis Security Non-Human Identity Management Platform
SP003 Aembit Aembit | Agentic AI and Workload Identity & Access Management
SP004 Entro Security Agentic AI & Non-Human Identity Security Platform | Entro Security
SP005 Astrix Security Identity Security for AI Agents & NHIs | Astrix Security
SP006 CyberArk Machine Identity Security
SP007 CyberArk State of Machine Identity Security Report
SP008 HashiCorp Developer Secure AI agent authentication using HashiCorp Vault dynamic secrets | HashiCorp Developer
SP009 HashiCorp Developer Identity secrets engine | Vault | HashiCorp Developer
SP010 Saviynt Non-Human Identity Management | Non-Human Identities (NHI) Security
SP011 Saviynt Non-Human Identity Security with Identity Security Posture Management | ISPM Solution for NHI | Saviynt
SP012 Saviynt Saviynt & Wiz: Unified Non-Human Identity Security
SP013 Delinea What are Non-Human Identities (NHIs)?
SP014 Delinea How to Secure Non-Human Identities and AI Agents
SP015 Delinea The Importance of Continuous Discovery in Identity Security
SP016 GitGuardian GitGuardian Launches Comprehensive Non-Human Identities Security Strategy
SP017 GitGuardian Top 10 Non-Human Identity Security Tools and Platforms for 2026
SP018 GitGuardian OWASP NHI Top 10 Risks for 2025 Explained by GitGuardian
SP019 SPIFFE Secure Production Identity Framework for Everyone
SP020 WorkOS March Updates — WorkOS
SP021 CrowdStrike Marketplace Oasis NHI Security Cloud
SP022 Wiz Oasis Security integration | Wiz
SP023 Gartner Peer Insights Oasis Security Reviews & Ratings 2026 | Gartner Peer Insights
SP024 SourceForge Oasis Security
SP025 Slashdot Oasis Security
SI001 Oasis Security Non Human Identity Management SAAS SUBSCRIPTION AGREEMENT
SI002 Oasis Security DATA PROCESSING AGREEMENT/ ADDENDUM (“DPA”)
SI003 Oasis Security SLA
SI004 AWS Marketplace AWS Marketplace: OASIS Security
SI005 Oasis Security non-human identity management | About oasis
SI006 Oasis Security NHI Provisioning: Secure Non-Human Identities from Day One
SI007 Oasis Security How Financial Services Secures Azure NHIs | Oasis Security
SI008 Oasis Security Governance
SI009 Oasis Security secret rotation | Oasis Security
SI010 Oasis Security Finance
SI011 Oasis Security Non-Human Identity Management Careers | OASIS Security
SI012 Newswire Oasis Security Raises $120M Series B to Secure the Rise of Enterprise AI Agents
SI013 Globes Israeli co Oasis Security raises $120m
SI014 SiliconANGLE Oasis Security raises $120M to secure nonhuman identities across AI and cloud environments
SI015 PR Newswire Oasis Security Launches Channel Program to Accelerate Growth and Make Non-Human Identity Management Mainstream
SI016 GuidePoint Security GuidePoint Security OASIS+
SI017 CrowdStrike Marketplace Oasis NHI Security Cloud
SI018 Wiz Oasis Security integration | Wiz
SI019 Okta Investor Relations Okta Announces Fourth Quarter And Fiscal Year 2026 Financial Results
SI020 SailPoint Investor Relations SailPoint Announces Fiscal Fourth Quarter and Full Year 2026 Results
SI021 Rubrik Rubrik Reports Fourth Quarter and Fiscal Year 2026 Financial Results
SI022 CyberArk CyberArk Announces Record Fourth Quarter and Full Year 2025 Results
SI023 SEC Annual Report for Fiscal Year Ending January 31, 2026 (Form 10-K)
SI024 SEC EDGAR Filing Documents for 0002030781-26-000003
SI025 Windsor Drake Identity & Access Management Valuations: Q2 2026
SI026 Finro Cybersecurity valuation benchmarks are routinely misread
SI027 SEC EDGAR Entity Landing Page - CyberArk
SE001 Oasis Security Oasis Agentic Access Management
SE002 Oasis Security Oasis Agentic Access Management (AAM™): Secure, Govern, and Control AI Agent Access
SE003 Oasis Security AI Access Partnership Program | Enterprise-Ready AI Security | Oasis Security
SE004 Oasis Security Cursor & Oasis: Intent-Based Access & Governance for AI Agents
SE005 Oasis Security Agentic Access Management: Why Visibility Is the Foundation of AI Governance
SE006 Oasis Security AI & NHI Security: Navigating LLM + MCP Risks
SE007 Oasis Security ClawJacked: OpenClaw Vulnerability Enables Full Agent Takeover
SE008 Oasis Security RPA to AI Agents Secure Access | Oasis Security
SE009 Oasis Security Governance
SE010 Oasis Security Posture Management
SE011 Oasis Security secret rotation | Oasis Security
SE012 Oasis Security AI
SE013 Oasis Security How Financial Services Secures Azure NHIs | Oasis Security
SE014 Oasis Security Oasis + Wiz: From Cloud Exposure to Identity-Governed Action
SE015 Oasis Security Zero Trust for Non-Human & Agentic Identities | Oasis + Zscaler
SE016 Oasis Security Oasis Joins the CrowdStrike Marketplace | Strategic Partnership
SE017 Oasis Security Agentic AI Security: Oasis Named in Gartner AI TRISM Report
SE018 Oasis Security Non-Human Identity Management Careers | OASIS Security
SE019 Oasis Security AI-Native Engineering Teams: Speed, Culture, and Security Lessons
SE020 HashiCorp Developer Secure AI agent authentication using HashiCorp Vault dynamic secrets | HashiCorp Developer
SE021 GitGuardian Core concepts | GitGuardian documentation
SE022 SPIFFE Secure Production Identity Framework for Everyone
SE023 NIST AI Agent Standards Initiative
SE024 PR Newswire Oasis Security Launches Agentic Access Management, the First Identity Solution Built for AI Agents
SE025 PR Newswire Oasis Security and Sequoia Launch the First Practitioner-Built Governance Framework for Agentic AI Access
SE026 CyberArk State of Machine Identity Security Report
SE027 Delinea 2026: AI Breaks Identity Security and Forces a New Playbook
SE028 Wiz Oasis Security integration | Wiz
SE029 CrowdStrike Marketplace Oasis NHI Security Cloud
SU001 Oasis Security non-human identity management | About oasis
SU002 Oasis Security Non-Human Identity Management Platform
SU003 Oasis Security Non Human Identity Management Platform | OASIS Security
SU004 Oasis Security How Financial Services Secures Azure NHIs | Oasis Security
SU005 Oasis Security Non-Human Identity Management: NHI Visibility with Oasis
SU006 Oasis Security Video: Mars Case Study: Scaling Non-Human Identity Security | Oasis Security
SU007 Oasis Security Webinar: Optimizing Non-Human Identities (NHIs) in Azure Environment
SU008 Oasis Security Webinar: NHIM Case Study | Security Challenges | Oasis Security
SU009 Oasis Security Whitepaper: Oasis Security for Financial Services
SU010 Oasis Security Whitepaper: Securing Non-Human Identities for Financial Services
SU011 Oasis Security Bank of America
SU012 Oasis Security Finance
SU013 Oasis Security Healthcare
SU014 Oasis Security AI Access Partnership Program | Enterprise-Ready AI Security | Oasis Security
SU015 Gartner Peer Insights Oasis Security Reviews & Ratings 2026 | Gartner Peer Insights
SU016 SourceForge Oasis Security
SU017 Slashdot Oasis Security
SU018 GuidePoint Security GuidePoint Security OASIS+
SU019 PR Newswire Oasis Security Launches Channel Program to Accelerate Growth and Make Non-Human Identity Management Mainstream
SU020 CrowdStrike Marketplace Oasis NHI Security Cloud
SU021 Wiz Oasis Security integration | Wiz
SU022 Newswire Oasis Security Raises $120M Series B to Secure the Rise of Enterprise AI Agents
SU023 Globes Israeli co Oasis Security raises $120m
SU024 Oasis Security Video: Addressing Risks of Unmanaged Non-Human Identities
SU025 Oasis Security Video: Insights from Oasis CEO Danny Brickman on ISMG
SU026 Oasis Security Video: Non-Human Identity Management: What and Why
SR001 Oasis Security DATA PROCESSING AGREEMENT/ ADDENDUM (“DPA”)
SR002 Oasis Security Non Human Identity Management SAAS SUBSCRIPTION AGREEMENT
SR003 Oasis Security SLA
SR004 NIST AI Agent Standards Initiative
SR005 Cloud Security Alliance The AI Agent Governance Gap: What CISOs Need Now
SR006 GitGuardian OWASP NHI Top 10 Risks for 2025 Explained by GitGuardian
SR007 CyberArk State of Machine Identity Security Report
SR008 Delinea 2026: AI Breaks Identity Security and Forces a New Playbook
SR009 Palo Alto Networks How to Assess Maturity When Machine Identities Outnumber Humans 109:1
SR010 ShareuHack OWASP Agentic AI Security Maturity Framework 2026: Where Does Your Agent Stand?
SR011 Oasis Security AI & NHI Security: Navigating LLM + MCP Risks
SR012 Oasis Security ClawJacked: OpenClaw Vulnerability Enables Full Agent Takeover
SR013 Oasis Security Claude.ai Prompt Injection Vulnerability | Oasis Security
SR014 Oasis Security Claude Tag: Agent Identity and the NHI Governance Gap
SR015 Oasis Security Cline Kanban WebSocket Hijack: How a Localhost Vulnerability Exposes AI Agents | Oasis Security
SR016 Oasis Security Cursor “Open-Folder” Autorun Vulnerability Exposes Developers to Silent Code Execution | Oasis Security Research
SR017 Oasis Security One-Click Attack on VS Code Exposes Developer Machines
SR018 Oasis Security Lessons from the MCP Breach: Shadow AI & Discovery
SR019 Oasis Security McHire AI Breach: Password “123456” Exposed 64M Applicants
SR020 Oasis Security Non-Human Identity Insights from the Change Health Breach
SR021 Oasis Security Non-Human Identities: Insights from the Cloudflare Breach
SR022 Oasis Security Cisco Breach: NHI Compromise Exposes DevOps Security Risks
SR023 Oasis Security AI Access Partnership Program | Enterprise-Ready AI Security | Oasis Security
SR024 Oasis Security Zero Trust for Non-Human & Agentic Identities | Oasis + Zscaler
SR025 Oasis Security Oasis + Wiz: From Cloud Exposure to Identity-Governed Action
SR026 PR Newswire Oasis Security Launches Channel Program to Accelerate Growth and Make Non-Human Identity Management Mainstream
SR027 GuidePoint Security GuidePoint Security OASIS+
SR028 Newswire Oasis Security Raises $120M Series B to Secure the Rise of Enterprise AI Agents
SR029 Globes Cyera in advanced talks to buy Oasis Security for $1b
SR030 Finro Cybersecurity valuation benchmarks are routinely misread
SR031 Oasis Security AI-Native Engineering Teams: Speed, Culture, and Security Lessons
SR032 Oasis Security Non Human Identity Management Platform | OASIS Security
SV001 Newswire Oasis Security Raises $120M Series B to Secure the Rise of Enterprise AI Agents
SV002 Globes Israeli co Oasis Security raises $120m
SV003 Globes Cyera in advanced talks to buy Oasis Security for $1b
SV004 Oasis Security Non Human Identity Management Platform | OASIS Security
SV005 Oasis Security Non-Human Identity Management Platform
SV006 PR Newswire Oasis Security Launches Agentic Access Management, the First Identity Solution Built for AI Agents
SV007 PR Newswire Oasis Security and Sequoia Launch the First Practitioner-Built Governance Framework for Agentic AI Access
SV008 Oasis Security AI Access Partnership Program | Enterprise-Ready AI Security | Oasis Security
SV009 Okta Investor Relations Okta Announces Fourth Quarter And Fiscal Year 2026 Financial Results
SV010 SailPoint Investor Relations SailPoint Announces Fiscal Fourth Quarter and Full Year 2026 Results
SV011 Rubrik Rubrik Reports Fourth Quarter and Fiscal Year 2026 Financial Results
SV012 CyberArk CyberArk Announces Record Fourth Quarter and Full Year 2025 Results
SV013 SEC Annual Report for Fiscal Year Ending January 31, 2026 (Form 10-K)
SV014 SEC EDGAR Filing Documents for 0002030781-26-000003
SV015 SEC XBRL Viewer
SV016 Windsor Drake Identity & Access Management Valuations: Q2 2026
SV017 Windsor Drake Identity & Access Management Valuations: Q2 2026
SV018 Finro Cybersecurity Multiples Q2 2026 | 265 companies, 9 niches | Finro
SV019 Finro Cybersecurity valuation benchmarks are routinely misread
SV020 Multiples.vc Multiples Cybersecurity Index
SV021 Astrix Security A New Chapter: Astrix Security is Joining Cisco
SV022 GitGuardian GitGuardian Raises $50M Series C to Address Non-Human Identities Crisis and AI Agent Security Gap
SV023 CyberArk Machine Identities Outnumber Humans by More Than 80 to 1: New Report Exposes the Exponential Threats of Fragmented Identity Security
SV024 CyberArk State of Machine Identity Security Report
SV025 CyberArk Venafi is now CyberArk Machine Identity Security
SV026 SiliconANGLE Oasis Security raises $120M to secure nonhuman identities across AI and cloud environments
SV027 Access Newswire Oasis Security Raises $120 Million in Series B Funding to Revolutionize the Agentic Access Era
SV028 TechCompanyNews Oasis Security Secures $120M Series B to Accelerate Growth in AI Agent and Non-Human Identity Security
SV029 PR Newswire Oasis Security Launches Channel Program to Accelerate Growth and Make Non-Human Identity Management Mainstream
SV030 Oasis Security Video: Mars Case Study: Scaling Non-Human Identity Security | Oasis Security