初创公司尽调
尽调报告 Cybersecurity Series B 2026-07-10

Oasis Security

智能体访问治理:为非人类身份的新控制层定价

Oasis Security 所在的非人类身份治理赛道增速快、战略重要性高,但公开材料目前更支持继续尽调,而不是直接形成高确信度判断,因为影响估值的经营指标仍未披露。

封面要素

最近融资 01
$120M Series B [CO010]
累计融资 02
195 USD millions [CO011]
估值 03
700 USD millions [CO012]
成立时间 04
2022 [CO001]
客户结构 05
Fortune 500 majority [CO013]
员工数 06
142 [CO017]

公司概况

Oasis Security 是一家与纽约和以色列均有连接的网络安全公司,切入现代企业基础设施里最重要的身份变化之一:非人类身份和 AI 智能体的上升。它的平台把发现、归属映射、态势管理、密钥轮换、配置开通和智能体访问控制放在一起,帮助企业在云、SaaS、本地部署和开发者工具环境中治理机器身份与 AI 智能体。Danny Brickman 和 Amit Zimerman 于 2022 年创立 Oasis,公司很快从隐身状态走到 $120M Series B,讲出了以 Fortune 500 为主的客户故事,并把定位从 NHI 生命周期管理扩展到更宽的智能体访问治理。战略叙事很强,但公司仍是私人公司,财务指标披露明显不足,投资人还无法有把握地验证隐含估值。

官网
www.oasis.security
成立时间
2022-01-01
创始人
Danny Brickman, Amit Zimerman
创立地点
Tel Aviv, Israel
总部
Tel Aviv, Israel & New York, USA
产品
Oasis 销售一套软件平台,用于发现、治理并保护非人类身份和 AI 智能体。核心功能包括身份盘点、上下文和归属映射、态势与异常分析、生命周期治理、密钥轮换、配置开通,以及面向智能体访问的即时 / 策略驱动控制。
客户
主要服务大型企业,尤其是金融服务、医疗、制造、物流、保险和 AI 平台生态中受监管或运营复杂度高的组织;销售路径包括直接企业销售和合作伙伴辅助采购。
商业模式
定制报价的企业 SaaS,通过议价订阅协议、多年期企业合同和合作伙伴 / Marketplace 路径销售。
阶段
Series B
融资情况
2026 年 3 月完成 $120M Series B;公开报道显示累计融资约 $195M,最有公开依据的估值锚点约为 ~$700M 投后估值。
[CO001, CO002, CO010, CO011, CO012, CO013, CO017, CO032]

执行摘要

主要优势

  • 与 AI 智能体和非人类身份治理兴起高度同频
  • 融资推进很快,已完成顶级网络安全和软件投资机构支持的 $120M Series B
  • 客户叙事偏 Fortune 500,并且在医疗、金融服务、工业和大型企业环境中已有真实部署深度
  • 产品宽度已覆盖发现、态势、轮换、配置和智能体访问控制,不再只是单点功能
  • 大型厂商开始融资或收购相邻机器身份资产,战略稀缺性在改善

主要风险

  • ARR、毛利率、烧钱速度、留存和客户集中度仍未披露,估值很难承销
  • 公司切入的市场中,标准和采购预期仍在追赶智能体 AI 安全需求
  • 执行不仅取决于产品质量,还取决于合作伙伴生态和信任转化
  • 如果 Oasis 无法验证高质量经常性收入,隐含估值溢价可能迅速压缩
  • 据报道的 Cyera 洽谈等战略进程噪音可能分散执行精力,但不保证带来上行

未决问题

  • 当前 ARR 和季度 ARR 桥接
  • 毛利率、烧钱速度、现金跑道和资本效率指标
  • NRR / GRR、流失率以及按细分市场划分的续约行为
  • 头部客户、合作伙伴和垂直行业集中度
  • 股权结构表条款、优先权、风险债务和任何老股交易
  • 可供引用、且与扩张绑定的客户证据,而不只是初始部署

目录

Chapter 01

01公司概况

1.1 身份、产品范围与创立背景

理解 Oasis Security,最好不要把它看成一个狭义的密钥工具,而是一家走出隐身状态后的基础设施安全公司,卖的是非人类身份治理。公司在官网首页、关于页面、产品页和创立博客中,都把平台描述成一套系统:发现机器身份,映射归属和使用上下文,并编排监控、认证、修复、下线等生命周期控制。它的产品语言刻意拉得很宽:Oasis 称覆盖 IaaS、SaaS、PaaS 和本地部署环境,端点包括 AWS、Azure、BigQuery、GitHub、ChatGPT、Salesforce、Office 365、Copilot 等。这个宽度很关键,因为它暗示公司想站在碎片化 vault 和点状工具之上,成为身份治理层。官方起源故事也给 Oasis 加了一层独特叙事:Danny Brickman 称公司起步于特拉维夫一间简陋房间,团队成员来自以色列网络行动;独立报道则将 Brickman 和 Amit Zimerman 确认为创始组合。结果是一家公司技术根基明显带有以色列色彩,但商业叙事如今锚定美国企业身份安全。[CO001, CO002, CO003, CO004, CO005, CO006]

关键 KPI 快照表
指标数值 / 状态日期置信度缺口 / 注意事项
成立时间20222022多个 2024-2026 年来源对成立年份说法一致
商业总部纽约2026Tech Company News 和 BankInfoSecurity 支持这一点,但公司网站没有发布企业地址页面
技术 / 起源足迹Tel Aviv 根基;以色列招聘加美国招聘2024-2026官方创立博客和 Globes 指向以色列根基,但没有公开正式双办公室名册
最新披露轮次$120M Series B,Craft Ventures 领投2026-03-19轮次细节得到公司和独立媒体交叉印证
累计披露融资$195M2026-03-19官方和独立 2026 年报道口径一致
证据最充分的估值估计~$700M 投后估值2026-03数值由市场消息人士报道,并非公司正式披露
客户组合客户基础多数来自 Fortune 5002026公司说法;确切客户数未披露
公开具名客户Chipotle;JLL;Mercury Financial2024-01公开浮现的客户名称只有少数
ARR 信号新增 ARR 同比增长 5x2026披露了增长率,未披露 ARR 金额
员工数信号Jan 2024 为 45 人;Mar 2026 为 142 人2024-2026后一数字来自一篇独立文章,而非公司披露
治理披露创始人与总裁公开;完整董事会未公开2026未找到完整董事会名册或委员会信息
M&A 背景Cyera 收购谈判被报道;无正式公告2026-07-06不利战略背景可能快速变化,且未获公司文件或公告确认

各行刻意区分披露数值、市场估计和未披露项目,方便后续章节复用快照时不把估计当成公司确认事实。

[CO001, CO011, CO012, CO013, CO014, CO016]
FO002: 公司快照逻辑

Oasis 把机器身份发现和治理,与 AI 智能体采用、企业采购和生态集成连在一起。

[CO004, CO005, CO006, CO013, CO020, CO023]

1.2 融资历史、投资人图谱与治理信号

Oasis 通过私募融资里程碑的速度异常快。公司于 2024 年 1 月公开亮相,当时已经完成 $35 million Series A,累计融资 $40 million;2024 年 5 月又完成 $35 million 延伸轮,管理层和媒体称估值较上一轮翻倍,累计融资升至 $75 million。最重要的融资事件是 2026 年 3 月 Series B:Oasis 宣布由 Craft Ventures 领投 $120 million,老股东 Cyberstarts、Sequoia Capital 和 Accel 继续跟投,累计融资达到 $195 million。Globes 和 Tech Company News 的独立报道将投后估值放在约 $700 million,明显低于用户提供背景中的 $1.2 billion,因此它是当前更有公开依据的价值锚点。治理披露比融资披露更薄。公开来源清楚识别了创始人,以及 2026 年 4 月 Michael DeCesare 出任总裁,但没有披露完整董事会名单、委员会结构或股权结构细节。因此,投资人阵容是优势,治理透明度仍是未解决的尽调项。[CO001, CO002, CO007, CO008, CO009, CO010]

领导层与创始人表
人物职务背景职能覆盖 / 相关性关键人依赖
Danny Brickman联合创始人兼 CEO公开资料称其曾任 IDF 网络 R&D 负责人,拥有 7 年以上军事网络经验创始愿景、品类布道、企业可信度,以及产品战略的外部代表
Amit Zimerman联合创始人兼 CPO多篇融资报道将其列为联合创始人兼首席产品官负责产品战略,并把 NHI 问题集转译成技术产品
Michael DeCesare总裁(2026 年 4 月任命)职业网络安全 GTM 操盘手;Series B 后加入,负责销售、营销、联盟和客户成功在创始人主导早期销售之后,将 GTM 和渠道扩张专业化
创始团队 / IDF 网络安全同侪非正式技术创始班底官方创立博客指向围绕创始人的更广泛 Tel Aviv 网络运营核心支撑公司拥有深厚实战者 DNA 的说法,即便公开具名创始人只有两位

覆盖范围不完整,因为已审阅来源没有发布超出创始人和 2026 年总裁任命之外的正式高管或董事会名册。

[CO002, CO003, CO019, CO034]
利益相关方 / 投资人地图
利益相关方角色控制权 / 经济重要性证据尽调请求
Craft VenturesSeries B 领投方2026 年主要资金提供方;在最大已披露轮次后,很可能拥有重要董事会影响力Series B 新闻稿及后续报道确认持股、清算优先权和董事会权利
Cyberstarts重复投资人既有投资人再次参与 Series B,显示持续的赞助方信心Series B 新闻稿确认累计持股和任何治理权利
Sequoia CapitalSeries A 和延伸轮支持方;Series B 参与方顶级赞助方,跨多个轮次参与TechCrunch、CTech、Access Newswire、Series B 报道确认 Sequoia 是否保留正式董事会或观察员权利
AccelSeries A 领投组、延伸轮共同领投、Series B 参与方贯穿每个已披露融资阶段的长期投资人CTech、Access Newswire、Series B 报道确认持股规模和所有权集中度
Maple CapitalSeries A 参与方仅在最初退出隐身融资中被具名TechCrunch 和 CTech确认该基金在后续轮次是否保留按比例跟投权
GuidePoint Security战略经销伙伴不是股权投资人,但可能是北美重要渠道放大器PR Newswire 渠道发布;GPSEC 日程要求提供该渠道动作的来源管线和转化指标
CrowdStrike 与 Wiz 生态伙伴集成分发节点应用市场 / 集成曝光即便没有直接经济所有权,也会影响交易速度应用市场和集成页面厘清附着率、共同客户和来源贡献

该地图混合了股权利益相关方和商业战略伙伴,因为公开股权结构披露稀疏,而伙伴杠杆已经是当前增长叙事的一部分。

[CO008, CO009, CO010, CO020, CO023, CO024]

1.3 牵引信号、合作伙伴验证与品类时机

牵引证据真实存在,但仍有选择性。公司最强的说法是:Oasis 的客户多数来自 Fortune 500,进入 Series B 前新增 ARR 同比增长 5 倍。这个方向很亮眼,尤其是管理层还称大部分新增 ARR 来自多年期企业协议。独立公开客户证据则更浅:TechCrunch 点名 Chipotle、JLL 和 Mercury Financial 为早期用户;Gartner Peer Insights 在 2026 年初只有一条银行业评价,评分 5.0。合作伙伴界面强化了采用故事。CrowdStrike 的 Marketplace 上架页和 Wiz 的集成页面都把 Oasis 描述成活跃生态参与者,而不是概念型集成。第三方品类信号同样重要,说明市场窗口真实存在。NIST 在 2026 年启动 AI Agent Standards Initiative,Palo Alto Networks 称机器身份与人类身份的比例达到 109:1,CyberArk 则把机器身份问题描述为可能引发入侵和宕机的风险向量。因此,Oasis 不是在卖一个人为拼出的品类,而是在切入大型安全厂商和标准机构也认为紧迫的问题。[CO013, CO014, CO015, CO016, CO020, CO021]

FO003: 快照 KPI

公开披露的指标在融资和增长方向上较强,但客户数、ARR 金额和治理细节偏弱。

[CO012, CO013, CO014, CO016, CO017, CO018]

1.4 里程碑、披露缺口与反向背景

公开来源给出的里程碑足以支撑公司概况章节,但仍留下明显缺口。公司从 2024 年 1 月走出隐身状态,到 2024 年 5 月 Series A 延伸轮,2025 年 4 月正式推出渠道计划,2026 年 3 月完成 Series B,并在 2026 年 4 月扩充高管团队。这些里程碑说明公司正在把早期产品楔子推向规模化企业平台。缺失的部分同样关键。已审阅来源没有公布精确客户数、确切 ARR 金额、董事会名单或经审计财务。即便讨论最多的估值数字,也只是市场估计,并非董事会认可后由公司披露的数字。最清晰的反向背景是 Globes 2026 年 7 月报道:Cyera 正在就最高 $1 billion 收购 Oasis 进行深入谈判,但尚无正式公告。这并不否定 $700 million 融资基准,却说明到本报告生成日,围绕 Oasis 的战略选项叙事已经变化。投资人因此应把公司看作资金充足、赛道关联度高,但在支撑后续章节形成价格敏感判断的指标上仍明显披露不足。[CO011, CO012, CO017, CO018, CO020, CO021]

里程碑表
日期事件类型金额 / 状态参与方含义
2022公司成立创立已成立Danny Brickman;Amit Zimerman确认公司是 2022 年创立的创业公司,而不是 2023 年才诞生
2024-01退出隐身并宣布 Series A融资$35M Series A;当时累计融资 $40MSequoia;Accel;Cyberstarts;Maple;天使投资人公开发布前已验证早期客户牵引力
2024-05Series A 延伸轮融资$35M 延伸轮;累计融资 $75MAccel;Cyberstarts;Sequoia将上一轮估值翻倍,并为追加招聘提供资金
2025-04渠道计划启动合作计划上线;GuidePoint 被具名为经销商Oasis;GuidePoint Security标志销售从创始人主导转向杠杆化分发
2025-05GuidePoint GPSEC 会议场次治理公开会议露出GuidePoint;Oasis显示 Series B 前,NHI 思想领导力已进入渠道活动
2026-03-19宣布 Series B融资$120M;累计融资 $195MCraft Ventures、Cyberstarts、Sequoia、Accel 等投资方为更广泛 GTM 和智能体 AI 扩张建立资金基础
2026-04-23任命总裁治理Michael DeCesare 加入Oasis在 ARR 快速增长后补入专业 GTM 负责人
2026-07-06Cyera 收购谈判被报道反向仅被报道;未正式宣布Cyera;Oasis引入战略选项噪音,并可能把估值重置到约 $1B

时间线只使用已审阅公开来源中出现日期的事件,并将 2026 年 7 月 M&A 传闻与已完成融资事实分开。

[CO001, CO007, CO009, CO010, CO019, CO020]
FO001: 公司里程碑时间线

公开里程碑显示,Oasis 从隐身期退出到渠道扩张、Series B 融资和战略选项传闻,推进速度很快。

[CO001, CO007, CO009, CO010, CO019, CO020]

1.5 图表

Chapter 02

02市场分析

2.1 市场边界、纳入支出与现状替代方案

误读 Oasis 市场最快的方式,就是把它当作换了包装的密钥管理器。公开来源定义的其实是更宽的问题集:如今的 NHI 包括应用和服务身份、API 与 OAuth 令牌、机器和设备身份、加密身份、机器人、工作负载,以及越来越多的 AI 智能体。这意味着相关支出边界包括发现、态势、归属分配、生命周期治理,以及自动化行动主体的运行时授权。现状也因此高度碎片化。一些买家尝试用 HashiCorp Vault 等密钥库或身份存储解决部分问题;另一些买家依赖云原生 IAM、SPIFFE 式工作负载身份,或手工 CMDB 归属流程。这些替代方案能处理凭据签发或底层工作负载身份,却无法单独在企业范围内覆盖每一个机器身份和被委托的 AI 动作。NHI 市场因此更像一层汇聚层,夹在传统 IAM/PAM、密钥管理、平台工程和 AI 治理工作流之间。[CM001, CM002, CM003, CM021, CM023, CM027]

市场定义表
细分 / 品类纳入支出排除支出买方 / 付款方与 Oasis 的相关性
专用 NHI 治理机器身份和 AI 身份的发现、归属、态势、生命周期、修复、政策编排人类员工 IAM 和纯用户 SSOCISO / IAM / 平台安全赞助方直接目标品类
Vault / 密钥管理密钥存储、签发、轮换、身份存储管道对每个 NHI 和 AI 动作的完整业务治理平台工程 / DevSecOps既有方案替代品和集成点
工作负载身份框架基础设施和服务的加密工作负载身份业务负责人映射、合规工作流、跨 SaaS 治理平台工程 / 基础设施团队基础性替代品,不是完整治理层
云原生 IAM单一超大规模云内的云权限、角色、服务主体跨云、SaaS 和 AI 智能体生命周期治理云卓越中心相邻既有品类
智能体身份 / 开发者访问平台会话范围内的智能体凭证和 MCP 式身份边界广泛 NHI 态势和企业级归属清单开发者工具 / 平台团队新兴相邻支出

边界刻意画在治理和生命周期控制周围,而不是所有能够保存或铸造凭证的产品。

[CM001, CM002, CM003, CM027, CM028, CM029]

2.2 规模测算口径、身份分层与区域形态

NHI 治理的公开市场规模信号方向很强,但数字并不干净。Mordor Intelligence 将较窄的 NHI 安全细分市场估为 2026 年 $8.22 billion、2031 年 $22.94 billion;Research and Markets 及其 Yahoo Finance 分发伙伴则把更宽的 NHI 访问管理类别估为 2026 年 $12.2 billion、2036 年 $38.8 billion。这个差距不是噪音,而是边界不同。较宽估算覆盖不同身份类型、部署模式、组织规模和垂直行业上的解决方案与服务层;较窄估算更接近安全控制子集。区域形态比精确 SAM 更清楚:北美当前领先,亚太预计增长最快,大型企业主导现有需求。较宽预测还明确列出身份类型分层:应用和服务身份、API 与 OAuth 令牌身份、机器和设备身份、加密身份、AI 智能体身份都已经是一线子分段。正确结论是:市场真实、庞大且快速扩张,但公开信息无法给出干净的 Oasis 专属 SOM。[CM004, CM005, CM006, CM007, CM008, CM009]

TAM / SAM / SOM 或规模测算视角表
发布方 / 视角年份 / 展望期地域数值增长 / CAGR方法 / 限制
Mordor Intelligence:NHI 安全市场2026 / 2031全球2026 年 $8.22B;2031 年达 $22.94B22.78% CAGR较窄的安全视角;对治理 / 控制支出有用,但不是已发布的 Oasis 专属 SAM
Research and Markets / Yahoo:NHI 访问管理2026 / 2036全球2026 年 $12.2B;2036 年达 $38.8B12.2% CAGR更宽的访问管理口径,包含跨身份类型的解决方案和服务
Yahoo / R&M 的区域视角2026按区域划分的全球北美最大;亚太增长最快n/a定性区域层级,不是离散子市场金额表
Research and Markets 的身份类型视角2026-2036全球应用 / 服务;API/OAuth;机器 / 设备;加密;AI 智能体身份n/a细分视角有助于框定,但本身不能产出干净的 SOM
Oasis 相关可服务切片2026北美 + 受监管企业优先未公开单独拆出n/a需要管理层对附着率、垂直重点和买方转化作出假设

市场数字保留为不同视角,因为公开来源采用不同边界和预测期;最后一行刻意不填数字,以避免编造 SOM 精度。

[CM004, CM005, CM006, CM007, CM008, CM009]
FM001: 市场规模视角

公开市场来源支持三层视角:宽口径 NHI 访问管理、更窄的 NHI 安全,以及尚未公开的类 Oasis 可服务切片。

[CM001, CM004, CM006, CM007, CM033, CM037]
FM002: 市场估计区间

已发布估计最好视为有边界的区间,因为各来源使用的品类定义和预测周期不同。

[CM004, CM005, CM006, CM011, CM014]

2.3 买家、垂直用例与采用如何真正起步

买家结构很重要,因为这个品类很少只归一个团队所有。Oasis、Saviynt、Delinea、GitGuardian、Aembit 和 HashiCorp 的产品叙事都指向一个共同控制模型:IAM/PAM 负责人关心身份治理,云和平台团队关心工作负载访问模式,受监管业务负责人关心可审计性和韧性。Oasis 自己的解决方案页面把这一点讲得更具体。AI 页面强调把 AI 智能体限制在获批模型供应商内,并执行最小权限;金融页面把痛点连接到 PCI DSS 4.0、SOC 2 和数字运营连续性;医疗页面则连接到患者隐私、HIPAA/GDPR 式义务和不间断护理。整个市场里,采用通常从发现和盘点开始,再进入归属认定和风险标记,然后推进到生命周期策略,最后才走向运行时授权或无密钥执行。这个顺序提醒我们:很多买家会先落在可见性和态势上,等信任建立后才把内联访问控制交给供应商。[CM015, CM021, CM022, CM025, CM026, CM029]

细分 / 买方地图
细分买方用户付款方 / 预算所有者工作流触发点采用触发点
AI 智能体治理IAM 或平台安全负责人安全工程师;AI 平台团队安全和平台预算共同承担AI 智能体开始访问企业数据或工具需要限制委托权限并证明可审计性
受监管金融服务CISO / IAM / 合规赞助方云安全和应用团队安全 + 合规预算PCI DSS / SOC 2 证据,或核心工作流中的有毒组合审计压力加上韧性担忧
医疗 / 患者数据环境安全 + 隐私负责人基础设施、应用和运营团队安全 + 隐私预算过度授权服务身份带来患者数据泄露或护理中断风险需要 HIPAA/GDPR 式证据和不中断运营
平台工程 / DevSecOps平台工程负责人开发者和 SRE平台 / 基础设施预算密钥蔓延、令牌泄露或服务账号归属缺口需要自动化和短期访问
多云企业安全IAM / 云安全负责人云与身份运营团队共享安全预算跨云角色蔓延,以及 SaaS 到云的身份链需要跨碎片化工具的统一可见性

预算归属标为共享或拆分,是因为公开供应商材料显示采购通常由多方共同推动,而不是只有一个通用付费方。

[CM030, CM031, CM032, CM033, CM034, CM038]
FM003: 买方紧迫度 / 归属图

买方归属分散;合规、AI 智能体暴露和平台蔓延交汇处,紧迫度最高。

[CM030, CM031, CM032, CM033, CM035, CM036]

2.4 增长驱动、采用约束与标准缺口

最强增长驱动很简单:机器身份和 AI 智能体的扩散速度,已经超过人类 IAM 系统原本能承载的范围。Palo Alto 称机器与人类身份比例在 2026 年达到 109:1,并且仍在上升;Axis Intelligence 同时强调密钥蔓延和长期凭据暴露。在此之上,NIST 已启动 AI Agent Standards Initiative,市场供应商也把它转译成围绕开放协议、最小权限和治理的产品叙事。但同一批来源也说明,市场转化不会一路顺滑。OWASP 式成熟度工作显示采用与保护之间缺口很大;Cloud Security Alliance 称可执行控制尚不存在;ITECS 认为影子 AI 已经跑在可见性前面;Delinea 警告 AI 智能体往往带有持久且权限很宽的访问。实际采购中,紧迫性和合规把买家向前拉,碎片化工具、不清晰的归属和替换既有密钥库或云 IAM 模式的运营负担又把他们拖住。这个组合支撑的是一个高速增长但摩擦真实的市场,而不是直线式抢地盘。[CM011, CM012, CM013, CM014, CM016, CM017]

增长驱动因素与约束因素表
驱动因素 / 约束因素方向时点影响尽调问题
机器身份从 82:1 升至 109:1驱动因素当前问题量累积速度快过人工 IAM 团队的响应能力询问买方目前盘点了多少服务身份,以及数量增长有多快
99% 已采用 AI agent,其中 40% 已触及组织数据驱动因素当前AI agent 访问已从未来问题变成当下采购触发点验证访问治理是否已进入 AI 上线检查点
零信任、开放协议和新兴标准工作驱动因素近期标准活动让品类更正当,也扩大预算讨论范围检查标准是在帮助企业形成采购标准,还是拖慢采购
密钥蔓延和长期有效凭证驱动因素当前凭证泄露给买方带来具体运营痛点量化有多少事件或审计发现对应 NHI 缺口
影子 AI 和不成熟控制约束因素当前未经批准的使用会放大需求,也让范围界定和归属更难询问买方能否拿出可靠的 AI agent 清单
工具碎片化和既有替代方案约束因素当前Vault、云 IAM 和工作负载身份工具可能推迟专用平台采购确认 Oasis 类产品实际替代了哪些既有预算或工具

这些行有意同时纳入正向需求驱动和负向采用摩擦,因为市场扩张很快,但并非毫无阻力。

[CM011, CM012, CM013, CM016, CM017, CM018]
FM004: 从可见性到运行时控制的采用路径

多数买家会分阶段推进:先盘点清单,再明确归属、制定生命周期策略,最后采用会话级运行时控制。

[CM003, CM022, CM025, CM026, CM027, CM028]

2.5 图表

Chapter 03

03竞争格局

3.1 图谱:直接同行、套件型巨头、相邻玩家与替代方案

Oasis 周围的竞争图谱拥挤,但并不平坦。第一簇是直接的 NHI 和智能体身份纯玩家:Oasis 自身、Entro、Aembit,以及在 2026 年 6 月被 Cisco 吸收前的 Astrix。第二簇是套件型巨头:CyberArk、Saviynt 和 Delinea,它们都从更宽的身份安全或机器身份平台切入。第三簇是运行时和基础设施控制:HashiCorp Vault、SPIFFE/SPIRE,以及 WorkOS 等更新的开发者优先身份进入者。它们并不总是直接替代威胁,但在具体买家用例中是合法替代方案。关键含义是,Oasis 很少只打一条单一赛道。有些交易会把它与生命周期治理同行比较;另一些交易会追问,买家为什么不能扩展既有密钥库、PAM 或工作负载身份框架。多品类竞争提高了买家教育负担,也放大了清晰占住品类心智的重要性。[CP001, CP010, CP018, CP020, CP027, CP028]

竞争对手画像表
供应商 / 集群角色核心切入点公开信号战略影响
Oasis直接同业 / 品类塑造者混合 NHI 生命周期治理,加上 AI agent 访问叙事已集成 CrowdStrike 和 Wiz;评价数量少但正面若买方想要统一控制平面,故事很强
Aembit运行时控制相邻玩家面向工作负载和 AI agent 的无密钥、短期访问官网主打运行时访问和开发者效率运行时控制优先时会威胁 Oasis
Entro直接同业覆盖代码到云界面的发现、分类、可观测性和修复官网强调 AI agent 和 NHI 可观测性在可见性加修复叙事上贴身竞争
Astrix / Cisco正被平台吸收的直接同业AI agent 和 NHI 安全能力正在并入 Cisco独立销售已于 2026 年 6 月 30 日结束整合能放大分销,也会减少买方选择
CyberArk套件型既有厂商机器身份可见性、自动化和生命周期保护状态报告强化了泄露 / 中断紧迫性和存量客户逻辑在已经信任 CyberArk 的账户里威胁很大
Saviynt套件型既有厂商更大身份云中的治理优先 NHI 态势与修复推出 ISPM,并与 Wiz 合作在治理主导账户里威胁 Oasis
Delinea套件型既有厂商面向 NHI 和 AI agent 的持续发现,以及特权访问卫生发现和安全 AI agent 叙事可能让清单和态势功能商品化

画像同时覆盖直接同业和相邻既有厂商,因为真实采购中,Oasis 往往会和已获得内部支持的身份、云或访问供应商对比。

[CP001, CP004, CP005, CP006, CP007, CP011]
FP001: 竞争定位图

赛道一轴看套件广度,另一轴看运行时 / 访问深度;Oasis 处在广泛治理套件和运行时优先邻近厂商之间。

[CP001, CP004, CP007, CP009, CP012, CP020]

3.2 画像:谁拥有生命周期宽度,谁拥有运行时深度

最强的画像对比,是生命周期宽度供应商与运行时深度供应商之间的差异。Oasis、Entro 和 Saviynt 都强调发现、上下文归属、态势和修复。CyberArk 以机器身份规模和生命周期宽度竞争,但出发点是更宽的企业身份基础,并带有证书和密钥管理传承。Delinea 也在推动持续发现和特权访问卫生。相比之下,Aembit 和 HashiCorp 更明确地强调短期或动态访问模式:Aembit 销售面向智能体 AI 和工作负载的无密钥、基于策略的运行时访问;HashiCorp 验证基于 OAuth 的 AI 智能体认证和动态密钥。SPIFFE 更偏基础设施原生,提供加密工作负载身份控制平面,但没有业务治理外壳。这些差异很重要,因为买家重视的层并不相同。担心过度授权孤儿身份的安全负责人可能更偏好生命周期治理;专注消除静态密钥的平台团队可能先要运行时管道。[CP002, CP003, CP004, CP005, CP007, CP009]

功能 / 能力矩阵
能力OasisCyberArkSaviyntDelineaAembitEntro / Astrix
发现 / 清单广度是;跨混合系统的核心叙事是;机器身份可观测性是;持续发现和态势是;持续发现 / 清单不是主线叙事是;发现和分类处在核心位置
生命周期治理 / 修复是;开通、监控、退役、修复是;生命周期保护和自动化是;风险洞察和自动化修复是;治理和特权卫生部分;以访问为导向的控制是;明确营销修复能力
运行时短期 / 无密钥访问通过 AI agent 访问有所暗示,但不是官网最清晰的切入点在已审阅页面中不是核心公开切入点在已审阅页面中不是核心公开切入点在已审阅页面中不是核心公开切入点是;无密钥短期访问是核心在已审阅公开材料中不够明确
AI agent 专属叙事是;AI agent 访问讯息突出间接,通过机器身份和 AI 系统安全是;更广的身份类型包括 AI agent是;直接点名 AI agent是;面向 AI agent 的 IAM是;AI agent 和 NHI 叙事明确
基础设施原生原语集成面广,但自身不是低层原语密钥 / 证书 / 工作负载积累套件主导的治理层套件主导的治理层工作负载访问平面发现主导的叠加层;Astrix 现已绑定 Cisco
公开可见的分销杠杆CrowdStrike 和 Wiz 伙伴入口存量客户和报告权威性套件品牌加生态叙事套件品牌和安全报告姿态运行时细分定位Astrix 获得 Cisco 拉力;Entro 保持直接品牌

该矩阵是定性判断,因为公开页面强调能力和定位,而不是一致、可对标的性能指标。

[CP002, CP003, CP004, CP005, CP007, CP009]
定价 / 打包对比
供应商公开定价姿态打包线索采购影响置信度
Oasis已审阅材料未见公开标价企业平台与伙伴主导动线真实对比需要进入销售流程或伙伴接触
CyberArk已审阅材料未见公开标价企业套件 / 机器身份平台预算匹配需从范围和存量客户杠杆推断
Saviynt已审阅材料未见公开标价身份云 / NHI 模块叙事很可能卖进更广的身份云预算
Delinea已审阅材料未见公开标价身份安全与发现主导的套件动线定价对比很可能只在企业采购流程内发生
Aembit已审阅材料未见公开标价运行时访问 / 工作负载 IAM 动线可能被归入基础设施支出,而不是广义治理支出
Entro / Astrix已审阅材料未见公开标价纯 NHI / AI agent 安全叙事纯玩家价值必须对照既有厂商捆绑包来证明

此表有意呈现定价不透明,而不是编造套餐细节;没有公开价格卡,本身就是企业采购中的一个有意义竞争事实。

[CP035, CP036, CP037]
FP002: 产品成熟度 / 能力图

最持久的差异化不再是简单发现,而是生命周期编排、运行时控制和分发能力的组合。

[CP027, CP028, CP029, CP031, CP033, CP034]

3.3 分发能力、证据点与切换动态

分发能力正在成为决定性差异点。Oasis 在 CrowdStrike 和 Wiz 上有可见的合作伙伴界面,两项集成都讲出了有利故事:平台不仅发现身份,还引入端点或云上下文,并把上下文连接到受治理的修复动作。这比官网单独宣称更像成熟商业信号。与此同时,Oasis 的公开证据仍比合作伙伴故事更薄。Gartner 只有一条可见评价,SourceForge 和 Slashdot 提供的是产品目录摘要,而不是企业级参考深度。这种不对称在正面销售周期里很关键。切换成本看起来也更像叠加,而不是完全替换。买家可以保留 Vault、SPIFFE、云 IAM 或其他工作负载原语,再在上面加一层治理。这使市场结构上容易多供应商共存,降低了整体替换摩擦,但也提高了证明门槛:Oasis 为什么应成为统一控制平面,而不只是又一个仪表盘。[CP017, CP021, CP022, CP023, CP024, CP025]

FP003: 护城河 / 就绪度 KPI

公开信号显示 Oasis 确有生态动能,但客户佐证深度和定价透明度仍落后于产品叙事。

[CP006, CP021, CP024, CP032, CP037]

3.4 护城河耐久性、整合与商品化风险

Oasis 的护城河可信,但还谈不上不可撼动。最好版本的论点是:它在一个面向市场的平台里统一了盘点、上下文归属、生命周期动作和智能体访问叙事。较弱版本则是:生态里的许多玩家都在补齐这些部件。Saviynt 和 Delinea 正在加深发现与态势;CyberArk 已经掌握大额机器身份预算锚点;HashiCorp 和 Aembit 通过运行时模式攻击静态凭据;Astrix 被 Cisco 吸收则说明大型平台想要这组能力。品类因此可能从两端商品化——套件从发现和态势向内推,基础设施供应商从运行时访问向外打。公开定价不透明,让外部更难看清谁最便宜;但这大概率会提高而非降低分发、部署模型和参考客户深度在购买决策中的作用。结果是一个 Oasis 仍能取胜的市场,但前提是它持续从点状能力走向可见的一体化控制平面。[CP006, CP008, CP013, CP019, CP031, CP033]

护城河耐久性 / 竞争风险登记表
风险或护城河因素施压方证据对 Oasis 的影响尽调问题
统一生命周期治理叙事套件型既有厂商Saviynt、Delinea 和 CyberArk 都营销发现加生命周期广度Oasis 必须证明集成深度,而不只是会用品类词汇要求证明客户是在整合工具,而不是再加一个仪表盘
运行时访问差异化Aembit / HashiCorp / WorkOS 相邻玩家短期、无密钥或会话范围访问,是很强的相邻切入点Oasis 不能让运行时访问变成别人的长期控制平面厘清运行时控制占主导时,Oasis 多常能赢
分销与平台拉力Cisco、CrowdStrike、Wiz、既有套件厂商Astrix 并入 Cisco;Oasis 展示伙伴入口;套件厂商有存量客户渠道和生态杠杆可能和功能一样重要量化来源管道、附加率和经销商影响
公开证明深度Gartner / 目录显示可见评价量偏薄一条 Gartner 评价加目录描述,弱于许多企业买方偏好的证明强度客户背书稀缺可能拖慢后期采购按垂直行业和部署阶段索取客户背书
多栖部署 / 叠加式采用Vault、SPIFFE、云 IAM买方可以保留原语,同时叠加治理层该品类可能是叠加式,降低替换摩擦,也降低锁定询问 Oasis 是替代预算,还是只是叠加到预算之上
整合与商品化Cisco / 套件 / 清单扩展Astrix 整合以及更广的套件功能扩展,压缩独立玩家空间单靠发现的叙事可能比集成控制平面更快商品化跟踪 Oasis 能否靠广度和执行挡住捆绑打法

这些行聚焦战略耐久性,而非原始产品清单,因为真正的问题是:相邻层整合后,Oasis 能否继续守住控制平面相关性。

[CP006, CP017, CP019, CP030, CP031, CP032]

3.5 图表

Chapter 04

04财务情况

4.1 收入模式、采购路径与合同栈

最好的公开证据显示,Oasis 卖的是经常性企业软件,不是项目制咨询。它 2025 年 7 月的 SaaS 订阅协议绑定订单,再叠加公开 DPA 和 SLA;AWS Marketplace 则把买家导向定制私有报价,而不是固定目录价。这个组合是典型企业 SaaS 供应商姿态:逐客户谈判条款,并预期持续服务交付。合同栈还显示,Oasis 已经进入隐私、正常运行时间和支持承诺很重要的采购环境,这通常与年度或多年期订阅销售相关,而不是一次性工具采购。支撑这个收入模式的产品面足够宽,能支持扩张。Oasis 不只是盘点非人类身份;它把配置开通、归属分配、认证、轮换、态势管理和下线包装成生命周期能力。配置开通发布在财务上尤其重要,因为它把产品延伸到 Terraform、ServiceNow、通用 API 等工作流触发器,也延伸到 AWS、Azure、GCP、HashiCorp、CyberArk 和 Azure Key Vault 等云与密钥库生态。这样一来,收入质量更可能来自平台嵌入,而非孤立点功能采用。不过,定价透明度仍弱。AWS Marketplace 证实买家可请求私有报价,但没有公开目录价、席位指标或基于资产的分层价目表,外部无法据此推断 ACV。结论是,Oasis 可以被描述为一家定制报价、企业订阅型软件公司,并由合作伙伴辅助采购;但它实际落地的价格架构尚未公开可见。[CI001, CI002, CI003, CI004, CI007, CI008]

收入来源表
收入来源机制单位当前状态收入质量尽调问题
平台订阅订单支持的 SaaS 协议下,提供经常性软件访问按客户订阅期公开合同文本证实;价格未披露若多年期且黏性强,则质量高按客户群组、期限长度和续约组合索取 ARR
生命周期治理附加模块开通、权属、轮换、认证、退役工作流按模块 / 功能包能力已公开营销;附加率未披露中到高;很可能是扩张杠杆索取附加率和模块级追加销售数据
伙伴 / 市场采购AWS Marketplace、CrowdStrike Marketplace、GuidePoint、Wiz 关联生态按谈判合同 / 私有报价采购路径已确认;经济条款未披露中;提升触达,但可能压缩实际利润率索取伙伴折扣表和渠道 ARR 占比
受监管行业工作流金融服务及其他合规敏感用例按企业部署买方需求已验证;实际价格未披露中;可能提高 ACV 和留存按垂直行业和合规用例索取 ACV
支持 / 服务义务围绕平台提供有 SLA 支撑的支持和上线服务内嵌于订阅,或作为独立服务支持承诺公开;独立服务收入未披露未知;可能压缩毛利率索取服务组合、支持成本和单账户上线投入

这些行描述公开收入机制和分析师推断的货币化杠杆。Oasis 未披露各收入来源贡献。

[CI001, CI003, CI013, CI016, CI019, CI036]
定价 / 货币化表
要素公开证据标价与实际价格未知项影响
AWS Marketplace 报价通过私有报价定制价格未显示标价未披露席位、身份或资产计量口径显示其采用谈判式企业定价,而非商品化 SaaS
直接 SaaS 订阅有订单关联合同和续约条款实际价格未知折扣区间、期限长度、最低额未知合同很可能按客户规模和复杂度定制
渠道主导销售GuidePoint 和伙伴计划显示经销商动线伙伴经济条款未知经销商利润率、MDF 和联合销售分成未知可能加速增长,但降低净实现价格
市场 / 生态集成CrowdStrike 和 Wiz 路径提高采购相关性价格藏在企业谈判之后捆绑与独立销售经济性未知集成提升赢单率的作用,可能大过立刻提高实际价格
垂直合规价值金融页面定位 PCI DSS / SOC 2 / GDPR 工作流价值定价合理,但公开材料没有证据垂直 ACV 溢价尚未证明若客户数据验证,可能支撑溢价定价

公开证据支持谈判式定价和伙伴辅助采购,但不支持判断实际 ASP 或折扣。

[CI007, CI014, CI016, CI017, CI036]
FI001: 收入模式桥

公开文件指向议价式企业 SaaS 路径:合同承接,合作伙伴协助采购。

[CI001, CI003, CI013, CI019]

4.2 交付模型、成本结构与单位经济信号

Oasis 没有公布单位经济,但公开架构指向了成本基础大致落点。Outpost 模式把敏感身份操作留在客户边界内,中央平台处理控制逻辑、元数据、生命周期自动化和分析。这个设置说明公司更像软件重模型,边际交付负担应主要来自工程、云分析、客户支持和合作伙伴赋能,而不是硬件、库存或大额营运资本波动。密钥轮换和治理页面进一步支持这个判断,因为它们把风险修复描述为自动化经常性控制,而不是靠人工堆出来的专业服务。本章最强的公开生产证据是金融服务案例研究。Oasis 描述了一家私人信贷客户中的快速 Azure AD 部署、自动发现、风险态势分析、陈旧账户清理和自动身份轮换。尽管案例由公司撰写,且没有披露合同价值,它仍然有用,因为它显示平台可以进入合规和凭据卫生有经济价值的受监管客户工作流。金融解决方案页面还把买家场景连接到 PCI DSS 4.0、SOC 2 和 GDPR 敏感环境,意味着公司瞄准的用例里,预算负责人往往不只关心开发者便利性,也在意风险降低、可审计性和运营韧性。不过,公开记录不足以支撑硬指标判断。没有披露 ACV、毛利率、获客成本(CAC)、NRR 或服务收入占比。唯一稳妥的结论是定性的:Oasis 的结构看起来有能力取得软件式利润率,但外部还无法衡量支持、服务或渠道折扣在实践中压缩了多少利润率。[CI005, CI006, CI012, CI014, CI015, CI018]

单位经济表
指标公开数值 / 状态置信度重要性尽调问题
ARR未公开披露估值和销售效率的核心分母索取当前 ARR,以及过去 8 个季度按细分市场拆分的数据
收入增长公司通过 Globes 称上一年 ARR 增长五倍显示增长势头,但没有基数就无法审计索取经审计或董事会口径的 ARR 桥接表
毛利率未公开披露;可推断具备软件式毛利率潜力决定回本周期和经营杠杆要求提供毛利率 bridge,拆分平台、支持、服务和伙伴折扣
NRR / GRR未公开披露评估扩张收入韧性所需要求提供 NRR、GRR、分群留存和模块扩张数据
CAC / payback未公开披露检验增长是否资本高效所需要求提供 S&M 支出、按渠道拆分的 CAC,以及按毛利率计算的回本周期
服务负担支持 / SLA 义务公开;服务工作规模未公开上线导入若重人力,服务会拖累利润率要求提供实施工时、支持工单和专业服务收入占比

本表有意区分可观察事实和仍是尽调阻碍的非公开指标。

[CI005, CI006, CI023, CI026, CI037]
FI002: 单位经济模型桥

公开记录只能支撑 Oasis 单位经济模型的定性图景,不能支撑量化判断。

[CI010, CI015, CI017, CI020, CI037]
FI003: 财务估计区间

只有融资结构得到直接披露;其余财务区间要么未知,要么只有叙事支撑。

[CI021, CI022, CI033]

4.3 资本充足性、融资背景与缺失的现金跑道输入

Oasis 显然有资本继续投入,但公开来源不足以把这个事实转成现金跑道模型。2026 年 3 月 Series B 带来 $120 million;Newswire、Globes 和 SiliconANGLE 的同期报道都把该轮融资放在企业 AI 智能体和非人类身份造成的安全问题背景下。Globes 还报道了 $195 million 累计融资、市场来源称大约 $700 million 的估值、ARR 增长 5 倍,以及客户群主要由 Fortune 500 公司组成。即便这些牵引数字来自公司口径而非审计,它们在方向上仍重要:Oasis 不是在无人关注的位置融资。隐藏的部分是资产负债表一侧。本文审阅的公开材料没有披露 Series B 后账上现金、月度烧钱速度、毛利率或净收入留存率,也没有发现债务工具或授信额度。GuidePoint 的 OASIS+ 定位显示联邦市场进入意图,渠道计划和 Marketplace 上架页显示合作伙伴动作扩张,但这些都无法转成直销、联邦或合作伙伴主导业务之间的量化收入拆分。正确结论因此是不对称的。相对于公司早期年龄,Oasis 看起来足以支撑近期产品和市场进入扩张;但证据仍过于不完整,无法有把握地估计剩余现金跑道或下一轮触发点。尽调团队需要月度财务报表、ARR 历史和集中度数据,才能对资本充足性形成强判断。[CI016, CI017, CI021, CI022, CI023, CI024]

资本充足性表
项目公开数值 / 状态置信度重要性尽调请求
最新轮次2026 年 Series B 融资 $120M新近外部资本延长经营 runway确认交割日到账现金,以及是否有托管或分期拨付条件
累计融资Globes 报道约 $195M显示创立以来的累计资本支持核对股权结构表和一级融资总额
估值背景市场消息称估值约 $700M设定增长预期和下一轮证明负担确认投后估值、优先权条款和期权池影响
债务 / 项目融资未发现公开债务设施没有债务可降低固定财务义务确认是否存在 venture debt、授信额度或 SAFE
现金 runway无法凭公开数据可靠估算缺少 burn 和现金余额提供月度 burn、现金余额和董事会 runway 预测

融资证据扎实;runway 不扎实。不能把公开证据误当完整流动性视图。

[CI021, CI022, CI024, CI025, CI038]
FI004: 资本强度 / 现金流图

公开证据显示成本底座以软件为主,但烧钱和利润率仍有大量量化空白。

[CI018, CI025, CI037, CI038]

4.4 收入质量与资本强度的同行基准

Oasis 是私人公司,公开身份和安全供应商因此提供了唯一干净的经常性收入基准。Okta、SailPoint、Rubrik 和 CyberArk 都在 2026 年期间披露了十亿美元级订阅或 ARR 规模,Okta 和 SailPoint 也有当前 SEC 文件轨迹,确认市场把身份安全视为经常性软件品类。这些公司不是 Oasis 的直接产品匹配,但它们确立了投资人和收购方评估身份业务时使用的经济语言:订阅收入、ARR、SaaS ARR、RPO,以及大型客户经常性群组。这些同行也说明了为什么 Oasis 的缺失披露很重要。如果管理层能证明强劲 ARR 增长、健康留存和软件式毛利率,公司就有可能被放进高溢价的身份安全收入模型,而不是服务或基础设施转售商模型。否则,同样的透明度缺失会变成折价因素。从这个意义上说,可比公司有用,不是因为它们今天能给 Oasis 一个精确倍数,而是因为它们定义了 Oasis 在融资或并购过程中必须满足的证明门槛。分析师估值研究进一步强化了这一点。Windsor Drake 的 2026 年 Q2 IAM 报告显示,主流公开 IAM 约为 6.0x NTM 收入,而非人类和 AI 智能体身份平台可以达到 15x-30x 区间。Finro 警告成熟上市网络安全可比公司可能误导对 AI 原生私人公司的判断,这个方向上是公平的;但它也两面成立:如果没有 Oasis 的硬 ARR 和利润率证据,区间里的高溢价部分更多是愿景,而不是已经被数据承销。[CI028, CI029, CI030, CI031, CI032, CI033]

4.5 财务结论与尽调阻断项

对 Oasis 最有吸引力的财务解读很直接。它看起来是一家有合同支撑、定制报价的企业 SaaS 公司,切入痛点强且扩张中的身份问题,产品深度足以支持扩张,新融资也足以继续压市场。公开同行组显示,身份安全赢家可以成长为规模很大的经常性收入业务;Oasis 的合作伙伴足迹说明它正试图同时靠直接企业关系和分发渠道扩张。问题在于,公开证据只停留在叙事质量和融资质量。外部无法审计 ARR、收入结构、毛利率、烧钱速度、NRR、CAC 或客户集中度。即便定价,也只是能看出基于报价,除此之外并不透明。因此,Oasis 的财务章节应被解读为结构有利,但仅凭公开信息还不能承销。尽调中的门槛事项具体且无法绕开:季度 ARR 桥接表、细分市场和渠道结构、按组件拆分的毛利率、烧钱和现金跑道材料,以及头部客户和合作伙伴集中度数据。如果管理层能快速拿出这些材料,且数字与增长叙事一致,财务姿态会明显增强。否则,披露缺失本身会成为风险因素,因为估值预期已经受到非人类身份和智能体访问的高溢价品类叙事影响。[CI026, CI033, CI034, CI035, CI036, CI038]

公开财务缺口表
缺失指标影响重要性具体尽调路径
当前 ARR 及季度历史重大估值、增长和资本规划都需要要求提供 8 个季度 ARR bridge,拆出新增 / 扩张 / 流失
毛利率和 COGS 拆分重大判断软件质量和回本周期所需按平台、支持、服务和伙伴折扣拆分毛利率
burn、现金余额和 runway重大评估融资依赖所需要求提供月度 P&L、资产负债表和董事会 runway 材料
联邦政府 / 渠道 / 头部客户集中度重大评估韧性和下行风险所需要求提供按 ARR 排名前 10 的客户、联邦 / 商业拆分和渠道贡献
价格实现和折扣需要把叙事需求接到收入质量要求提供价格手册、MSA / 订单表示例和实际折扣分析

投资人要基于经济性而非叙事承销 Oasis,至少需要这些私有数据。

[CI026, CI027, CI035]

4.6 图表

Chapter 05

05产品与技术

5.1 产品定义与模块图谱

Oasis 不再把自己只呈现为非人类身份盘点供应商。公开产品故事现在有两个相连层。第一层是传统 NHI 管理平台,覆盖服务账户、应用、角色、密钥和其他机器身份的治理、态势与密钥轮换。第二层是 Agentic Access Management,把这些控制扩展到能够在企业系统中推理和行动的 AI 智能体。核心产品承诺不只是“发现身份”,而是通过配置开通、归属、审批、策略执行、轮换和下线,把每一个机器或智能体动作转化为受治理的身份工作流。这个模块图谱在年轻品类中罕见地连贯。Oasis 的治理页面集中在安全配置开通、归属分配、权限控制、轮换、认证和下线。态势管理页面增加了针对攻陷尝试、有毒组合、策略违规和异常的分析。密钥轮换页面再把这些洞察转成运营动作:发现、观察、策略管理、安全轮换和生命周期清理。面向 AI 智能体,AAM 增加了意图分析、短期会话身份,以及把提示词连接到动作的责任链日志。合在一起看,Oasis 正在搭一套控制平面,回答谁或什么可以行动、为什么可以行动、访问能持续多久,以及事后如何审计动作。[CE001, CE002, CE003, CE004, CE005, CE015]

产品模块 / 资产矩阵
模块主要用户当前公开状态差异化尽调缺口
Agentic Access Management负责管理 AI agent 的身份 / 安全团队已公开发布感知意图的控制,叠加 JIT 身份和审计链路需要生产环境基准和部署数量
治理身份 / IAM 管理员公开方案页所有权、认证、权限控制、退役需要工作流深度和管理规模证据
态势管理安全运营 / 云安全公开方案页用 AI 分析异常、危险组合并排序需要误报率和修复率数据
密钥轮换安全 + 平台工程公开方案页自动轮换和生命周期清理,替代手工脚本需要跨环境的轮换成功率指标
NHI Provisioning / Outpost平台 / DevSecOps 团队博客和方案页已公开描述不绑定云或密钥库的配置,并在客户边界内执行需要客户证明和架构深度

状态基于公开产品页和博客,而不是客户数量披露。

[CE001, CE011, CE015, CE016, CE017, CE036]
工作流 / 用例表
用户任务当前工作流Oasis 方案声称的可衡量收益局限
治理 AI agent 动作Agent 决定在企业工具间执行动作意图分析、策略执行、JIT 身份、审计链减少常驻权限,责任更清楚无公开效果基准
发现影子 AI 和未管理 agent安全团队检查终端、SaaS 和云,识别新出现的使用AI 方案可视性和元数据分析更早发现未授权工具和 NHI未发布各环境覆盖深度
安全配置机器身份开发者或应用负责人申请新身份Terraform / ServiceNow / API / UI 审批流,自动创建从第一天起带策略,更快完成配置无公开周期时长指标
优先处理高风险身份团队手工分流态势问题态势分析检测入侵尝试和危险组合暗示优先级排序准确度更高无公开精确率 / 召回率数据
安全轮换或退役密钥风险或策略触发后,团队轮换或退役凭据发现-观察-管理生命周期,安全轮换和清理减少陈旧凭据暴露无按连接器拆分的公开成功率数据

收益为公司声称,除非明确描述为生产案例结果。

[CE002, CE003, CE007, CE012, CE016, CE017]
FE001: 产品架构图

Oasis 的公开产品叙事把治理、分析、配置开通和智能体运行时控制叠在企业身份资产之上。

[CE001, CE011, CE015, CE016, CE017, CE033]

5.2 架构与部署模型

公开架构模式是一套治理控制平面,覆盖异构身份环境。Oasis 记录的配置开通工作流可以从 Terraform、ServiceNow、通用 API 触发器或 Oasis UI 启动。它同时支持基于凭据和联合身份,这一点很重要,因为买家可以在直接管理密钥与基于信任的访问模式之间选择,例如 managed identities、IAM roles 和 OIDC。这不是狭义密钥库的足迹;它是一个试图站在多个身份原语之上、围绕它们编排生命周期控制的产品。Oasis Outpost 是最重要的架构线索。Outpost 被描述为一个采集器容器,部署在客户云边界内,因此特权身份操作、密钥生成和密钥存储都留在本地。Oasis 自身交换控制消息和元数据,而不是成为进入客户环境的后门。这种设计有助于企业接受,因为它降低了客户在自动化敏感机器凭据时必须跨出的信任跳跃。它也说明 Oasis 更偏向优化治理和编排,而不是直接拥有每一个执行点。金融服务案例研究增加了实际部署证据。Oasis 描述了快速 Azure AD 集成、自动发现、态势分析、陈旧账户清理和自动身份轮换。尽管案例由公司撰写,它仍说明产品目标是安装进真实企业身份资产,而不是只提供概念路线图平台。[CE006, CE007, CE008, CE011, CE012, CE013]

技术 / 运营架构表
层 / 组件角色依赖风险
策略引擎根据治理规则评估意图和访问准确上下文和策略定义策略漂移或意图解读模糊
JIT 会话身份服务发放短期、最小权限凭据底层身份提供商和会话管线发放失败或范围设置不佳可能阻断工作流
Outpost 采集器在客户边界内执行特权身份操作客户云 / 容器环境运营开销和部署摩擦
配置连接器集成 Terraform、ServiceNow、API、UI 触发工作流第三方 API 和工作流系统API 变更会让连接器脆弱
分析 / 态势层检测异常、危险组合和风险态势问题遥测质量和数据标准化遥测不完整会带来误报或盲区
集成底座接入 Wiz、Zscaler、Cursor、市场渠道和其他生态伙伴产品和商业关系对伙伴路线图形成战略依赖

本表反映 Oasis 页面和生态公告公开描述的运营模式。

[CE002, CE003, CE012, CE014, CE019, CE020]
FE002: 客户工作流 / 运营流程

公开工作流从发现和请求接入开始,再进入策略、配置开通、执行和审计。

[CE003, CE006, CE012, CE013, CE018]
FE003: 关键依赖图

Oasis 架构依赖身份来源、工作流系统、执行伙伴和操作人员上下文。

[CE012, CE014, CE019, CE020, CE033, CE035]

5.3 集成生态与运营者工作流

Oasis 的运营者工作流高度依赖集成,而不是封闭栈假设。Wiz 集成用问题和数据安全态势发现增强 Oasis,让身份动作可以按爆炸半径排序。Zscaler 合作把身份治理与机器到机器、智能体流量的内联执行配对。Cursor 合作展示了这个模型如何向上延伸到智能体 IDE:智能体在 IDE 中运行命令、调用 MCP 工具,并与内部系统交互。最后,CrowdStrike Marketplace 动作和 AI Access Partnership Program 说明,Oasis 想嵌入更宽的企业 AI 和安全采购旅程,而不是只作为独立仪表盘销售。这种生态姿态在战略上很重要。它让 Oasis 可以从云暴露平台抓取上下文,在零信任执行层影响执行,并直接插入开发者和 AI 智能体工作流。这个宽度可能扩大分发和粘性,但也意味着产品价值部分依赖于持续维护与第三方系统的互操作性,而这些系统自身的 API 和产品策略会演进。从技术角度看,Oasis 似乎正在建设身份治理层,把许多系统的信号标准化,并转成有边界、可审计的访问决策。[CE009, CE010, CE019, CE020, CE021, CE033]

FE004: 产品成熟度 / 能力图

公开证据在工作流广度和生态触达上最强,在外部基准性能证明上较弱。

[CE018, CE019, CE020, CE032, CE036]

5.4 信任、标准与技术成熟度

Oasis 的信任故事有三根支柱:可审计性、标准对齐和技术可信度。可审计性来自 AAM 的说法:每个智能体动作都会从提示词到动作记录进责任链记录。标准对齐来自 AAM Framework 发布和更宽的 NIST AI Agent Standards Initiative;两者合在一起显示,公司试图把叙事锚定在正在成熟的外部治理讨论中,而不只是产品营销。技术可信度则由 OpenClaw 披露强化:Oasis 研究员公开详述了一条智能体接管链,并称上游团队在 24 小时内发布修复。同时,标准环境仍处早期。NIST 的倡议围绕安全互操作性和开放协议,不是买家今天就能直接采用的成熟清单。这给 Oasis 塑造最佳实践留下空间,但也意味着它的许多治理主张走在稳定第三方认证规范之前。公开材料还通过招聘和工程文化展示开发者信号,但没有呈现那种深度公开 API 或软件包生态,外部难以独立检查技术采用。因此,当前技术成熟度信号在叙事连贯性和生态相关性上很强,但在公开基准和开放实现证据上更轻。[CE022, CE023, CE024, CE025, CE026, CE027]

信任 / 质量 / 合规表
控制项 / 信号状态范围证据质量缺口
prompt 到 action 的审计链公开描述AAM agent 会话中 — 公司产品页和发布稿未发布样本审计工件或 schema
AAM Framework已公开发布agentic access 治理模型和成熟度评估中 — 有发布稿支撑,但仍由公司主导无独立采用数据
NIST 标准对齐外部倡议AI agent 的安全互操作 / 开放协议存在性置信度高,实施细节置信度低标准仍在形成
研究能力公开 OpenClaw 披露AI agent 威胁分析中 — 公司撰写,但事件叙事具体需要更广泛证明研究产出可复现
开发者信号招聘页和 AI 原生工程文章招聘和工程文化中 — 信号真实但间接未看到公开 SDK / 软件包生态

本表捕捉信任和成熟度信号,不能替代正式认证审查。

[CE022, CE023, CE025, CE028, CE032]

5.5 路线图方向与产品风险

即便没有正式产品路线图文件,公开发布节奏也能看出路线图。Oasis 从 NHI 生命周期管理起步,随后加入更明确的配置开通和治理工作流;到 2025 年末至 2026 年中,它已经明显转向智能体访问管理、生态合作伙伴关系,以及由从业者构建的治理框架。这是一条可信的扩张路径,因为 AI 智能体继承了服务账户和工作负载身份的底层身份问题,只是自主性更高、决策回路更快。主要技术风险也同样清晰。第一,公司围绕意图分析、策略执行和生命周期自动化提出高价值主张,但没有公开发布基准数据、吞吐指标或效果对比。第二,架构依赖云、密钥库、IDE 和安全平台合作伙伴持续配合。第三,开发者信号主要来自招聘和观点输出,而不是可见的开源或 SDK 足迹。这些风险都不会打破产品逻辑,但意味着买家尽调应迅速从“故事听起来对”转向“拿出实现细节、部署证据和性能数据”。[CE029, CE030, CE031, CE032, CE033, CE034]

路线图 / 发布 / 开发阶段表
日期 / 阶段功能或里程碑状态含义来源
2025-10与 Sequoia 联合发布 AAM Framework公开发布把 Oasis 推入 agentic AI 治理框架赛道PR Newswire 框架发布稿
2025-11Agentic Access Management 发布公开发布将 Oasis 从 NHI 生命周期扩展到 AI agent 运行时控制PR Newswire AAM
2026-01Gartner AI TRISM 提及公开市场验证信号显示外部市场已经注意到这个品类Oasis Gartner 博客
2026-06Cursor 受治理访问公告公开集成发布显示产品适配 agentic 开发者工作流Oasis Cursor 博客
2026-06Wiz Integration Network 公告公开集成发布把身份治理接到云暴露面和 DSPM 发现Oasis Wiz 博客
2026-06Zscaler 和 CrowdStrike 生态推进公开伙伴发布扩大执行和采购入口Oasis 伙伴博客

公开路线图信号显示方向和顺序,但不给出完整 GA 成熟度细节或采用数量。

[CE021, CE022, CE024, CE033, CE036]

5.6 图表

Chapter 06

06客户情况

6.1 客户群分层与垂直行业结构

Oasis 的公开客户故事明显是企业优先,并高度偏向受监管或运营复杂的环境。最宽的信号来自它自己的关于页面,称许多行业的领先组织都在使用产品。更具体的信号来自 Newswire 和 Globes:Oasis 服务数十家 Fortune 500 公司,客户群多数来自 Fortune 500。垂直行业页面和案例研究界面最强地指向医疗、金融服务、物流、保险、制造和大型消费品牌。这些环境正是机器身份扩散最快、运营停机代价高、审计压力真实的场景。一个有意思的细节是,Oasis 同时卖给最终企业用户和面向合作伙伴的生态。AI Access Partnership 页面面向想要开箱即带治理能力的企业 AI 供应商,而不只是最终企业买家。GuidePoint、CrowdStrike Marketplace 和 Wiz 进一步延展市场进入路径,说明客户获取可能同样来自采购工具和合作伙伴工作流,而不只是直销。这拓宽了获客路径,但也让外部更难只凭公开证据看清安装基数的精确构成。最终结果是:客户图谱具有强烈的头部企业偏向,垂直丰富度不错,但分母透明度弱。公开材料让 Oasis 已经进入大型复杂买家显得可信,却没有披露每个细分里有多少客户,或哪些细分主导经常性收入。[CU001, CU008, CU009, CU010, CU018, CU027]

客户分群表
细分市场公开证明主要用例证据质量战略价值关键缺口
Fortune 500 / 大型企业Newswire 和 Globes 称有数十家 Fortune 500 客户 / 客户多数来自 Fortune 500;首页展示 F50/F500/F300/F200 示例在复杂环境中治理 NHI 和 AI agent 访问高 — 验证企业需求真实未披露客户数或按细分拆分的 ARR
金融服务私募信贷 Azure 案例;Antares 白皮书;金融方案页;面向 Bank of America 的 ABM 页面可视性、轮换、生命周期治理、合规高 — 受监管买方,预算逻辑强具名生产参考仍有限
医疗健康医疗服务提供商案例;医疗方案页;Fortune-50 成果主张审计就绪、可视性、医疗运营不中断高 — 合规有望带来粘性成果主张由公司撰写
工业 / 制造工业 Azure 线上研讨会;F200 制造业 M&A 合规主张分类 NHI、修复过度权限、跨被收购环境合规中到高 — 复杂混合资产线上研讨会未给出具名客户
物流 / 保险 / CPG只有首页成果主张运营韧性和轮换效率低到中中 — 显示金融 / 医疗之外的覆盖宽度多为匿名,细节较少
面向伙伴的 AI 厂商AI Access Partnership Program把治理嵌入 AI 产品,面向企业销售中 — 将 GTM 路径扩到直采买方之外销售管线信号,不是部署证明

分群视角混合了具名客户、匿名案例和公司主张的成果示例。

[CU001, CU008, CU009, CU010, CU018, CU032]
FU001: 客户旅程图

Oasis 公开材料里最强的客户旅程,起点是复杂身份痛点,终点是受治理的生命周期自动化。

[CU002, CU011, CU018, CU024, CU025, CU038]

6.2 具名客户证据与案例研究深度

最丰富的公开客户证据大多由公司撰写,但并非空洞营销话术。Oasis 在多个行业展示了详细部署叙事。金融服务中的一家私人信贷公司被描述为在 Azure AD 中使用 Oasis 做可见性、定制安全策略、陈旧账户清理和自动身份轮换。医疗服务提供商案例研究的数据更丰富:据称该环境有 8,500 个人类身份、超过 100,000 个 NHI、超过 50,000 张证书、约 10,000 个服务账户,由 18 人安全团队和约 50 人 IT 运营团队管理。一场工业公司网络研讨会又补充了 Azure 修复和合规叙事。两个具名公开参考尤其突出。Mars 出现在 2026 年 4 月一份专门案例研究资源中,主题是高度碎片化云身份可见性。Antares 出现在金融服务白皮书中,被描述为借助 Oasis 简化生命周期管理并减少手工工作。这些具名参考比匿名垂直案例更接近采购级证据,尽管仍缺少合同细节、部署时长或扩张历史。相比之下,Bank of America 账户页面应被视为基于账户的营销,而不是真实部署证据。核心尽调结论是:Oasis 有真实用例深度,也至少有一些具名公开证据,但公开证据分布仍不均衡。具名客户证据存在,可许多最能说明运营细节的案例研究仍然匿名。[CU002, CU011, CU012, CU013, CU014, CU015]

具名客户证据表
客户 / 引用细分领域部署 / 用例生产还是试点结果 / 证据局限
Mars全球消费品牌 / 制造业高度碎片化的云环境;看清服务账号和 API 密钥看起来是偏生产环境的案例研究2026 年 4 月专门案例研究资料合同范围、期限和扩张情况未知
Antares金融服务生命周期管理,减少手工工作看起来是偏生产环境的白皮书引用出现在金融服务白皮书中除定性收益外,没有量化的前后对比指标
私募信贷公司(未具名)金融服务Azure AD 可视性、清理闲置账号、自动轮换身份看起来是偏生产环境的案例研究包含运营步骤和 CISO 引语客户名称未披露
医疗服务商(未具名)医疗健康看清混合云中 100,000+ 个 NHI看起来是偏生产环境的案例研究给出详细环境和团队规模指标客户名称未披露
工业公司(未具名)工业 / 制造业Azure NHI 发现、权限整改、合规改善可能是生产部署或后期部署网络研讨会描述了具体工作流问题和整改动作客户名称未披露
Bank of America 页面金融服务 ABM 目标客户面向单一企业的营销页面不是证据说明 Oasis 瞄准超大型银行环境不应计入真实客户引用

本清单有意只列部分样本,并把证据和非证据分开。

[CU011, CU012, CU013, CU014, CU015, CU016]
FU003: 客户证明矩阵

公开客户证明最强处是公司撰写案例里的运营细节,最弱处是独立留存可见度。

[CU017, CU020, CU023, CU030, CU035, CU038]

6.3 采用信号、评价界面与独立客户声音

公开采用信号在 Oasis 讲企业结果时最强,落到外部评论平台时最弱。正面看,官网列出多项企业成果:一家 Fortune-50 医疗机构避免了一笔估计的 HIPAA 罚款,一家 Fortune-500 物流买家将密钥轮换工作量削减 35%,一家保险客户遏制了一次影响半数生产负载的宕机,一家制造业客户把 M&A 合规要求落到新收购环境上。产品页又给出一条 Fortune 1000 客户引语,称在一个云环境里发现 17,000 多个非人身份。这些信号有分量,因为它们意味着产品已经在真实运营场景里用起来。独立客户声音要薄得多。Gartner Peer Insights 在抓取页面上显示 20 条评分、4.6/5,方向上是正面。但相较一家声称有几十家或更多大型企业部署的公司,样本仍然较小。SourceForge 和 Slashdot 提供产品条目,但抓取到的 SourceForge 页面整体评分为 0.0/5,两个长尾评论站点的实质评论都很有限。这不能证明客户不满意,但说明除 Gartner 外,公开评论面很浅。投资人因此应同时拆开两件事:第一,Oasis 很可能有真实企业采用;第二,独立公开声音仍太稀疏,还不足以判断大规模满意度、部署难易度或续约行为。[CU003, CU004, CU005, CU006, CU007, CU020]

客户增长 / 采用轨迹表
公开信号数值 / 观察日期置信度含义缺失分母
Fortune 500 覆盖数十家 Fortune 500 客户2026-03-19大型企业牵引力看起来真实总客户数未知
Fortune 500 构成据称客户群多数来自 Fortune 5002026-03-19存量客户可能集中在大客户没有按 ARR 或 logo 数拆分
多年期企业协议据称多数新增 ARR 由多年期协议带动2026-03-19正向耐久性信号没有续约或留存数据
医疗服务商复杂环境超过 100,000 个 NHI、50,000+ 张证书、约 10,000 个服务账号2026-04-22说明产品已用于大型、混乱的资产环境单一案例,客户匿名
Fortune 1000 引语云环境中 17,000+ 个 NHI抓取的产品页仍显示验证可视性痛点和企业级规模单条引语,客户未具名
评价样本20 条 Gartner 评分给出 4.6 / 52026 年抓取已有部分正向独立声音样本太小,无法推断队列层面结论

本表记录公开采用信号,不是经审计的公司 KPI。

[CU002, CU008, CU009, CU020, CU024]
留存 / 重复使用 / 满意度表
指标 / 信号公开数值细分领域 / 来源界面置信度为什么重要
Gartner 评分20 条评分给出 4.6 / 5独立评价渠道目前最好的独立满意度信号
多年期企业协议据称大部分新增 ARR 来自多年期协议大型企业说明收入可能有一定耐久性,采购也有承诺
持续生命周期工作流案例研究强调持续治理、轮换、归属权和安全态势金融服务 / 医疗健康 / 工业意味着是重复使用,不是一次性审计
独立评价深度Gartner 之外很薄;SourceForge / Slashdot 信息浅长尾公开评价渠道限制对广泛满意度结论的置信度
留存统计没有公开 NRR / GRR / 流失率所有细分领域客户耐久性尽调的主要阻碍

公开耐久性证据多为定性材料。

[CU020, CU021, CU022, CU023, CU024, CU025]
独立客户证据质量表
渠道显示内容证据强度主要局限
Gartner Peer Insights20 条评分给出 4.6样本小,抓取内容中的定性细节有限
SourceForge有产品页,但页面抓取到 0.0 / 5低 / 反向可能更多反映覆盖浅,而不是产品质量差
Slashdot有产品列表和品类露出结果细节很少
GuidePoint / 伙伴采购进入联邦和企业客户的销售路径不能证明终端客户采用
公司自写案例研究跨垂直行业的运营深度中到高可能有选择偏差,且可背书性有限

本表区分公开证据质量与客户数量、留存。

[CU017, CU020, CU021, CU022, CU023, CU035]
FU002: 采用 / 部署漏斗

公开部署路径对企业需求和用例深度提供了较多证据,但没有给出转化测算或留存队列。

[CU006, CU019, CU024, CU026, CU031]

6.4 留存、扩张与集中度风险

公开记录只有一个直接的持续性信号:Newswire 称,大多数新增 ARR 来自多年期企业协议。这是有用线索,因为多年合同通常意味着一定黏性和客户承诺。案例研究也描述了持续治理工作,而不是一次性评估,支持了经常性使用的理解。但公开证据到此为止。没有 NRR、GRR、流失、队列、续约率或合同期限分布,也没有公开客户数,无法把具名证据转成可信的渗透率或集中度模型。集中度风险是尚未解决的最大客户问题。如果 Oasis 确实服务几十家 Fortune 500 公司,但总客户数仍处早期,少数超大账户就可能重度左右收入。公开记录也没有披露有多少业务来自 GuidePoint、CrowdStrike Marketplace、Wiz 驱动的工作流或更广泛的伙伴渠道。这些路径显然对获客和采购入口很重要,但若使用过度,也可能集中议价权,或扭曲部署归属。正确尽调姿态是谨慎乐观。Oasis 的公开客户证据在工作流相关性和部署轶事上很强,但留存数学和集中度可见度偏弱。这意味着没有内部队列和分层数据,客户质量还无法充分承销。[CU024, CU025, CU026, CU027, CU028, CU036]

扩张与集中度风险表
扩张驱动因素 / 风险公开证据影响置信度尽调路径
靠生命周期模块先落地再扩张案例研究描述治理、轮换、态势和配置开通工作流时间拉长后,可能提高粘性和 ACV索取模块挂载率,以及按队列拆分的扩张数据
伙伴协助采购GuidePoint、CrowdStrike Marketplace、Wiz、渠道计划可能扩大触达面,但把议价权推向伙伴索取伙伴归因 ARR 和 pipeline 占比
大型企业集中度数十家 / 多数为 Fortune 500 的口径可能让收入依赖少数账号低到中索取按 ARR 排名的前 10 大客户和 logo 数
联邦 / 受监管行业集中度GuidePoint OASIS+ 和垂直行业页面显示其强推受监管市场可增强耐久性,也会抬高采购摩擦低到中索取按垂直行业、联邦路径拆分的收入
POV 转生产的不确定性部分首页高曝光证据明确只是 POV若未转化,可能高估生产环境牵引力索取 POV 转化率和投产周期

缺少客户数量和 ARR 集中度数据,集中度分析受限。

[CU024, CU027, CU028, CU031, CU036, CU037]

6.5 证据要点

Chapter 07

07风险

7.1 风险栈概览与严重性排序

Oasis 正在解决真实问题,但所处威胁环境比标准、买方教育和公开证据都跑得更快。外部背景异常严苛。NIST 的 AI Agent Standards Initiative 仍停留在行业主导协议和差距分析阶段,还不是可执行控制;Cloud Security Alliance 则表示,企业现在已经需要可落地的治理。与此同时,机器身份远多于人类身份,AI 智能体在快速扩散,多个近期事件也显示,一旦信任边界薄弱,周边工具链会有多脆弱。由此形成了独特风险画像。Oasis 暴露的主要不是单一灾难性监管禁令,也不是单一硬件依赖。它最大的风险是层层叠加:在标准尚未敲定前先销售,依赖多个合作伙伴生态,在缺少公开基准证据的情况下证明控制质量,并服务要求严苛的受监管买方,他们采购周期长、安全审查负担高。产品逻辑可能是对的,但执行门槛还在上升。对投资人来说,最重要的风险并不抽象,而是可监测:企业安全审查是否缩短,集成是否保持稳定,公开证据是否从研究和叙事走向成熟,管理层能否把品类紧迫感转成可信的大规模部署,同时不被战略噪音分心。[CR001, CR002, CR022, CR024, CR037, CR039]

FR001: 风险热力图

Oasis 的首要风险集中在信任转化、生态脆弱性和证据滞后,而不是单一致命合规事件。

[CR001, CR007, CR026, CR028, CR029, CR042]

7.2 监管、法律与信任风险

Oasis 卖进的是合规和信任负担很高的环境,但外部标准层还不成熟。NIST 正围绕安全互操作和开放协议建设智能体 AI 标准,CSA 则明确认为,企业是在智能体专用控制尚未敲定前就已投入运营。这个错位有风险:Oasis 可以受益于紧迫感,也可能不得不反复教育买方,并捍卫尚未被标准机构完全成文化的品类假设。公司自己的公开合同栈部分缓解了这一点,也把部分风险推回客户。DPA 引用 GDPR、UK GDPR 和以色列隐私法;SaaS 协议则要求客户为自身数据的法律依据和权限负责。SLA 承诺 99.9% 可用性,但补救限制为服务积分,且上限为订阅价值的 20%。换句话说,Oasis 具备基础企业合同文件,但实践中客户仍承担相当合规和宕机风险。法律和监管风险因此不太像 Oasis 眼前会遭执法,更多是信任转化问题。医疗、金融和 AI 治理买方会期待一套快速升级的证据栈:更清晰的标准对齐、更好的外部验证,以及证明公开法律语言能落到可靠运营控制上的证据。[CR003, CR004, CR005, CR006, CR007, CR033]

监管 / 法律风险登记表
规则 / 合同风险司法辖区 / 场景状态可能性严重性缓解措施残余风险尽调路径
智能体 AI 标准尚不成熟美国 / 全球标准NIST 计划在推进;控制集尚未定型采用 NIST 和实践者框架;展示控制映射索取标准路线图和客户控制映射示例
跨境隐私义务GDPR / UK GDPR / 以色列隐私法DPA 明确提及合同 DPA 与客户法律依据义务索取隐私架构和 DPA 谈判记录
客户法律依据负担SaaS 协议 / DPA实质上转移给客户已写入合同栈审阅红线版本和最大客户法律异议
停机补救有限公开 SLA仅服务抵扣,封顶 20%可用性承诺加支持响应目标索取 uptime 历史和重大事故记录
受监管买家的信任负担医疗健康 / 金融 / AI 治理买家预期高;证据栈不完整扩充外部验证和审计材料索取认证状态、审计报告和基准研究

严重性反映承销影响,不代表执法法律确定性。

[CR001, CR002, CR003, CR004, CR005, CR006]

7.3 运营、技术与安全风险

文件里最强的证据是,底层问题空间确实危险。Oasis 自己的研究和事件分析记录了一连串智能体和 NHI 失败案例:OpenClaw 可被访问过的网站接管、Claude 提示注入导致数据外泄、Claude Tag 中共享智能体身份边界模糊、Cline 的 localhost 劫持、Cursor 静默打开文件夹即执行、VS Code MCP 一键妥协、恶意 MCP 包外泄、McHire 弱默认凭证失败,以及 Change Healthcare、Cloudflare 和 Cisco 这些较早但仍高度相关的入侵事件。合在一起看,这些不是边缘个案。它们显示,AI 和机器身份系统的访问边界反复失守。这种模式既是 Oasis 的商业机会,也是产品风险。如果买方认定智能体系统太不安全,无法大范围部署,需求可能暂停。如果买方激进部署,负担又会转向 Oasis 这样的供应商:必须证明其控制确实能降风险。来自 OWASP、CyberArk、Palo Alto、Delinea 等来源的外部威胁摘要也强化了同一点:治理缺口、过度授权、下线流程薄弱、密钥泄露和不成熟的 AI 控制都很常见。公开证据尚未显示 Oasis 发布足以一锤定音回应这一挑战的第三方效能基准。运营上,由于客户侧执行和本地控制边界很重要,这种部署模型比纯中心化托管更安全。但这也意味着,实施质量、连接器韧性和客户自身运营成熟度都会进入产品风险方程,不是 Oasis 可以完全抽象掉的东西。[CR008, CR009, CR010, CR011, CR012, CR013]

运营 / 质量 / 安全风险登记表
失效模式可能性严重性缓解成熟度残余风险未解决缺口
提示词注入 / 工具误用中 —— Oasis 研究和产品论点覆盖该问题需要外部有效性证据,证明能抵御此类攻击
共享或模糊的智能体身份低到中需要更强买家证据,证明 AAM 能解决共享身份风险
localhost / IDE / MCP 智能体被攻陷低到中生态仍然多变,演进很快
密钥泄漏 / 凭证未轮换中到高需要客户成功证据和连接器层指标
供应链 / 包在智能体工作流中被滥用低到中需要依赖监控和连接器加固证据
运营中断或服务降级中 —— 已有 SLA需要 uptime 历史和事后复盘可见性

本表归并 Oasis 研究和外部事故报告中反复出现的技术风险。

[CR008, CR009, CR010, CR011, CR012, CR013]
FR002: 风险传导图

智能体访问一旦失效,会很快从技术控制缺口传导到客户、财务和战略结果。

[CR009, CR014, CR016, CR017, CR037, CR041]

7.4 合作伙伴、客户与模型风险

Oasis 的 GTM 路径既是护城河的一部分,也是风险栈的一部分。AI Access Partnership Program 公开向买方和伙伴推介:可绕过漫长安全审查。公开生态还覆盖 GuidePoint 的 OASIS+ 路径、渠道计划、Wiz、Zscaler 及其他周边平台。这些依赖帮助 Oasis 接触客户、嵌入企业安全工作流,但也意味着平台稳定性、分销杠杆,甚至部分买方信任,都是从伙伴那里借来的。客户风险也有两面。大型受监管企业一旦拿下就可能黏性强,但采购慢、支持成本高,且常常集中。公开材料显示其牵引力面向 Fortune 500,客户成果有分量,但仍未量化留存、集中度或伙伴归因 ARR。缺少这些可见度很重要,因为此时很难判断大型标识代表的是耐久客户基础,还是少数要求很高且杠杆过大的账户。财务模型风险今天主要是信息风险。2026 年 3 月 Series B 降低了眼前融资焦虑,多年协议措辞也有帮助,但烧钱速度、现金跑道和集中度仍未披露。Finro 关于公开可比对象薄弱会带来估值压缩风险的提醒很有用:再好的品类叙事也不能替代融资纪律。[CR026, CR027, CR028, CR030, CR031, CR038]

合作伙伴 / 依赖风险登记表
依赖项合作方角色集中度失效场景严重性缓解措施残余风险
采购 / 联邦路径GuidePoint进入 OASIS+ 和伙伴主导企业交易的通道Unknown伙伴降低 Oasis 优先级,或合同路径表现不佳分散直销路径和伙伴
云暴露上下文Wiz丰富风险优先级和整改上下文Unknown集成断裂,或战略一致性走弱守住独立价值和替代上下文
内联执行Zscaler用网络 / 零信任执行补足治理Unknown执行层依赖压缩方案可迁移性让治理层保持厂商中立
渠道扩张伙伴计划放大认知度和企业触达Unknown渠道冲突或赋能不足拖慢增长衡量伙伴产能,并保留回到直销动作的备选
AI 平台合作AI Access Partnership 参与方分发进入 AI 厂商生态Unknown安全审查承诺未转化为生产环境客户赢单跟踪从伙伴兴趣到实际部署的转化

公开来源未量化伙伴归因 ARR 或部署量,因此集中度未知。

[CR007, CR026, CR027, CR038]
人员 / 执行风险登记表
角色 / 职能依赖或缺口可能性严重性缓解措施尽调路径
安全工程交付速度必须快过威胁面扩张保持研究驱动的反馈闭环紧密审查安全 SDLC 和漏洞响应指标
产品 / 标准策略在规范定型前销售,需要大量市场教育把产品宣称对齐 NIST / 从业者框架要求审查标准对齐和产品路线图
合作伙伴管理生态越宽,协调负担越重建立专门的伙伴赋能和备用方案索取按使用量和支持负担排序的核心集成
市场进入的信任打法漫长的安全审查会拖慢管线搭建可复用的证明栈和采购手册索取与安全审查结果挂钩的赢单 / 输单数据
管理层专注度战略传闻或流程噪音会分散团队注意力明确内部沟通和客户口径询问 M&A 应急和留任计划

执行风险不低,因为 Oasis 所在市场变化快、信任门槛高。

[CR007, CR029, CR032, CR038, CR039]
FR003: 依赖图

Oasis 依赖标准组织、伙伴生态以及客户运营的控制边界,才能让这个品类真正落地。

[CR001, CR025, CR026, CR027, CR039]

7.5 缓释措施、监测项与否决条件

Oasis 风险栈令人鼓舞的一点是,大部分风险可以较早验证。几个最高风险并非二元不可知。管理层可以拿出证据,证明企业安全审查在提速、客户留存健康、伙伴集中度适中、公开证据在扩展、漏洞响应纪律严格。如果 Oasis 能推动这些指标,风险论证会实质性削弱,因为公司的市场相关性已经可信。否决条件同样具体。如果公开事件持续显示生态脆弱,而 Oasis 拿不出控制有效性的基准证据,买方信任可能停滞。如果伙伴依赖上升却没有备选方案,分销韧性会变弱。如果潜在 M&A 的战略噪音开始分散团队或客户注意力,执行风险会上升。如果估值预期上行时财务披露仍然很薄,投资人应假设模型风险只是被带到下一轮,而不是已经解决。简言之,Oasis 的风险画像最好理解为可管理但前置。公司必须在周围智能体访问威胁面扩张之前,更快证明纪律、信任和韧性。[CR029, CR032, CR037, CR038, CR039, CR042]

风险缓释与否决标准表
风险可监控触发信号阈值 / 事件行动含义
信任证明滞后没有新的外部验证未来 2 个季度基准测试 / 审计材料没有进展下调确信度;形成投资判断前要求直接证据
合作伙伴依赖单一合作伙伴主导新增管线>35% 的新增 ARR 归因于单一合作伙伴路径按集中度风险处理,重新切估值
安全审查摩擦企业审查持续缓慢赢单 / 输单数据显示,安全审查是延期首因假设品类采用曲线慢于计划
运营可靠性出现重大宕机且响应不透明客户可见事故叠加薄弱的复盘纪律重新评估产品运营成熟度
战略分心M&A 噪音干扰执行员工流失升高、客户犹豫或路线图滑坡提高执行风险折价
经营模型不透明财务 / 留存指标仍未披露尽调中没有队列、烧钱或集中度披露转向继续研究 / 避免被动接受价格

这些是投资否决标准,不是通用安全最佳实践。

[CR028, CR029, CR030, CR035, CR038, CR042]

7.6 证据要点

Chapter 08

08估值

8.1 投资逻辑与反向逻辑

Oasis 的公开乐观逻辑很有说服力。随着 AI 智能体和非人身份在企业系统中扩散,公司所在品类的重要性快速上升。Oasis 有可见的 Series B、知名投资人、面向企业的客户引用,以及一个产品叙事:成为智能体企业的访问治理层。战略稀缺性真实存在:同品类公司正在获得融资,大型安全厂商正在整合相邻机器身份资产,行业研究也已把非人身份和 AI 智能体身份视为一阶安全控制问题。反向逻辑同样重要。Oasis 尚未公开披露支撑溢价估值所需的运营指标。ARR、毛利率、留存、烧钱速度和集中度都缺失。因此,公开品类热度不能直接转化为承销信心。投资人可以相信问题真实存在,同时仍得出结论:价格还无法足够精确地判断。这种张力很重要,因为这里的估值对叙事很敏感。如果增长质量确如公司和记者暗示那样强,Oasis 也许确实配得上溢价标记。但在分母披露之前,公开文件最好被解读为战略上有前景,而不是估值上已经完整。[CV004, CV005, CV006, CV007, CV009, CV024]

建议摘要表
建议确信度风险评级估值立场决策含义
继续研究有投机性但说得通保持跟进,但在拿到私有指标前不要为公开估值标记背书
为何不买入N/AN/A对价格太敏感ARR、留存、利润率和集中度仍未披露
为何不完全回避N/AN/A品类上行空间真实存在战略稀缺性和企业牵引力支持继续尽调

这张表衡量价格敏感性,不是泛泛的质量评分。

[CV032, CV033, CV034, CV042]
投资逻辑 / 反向逻辑表
论点什么会改变判断
AI 智能体和 NHI 快速扩散,Oasis 所在品类具备战略重要性若 ARR 质量偏弱或企业转化停滞,投资逻辑会软化
企业牵引力和多年协议表述显示买方兴趣严肃披露客户数和队列数据可强化论证
战略 M&A 和同业融资显示退出可选性若 M&A 传闻消退且公开可比公司倍数压缩,上行空间会收窄
ARR、利润率和留存数据缺失,当前估值标记难以形成投资判断披露 ARR、NRR、毛利率和烧钱速度,才能给出更稳的估值判断
伙伴渠道带来的分销可选性可能加速采用若出现伙伴集中或转化偏弱,好处会变成风险

投资逻辑和反向逻辑都取决于证据质量,不只取决于品类叙事。

[CV006, CV007, CV024, CV025, CV038, CV039]
FV001: 建议逻辑

建议逻辑从品类上行空间强开始,经过经济性数据缺口,落到继续研究。

[CV004, CV005, CV009, CV032, CV042]

8.2 融资背景与入场纪律

最可靠的公开价格锚是 2026 年 3 月融资。Newswire、Globes、SiliconANGLE、Access Newswire 和 TechCompanyNews 都支持 $120 million Series B。Globes 补充了最有用的估值细节:据报道,市场消息人士认为 Oasis 价值约 $700 million,累计融资达到 $195 million。这就是公开融资记录中的价格标记。2026 年 7 月出现了第二个但更弱的估值信号:Globes 报道称,Oasis 正就以最高 $1 billion 出售给 Cyera 进行深入谈判,主要为现金,另有少量股票。投资人不应把这当成已成交的市场标记。更好的解读是,大型安全玩家或私人平台可能认为 Oasis 有战略相关性。传闻提高了上行可选性,但也带来过度解读未确认流程的风险。因此入场纪律仍应收紧。上一轮约 $700 million 的融资标记可信。接近 $1 billion 的传闻战略上限值得关注。但没有股权结构、优先权或单位经济披露时,有纪律的投资人不应默认按高情景承销。[CV001, CV002, CV003, CV008, CV026, CV027]

FV002: 估值敏感性

Oasis 估值最受三件事牵动:收入质量证据、战略需求、估值倍数纪律。

[CV003, CV010, CV011, CV027, CV028]

8.3 可比框架与市场情绪

正确的可比框架是经常性收入型身份安全,而不是泛服务或基础设施软件。Okta、SailPoint、Rubrik 和 CyberArk 都用订阅收入或 ARR 讲自己的业务。它们的文件和官方业绩也强化了投资人看重身份平台的经常性收入质量、留存和扩张。这些公司规模大得多,产品范围也不能与 Oasis 直接相比,但它们确立了这个品类的语言。分析师估值工作提供了第二层。Windsor Drake 的 2026 年 Q2 IAM 报告将主流公开 IAM 定在约 6.0x NTM 收入,同时称非人身份和 AI 智能体身份平台在私募轮中大致可达到 15x 至 30x。Finro 认为,用成熟公开网络安全可比公司去衡量私人 AI 原生公司,可能严重误导。Multiples.vc 显示,2026 年更广泛网络安全行情也已明显改善。战略整合强化了这一点:Astrix 出售给 Cisco,以及 CyberArk 围绕 Venafi 的机器身份整合,说明大型平台仍在买入这一控制层。问题在于 Oasis 尚未披露 ARR。因此,可比集能说明 Oasis 可能成为什么样的公司,却还不能说明 Oasis 今天真正应得什么倍数。[CV010, CV011, CV012, CV013, CV014, CV015]

可比估值表
可比对象指标倍数 / 估值 / 状态参考意义局限
OktaFY2026 订阅收入 $2.855B公开市场经常性收入型身份龙头展示市场如何给规模化身份公司定价覆盖员工身份,范围比 Oasis 宽得多
SailPointFY2026 ARR $1.125B;其中 SaaS ARR $746M公开 / 近期重新上市的身份安全同业以 ARR 为核心的身份可比对象规模更大,也比 Oasis 更成熟
RubrikFY2026 订阅 ARR $1.46B高增长安全 SaaS 可比对象可作为经常性收入和增长基准不是身份原生厂商
CyberArk2025 总 ARR $1.44B;订阅 ARR $1.267B身份 / 机器身份老牌厂商机器身份方向的强战略可比对象PAM 范围更宽,且具备老牌厂商规模
Astrix / Cisco2026 年战略交易显示市场对 NHI / 智能体身份控制有 M&A 意愿为该品类提供战略验证本文件中交易条款未完全公开
GitGuardian2026 年 $50M Series C私有市场相邻 NHI / AI 智能体安全融资信号验证投资人对该细分的兴趣融资轮不是直接估值倍数

这张表提供估值镜头,不等于主张 Oasis 应完全按任一可比对象交易。

[CV014, CV015, CV017, CV018, CV019, CV020]
FV003: 估值 / 回报区间

公开证据只能支撑很宽的区间:估值锚点看得见,分母看不见。

[CV003, CV010, CV011, CV026, CV027, CV028]

8.4 情景分析与建议

基准情景的决策是锚定最后一个站得住脚的公开融资标记,不向外推演太远。也就是把约 $700 million 视为当前公开基准,不是因为它一定正确,而是因为它证据最足。如果 Cyera 兴趣在方向上成立,或管理层能验证溢价 ARR 增长和留存质量,乐观情景可以可信地接近 $1.0 billion。如果市场在 Oasis 给出支撑溢价私募品类框架的指标之前,先回到公开 IAM 的估值纪律,悲观情景会落到数亿美元中段。基于这个格局,最站得住脚的建议是继续研究。Oasis 看起来值得持续跟踪,但仅凭公开证据还不能自信买入。信心为中等,因为品类顺风和融资标记真实存在,但运营证据不完整。风险评级仍高,因为披露、依赖和证明问题仍具实质性。这家公司可能很好,甚至可能具备战略稀缺性。问题在于,公开文件仍不足以判断当前隐含价格是有吸引力、只是合理,还是已经偏紧。[CV026, CV027, CV028, CV032, CV033, CV034]

乐观 / 基准 / 悲观情景表
情景核心假设估值 / 回报逻辑关键风险概率信号
乐观Oasis 证明 ARR 质量强,守住高溢价品类定位,战略买方兴趣也落成事实$900M-$1.0B+ 区间因战略稀缺性或高溢价收入倍数支撑而变得可信披露缺口闭合太慢;传闻没有落成现实可能成立,但需要新证据
基准最新公开标记估值仍是最佳锚点,品类动能延续且没有重大负面意外~$700M 仍是公允参考,直到更新指标出现投资判断仍不完整当前最站得住脚的情景
悲观公开可比公司纪律收紧,Oasis 无法证明 ARR、留存或集中度质量值得溢价若溢价叙事削弱,下行区间为 $450M-$550M估值压缩以及伙伴 / 买方摩擦若披露继续偏薄,则有可能
观望持有投资人保持跟进但没有定价确信度披露 ARR、NRR 和利润率前不行动若动能加速,会有机会成本近期合理姿态
战略收购M&A 进程或战略稀缺性推高溢价,高于最近一轮更多取决于买方协同,而非公开可比公司流程未确认;存在整合和留任风险可见度低,但可选性真实存在

估值区间是基于公开融资和可比公司语境估算的情景锚点,不来自 Oasis 披露的 ARR。

[CV003, CV008, CV024, CV026, CV027, CV028]
投资逻辑破裂与否决触发因素表
触发因素阈值对投资逻辑的传导行动含义
ARR 质量不及预期管理层无法证明 ARR 增长、留存或毛利率足够强高溢价品类估值逻辑立即削弱下调估值或退出
战略兴趣消失Cyera 式兴趣最后只是幻象,买方胃口不再乐观情景天花板下移只锚定基准 / 悲观情景
伙伴集中度上升单一路径或伙伴主导管线 / ARR分销可选性变成依赖风险施加集中度折价
公开证明滞后外部验证或客户指标没有实质改善信任和尽调负担仍然过高将建议维持在继续研究
可比公司倍数再次压缩公开 IAM 和网络安全倍数明显回落叙事溢价收窄收紧入场纪律和下行区间

这些是否决标准,和估值绑定、对价格敏感,不是通用产品问题。

[CV025, CV029, CV030, CV037, CV042]
最终尽调索取清单
主题缺失证据重要性负责人 / 尽调路径
ARR 和收入质量当前 ARR、细分结构、NRR / GRR、季度桥接估值和确信度的核心分母管理层 / 数据室
毛利率和烧钱速度毛利率桥接、COGS 拆分、月度烧钱、现金跑道用于评估资本充足性和下行风险财务尽调
客户集中度前 10 大客户、伙伴归因、联邦 / 商业拆分决定耐久性和议价风险收入运营 / CFO
股权结构表和优先权优先权、债务、老股交易、期权池入场价格不只看表面估值法务 / 融资尽调
M&A 进程状态战略兴趣真实性及其对团队 / 客户的影响避免只凭传闻出价过高董事会 / 管理层讨论
可背书证明具名客户、扩张案例、部署成熟度将叙事溢价转成可信证明客户尽调 / 访谈

缺少这些索取项,估值判断就无法越过继续研究。

[CV009, CV031, CV032, CV036, CV042]
FV004: 投资 KPI

KPI 视图凸显了支撑建议的两件事:明面上的估值锚点,以及藏起来的分母。

[CV001, CV002, CV003, CV008, CV032]

8.5 证据要点

免责声明

本报告基于截至 2026-07-10 的公开来源,不构成投资建议。关键财务、合同、客户、法律和技术细节仍未公开; 任何投资决定前,都应直接向管理层核实,并对照一手文件验证。

证据索引

结论
编号陈述可信度来源
CO001 Oasis Security was founded in 2022. SO011, SO014, SO015
CO002 The publicly identified founders are Danny Brickman, who serves as CEO, and Amit Zimerman, who serves as CPO. SO011, SO013, SO014
CO003 Oasis's origin story is tied to Israeli cyber-service experience and a founding team that says the company began in Tel Aviv. SO004, SO007
CO004 Oasis positions itself as a purpose-built platform for discovering, governing, and securing non-human identities across hybrid cloud environments. SO001, SO002, SO003
CO005 The product description centers on inventory, contextual ownership mapping, and lifecycle management rather than vault-only secrets storage. SO003, SO002
CO006 Oasis says its platform spans IaaS, SaaS, PaaS, and on-prem environments, including AWS, Azure, BigQuery, GitHub, ChatGPT, Salesforce, Office 365, and Copilot. SO001
CO007 The company emerged from stealth in January 2024 with a previously closed $35 million Series A round and $40 million total funding to date. SO007, SO008
CO008 The January 2024 Series A round was led by Sequoia Capital, Accel, Cyberstarts, and Maple Capital, with angels including Guy Podjarny and Michael Fey also participating. SO007, SO008
CO009 Oasis announced a $35 million Series A extension in May 2024 that brought total funding to $75 million and doubled the prior Series A valuation. SO009, SO010, SO011
CO010 Oasis announced a $120 million Series B round on March 19, 2026 led by Craft Ventures with existing investors Cyberstarts, Sequoia Capital, and Accel participating. SO006, SO012, SO014
CO011 Public sources consistently place Oasis's lifetime capital raised at $195 million after the Series B round. SO006, SO014, SO015
CO012 Independent market reporting estimated the Series B post-money valuation at roughly $700 million rather than the $1.2 billion figure in the prompt. SO013, SO014
CO013 Oasis says it serves large enterprises and that a majority of its client base comes from the Fortune 500. SO006, SO013
CO014 The company says new ARR grew fivefold year over year in the run-up to its March 2026 financing. SO006, SO016, SO013
CO015 Oasis says most of its new ARR is driven by multi-year enterprise agreements, implying an enterprise-sales motion rather than low-touch self-serve adoption. SO006
CO016 TechCrunch identified Chipotle, JLL, and Mercury Financial as early users while Oasis was still in stealth. SO007
CO017 BankInfoSecurity reported that Oasis employed 142 people in March 2026. SO015
CO018 Calcalist reported a headcount of 45 employees at the January 2024 Series A announcement, showing rapid post-stealth hiring if the 2026 headcount estimate is directionally correct. SO008, SO015
CO019 Oasis appointed Michael DeCesare as president in April 2026 to run the global go-to-market organization spanning sales, marketing, alliances, and customer success. SO005, SO016, SO017
CO020 The company launched a formal channel program in April 2025 and named GuidePoint Security as a strategic reseller partner in North America. SO018, SO005
CO021 Oasis said the channel program generated millions of dollars in pipeline and dozens of deal registrations in less than one year. SO018
CO022 Gartner Peer Insights showed Oasis at 5.0 out of 5 from a single banking-sector review as of February 2026, which is positive but too sparse to treat as broad market proof. SO019
CO023 CrowdStrike's marketplace listing says Oasis correlates endpoint telemetry with identity context across service accounts, service principals, API keys, OAuth tokens, machine identities, DevOps tools, and AI agents. SO020
CO024 Wiz's integration page says Oasis ingests Wiz Issues and DSPM findings so identity teams can add blast-radius context and lifecycle remediation to cloud findings. SO021
CO025 GuidePoint placed Oasis on the 2025 GPSEC agenda for a session titled “Beyond IAM: Why Non-Human Identity is the Missing Layer,” indicating channel-led thought-leadership before the 2026 Series B. SO022
CO026 NIST launched an AI Agent Standards Initiative in February 2026, strengthening the timing argument for agent-governance platforms such as Oasis. SO023
CO027 Palo Alto Networks said machine identities reached 109-to-1 versus humans in 2026, up from 82-to-1 a year earlier, which supports Oasis's view that the problem set is growing faster than human IAM can absorb. SO024
CO028 CyberArk reported that machine identities outnumber humans by more than 80-to-1 and framed fragmented identity security as a material breach and outage risk, underscoring the urgency of the category Oasis sells into. SO025
CO029 Oasis repeatedly describes itself as the first solution purpose-built for non-human identity visibility, security, and governance. SO002, SO004
CO030 The about page says leading organizations across a wide range of industries already use Oasis, even though the company discloses only a small number of named customer references publicly. SO002, SO007
CO031 Oasis says it uses AI-based analytics, heuristics, and certification workflows to identify owners and resolve gaps in NHI accountability. SO002, SO003
CO032 The company frames agentic access as a new layer because traditional IAM cannot govern AI agents and machine identities at the speed and scale of modern enterprise automation. SO001, SO006
CO033 Globes said the May 2024 Series A extension would fund additional hiring across Israel and the United States. SO011
CO034 BankInfoSecurity described CEO Danny Brickman as an ex-IDF cyber R&D leader with more than seven years of military service. SO015
CO035 A July 2026 Globes report said Cyera was in advanced talks to acquire Oasis for up to $1 billion, but the article also said the companies had not formally announced a deal. SO026
CO036 Tech Company News described Oasis as headquartered in New York. SO013
CO037 The stealth-emergence blog says Oasis began in a modest room in Tel Aviv, supporting a dual U.S.-commercial and Israel-R&D identity even though the public website does not publish a formal two-office roster. SO004, SO011
CO038 No reviewed source published a precise customer count, ARR dollar figure, board roster, or audited financial statement for Oasis as of 2026-07-10. SO005, SO006, SO019
CM001 The non-human identity market boundary includes application and service identities, API and OAuth tokens, machine and device identities, cryptographic identities, and AI agent identities. SM003, SM011, SM018
CM002 The category is broader than secrets management alone because vendors now package discovery, posture, lifecycle governance, and runtime authorization around NHIs. SM015, SM016, SM020, SM021
CM003 Status-quo substitutes include vaults and identity stores such as HashiCorp Vault, workload identity frameworks such as SPIFFE, cloud-native IAM, and manual ownership processes. SM021, SM022, SM024
CM004 Mordor Intelligence sized the NHI security market at $8.22 billion in 2026. SM001
CM005 Mordor Intelligence projects the NHI security market to reach $22.94 billion by 2031, a 22.78% CAGR from 2026. SM001
CM006 Research and Markets and Yahoo Finance place the broader NHI access-management market at $12.2 billion in 2026 and $38.8 billion by 2036, implying a slower but larger envelope than the narrower NHI-security lens. SM002, SM003
CM007 The gap between the $8.22 billion and $12.2 billion 2026 estimates is best explained by different market boundaries rather than a direct contradiction. SM001, SM002, SM003
CM008 North America is described as the largest 2026 market while Asia-Pacific is expected to grow fastest. SM002, SM003
CM009 Large enterprises and cloud-based deployments lead the current market share in the broader NHI access-management forecast. SM002, SM003
CM010 Research and Markets explicitly breaks the market into solutions and services across identity types, deployment modes, organization sizes, and verticals. SM003
CM011 Palo Alto Networks said machine identities reached 109-to-1 versus humans in 2026, up from 82-to-1 a year earlier. SM004, SM005
CM012 Palo Alto Networks also said 77% of organizations expect the machine-to-human identity ratio to keep climbing. SM004
CM013 According to Palo Alto's 2026 landscape reporting, 99% of organizations have adopted AI agents and 40% of those agents already have access to organizational data. SM004
CM014 Axis Intelligence highlighted how vendor methodologies still diverge widely, citing 2025-2026 ratios from 45-to-1 to 144-to-1 and a composite around 79-to-1. SM005
CM015 Axis Intelligence said GitGuardian found 28.65 million new hardcoded secrets exposed on public GitHub in 2025, with AI-service leaks up 81.5% year over year. SM005
CM016 Axis Intelligence also said 64% of secrets confirmed valid in 2022 remained exploitable as of January 2026. SM005
CM017 NIST's 2026 AI Agent Standards Initiative is organized around interoperability, security, and open protocols for autonomous agents. SM006, SM007
CM018 Cloud Security Alliance noted that no enforceable, agent-specific security controls exist yet and substantive standards will take time to emerge. SM008, SM006
CM019 The OWASP maturity article says 83% of organizations plan to deploy agentic AI, yet only 29% believe they can adequately protect it. SM009
CM020 ITECS argued that 68% of employees already use AI tools without IT approval, creating a Shadow AI visibility gap. SM010
CM021 Saviynt argues that NHIs are broader than machine identities alone and also include bots, workloads, and AI agents. SM015, SM018
CM022 Saviynt's ISPM positioning centers on continuous discovery, real-time inventory, risk insights, and automated remediation for NHIs. SM016
CM023 Delinea defines NHIs to include applications, services, scripts, devices, APIs, bots, and AI agents. SM018
CM024 Delinea warns that NHIs and AI agents often carry persistent, broadly privileged access with weak ownership and review discipline. SM020
CM025 Aembit positions short-lived, secretless access as the buyer answer for agentic AI and workload identity use cases. SM023
CM026 HashiCorp's validated AI-agent pattern uses OAuth token exchange and dynamic secrets, showing that engineering-centric buyers are moving away from static credentials. SM021
CM027 HashiCorp's identity engine treats an entity as a client with multiple aliases and audit-linked actions, illustrating the identity-store foundation many teams use before buying a broader governance layer. SM022
CM028 SPIFFE and SPIRE provide a uniform cryptographic identity control plane for workloads across heterogeneous infrastructure. SM024
CM029 WorkOS's March 2026 release added agent-oriented features such as Pipes MCP and session-scoped identity boundaries, showing that agent identity is spreading into developer-access platforms. SM025
CM030 Oasis's AI solution page frames the buyer need as restricting AI agents to approved model suppliers, enforcing least privilege, and monitoring delegated permissions. SM026
CM031 Oasis's finance page ties the problem to PCI DSS 4.0, SOC 2, GDPR, and resilience of core financial workflows. SM027
CM032 Oasis's healthcare page ties the problem to HIPAA/GDPR-style privacy risk, audit readiness, and uninterrupted care operations. SM028
CM033 The core buyer set appears to span IAM/PAM leaders, cloud and platform security teams, and regulated application owners rather than a single budget owner. SM015, SM016, SM026, SM027, SM028
CM034 Across competing solution narratives, the practical adoption path starts with discovery and inventory, then owner attribution, then lifecycle policy, and finally runtime access control or secretless enforcement. SM016, SM019, SM023
CM035 The main growth drivers are AI-agent adoption, cloud-native sprawl, zero-trust programs, certificate/secret lifecycle pressure, and rising audit expectations. SM002, SM004, SM006, SM015, SM016
CM036 The main adoption constraints are immature standards, shadow AI, unclear ownership, fragmented tooling, and the integration burden of replacing entrenched vault or IAM workflows. SM008, SM010, SM020, SM022, SM024
CM037 Public sources do not isolate a clean agentic-access SAM or SOM, so market sizing must be treated as overlapping lenses rather than a precise bottom-up forecast. SM001, SM002, SM003, SM008
CM038 The addressable spend is not purely security budget: it also touches developer productivity, platform operations, and compliance programs. SM023, SM025, SM027, SM028
CP001 The competitive landscape splits into direct NHI lifecycle-governance platforms, runtime/workload access controls, broad identity suites, and infrastructure-level substitutes. SP003, SP004, SP006, SP008, SP010, SP019
CP002 Oasis positions itself as a hybrid-platform vendor spanning IaaS, SaaS, PaaS, and on-prem environments rather than a single-system access tool. SP001
CP003 Oasis's core product story is inventory, contextual ownership, and lifecycle management for NHIs. SP002
CP004 Aembit positions itself around secretless, policy-based, short-lived access for agentic AI and workloads. SP003
CP005 Entro positions itself around discovery, classification, observability, and remediation across clouds, code, CI/CD, on-prem, and collaboration tools. SP004
CP006 Astrix says it is now part of Cisco and ended standalone sales of new licenses effective June 30, 2026. SP005
CP007 CyberArk markets machine identity security around comprehensive visibility, advanced automation, and lifecycle protection for secrets, certificates, and workload identities. SP006
CP008 CyberArk's state report says 50% of organizations reported breaches linked to compromised machine identities and 72% had at least one certificate-related outage in the past year. SP007
CP009 HashiCorp's competitive angle is dynamic secrets and OAuth-based AI-agent authentication rather than broad posture management. SP008
CP010 HashiCorp's identity engine centers on entities, aliases, and audit-linked actions, illustrating an engineering-centric identity store rather than a business-governance console. SP009
CP011 Saviynt argues NHIs are broader than machine identities alone and include workloads, bots, accounts, and AI agents. SP010
CP012 Saviynt's posture-management message emphasizes continuous discovery, risk insights, and automated remediation for NHIs. SP011
CP013 Saviynt also uses the Wiz Integration Network to pitch unified cross-cloud identity visibility and least-privilege context. SP012
CP014 Delinea defines NHIs as applications, services, scripts, devices, APIs, bots, and AI agents. SP013
CP015 Delinea warns that NHIs and AI agents often carry persistent, broadly privileged access that would be unacceptable for humans. SP014
CP016 Delinea treats continuous discovery and identity inventory as the foundational step in identity security. SP015
CP017 GitGuardian's 2024 strategy update says layered NHI security requires integrations across five secrets-management platforms including HashiCorp Vault and CyberArk. SP016
CP018 GitGuardian's 2026 tooling taxonomy divides the market into secrets detection, NHI lifecycle/governance platforms, machine identity and certificate management, and vault/authorization extensions. SP017
CP019 GitGuardian's OWASP commentary highlights improper offboarding, secret leakage, overprivileged NHIs, and insecure authentication as central buyer fears. SP018
CP020 SPIFFE and SPIRE provide a uniform cryptographic workload-identity control plane, making them powerful substitutes for infrastructure teams but not a full enterprise governance suite. SP019
CP021 WorkOS's March 2026 release added Pipes MCP and session-scoped agent boundaries, signaling an adjacent developer-first entrant into agent identity control. SP020
CP022 Oasis's CrowdStrike marketplace listing emphasizes endpoint-correlated identity context plus governed remediation such as rotating credentials and revoking tokens. SP021
CP023 Oasis's Wiz integration emphasizes blast-radius-aware prioritization and lifecycle actions such as hygiene, attestation, safe key rotation, and decommissioning. SP022
CP024 Gartner Peer Insights gives Oasis visible but very thin public review proof: one 5.0 review and a visible “top alternatives” frame rather than broad review volume. SP023
CP025 SourceForge describes Oasis as the first enterprise platform purpose-built to secure the complete lifecycle of NHIs for companies seeking this outcome. SP024
CP026 Slashdot likewise describes Oasis around end-to-end NHI lifecycle protection rather than narrow secret storage. SP025
CP027 Direct NHI pure plays such as Oasis, Entro, Aembit, and historically Astrix compete on modern AI-agent and machine-identity narratives more than legacy PAM rhetoric. SP003, SP004, SP005, SP001
CP028 Broad identity suites such as CyberArk, Saviynt, and Delinea compete through larger installed bases and wider identity portfolios. SP006, SP010, SP013
CP029 Runtime-control vendors and infrastructure substitutes win when buyers prioritize short-lived access, developer velocity, or workload-native plumbing over enterprise posture inventory. SP003, SP008, SP019, SP020
CP030 The market is likely to stay multi-vendor because buyers can keep vaults, workload identity frameworks, and cloud IAM while adding a governance layer on top. SP008, SP009, SP019, SP022
CP031 Consolidation is already visible: Astrix is being absorbed into Cisco, suggesting platform vendors value AI-agent/NHI controls but also reducing independent-choice surface for buyers. SP005
CP032 Marketplace and integration surfaces matter competitively because they reinforce distribution and technical context rather than only feature lists. SP021, SP022, SP012
CP033 Oasis's moat is more about unified lifecycle governance and agentic-access messaging than about owning the lowest-level secret store or workload identity primitive. SP001, SP002, SP021, SP022
CP034 Discovery-only positions face commoditization pressure because suite vendors are rapidly adding inventory and posture features. SP011, SP015, SP017
CP035 Pricing is still largely opaque across the public enterprise pages reviewed, which preserves sales-led procurement friction and weakens simple product-to-product price comparison. SP001, SP003, SP006, SP010, SP013
CP036 Because public pricing is sparse, buyers are more likely to compare vendors on control-plane depth, integration fit, and deployment model than on a posted per-seat list price. SP001, SP003, SP008, SP022
CP037 Oasis currently has stronger public partner visibility than public pricing transparency. SP021, SP022, SP023
CP038 The category remains early enough that no single vendor publicly demonstrates undisputed control over discovery, lifecycle, runtime access, and distribution simultaneously. SP003, SP004, SP006, SP008, SP010, SP013, SP021
CI001 Oasis sells its platform through a SaaS subscription agreement tied to an order form rather than a public self-serve plan. SI001, SI004
CI002 The subscription agreement auto-renews for successive terms unless either party gives at least 60 days notice of non-renewal. SI001
CI003 Oasis publishes a contract stack that includes a SaaS agreement, a DPA, and an SLA, which is typical of an enterprise software vendor selling recurring service. SI001, SI002, SI003
CI004 The DPA expressly references GDPR, UK GDPR, and Israeli privacy law, signaling that Oasis expects to process regulated customer data across multiple jurisdictions. SI002
CI005 Oasis commits to a 99.9% monthly uptime service level in its public SLA. SI003
CI006 The same SLA targets an initial response within three business hours for severity-1 incidents and five business hours for severity-2 incidents. SI003
CI007 AWS Marketplace lists Oasis with custom pricing and directs buyers to request a private offer rather than showing a public list price. SI004
CI008 Oasis positions itself as a unified NHI management platform spanning visibility, security, and governance across hybrid cloud environments. SI005
CI009 Oasis NHI Provisioning supports Azure, GCP, AWS, on-prem environments, and third-party vaults including HashiCorp, Azure Key Vault, and CyberArk. SI006, SI009
CI010 Provisioning can be initiated from Terraform, ServiceNow, a generic API trigger, or the Oasis UI. SI006
CI011 Provisioning supports both credential-based identities and federated identities such as managed identities, IAM roles, and OIDC-linked trust relationships. SI006
CI012 Oasis Outpost keeps privileged identity operations, secret generation, and storage inside the customer perimeter while Oasis only exchanges control messages and metadata. SI006
CI013 Oasis governance materials package provisioning, ownership assignment, privilege controls, rotation, attestation, and decommissioning as productized lifecycle features. SI008, SI009
CI014 The finance solution page frames Oasis as a compliance and least-privilege workflow product for PCI DSS 4.0, SOC 2, and GDPR-sensitive buyers. SI010
CI015 The financial-services case study describes rapid Azure AD deployment, auto-discovery of NHIs, posture analysis, disabling stale accounts, and automated identity rotation. SI007
CI016 Indirect procurement is available through AWS Marketplace, CrowdStrike Marketplace, Wiz integrations, and GuidePoint’s federal contracting motion. SI004, SI016, SI017, SI018
CI017 Oasis said its 2025 channel program was intended to make channel a key source of growth and launched with GuidePoint as a reseller partner. SI015, SI016
CI018 The careers page shows Oasis is still recruiting builders and operators, consistent with ongoing post-Series-B investment in engineering and go-to-market capacity. SI011
CI019 The public contract and marketplace materials collectively indicate a recurring software model, not a one-off project services business. SI001, SI003, SI004
CI020 Secret rotation is presented as an automated ongoing control rather than as a manual consulting workflow, supporting software-like gross-margin potential over time. SI008, SI009
CI021 Oasis announced a $120 million Series B in March 2026 led by Craft Ventures with Accel, Cyberstarts, and Sequoia participating. SI012, SI013, SI014
CI022 Globes reported that Oasis had raised $195 million in total and that market sources believed the Series B valued the company at about $700 million. SI013
CI023 Globes also reported that Oasis said ARR increased fivefold over the prior year and that most customers were Fortune 500 companies. SI013
CI024 The March 2026 funding coverage framed the round around securing enterprise AI agents, implying the new capital was intended for category expansion rather than emergency refinancing. SI012, SI014
CI025 No public debt facility, credit line, or project-finance obligation was identified in the financial evidence reviewed for this chapter. SI001, SI012, SI013, SI015
CI026 Public sources reviewed for this chapter do not disclose Oasis ARR, revenue, gross margin, burn rate, cash balance, or NRR in enough detail for underwriting. SI004, SI012, SI013, SI015, SI018
CI027 Federal revenue concentration cannot be quantified publicly even though GuidePoint’s OASIS+ contract shows federal-channel intent through 2030. SI015, SI016
CI028 Okta reported $2.855 billion of FY2026 subscription revenue and 15% growth in remaining performance obligations, illustrating the recurring-revenue model of scaled identity vendors. SI019, SI023
CI029 SailPoint reported FY2026 ARR of $1.125 billion and SaaS ARR of $746 million, showing strong market value for durable identity-security subscriptions. SI020, SI024
CI030 Rubrik reported $1.46 billion of subscription ARR and 2,805 customers above $100K subscription ARR in fiscal 2026. SI021
CI031 CyberArk ended 2025 with $1.44 billion of total ARR and $1.267 billion of subscription ARR, confirming that privileged and machine-identity leaders already monetize at billion-dollar recurring scale. SI022, SI027
CI032 These peer disclosures support using recurring-revenue logic rather than services multiples when framing Oasis, even though Oasis itself does not disclose ARR. SI019, SI020, SI021, SI022
CI033 Windsor Drake’s Q2 2026 IAM report put public IAM valuations near 6.0x NTM revenue while non-human and AI-agent identity platforms cleared roughly 15x to 30x revenue. SI025
CI034 Finro warned that mature public cybersecurity comps can materially understate private AI-native cybersecurity valuations, which is an adverse signal against simplistic public-comp benchmarking. SI026
CI035 The combination of custom quote pricing, no public ARR disclosure, and no public burn disclosure means Oasis cannot be underwritten from public evidence alone. SI004, SI013, SI026
CI036 Oasis’s contract stack and marketplace footprint imply annual or multi-year subscription revenue with partner-assisted procurement, but realized pricing and discounting remain opaque. SI001, SI004, SI015, SI016
CI037 The likely cost base is software R&D, cloud analytics, support, and partner enablement rather than hardware or working capital, but public sources do not quantify the split. SI006, SI011, SI015, SI018
CI038 Public evidence is strong enough to conclude Oasis is well funded for near-term growth, but not strong enough to estimate remaining runway with confidence. SI012, SI013, SI026
CE001 Oasis Agentic Access Management is positioned as a purpose-built governance layer for AI agents across their lifecycle. SE001, SE024
CE002 AAM evaluates agent intent in real time and applies policy before the action reaches enterprise data or systems. SE001, SE024
CE003 AAM grants short-lived least-privilege session identities instead of standing access or long-lived secrets. SE001, SE002, SE024
CE004 Oasis describes a full chain-of-custody for agent actions linking prompt, intent, policy, session, and action. SE001
CE005 The AAM launch blog says actions such as reviewing pull requests, modifying production records, and triggering workflows are converted into time-bound least-privilege sessions. SE002
CE006 Visibility is treated as the first operational step for AI governance: teams must discover agents, understand what identities they use, what data they access, and who is accountable. SE005
CE007 The AI solution page says Oasis can detect AI adoption across endpoints, SaaS, and cloud while surfacing unauthorized tools and unmanaged NHIs. SE012
CE008 The same AI page frames control around least privilege, identity-based controls, provisioning, rotation, and automated enforcement. SE012
CE009 Cursor agents are described as executing commands, calling MCP tools, and interacting with internal systems, which is why Oasis pairs intent-based access with audit trails. SE004
CE010 The AI Access Partnership Program promises built-in governance, admin visibility, audit-ready reporting, and co-selling access to Fortune 500 demand. SE003
CE011 Oasis NHI Provisioning supports AWS, Azure, GCP, on-prem environments, and vault integrations such as HashiCorp, Azure Key Vault, and CyberArk. SE009, SE011
CE012 Provisioning can start through Terraform, ServiceNow, a generic API trigger, or the Oasis UI. SE009
CE013 Provisioning supports both credential-based identities and federated identities, including managed identities, IAM roles, and OIDC-linked trust relationships. SE009
CE014 Oasis Outpost is deployed inside the customer perimeter so secret generation and storage stay local while Oasis exchanges control messages and metadata. SE009
CE015 Governance features are packaged around secure provisioning, ownership assignment, attestation, privilege controls, rotation, and decommissioning. SE009, SE021
CE016 The posture-management page says Oasis uses AI-based analytics to detect compromise attempts, policy violations, misconfigurations, toxic combinations, and anomalies. SE010
CE017 The secret-rotation page organizes the workflow around discovery, observation, policy management, safe rotation, and decommissioning of secrets. SE011
CE018 The financial-services case study describes rapid Azure AD deployment, auto-discovery, risk-posture insights, stale-account disablement, and automated identity rotation. SE013
CE019 The Wiz integration enriches Oasis with Wiz Issues and DSPM findings so teams can correlate privilege, sensitive-data context, and usage before lifecycle actions. SE014, SE028
CE020 The Zscaler partnership positions Oasis as the identity-governance layer while Zscaler provides inline enforcement for machine-to-machine and agentic traffic. SE015
CE021 The CrowdStrike marketplace partnership is presented as part of a wider shift toward unified next-generation identity protection. SE016, SE029
CE022 The AAM Framework launch says Oasis and Sequoia created a seven-pillar, practitioner-built governance framework plus a free maturity assessment. SE025
CE023 NIST’s AI Agent Standards Initiative is designed around secure interoperability and open protocols, which means the external standards environment is still being defined in 2026. SE023
CE024 Oasis said Gartner named it in a January 2026 report on top-funded startups in AI TRISM and agentic AI. SE017
CE025 Oasis researchers disclosed a vulnerability chain in OpenClaw that allowed full agent takeover from a visited website and said the upstream team fixed it within 24 hours. SE007
CE026 Oasis’s LLM and MCP risk post says over 90% of Fortune 500 companies use LLM tools, thousands of MCP servers are published online, and the MCP repository has been forked more than 4,000 times. SE006
CE027 The RPA-to-agents post argues that adaptive AI agents introduce more access-governance complexity than rule-based automation. SE008
CE028 The careers page describes Oasis as a team of builders tackling NHI security at scale, and the AI-native engineering post signals an engineering culture centered on rapid AI-assisted development. SE018, SE019
CE029 HashiCorp’s validated pattern for AI-agent identity uses OAuth token exchange and dynamic secrets, offering an external technical analogue to Oasis’s short-lived credential model. SE020
CE030 GitGuardian’s NHI governance concepts emphasize discovery, ownership, and lifecycle control, which lines up with the way Oasis packages its product modules. SE021, SE009
CE031 SPIFFE provides a cryptographic workload-identity control plane, whereas Oasis’s public materials emphasize broader governance, lifecycle, and enterprise workflow controls across heterogeneous systems. SE022, SE009, SE012
CE032 Public Oasis materials show availability commitments in the SLA but do not publish benchmarked false-positive, throughput, or efficacy metrics for AAM or posture analytics. SE001, SE010
CE033 The partner stack suggests Oasis deliberately avoids being a closed stack: it integrates with cloud, ticketing, vault, exposure-management, inline-enforcement, IDE, and marketplace ecosystems. SE003, SE004, SE014, SE015, SE016
CE034 The AI Access Partnership Program indicates Oasis wants to embed governed execution patterns into third-party AI platforms, not only secure existing non-human identities after the fact. SE003, SE004
CE035 The documented control-plane pattern suggests Oasis is primarily a governance and orchestration layer rather than a network-inline proxy or a standalone vault. SE009, SE014, SE015, SE020
CE036 Across 2025-2026 public releases, Oasis expanded from NHI lifecycle management into agentic access governance through AAM, the partnership program, the framework, and ecosystem integrations. SE002, SE003, SE024, SE025
CU001 Oasis says leading organizations across a wide range of industries use its platform. SU001
CU002 The product page includes a Fortune 1000 Head of Identity quote describing 17,000-plus NHIs in the customer’s cloud environment and saying Oasis visibility made the problem a no-brainer. SU002
CU003 The home page says a Fortune-50 healthcare provider eliminated a critical exposure and avoided an estimated $3-5 million HIPAA breach fine. SU003, SU013
CU004 The same home page says a Fortune-500 logistics company cut secret-rotation effort by 35 percent. SU003
CU005 Oasis also says an F500 insurance customer capped an outage affecting 50 percent of production workloads. SU003
CU006 Oasis says an F300 consumer packaged goods customer reduced attack surface by 60 percent in days during a proof of value. SU003
CU007 The home page further claims an F200 manufacturing customer enforced M&A compliance on newly acquired environments. SU003
CU008 Newswire said Oasis serves dozens of Fortune 500 companies. SU022, SU023
CU009 Globes reported that a majority of Oasis’s client base comes from the Fortune 500. SU023
CU010 The AI Access Partnership page says Fortune 500 customers are actively looking for vetted secure AI solutions through the Oasis enterprise network. SU014
CU011 A private-credit financial-services customer deployed Oasis into Azure AD and used it for visibility, tailored security policies, stale-account cleanup, and automated identity rotation. SU004, SU012
CU012 The healthcare-provider case study describes an environment with 8,500 human identities, more than 100,000 NHIs, over 50,000 certificates, and about 10,000 service accounts. SU005, SU013
CU013 The same healthcare case says an 18-person security team and roughly 50 IT-operations staff were trying to manage that identity sprawl across cloud and on-prem systems. SU005
CU014 The Mars case study says Mars used Oasis to secure a hyper-fragmented cloud environment and achieve instant visibility into service accounts and API keys. SU006
CU015 An industrial-company webinar says the buyer used Oasis to uncover and classify NHIs across Azure, remediate excessive privilege, and improve continuous compliance. SU007
CU016 A financial-services whitepaper says Oasis helped Antares streamline NHI lifecycle management, minimize manual effort, and take a more proactive security posture. SU009, SU010
CU017 The leading-organizations webinar and other resource pages show that Oasis’s customer-proof surface is richer in detailed vertical case studies than in a simple named-customer roster. SU008, SU004, SU005, SU006
CU018 Public customer evidence skews toward regulated or operationally complex enterprise environments such as financial services, healthcare, industrial Azure estates, logistics, insurance, manufacturing, and large consumer brands. SU003, SU004, SU005, SU007, SU009, SU012, SU013
CU019 The product and home pages imply production use cases, not merely conceptual pilots, because the quoted outcomes concern exposure removal, outage mitigation, lifecycle automation, and compliance work. SU002, SU003
CU020 Gartner Peer Insights shows Oasis Security at 4.6 out of 5 from 20 ratings on the captured 2026 page. SU015
CU021 SourceForge lists Oasis but shows an overall 0.0 out of 5 and thin review depth on the captured page, which is an adverse signal about long-tail public review coverage rather than necessarily about product quality. SU016
CU022 Slashdot also lists Oasis, but the captured page provides little usable review depth or customer-outcome specificity. SU017
CU023 Independent public customer-voice evidence is therefore materially thinner than Oasis’s company-authored case-study surface. SU015, SU016, SU017
CU024 Newswire said most new ARR is driven by multi-year enterprise agreements, which is a positive durability signal even though contract counts and renewal cohorts are undisclosed. SU022
CU025 Public sources reviewed for this chapter do not disclose customer count, NRR, GRR, churn, contract length distribution, or top-customer concentration. SU015, SU022, SU023
CU026 The case studies emphasize ongoing lifecycle governance and policy enforcement, which suggests recurring usage rather than one-time audit work. SU004, SU005, SU006, SU007, SU009
CU027 GuidePoint’s OASIS+ contract and the 2025 channel-program announcement show an active partner-led route to federal and enterprise procurement. SU018, SU019
CU028 The CrowdStrike Marketplace and Wiz integration pages add additional procurement and workflow surfaces that can support expansion even when direct customer references are sparse. SU020, SU021
CU029 The Bank of America page is an account-targeted marketing page and should not be treated as proof that Bank of America is a live customer. SU011
CU030 The strongest named public customer references surfaced in this chapter are Mars and Antares; other operationally rich examples remain anonymous by vertical. SU006, SU009, SU004, SU005, SU007
CU031 The home-page proof point for the F300 CPG customer is explicitly described as a proof of value, so it should not be treated as full production-retention evidence. SU003
CU032 The financial-services whitepaper and solution page show Oasis tailoring its customer story to institutions worried about PCI DSS 4.0, SOC 2, GDPR, and operational resilience. SU010, SU012
CU033 The healthcare solution page similarly ties Oasis to patient-privacy, HIPAA/GDPR-style compliance, audit readiness, and uninterrupted care operations. SU013
CU034 The AI Access Partnership page suggests enterprise AI-platform vendors are themselves a partner-facing customer segment for Oasis, not only end-user enterprises. SU014
CU035 The Noname Security CISO podcast and ISMG interview show practitioner awareness and ecosystem education, but they are not substitutes for deployment proof or retention data. SU024, SU025, SU026
CU036 Public evidence does not reveal what share of revenue comes from the top ten customers, from the federal segment, or from partner-led customers. SU018, SU019, SU022, SU023
CU037 If dozens of Fortune 500 customers are real but still concentrated in a small number of large accounts, concentration risk could be material; the public record is too thin to resolve that risk. SU022, SU023
CU038 The best-supported public conclusion is that Oasis has genuine enterprise traction and meaningful use-case depth, but its public proof is much stronger on deployment anecdotes than on broad retention or satisfaction statistics. SU003, SU015, SU022, SU023
CR001 NIST’s AI Agent Standards Initiative is a 2026 standards effort around secure interoperability and open protocols rather than a mature, enforceable control regime. SR004, SR005
CR002 CSA’s 2026 governance-gap note says substantive agent-specific standards are still pending and enterprises are operating ahead of clear controls. SR005, SR004
CR003 Oasis’s DPA expressly references GDPR, UK GDPR, and Israeli privacy law, confirming that customer deployments can create cross-jurisdiction privacy obligations. SR001
CR004 The SaaS agreement makes customers responsible for having the necessary legal basis and permissions for customer data processed through the service. SR002, SR001
CR005 Oasis’s public SLA offers 99.9 percent monthly uptime but limits the customer remedy to service credits rather than broader damages. SR003
CR006 Maximum service credits are capped at 20 percent of the amount due during the applicable subscription term. SR003
CR007 The AI Access Partnership page explicitly promises to bypass lengthy security reviews, which is evidence that procurement and trust review friction is a real go-to-market risk in this category. SR023
CR008 OpenClaw showed that a developer visiting an ordinary website could lose full control of an AI agent if browser and local-agent trust boundaries are poorly designed. SR012
CR009 The Claude.ai prompt-injection chain described by Oasis turned untrusted content into data exfiltration and tool-misuse risk. SR013
CR010 Claude Tag demonstrates a governance risk where an agent acts under its own shared identity rather than under the identity of each human participant in a channel. SR014
CR011 Oasis reported a critical CVSS 9.7 localhost WebSocket hijack in Cline that could exfiltrate workspace data and inject agent commands. SR015
CR012 Oasis reported that Cursor could execute code on folder open because Workspace Trust was off by default. SR016
CR013 Oasis reported that a single click on a crafted VS Code MCP install dialog could enable full code execution or reroute tool calls through an attacker account. SR017
CR014 The MCP breach write-up shows how a malicious package in an AI workflow can quietly exfiltrate sensitive email traffic at scale. SR018
CR015 The McHire breach write-up shows that default credentials plus IDOR flaws can expose tens of millions of applicant records in AI-assisted systems. SR019
CR016 The Change Healthcare breach analysis points to compromised credentials and missing MFA as a catastrophic failure mode for non-human or privileged access. SR020
CR017 The Cloudflare breach analysis highlights how one unrotated token and a few service accounts can preserve attacker access even after a major incident is discovered. SR021
CR018 The Cisco breach analysis ties public DevHub exposure, hard-coded credentials, tokens, and keys directly to enterprise data leakage risk. SR022
CR019 GitGuardian’s OWASP NHI Top 10 summary names secret leakage, improper offboarding, overprivileged NHIs, and insecure authentication as recurring failure modes. SR006
CR020 CyberArk’s state report says organizations increasingly recognize machine-identity security as essential, but preparedness remains uneven. SR007
CR021 Delinea argues that AI is now embedded across workflows faster than governance and identity protections are maturing. SR008
CR022 Palo Alto said machine identities reached 109 to 1 versus humans in 2026, magnifying the blast radius of identity-governance failures. SR009
CR023 The ShareuHack OWASP summary argues that many organizations intend to deploy agentic AI before they can adequately protect it. SR010
CR024 Oasis’s own LLM-and-MCP risk post says LLMs are used by over 90 percent of Fortune 500 companies and that thousands of MCP servers are already available, which expands attack surface faster than governance can standardize. SR011
CR025 Oasis’s perimeter-execution and Outpost-style design reduces direct secret custody by the vendor but creates dependency on customer-side deployment correctness. SR002, SR003, SR024
CR026 The public product story depends on partner ecosystems such as Wiz, Zscaler, GuidePoint, and the channel program, creating integration and distribution dependency risk. SR024, SR025, SR026, SR027
CR027 GuidePoint’s OASIS+ route shows federal procurement ambition, but it also means Oasis depends on partner and contract-vehicle access for some government sales. SR027, SR026
CR028 The 2026 Series B and reports of multi-year enterprise agreements reduce immediate financing panic, but public sources still do not expose burn, cash, or runway. SR028, SR030
CR029 The July 2026 Globes report of advanced acquisition talks with Cyera up to $1 billion introduces strategic-distraction and process-risk even if the deal never closes. SR029
CR030 Finro’s warning about misread cybersecurity multiples is an adverse reminder that financing expectations can compress quickly if public comparables stay weak. SR030
CR031 The home page’s customer-outcome claims suggest large regulated deployments, but they do not provide the retention or concentration detail needed to judge revenue durability risk. SR032, SR028
CR032 The AI-native engineering post implies Oasis is moving quickly with AI-assisted development, which can increase execution speed but also raises process-discipline risk if security foundations lag. SR031
CR033 The combination of healthcare, financial-services, and AI-governance positioning means Oasis faces high buyer expectations on privacy, auditability, and policy enforcement. SR001, SR023, SR032
CR034 Service-credit-only remedies and customer-controlled data/legal obligations shift significant operational and compliance burden back to the customer. SR001, SR002, SR003
CR035 Public materials do not surface downloadable audit reports, third-party efficacy studies, or broad public benchmark data for AAM and posture analytics. SR023, SR032
CR036 Oasis’s strongest public technical credibility comes from vulnerability research and incident analysis, not from public operational metrics or certification detail. SR012, SR013, SR015, SR016, SR017
CR037 Machine-identity governance failures now transmit into customer risk, operational outages, privacy violations, and financing outcomes rather than staying isolated as a narrow security problem. SR006, SR007, SR022, SR030
CR038 Procurement friction is itself a thesis-break risk because Oasis is selling a new category into buyers already burdened by lengthy security reviews and evolving AI governance expectations. SR023, SR026
CR039 Public evidence does not show a mature external standards shield yet, so Oasis bears the risk of selling ahead of customer comfort and ahead of settled regulation. SR004, SR005, SR023
CR040 Large-enterprise and regulated-industry focus can be a moat, but it also concentrates Oasis in slower, more demanding procurement cycles where deployment and renewal proof must be stronger. SR028, SR032
CR041 The repeated breach examples across Cloudflare, Change Healthcare, Cisco, McHire, and AI coding tools support a high-likelihood environment for NHI and agentic-access incidents. SR015, SR016, SR017, SR019, SR020, SR021, SR022
CR042 The overall risk verdict is not that Oasis lacks product-market relevance, but that the company must prove implementation discipline, partner resilience, and buyer trust faster than the threat surface is expanding. SR005, SR023, SR026, SR030, SR032
CV001 Oasis announced a $120 million Series B in March 2026. SV001, SV002, SV026, SV027, SV028
CV002 Globes reported that Oasis had raised $195 million in total by March 2026. SV002, SV001
CV003 Globes reported that market sources believed the Series B valued Oasis at about $700 million. SV002
CV004 Newswire said new ARR grew 5x year over year and that most new ARR came from multi-year enterprise agreements. SV001
CV005 Newswire also said Oasis serves dozens of Fortune 500 companies, while Globes said a majority of the client base comes from the Fortune 500. SV001, SV002
CV006 The home and product pages show Oasis positioning itself as the access-management layer for AI agents and NHIs across major enterprise systems, which supports the strategic-upside thesis. SV004, SV005, SV006
CV007 The AI Access Partnership page suggests large enterprises are actively seeking vetted agentic-security controls, adding demand optionality beyond direct Oasis sales. SV008
CV008 The July 2026 Globes report of advanced talks to sell Oasis to Cyera for up to $1 billion is unconfirmed but does indicate strategic interest around the asset. SV003
CV009 Public evidence still does not disclose Oasis ARR, gross margin, burn, or retention, which prevents clean revenue-multiple underwriting. SV001, SV002, SV019
CV010 Windsor Drake’s Q2 2026 IAM report places mainstream public IAM around 6.0x NTM revenue. SV016, SV017
CV011 The same Windsor analysis says non-human and AI-agent identity platforms clear roughly 15x to 30x revenue in private rounds. SV016, SV017
CV012 Finro argues that mature public cybersecurity comps can materially understate private AI-native cybersecurity valuations. SV019, SV018
CV013 Multiples.vc reported the weighted market-cap performance of its cybersecurity index at +74.6 percent as of July 9, 2026. SV020
CV014 Astrix announced it was joining Cisco, which validates ongoing strategic-buyer appetite for NHI and AI-agent security assets. SV021
CV015 GitGuardian raised a $50 million Series C in February 2026 to expand in secrets and AI-agent security, showing investors are still funding adjacent NHI platforms. SV022
CV016 CyberArk said machine identities outnumber humans by more than 80 to 1 and that security concerns are a major blocker to agentic-AI adoption. SV023, SV024
CV017 Okta reported $2.855 billion of FY2026 subscription revenue. SV009, SV013
CV018 SailPoint reported FY2026 ARR of $1.125 billion and SaaS ARR of $746 million. SV010, SV014
CV019 Rubrik reported fiscal-2026 subscription ARR of $1.46 billion. SV011, SV015
CV020 CyberArk ended 2025 with $1.44 billion of total ARR and $1.267 billion of subscription ARR. SV012
CV021 The Okta, SailPoint, and Rubrik SEC filings confirm that the relevant public comp set is valued and discussed through recurring-revenue language, not project-services language. SV013, SV014, SV015
CV022 CyberArk’s Venafi integration and Astrix’s sale to Cisco show that machine-identity capabilities are being consolidated into larger security platforms. SV021, SV025
CV023 Oasis’s customer-proof surface includes named enterprise references such as Mars, which strengthens the upside case but does not solve retention opacity. SV030, SV005
CV024 The bull thesis is that Oasis becomes a control layer for enterprise agentic access while strategic buyers and growth investors keep paying premium identity-security multiples. SV006, SV007, SV011, SV016, SV021
CV025 The anti-thesis is that market excitement about AI agents outruns real buyer conversion and that missing ARR, margin, and retention proof prevent premium-multiple support. SV019, SV020, SV001, SV002
CV026 A sensible base case anchors near the best-supported public financing mark of about $700 million until fresher operating metrics emerge. SV002
CV027 A credible bull case reaches roughly $1.0 billion if strategic interest proves real or if Oasis can substantiate premium-category ARR and retention. SV003, SV016, SV021
CV028 A reasonable bear case falls toward the mid-hundreds of millions if investors revert to public-IAM comp discipline before Oasis discloses premium-quality metrics. SV016, SV019, SV020
CV029 Public comp data supports valuing identity-security businesses on recurring revenue quality, but Oasis does not yet disclose the denominator needed to apply that framework. SV017, SV018, SV021
CV030 The March 2026 Series B and peer-funding environment suggest Oasis is not under forced-financing pressure in the immediate term. SV001, SV022
CV031 However, the cap table, liquidation preferences, and any venture debt remain undisclosed publicly. SV001, SV002
CV032 Because the current public evidence is rich on category momentum but poor on unit economics, the most defensible recommendation is research-more rather than buy. SV001, SV002, SV019, SV020
CV033 Confidence in that recommendation is medium: the last financing mark is visible, but the operating evidence needed to accept or reject it is incomplete. SV002, SV003, SV019
CV034 Risk rating should remain high because standards, partner dependence, disclosure gaps, and proof burdens all remain material. SV007, SV008, SV019, SV020
CV035 Exit-readiness upside exists because larger security platforms are already consolidating machine-identity and adjacent identity-security assets. SV021, SV025
CV036 Exit-readiness is constrained by Oasis’s private-data opacity: a buyer or late-stage investor would still need ARR, retention, and concentration proof. SV001, SV002, SV019
CV037 The price sensitivity is high: if Oasis can prove strong ARR quality, premium-category framing becomes more credible; if not, the last mark looks harder to defend. SV002, SV016, SV019
CV038 The channel program and partnership surfaces increase distribution optionality, which could support a higher outcome if adoption keeps broadening. SV008, SV029
CV039 The same channel and ecosystem breadth can also obscure where real customer ownership, conversion, and pricing power sit. SV008, SV029
CV040 Series-B coverage consistently frames Oasis as a new category leader in agentic access and non-human identity management. SV001, SV026, SV028
CV041 Oasis’s home page outcome claims imply substantial enterprise value creation, but those claims are company-authored and therefore insufficient to close the valuation debate on their own. SV004, SV005
CV042 The best public case for upside is strategic scarcity in a growing category; the best public case for caution is that valuation has run ahead of disclosed operating proof. SV016, SV019, SV021, SV022, SV023
来源
编号出版方标题引文
SO001 Oasis Security Non Human Identity Management Platform | OASIS Security
SO002 Oasis Security non-human identity management | About oasis
SO003 Oasis Security Non-Human Identity Management Platform
SO004 Oasis Security Oasis Security Emerges from Stealth: CEO's Perspective Oasis began as a dream in a modest room in Tel-Aviv.
SO005 Oasis Security Newsroom
SO006 Oasis Security via Newswire Oasis Security Raises $120M Series B to Secure the Rise of Enterprise AI Agents Oasis has seen strong enterprise adoption, with new annual recurring revenue (ARR) growing 5x year over year.
SO007 TechCrunch Oasis Security leaves stealth with $40M to lock down the wild west of non-human identity management The fast-casual food chain Chipotle, property firm JLL and Mercury Financial are among its early users.
SO008 CTech Oasis Security raises $35 million Series A to resolve non-human identity security challenge
SO009 ACCESS Newswire Oasis Secures $35M Series A Extension to Automate Non-Human Identity Security
SO010 Built In NYC Oasis Security Raises $35M Series A Extension Round
SO011 Globes Oasis Security raises $35m, doubles valuation
SO012 SiliconANGLE Oasis Security raises $120M to secure nonhuman identities across AI and cloud environments
SO013 Tech Company News Oasis Security Raises $120 Million In Series B Funding Round Oasis Security raised $120 million in a Series B round led by Craft Ventures, bringing its total funding to $195 million and valuing the company at approximately $700 million post money.
SO014 Globes Israeli co Oasis Security raises $120m
SO015 BankInfoSecurity Oasis Raises $120M Series B to Safeguard Agentic Identities Oasis Security, founded in 2022, employs 142 people and has raised $195 million.
SO016 Digital IT News Michael DeCesare Named President of Oasis Security
SO017 CRN Oasis Aims For Partner Push To Enable ‘Next Wave’ Of Identity Security: President Michael DeCesare
SO018 PR Newswire Oasis Security Launches Channel Program to Accelerate Growth and Make Non-Human Identity Management Mainstream
SO019 Gartner Peer Insights Oasis Security Reviews & Ratings 2026 | Gartner Peer Insights 5.0 (1 Rating) ... SVP IAM ... 3B - 10B USD, Banking.
SO020 CrowdStrike Marketplace Oasis NHI Security Cloud
SO021 Wiz Oasis Security integration | Wiz
SO022 GuidePoint Security 2025 GPSEC St. Louis Agenda
SO023 NIST AI Agent Standards Initiative
SO024 Palo Alto Networks How to Assess Maturity When Machine Identities Outnumber Humans 109:1
SO025 CyberArk Machine Identities Outnumber Humans by More Than 80 to 1: New Report Exposes the Exponential Threats of Fragmented Identity Security
SO026 Globes Cyera in advanced talks to buy Oasis Security for $1b The companies have yet to make a formal announcement about the signing of a deal.
SM001 Mordor Intelligence Non-Human Identity (NHI) Security Market Size, Share & 2031 Growth Trends Report
SM002 Yahoo Finance / Research and Markets Non-Human Identity Access Management Market Global Forecast Report 2026-2036: Opportunities in Adoption of Zero Trust Architecture, Cloud-native Applications, and Regulatory Compliance Requirements
SM003 Research and Markets Non-Human Identity Access Management Market by Offering, Identity Type, Deployment Mode, Organization Size, and Vertical - Global Forecast to 2036
SM004 Palo Alto Networks How to Assess Maturity When Machine Identities Outnumber Humans 109:1
SM005 Axis Intelligence Machine Identity Statistics 2026: Non-Human Identity Ratios, Secrets Sprawl, and Certificate Lifecycle Data
SM006 NIST AI Agent Standards Initiative
SM007 Cloud Security Alliance NIST AI Agent Standards: Enterprise Governance Implications
SM008 Cloud Security Alliance The AI Agent Governance Gap: What CISOs Need Now
SM009 ShareuHack OWASP Agentic AI Security Maturity Framework 2026: Where Does Your Agent Stand?
SM010 ITECS Agentic AI Governance Framework 2026 | Shadow AI Guide
SM011 GitGuardian Core concepts | GitGuardian documentation
SM012 GitGuardian Non Human Identities Lifecycle Management: Best Practices
SM013 GitGuardian GitGuardian Launches Comprehensive Non-Human Identities Security Strategy
SM014 GitGuardian Non-Human Identity Security in the Age of AI
SM015 Saviynt Non-Human Identity Management | Non-Human Identities (NHI) Security
SM016 Saviynt Non-Human Identity Security with Identity Security Posture Management | ISPM Solution for NHI | Saviynt
SM017 Saviynt Saviynt & Wiz: Unified Non-Human Identity Security
SM018 Delinea What are Non-Human Identities (NHIs)?
SM019 Delinea The Importance of Continuous Discovery in Identity Security
SM020 Delinea How to Secure Non-Human Identities and AI Agents
SM021 HashiCorp Developer Secure AI agent authentication using HashiCorp Vault dynamic secrets | HashiCorp Developer
SM022 HashiCorp Developer Identity secrets engine | Vault | HashiCorp Developer
SM023 Aembit Aembit | Agentic AI and Workload Identity & Access Management
SM024 SPIFFE Secure Production Identity Framework for Everyone
SM025 WorkOS March Updates — WorkOS
SM026 Oasis Security AI
SM027 Oasis Security Finance
SM028 Oasis Security Healthcare
SP001 Oasis Security Non Human Identity Management Platform | OASIS Security
SP002 Oasis Security Non-Human Identity Management Platform
SP003 Aembit Aembit | Agentic AI and Workload Identity & Access Management
SP004 Entro Security Agentic AI & Non-Human Identity Security Platform | Entro Security
SP005 Astrix Security Identity Security for AI Agents & NHIs | Astrix Security
SP006 CyberArk Machine Identity Security
SP007 CyberArk State of Machine Identity Security Report
SP008 HashiCorp Developer Secure AI agent authentication using HashiCorp Vault dynamic secrets | HashiCorp Developer
SP009 HashiCorp Developer Identity secrets engine | Vault | HashiCorp Developer
SP010 Saviynt Non-Human Identity Management | Non-Human Identities (NHI) Security
SP011 Saviynt Non-Human Identity Security with Identity Security Posture Management | ISPM Solution for NHI | Saviynt
SP012 Saviynt Saviynt & Wiz: Unified Non-Human Identity Security
SP013 Delinea What are Non-Human Identities (NHIs)?
SP014 Delinea How to Secure Non-Human Identities and AI Agents
SP015 Delinea The Importance of Continuous Discovery in Identity Security
SP016 GitGuardian GitGuardian Launches Comprehensive Non-Human Identities Security Strategy
SP017 GitGuardian Top 10 Non-Human Identity Security Tools and Platforms for 2026
SP018 GitGuardian OWASP NHI Top 10 Risks for 2025 Explained by GitGuardian
SP019 SPIFFE Secure Production Identity Framework for Everyone
SP020 WorkOS March Updates — WorkOS
SP021 CrowdStrike Marketplace Oasis NHI Security Cloud
SP022 Wiz Oasis Security integration | Wiz
SP023 Gartner Peer Insights Oasis Security Reviews & Ratings 2026 | Gartner Peer Insights
SP024 SourceForge Oasis Security
SP025 Slashdot Oasis Security
SI001 Oasis Security Non Human Identity Management SAAS SUBSCRIPTION AGREEMENT
SI002 Oasis Security DATA PROCESSING AGREEMENT/ ADDENDUM (“DPA”)
SI003 Oasis Security SLA
SI004 AWS Marketplace AWS Marketplace: OASIS Security
SI005 Oasis Security non-human identity management | About oasis
SI006 Oasis Security NHI Provisioning: Secure Non-Human Identities from Day One
SI007 Oasis Security How Financial Services Secures Azure NHIs | Oasis Security
SI008 Oasis Security Governance
SI009 Oasis Security secret rotation | Oasis Security
SI010 Oasis Security Finance
SI011 Oasis Security Non-Human Identity Management Careers | OASIS Security
SI012 Newswire Oasis Security Raises $120M Series B to Secure the Rise of Enterprise AI Agents
SI013 Globes Israeli co Oasis Security raises $120m
SI014 SiliconANGLE Oasis Security raises $120M to secure nonhuman identities across AI and cloud environments
SI015 PR Newswire Oasis Security Launches Channel Program to Accelerate Growth and Make Non-Human Identity Management Mainstream
SI016 GuidePoint Security GuidePoint Security OASIS+
SI017 CrowdStrike Marketplace Oasis NHI Security Cloud
SI018 Wiz Oasis Security integration | Wiz
SI019 Okta Investor Relations Okta Announces Fourth Quarter And Fiscal Year 2026 Financial Results
SI020 SailPoint Investor Relations SailPoint Announces Fiscal Fourth Quarter and Full Year 2026 Results
SI021 Rubrik Rubrik Reports Fourth Quarter and Fiscal Year 2026 Financial Results
SI022 CyberArk CyberArk Announces Record Fourth Quarter and Full Year 2025 Results
SI023 SEC Annual Report for Fiscal Year Ending January 31, 2026 (Form 10-K)
SI024 SEC EDGAR Filing Documents for 0002030781-26-000003
SI025 Windsor Drake Identity & Access Management Valuations: Q2 2026
SI026 Finro Cybersecurity valuation benchmarks are routinely misread
SI027 SEC EDGAR Entity Landing Page - CyberArk
SE001 Oasis Security Oasis Agentic Access Management
SE002 Oasis Security Oasis Agentic Access Management (AAM™): Secure, Govern, and Control AI Agent Access
SE003 Oasis Security AI Access Partnership Program | Enterprise-Ready AI Security | Oasis Security
SE004 Oasis Security Cursor & Oasis: Intent-Based Access & Governance for AI Agents
SE005 Oasis Security Agentic Access Management: Why Visibility Is the Foundation of AI Governance
SE006 Oasis Security AI & NHI Security: Navigating LLM + MCP Risks
SE007 Oasis Security ClawJacked: OpenClaw Vulnerability Enables Full Agent Takeover
SE008 Oasis Security RPA to AI Agents Secure Access | Oasis Security
SE009 Oasis Security Governance
SE010 Oasis Security Posture Management
SE011 Oasis Security secret rotation | Oasis Security
SE012 Oasis Security AI
SE013 Oasis Security How Financial Services Secures Azure NHIs | Oasis Security
SE014 Oasis Security Oasis + Wiz: From Cloud Exposure to Identity-Governed Action
SE015 Oasis Security Zero Trust for Non-Human & Agentic Identities | Oasis + Zscaler
SE016 Oasis Security Oasis Joins the CrowdStrike Marketplace | Strategic Partnership
SE017 Oasis Security Agentic AI Security: Oasis Named in Gartner AI TRISM Report
SE018 Oasis Security Non-Human Identity Management Careers | OASIS Security
SE019 Oasis Security AI-Native Engineering Teams: Speed, Culture, and Security Lessons
SE020 HashiCorp Developer Secure AI agent authentication using HashiCorp Vault dynamic secrets | HashiCorp Developer
SE021 GitGuardian Core concepts | GitGuardian documentation
SE022 SPIFFE Secure Production Identity Framework for Everyone
SE023 NIST AI Agent Standards Initiative
SE024 PR Newswire Oasis Security Launches Agentic Access Management, the First Identity Solution Built for AI Agents
SE025 PR Newswire Oasis Security and Sequoia Launch the First Practitioner-Built Governance Framework for Agentic AI Access
SE026 CyberArk State of Machine Identity Security Report
SE027 Delinea 2026: AI Breaks Identity Security and Forces a New Playbook
SE028 Wiz Oasis Security integration | Wiz
SE029 CrowdStrike Marketplace Oasis NHI Security Cloud
SU001 Oasis Security non-human identity management | About oasis
SU002 Oasis Security Non-Human Identity Management Platform
SU003 Oasis Security Non Human Identity Management Platform | OASIS Security
SU004 Oasis Security How Financial Services Secures Azure NHIs | Oasis Security
SU005 Oasis Security Non-Human Identity Management: NHI Visibility with Oasis
SU006 Oasis Security Video: Mars Case Study: Scaling Non-Human Identity Security | Oasis Security
SU007 Oasis Security Webinar: Optimizing Non-Human Identities (NHIs) in Azure Environment
SU008 Oasis Security Webinar: NHIM Case Study | Security Challenges | Oasis Security
SU009 Oasis Security Whitepaper: Oasis Security for Financial Services
SU010 Oasis Security Whitepaper: Securing Non-Human Identities for Financial Services
SU011 Oasis Security Bank of America
SU012 Oasis Security Finance
SU013 Oasis Security Healthcare
SU014 Oasis Security AI Access Partnership Program | Enterprise-Ready AI Security | Oasis Security
SU015 Gartner Peer Insights Oasis Security Reviews & Ratings 2026 | Gartner Peer Insights
SU016 SourceForge Oasis Security
SU017 Slashdot Oasis Security
SU018 GuidePoint Security GuidePoint Security OASIS+
SU019 PR Newswire Oasis Security Launches Channel Program to Accelerate Growth and Make Non-Human Identity Management Mainstream
SU020 CrowdStrike Marketplace Oasis NHI Security Cloud
SU021 Wiz Oasis Security integration | Wiz
SU022 Newswire Oasis Security Raises $120M Series B to Secure the Rise of Enterprise AI Agents
SU023 Globes Israeli co Oasis Security raises $120m
SU024 Oasis Security Video: Addressing Risks of Unmanaged Non-Human Identities
SU025 Oasis Security Video: Insights from Oasis CEO Danny Brickman on ISMG
SU026 Oasis Security Video: Non-Human Identity Management: What and Why
SR001 Oasis Security DATA PROCESSING AGREEMENT/ ADDENDUM (“DPA”)
SR002 Oasis Security Non Human Identity Management SAAS SUBSCRIPTION AGREEMENT
SR003 Oasis Security SLA
SR004 NIST AI Agent Standards Initiative
SR005 Cloud Security Alliance The AI Agent Governance Gap: What CISOs Need Now
SR006 GitGuardian OWASP NHI Top 10 Risks for 2025 Explained by GitGuardian
SR007 CyberArk State of Machine Identity Security Report
SR008 Delinea 2026: AI Breaks Identity Security and Forces a New Playbook
SR009 Palo Alto Networks How to Assess Maturity When Machine Identities Outnumber Humans 109:1
SR010 ShareuHack OWASP Agentic AI Security Maturity Framework 2026: Where Does Your Agent Stand?
SR011 Oasis Security AI & NHI Security: Navigating LLM + MCP Risks
SR012 Oasis Security ClawJacked: OpenClaw Vulnerability Enables Full Agent Takeover
SR013 Oasis Security Claude.ai Prompt Injection Vulnerability | Oasis Security
SR014 Oasis Security Claude Tag: Agent Identity and the NHI Governance Gap
SR015 Oasis Security Cline Kanban WebSocket Hijack: How a Localhost Vulnerability Exposes AI Agents | Oasis Security
SR016 Oasis Security Cursor “Open-Folder” Autorun Vulnerability Exposes Developers to Silent Code Execution | Oasis Security Research
SR017 Oasis Security One-Click Attack on VS Code Exposes Developer Machines
SR018 Oasis Security Lessons from the MCP Breach: Shadow AI & Discovery
SR019 Oasis Security McHire AI Breach: Password “123456” Exposed 64M Applicants
SR020 Oasis Security Non-Human Identity Insights from the Change Health Breach
SR021 Oasis Security Non-Human Identities: Insights from the Cloudflare Breach
SR022 Oasis Security Cisco Breach: NHI Compromise Exposes DevOps Security Risks
SR023 Oasis Security AI Access Partnership Program | Enterprise-Ready AI Security | Oasis Security
SR024 Oasis Security Zero Trust for Non-Human & Agentic Identities | Oasis + Zscaler
SR025 Oasis Security Oasis + Wiz: From Cloud Exposure to Identity-Governed Action
SR026 PR Newswire Oasis Security Launches Channel Program to Accelerate Growth and Make Non-Human Identity Management Mainstream
SR027 GuidePoint Security GuidePoint Security OASIS+
SR028 Newswire Oasis Security Raises $120M Series B to Secure the Rise of Enterprise AI Agents
SR029 Globes Cyera in advanced talks to buy Oasis Security for $1b
SR030 Finro Cybersecurity valuation benchmarks are routinely misread
SR031 Oasis Security AI-Native Engineering Teams: Speed, Culture, and Security Lessons
SR032 Oasis Security Non Human Identity Management Platform | OASIS Security
SV001 Newswire Oasis Security Raises $120M Series B to Secure the Rise of Enterprise AI Agents
SV002 Globes Israeli co Oasis Security raises $120m
SV003 Globes Cyera in advanced talks to buy Oasis Security for $1b
SV004 Oasis Security Non Human Identity Management Platform | OASIS Security
SV005 Oasis Security Non-Human Identity Management Platform
SV006 PR Newswire Oasis Security Launches Agentic Access Management, the First Identity Solution Built for AI Agents
SV007 PR Newswire Oasis Security and Sequoia Launch the First Practitioner-Built Governance Framework for Agentic AI Access
SV008 Oasis Security AI Access Partnership Program | Enterprise-Ready AI Security | Oasis Security
SV009 Okta Investor Relations Okta Announces Fourth Quarter And Fiscal Year 2026 Financial Results
SV010 SailPoint Investor Relations SailPoint Announces Fiscal Fourth Quarter and Full Year 2026 Results
SV011 Rubrik Rubrik Reports Fourth Quarter and Fiscal Year 2026 Financial Results
SV012 CyberArk CyberArk Announces Record Fourth Quarter and Full Year 2025 Results
SV013 SEC Annual Report for Fiscal Year Ending January 31, 2026 (Form 10-K)
SV014 SEC EDGAR Filing Documents for 0002030781-26-000003
SV015 SEC XBRL Viewer
SV016 Windsor Drake Identity & Access Management Valuations: Q2 2026
SV017 Windsor Drake Identity & Access Management Valuations: Q2 2026
SV018 Finro Cybersecurity Multiples Q2 2026 | 265 companies, 9 niches | Finro
SV019 Finro Cybersecurity valuation benchmarks are routinely misread
SV020 Multiples.vc Multiples Cybersecurity Index
SV021 Astrix Security A New Chapter: Astrix Security is Joining Cisco
SV022 GitGuardian GitGuardian Raises $50M Series C to Address Non-Human Identities Crisis and AI Agent Security Gap
SV023 CyberArk Machine Identities Outnumber Humans by More Than 80 to 1: New Report Exposes the Exponential Threats of Fragmented Identity Security
SV024 CyberArk State of Machine Identity Security Report
SV025 CyberArk Venafi is now CyberArk Machine Identity Security
SV026 SiliconANGLE Oasis Security raises $120M to secure nonhuman identities across AI and cloud environments
SV027 Access Newswire Oasis Security Raises $120 Million in Series B Funding to Revolutionize the Agentic Access Era
SV028 TechCompanyNews Oasis Security Secures $120M Series B to Accelerate Growth in AI Agent and Non-Human Identity Security
SV029 PR Newswire Oasis Security Launches Channel Program to Accelerate Growth and Make Non-Human Identity Management Mainstream
SV030 Oasis Security Video: Mars Case Study: Scaling Non-Human Identity Security | Oasis Security