Two acquisitions closed two weeks apart in June 2026, and the non-human identity (NHI) security market has not looked the same since. Cisco absorbed Astrix Security. SailPoint swallowed Entro Security. That left Oasis Security as the last major independent pure-play vendor in a category Gartner flagged as one of the top cybersecurity trends of 2025, ahead of AI itself, according to Astrix co-founder Alon Jackson’s December 2025 interview cited on the company’s own site. The stakes are not abstract. CyberArk’s 2025 Identity Security Landscape report counted 82 machine identities for every human employee in the average enterprise, and Entro’s own H1 2025 research put that ratio at 144:1 in cloud-native shops, up from 92:1 a year earlier.
Every API key, service account, OAuth token, CI/CD credential, and now every autonomous AI agent needs an identity, a lifecycle, and an owner. Most enterprises still track almost none of it. This comparison, part of our ongoing coverage of cybersecurity threats in 2026, walks through Astrix Security (now part of Cisco), Oasis Security (independent, $195M raised), and Entro Security (now part of SailPoint) on architecture, pricing, integrations, and real breach evidence, so security and platform teams can figure out which approach fits before their next audit turns up a five-year-old service account with admin rights nobody remembers creating.
Don't miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
What Is Non-Human Identity Security, and Why It Exploded in 2026
Non-human identity security covers the credentials that let software, not people, authenticate and act: API keys, OAuth tokens, service accounts, SSH keys, certificates, and increasingly the identities assigned to autonomous AI agents. Traditional identity governance tools built for human logins were designed around people who authenticate, get reviewed once a quarter, and get deprovisioned when they leave. None of that logic holds for a Kubernetes service account that spins up a thousand times an hour or an AI agent that provisions its own sub-agents mid-task.
The category crystallized fast. A summary of Gartner’s 2025 IAM Summit, published by Zluri, reported that non-human identities now outnumber human identities 82:1 in the average enterprise, that the ratio can reach 40,000:1 in cloud-native environments, and that 99% of service accounts are over-permissioned. ManageEngine’s 2026 Identity Security Outlook found that 89% of organizations already run machine-to-human ratios of at least 25:1, and nearly half exceed 100:1, with healthcare organizations skewing highest. The OWASP NHI Top 10, published in 2025, gave security teams a shared vocabulary for the risk: secret leakage, overprivileged identities, long-lived credentials, insecure authentication, and orphaned identities with no clear owner.
Agentic AI made the sprawl worse in 2026, not better. GitGuardian’s State of Secrets Sprawl 2026 report found 28.65 million new hardcoded secrets added to public GitHub commits in 2025, a 34% year-over-year jump, and 1,275,105 exposed AI-service secrets (API keys for tools like Claude and Copilot), up 81% year over year. Commits co-authored by AI coding assistants leak secrets at roughly twice the rate of ordinary human commits, according to the same GitGuardian research. Every AI agent a company spins up needs its own credential, and most of those credentials are being created faster than anyone is tracking them.
Astrix Security, Oasis Security, and Entro Security at a Glance
All three companies started in roughly the same place: discovering and inventorying the non-human identities scattered across SaaS, cloud, and code, then adding governance and threat detection on top. Where they diverged is ownership structure, and in 2026 that divergence became the whole story.
| Category | Astrix Security | Oasis Security | Entro Security |
|---|---|---|---|
| Ownership as of Sept. 2026 | Acquired by Cisco; standalone sales ended June 30, 2026 | Independent | Acquired by SailPoint, deal closed June 29, 2026 |
| Total funding raised | $85M ($45M Series B, Aug. 2025, led by Menlo Ventures’ Anthology Fund) | $190M-$195M ($120M Series B, March 19, 2026, led by Craft Ventures) | $18M Series A (2024); acquired for a reported ~$200M |
| Core positioning | “Active Directory for non-human identities,” AI agent-centric governance | Non-Human Identity Management (NIM) platform with contextual, usage-based lifecycle governance | Secrets-and-NHI hybrid, now folded into SailPoint’s Agentic Fabric |
| Flagship 2026 feature | Agent Control Plane with real-time Agent Policies (RSA Conference, March 2026) | Agentic Access Management (AAM), launched November 2025 | Agentic Access Administration and WebGuard Chrome extension (May 2026) |
| Where it now lives | Cisco Identity Intelligence, Duo, Secure Access, Splunk | Standalone SaaS platform | SailPoint Identity Security Cloud / Agentic Fabric |
| Named enterprise customers | Workday, HubSpot, Figma, Priceline, NetApp | Mars, Chipotle, New American Funding, Osaic, Antares Capital | Elastic, Sprinklr, SafeBreach |
| Certifications | SOC 2 Type II | SOC 2 Type II, ISO 27001 | SOC 2 Type II, ISO 27001:2022 |
| Pricing model | Enterprise, AWS Marketplace SKU (historical example: $300K base + $100K per platform per year) | Enterprise, multi-year contracts, custom quote | Enterprise subscription, now bundled into SailPoint licensing |
| Self-serve tier | None | None | None |
| Best fit | Cisco-standardized security stacks | Organizations wanting an independent, AI-agent-native NHI platform | Existing SailPoint IGA customers extending into machine identity |
| Reported customer growth | Fortune 500-heavy, undisclosed count | 5x year-over-year new ARR growth, Fortune 500-concentrated | “Dozens” of named enterprise customers |
The Acquisition Wave: Why Two of Three Vendors Got Bought in June 2026
Cisco’s move on Astrix and SailPoint’s move on Entro were not coincidental timing. Both acquirers were racing to plug the same hole: their existing identity and access management platforms were built for human employees, and enterprise buyers were showing up to renewal conversations asking pointed questions about AI agent governance that neither vendor could answer natively.
SailPoint announced its intent to acquire Entro Security on June 15, 2026, and closed the deal on June 29, 2026, in a transaction reported at roughly $200 million. Entro’s NHI and credential security capabilities now ship as standalone offerings inside SailPoint’s portfolio, with what SailPoint calls native integration into its Agentic Fabric, a layer built to discover and secure autonomous AI agents and machine identities across an enterprise. Entro brought coverage for more than 1,200 types of secrets, tokens, and certificates in developer environments into that fabric.
Astrix’s path ran through Cisco. As of July 2026, Astrix’s own homepage confirmed the company is part of Cisco and that standalone sales of new licenses ended June 30, 2026. Cisco is folding Astrix’s discovery, governance, and Agent Control Plane capabilities into Identity Intelligence, Duo, Secure Access, and Splunk, betting that customers already standardized on Cisco’s network and security stack will want NHI governance bundled rather than bought separately.
Oasis Security took the opposite bet. Instead of selling, it raised a $120 million Series B on March 19, 2026, led by Craft Ventures with Sequoia Capital, Accel, and Cyberstarts participating, pushing total funding to somewhere between $190 million and $195 million depending on the source (Oasis has not disclosed a valuation). SiliconANGLE’s coverage of the round noted that Oasis CEO Danny Brickman described an AI agent with full-blown access as about as powerful as any credential can get, and that access on that scale piles pressure directly onto the CISO. The company has since positioned itself as the remaining large independent option in a field where the two other original leaders now answer to bigger corporate parents.
Funding and Valuation Comparison
| Vendor | Latest round | Amount | Date | Lead investor | Total raised |
|---|---|---|---|---|---|
| Astrix Security | Series B | $45M | August 3, 2025 | Menlo Ventures (Anthology Fund) | $85M, then acquired by Cisco (June 2026) |
| Oasis Security | Series B | $120M | March 19, 2026 | Craft Ventures | $190M-$195M, remains independent |
| Entro Security | Series A | $18M | June 18, 2024 | Dell Technologies Capital | $18M, then acquired by SailPoint for a reported ~$200M (closed June 29, 2026) |
The funding gap is the clearest signal of where investor conviction sits. Oasis’s $120 million single round exceeds Astrix’s entire pre-acquisition funding history, and it happened after both competitors had already found acquirers or were negotiating with them. That timing suggests Oasis’s backers were betting on independence as a durable strategy in a market where buyers, especially regulated ones, often prefer a best-of-breed vendor they can swap out over a feature bolted onto a bigger platform.
Market Size and Growth: How Big Is the NHI Security Opportunity
Market researchers disagree sharply on the exact size of the machine identity security category, which is itself a sign of how new and fragmented the space still is. Mordor Intelligence sized the machine identity management platform market at $3.80 billion in 2025 and $4.85 billion in 2026, projecting $14.28 billion by 2031 at a 24.11% CAGR. Globe Market Research put the broader machine identity management market at $4.1 billion in 2026, reaching $15.5 billion by 2035. SNS Insider, in a report published September 8, 2026, valued the wider machine identity security market at $9.85 billion in 2025, forecasting $26.97 billion by 2035.
| Research firm | Segment measured | 2025/2026 valuation | Forecast | CAGR |
|---|---|---|---|---|
| Mordor Intelligence (Aug. 2026) | Machine identity management platform market | $4.85B (2026) | $14.28B by 2031 | 24.11% |
| Globe Market Research (Aug. 2026) | Machine identity management market | $4.1B (2026) | $15.5B by 2035 | 15.9% |
| PMarketResearch (June 2026) | Worldwide machine identity management market | $2.88B (2026) | $8.18B by 2032 | 18.5% |
| WiseGuyReports (Aug. 2026) | Machine identity management market | $2.26B (2025) | $6.5B by 2035 | 11.1% |
| SNS Insider (Sept. 2026) | Machine identity security market (broader scope) | $9.85B (2025) | $26.97B by 2035 | 10.62% |
Whichever number a buyer trusts, the direction is unanimous: every published forecast shows double-digit compound growth through the early 2030s. That growth curve is exactly why Cisco and SailPoint moved on acquisitions instead of building in-house. Gartner’s broader identity governance and access management spending, cited in a 2026 IAM market analysis, sits inside a total information security spend of roughly $213 billion in 2025, forecast to reach about $240 billion in 2026, with identity governance among the faster-growing line items.
Architecture: How Each Platform Actually Discovers and Governs NHIs
Astrix Security / Cisco Identity Intelligence
Astrix built its platform around four pillars: discovery and governance for AI agents (mapping agent activity, flagging hygiene issues, reducing attack surface), agentic access and lifecycle management (provisioning through decommissioning), agentic threat detection and response (catching compromised credentials and out-of-scope agent actions), and centralized secrets management across vaults and cloud providers. At RSA Conference 2026 in March, the company announced an expanded Agent Control Plane with a real-time Agent Policies engine that lets security teams set allow, flag, and block rules scoped by user, department, agent platform, and resource type. The stated goal was covering every layer where AI agents operate, from managed AI platforms down to shadow deployments running on employee devices, applying Zero Trust principles and short-lived credentials at the moment an agent is created.
Oasis Security
Oasis describes itself explicitly as a Non-Human Identity Management platform, and its architectural bet is contextual intelligence: rather than extending human-centric identity governance models to machines, Oasis governs NHIs based on how they are actually used in production, tracking activity and ownership rather than static permission grants. Its November 2025 launch of Agentic Access Management (AAM) was marketed as the first identity solution purpose-built to govern AI agents across their entire lifecycle. The platform’s May 2026 blog post on why identity governance and administration (IGA) tooling falls short for machines lays out the core argument: human-centric models assume periodic access reviews and manual attestation, which does not scale to identities created and destroyed thousands of times a day.
Entro Security / SailPoint Agentic Fabric
Entro started closer to secrets scanning than pure identity governance, building deep coverage for more than 1,200 secret, token, and certificate types across code repositories, CI/CD pipelines, messaging tools, and logs. Its May 2026 feature update added Agentic Access Administration, a real-time policy engine governing what each AI agent can do and through which tools, plus a browser extension called WebGuard designed to stop sensitive data from leaving a prompt before it is ever sent. Since the SailPoint acquisition closed, that stack plugs into SailPoint’s Agentic Fabric, aiming to give customers a single governance layer spanning human employees, machine identities, and autonomous agents rather than three separate consoles.
How NHI Security Differs From PAM, Secrets Managers, and CIEM
Buyers new to the category often assume a secrets manager, a privileged access management (PAM) tool, or a cloud infrastructure entitlement management (CIEM) platform already covers this ground. Each one covers a slice, not the whole problem. HashiCorp Vault, AWS Secrets Manager, and Azure Key Vault store and rotate credentials, but they do not tell a security team which of those credentials belong to a decommissioned project, which ones an AI agent created on its own, or which ones carry standing privileged access nobody reviewed in two years. That gap is exactly why HashiCorp’s own Vault 2.x release, shipped in April 2026, leaned so heavily into workload identity federation and secret sync destinations across AWS, Azure, and GCP: even the storage layer vendors recognize that storage alone does not equal governance.
PAM platforms such as CyberArk, BeyondTrust, and Delinea focus on privileged accounts specifically, human and machine, with vaulting, session recording, and just-in-time elevation. They assume a relatively stable, known universe of privileged credentials. NHI platforms assume the opposite: an unbounded, constantly changing universe of low-privilege and high-privilege machine identities that outnumber anything a PAM deployment was sized for. CIEM tools like those built into major CNAPP suites map cloud entitlements and flag excessive permissions on cloud identities, but they typically stop at the cloud provider’s boundary and rarely extend into SaaS-to-SaaS OAuth grants, on-premises service accounts, or AI agent behavior. Astrix, Oasis, and Entro were all built to sit across those boundaries rather than inside one of them, which is precisely the pitch that got two of the three acquired by companies that already owned adjacent categories and wanted the connective tissue.
Pricing Breakdown
None of the three vendors publishes a public rate card, which is standard for enterprise security tooling sold through direct sales and channel partners. What is publicly documented paints a rough picture of scale and cost structure.
| Vendor | Pricing structure | Known reference price | Contract length | Marketplace availability |
|---|---|---|---|---|
| Astrix Security | Enterprise, scoped by identity count, integrations, deployment size | AWS Marketplace listing: $300,000 base annual commit + $100,000 per connected platform annually | Typically 12-month | AWS Marketplace (pre-acquisition SKU); new licenses now sold only via Cisco |
| Oasis Security | Enterprise, usage and identity-volume based | No public dollar figure; described as multi-year, Fortune 500-concentrated ARR | Multi-year | Direct sales |
| Entro Security | Enterprise, tied to NHI and secrets count plus environment footprint | No public dollar figure; now bundled into SailPoint Identity Security Cloud licensing | Aligned to SailPoint contract terms | SailPoint direct and partner channel |
The $300,000 base commitment historically listed for Astrix on AWS Marketplace gives a useful anchor point: NHI security is not a tool a mid-market team buys off a self-serve checkout page. It is a platform purchase that competes for budget against SIEM, CNAPP, and PAM renewals, and buyers should expect a multi-week sales cycle with a proof-of-value period before signing, regardless of which of the three vendors they engage.
Real-World Breaches That Prove the Category Matters
Skeptics of any young security category ask the same question: is this solving a real problem or manufacturing one? 2026 supplied blunt evidence for NHI security specifically.
The CISA GitHub leak. On May 14, 2026, GitGuardian discovered a public GitHub repository containing 844 MB of sensitive data tied to the US Cybersecurity and Infrastructure Security Agency, including administrative credentials for three AWS GovCloud accounts, a file literally named “importantAWStokens.txt,” plaintext usernames and passwords for internal systems, SSH keys, Kubernetes configs, GitHub Actions workflows, and Entra ID SAML certificates. Senator Maggie Hassan publicly pressed CISA for answers, and KrebsOnSecurity’s July 2026 postmortem noted the agency took more than 48 hours to invalidate the AWS keys after being notified, despite the exposure of what amounted to a full non-human identity inventory for a federal cybersecurity agency.
The GitHub internal breach. On May 20, 2026, GitHub disclosed that employee devices were compromised through a malicious VS Code extension, leading to exfiltration of data from internal repositories. GitHub’s incident response prioritized rotating high-impact secrets between May 18 and May 19, 2026, covering GitHub tokens, npm tokens, AWS credentials, HashiCorp Vault secrets, Kubernetes configs, 1Password vaults, private keys, connection strings, Docker credentials, and GCP service accounts, a list that reads like a checklist of exactly what NHI platforms are built to inventory and rotate automatically.
The Braintrust AWS breach. On May 6, 2026, AI evaluation platform Braintrust disclosed that an attacker gained unauthorized access to one of its AWS accounts, exposing API keys that customers had stored to reach cloud-based AI models. The incident illustrated how a single compromised non-human identity inside a vendor’s environment can cascade into credential exposure for every downstream customer relying on it.
Sprawl at scale. SpyCloud’s March 19, 2026 Identity Exposure Report recaptured 18.1 million exposed API keys and tokens in 2025 across payment platforms, cloud infrastructure, developer ecosystems, collaboration tools, and AI services. A separate August 22, 2026 investigation identified 768 active, publicly exposed AWS access keys capable of granting complete administrative control over corporate cloud accounts. GitGuardian’s retesting of previously flagged credentials found 64% were still valid as of January 2026, some of them first exposed back in 2022.
5 Real-World Use Cases for NHI Security Platforms
1. AI agent lifecycle governance. An enterprise rolling out internal AI coding assistants and customer-facing chatbots needs to know which agents exist, what data and systems each one can reach, and who owns the decision to decommission an agent once a project ends. Oasis’s Agentic Access Management and Astrix’s Agent Control Plane were both built specifically for this scenario, letting security teams set allow/flag/block policies per agent rather than discovering rogue agents after the fact.
2. CI/CD secrets exposure. A DevOps team running hundreds of GitHub Actions workflows and Jenkins pipelines accumulates API tokens and deployment keys faster than any manual process can track. Entro’s roots in secrets scanning across 1,200-plus credential types, now inside SailPoint’s Agentic Fabric, targets exactly this workflow, flagging tokens embedded in code or configuration before they ship to a public repository.
3. Third-party SaaS integration sprawl. Every Slack app, Salesforce connector, and Zapier automation an employee approves creates an OAuth grant that persists long after anyone remembers installing it. Astrix’s original product built its reputation on discovering exactly these SaaS-to-SaaS integrations, a use case that predates the current AI agent framing but remains a core driver of orphaned-identity risk.
4. Regulated-industry compliance mapping. Financial services and healthcare organizations facing SOC 2, ISO 27001, PCI-DSS, and GDPR audits increasingly find auditors asking pointed questions about service account ownership and machine identity review cadence. All three platforms map their controls to these frameworks, and Oasis in particular markets finance-sector workflows built around PCI DSS 4.0 requirements for automated credential rotation.
5. Post-incident credential rotation at scale. When a breach like the GitHub VS Code extension compromise hits, the difference between a contained incident and a cascading one often comes down to how fast an organization can identify every secret an attacker could have touched and rotate it. GitHub’s own response rotating secrets across nine categories within roughly 24 hours illustrates the target speed; organizations without an NHI inventory routinely take weeks to complete the same task manually.
Migration Guide: Moving From Manual Secrets Management to an NHI Platform
Teams coming from spreadsheets, static secrets managers, or nothing at all typically follow a similar rollout sequence regardless of which vendor they choose.
- Step 1: Connect read-only discovery first. All three platforms start with an agentless or read-only scan across cloud accounts (AWS, Azure, GCP), SaaS admin consoles, code repositories, and CI/CD systems to build an initial inventory before any policy enforcement begins.
- Step 2: Reconcile the inventory against known owners. Expect the first scan to surface far more identities than expected, often 25 to 150 times the human headcount based on ManageEngine’s 2026 findings. Assign an owner to every credential; anything unclaimed after 30 days becomes a candidate for review or revocation.
- Step 3: Classify by risk, not by type. Prioritize identities with standing privileged access, identities with no rotation in over 90 days, and identities tied to internet-facing services before worrying about low-risk internal automation accounts.
- Step 4: Enable short-lived credentials where possible. Migrate from static, long-lived API keys to workload identity federation or short-lived tokens for any identity the platform supports, reducing the blast radius of a future leak.
- Step 5: Layer in agent-specific policy. For organizations deploying AI agents, apply the platform’s agent policy engine (Astrix’s Agent Policies, Oasis’s AAM, or Entro’s Agentic Access Administration) before agents reach production, not after.
- Step 6: Integrate with existing SIEM/SOAR. Route NHI anomaly alerts into whatever detection stack the security operations center already monitors, rather than standing up a separate alert queue no one checks.
- Step 7: Set a recurring audit cadence. Machine identity reviews cannot follow the same quarterly cycle as human access reviews given the volume; most deployments settle on continuous automated review with human sign-off only on high-risk exceptions.
Pros and Cons of Each Platform
Astrix Security (Cisco)
Pros: Deep original focus on SaaS-to-SaaS integration discovery, strong AI agent policy engine launched at RSA 2026, immediate value for organizations already standardized on Cisco Duo, Secure Access, and Splunk, named Fortune 500 customers including Workday and Figma.
Cons: No longer sold as a standalone product; new buyers must engage through Cisco, which can slow procurement for organizations not already in Cisco’s ecosystem; product roadmap now depends on Cisco’s broader security portfolio priorities rather than an independent NHI-focused vision.
Oasis Security
Pros: Remains independent with a well-capitalized balance sheet ($190M-plus raised), purpose-built agentic access management, contextual usage-based governance model that avoids simply copying human IGA workflows, SOC 2 and ISO 27001 certified, strong Fortune 500 traction with 5x year-over-year ARR growth reported.
Cons: As a smaller independent vendor, integration breadth with legacy IGA and PAM tools may lag larger acquired competitors now backed by Cisco and SailPoint’s existing partner ecosystems; no public pricing makes budget planning harder for smaller buyers; being the last major independent also makes it a likely acquisition target itself.
Entro Security (SailPoint)
Pros: Deepest secrets-type coverage among the three (1,200-plus types), now integrated into SailPoint’s Agentic Fabric for unified human-plus-machine governance, strong fit for existing SailPoint Identity Security Cloud customers wanting to extend into machine identities without adding a new vendor relationship, SOC 2 Type II and ISO 27001:2022 certified.
Cons: Like Astrix, no longer available as an independent purchase; customers without an existing SailPoint relationship take on a bigger platform commitment than a point solution; product direction now answers to SailPoint’s IGA roadmap rather than a pure-play NHI focus.
Other Players Worth Watching in the NHI Space
The category extends well beyond the three vendors profiled here. GitGuardian’s NHI offering leans heavily on secrets-sprawl detection across public and private code, and its 2026 research (28.65 million new hardcoded secrets, 1.27 million exposed AI-service keys) has become a widely cited benchmark for the scale of the problem, even though GitGuardian positions itself more as a detection layer than a full lifecycle governance platform. Silverfort focuses on unified identity protection spanning both human and machine identities inside Zero Trust architectures. Defakto Security, formerly known as SPIRL, was named a 2025 Gartner Cool Vendor in Identity-First Security specifically for its NHI work. Token Security and Clutch Security round out a growing list of specialized entrants competing for budget in a category that, by every market forecast cited above, is still years away from consolidating around a handful of winners.
Buyers evaluating this wider field should also expect overlap with adjacent categories covered elsewhere on this site, including data security posture management vendors like Varonis, Cyera, and BigID, and shadow AI data-protection tools like Harmonic, Reco, and Nightfall. None of those platforms brand themselves primarily as NHI security, but each touches part of the same underlying problem: knowing what data an automated identity, human or otherwise, can actually reach.
Compliance and Certification Comparison
| Vendor | SOC 2 | ISO 27001 | Framework mapping |
|---|---|---|---|
| Astrix Security | Type II | Not independently confirmed post-acquisition | Now inherits Cisco’s broader compliance posture |
| Oasis Security | Type II | Certified | GDPR, PCI DSS 4.0 workflows for finance customers |
| Entro Security | Type II | 27001:2022 certified | SOC 2, ISO/IEC 27001, PCI-DSS, GDPR, AWS Well-Architected mapping |
Which Platform Fits Which Organization
For organizations already running Cisco Duo, Secure Access, or Splunk as their core security stack, buying into the Astrix capabilities now embedded in Cisco Identity Intelligence removes a vendor relationship rather than adding one. For SailPoint Identity Security Cloud customers looking to extend human-centric IGA into machine identities and AI agents without a second procurement cycle, Entro’s now-integrated stack is the path of least resistance. For everyone else, particularly organizations that want to avoid platform lock-in or that prioritize a vendor whose entire roadmap is dedicated to non-human identity rather than folded into a bigger security suite, Oasis Security is currently the only major independent option left standing, backed by a $120 million war chest and a customer base skewing Fortune 500.
Smaller organizations without an existing Cisco or SailPoint relationship and without the budget for a six-figure annual commitment may find all three platforms out of reach in the near term. For those teams, open-source and lower-cost building blocks, such as HashiCorp Vault’s secret sync and workload identity federation features or a combination of Gitleaks scanning with cloud-native secrets managers, can cover the highest-risk 80% of the problem while budget catches up to the category’s growth.
Company size is not the only variable worth weighing. Industry matters too. ManageEngine’s 2026 Identity Security Outlook found healthcare organizations report the highest machine-to-human ratios of any sector surveyed, a finding that tracks with how many connected devices, lab systems, and automated billing integrations a typical hospital network runs. Financial services firms, by contrast, tend to have somewhat lower raw ratios but face the heaviest compliance burden, which is why Oasis specifically built PCI DSS 4.0-aligned workflows and why Entro’s SOC 2, ISO 27001, PCI-DSS, and GDPR framework mapping matters more to a bank’s procurement team than the exact identity count. Technology companies running significant CI/CD pipelines and AI agent deployments sit somewhere in between on ratio but skew highest on secrets-sprawl risk specifically, given GitGuardian’s finding that AI-assisted commits leak secrets at roughly twice the baseline rate.
Organizations should also factor in how much of their NHI problem is already agentic versus how much is legacy service-account sprawl. A company just beginning to pilot internal AI agents can get away with a narrower agent-policy tool bolted onto existing identity infrastructure. A company with a decade of accumulated API keys, forgotten Zapier integrations, and orphaned CI/CD tokens needs the broader discovery-first approach all three vendors built their original products around, before agent governance becomes the priority layered on top.
The Verdict
The numbers make the case for this category better than any vendor pitch deck could. Machine identities outnumber humans somewhere between 45:1 and 144:1 depending on whose study you trust, 99% of service accounts carry excess permissions according to Gartner’s IAM Summit findings, and a federal cybersecurity agency itself needed more than 48 hours to invalidate leaked AWS keys after a public GitHub exposure in May 2026. That is not a market vendors invented to sell software. It is a governance gap that grew faster than most security teams’ headcount.
On the vendor question specifically: Oasis Security is the strongest choice for organizations that want an independent, AI-agent-native platform and can afford enterprise pricing, backed by the largest single funding round in the category’s history. Astrix’s capabilities, now inside Cisco, make the most sense for Cisco-standardized shops that would rather consolidate vendors than add one. Entro’s stack, now part of SailPoint, is the natural extension for existing SailPoint IGA customers. None of the three offers public self-serve pricing, so every serious evaluation should budget for a multi-week proof-of-value engagement before committing. Given the market’s projected growth, anywhere from 10.6% to 24.1% CAGR depending on the research firm, and the fact that two of three category leaders already got bought within two weeks of each other, expect more consolidation before this market settles into its final shape.
Frequently Asked Questions
What is non-human identity (NHI) security?
Non-human identity security covers the discovery, lifecycle management, and threat detection of credentials used by software rather than people, including API keys, OAuth tokens, service accounts, SSH keys, certificates, and identities assigned to autonomous AI agents. It differs from traditional identity governance because machine identities are created and destroyed far faster than human accounts and rarely go through manual access reviews.
Is Astrix Security still available to buy as a standalone product?
No. Astrix’s own site confirmed that standalone sales of new licenses ended June 30, 2026, following its acquisition by Cisco. Its capabilities are now sold as part of Cisco Identity Intelligence, Duo, Secure Access, and Splunk.
Is Entro Security still an independent company?
No. SailPoint announced its intent to acquire Entro Security on June 15, 2026, and the deal closed on June 29, 2026, in a transaction reported at roughly $200 million. Entro’s non-human identity and secrets security tools now operate inside SailPoint’s Agentic Fabric and Identity Security Cloud.
Which NHI security vendor is the best fit for a company not using Cisco or SailPoint?
Oasis Security is currently the largest independent, vendor-neutral option in the NHI security category, having raised $120 million in March 2026 specifically to pursue standalone growth rather than an acquisition exit.
How many machine identities does a typical enterprise actually have?
Estimates vary by study. CyberArk’s 2025 Identity Security Landscape report found 82 machine identities for every human employee. Entro’s H1 2025 research put the ratio at 144:1 in cloud-native environments. A summary of Gartner’s 2025 IAM Summit findings cited ratios reaching 40,000:1 in the most automation-heavy cloud-native environments, with 99% of service accounts carrying excessive permissions.
How much does an NHI security platform cost?
None of the three vendors publishes list pricing. A historical AWS Marketplace listing for Astrix showed a $300,000 base annual commitment plus $100,000 per connected platform per year for a 12-month contract, which gives a rough sense of scale for enterprise deployments. Oasis and Entro both sell through custom, multi-year enterprise contracts without public rate cards.
Do NHI security platforms cover AI agent governance specifically?
Yes, and this has become the primary battleground for all three vendors in 2026. Astrix built an Agent Control Plane with real-time Agent Policies, Oasis launched Agentic Access Management (AAM) in November 2025, and Entro added Agentic Access Administration and a WebGuard browser extension in May 2026, all specifically designed to govern what autonomous AI agents can access and do.
What compliance frameworks do NHI platforms map to?
All three vendors map their controls to SOC 2 Type II and ISO 27001, with Entro and Oasis also covering PCI-DSS and GDPR requirements explicitly. Auditors increasingly ask for evidence of machine identity ownership and review cadence during SOC 2 and ISO 27001 assessments, making this mapping a practical requirement rather than a marketing checkbox.
How is NHI security different from a secrets manager like HashiCorp Vault?
A secrets manager stores, encrypts, and rotates credentials on request, but it does not independently discover every credential scattered across an organization’s SaaS apps, code repositories, and cloud accounts, and it does not assign risk scores or ownership to machine identities the way Astrix, Oasis, and Entro are built to. Many organizations run both: a secrets manager as the vault, and an NHI platform as the discovery and governance layer that watches what happens outside the vault.


