Cybersecurity has spent years focused on people, their passwords, devices and access rights. But inside modern companies, another class of users has exploded in number, including software bots, service accounts, API keys, tokens, certificates and AI agents that interact with systems without being human. Oasis Security is building its business around that shift.
The startup has raised $120 million in a Series B round led by Craft Ventures, with participation from existing investors Cyberstarts, Sequoia Capital and Accel. The new financing brings Oasis Security’s total funding to $195 million and gives the company fresh capital to deepen product development and expand its commercial reach.
Fortune 500 demand is shaping the company’s growth
Founded in 2022 by Danny Brickman and Amit Zimerman, Oasis Security has offices in New York and Tel Aviv. The company helps businesses manage the security risks tied to non-human identities, including AI agents, service accounts and other automated tools that need access to internal systems.
The startup says Fortune 500 customers account for most of its business, with many large enterprises moving quickly to adopt AI agents and other autonomous tools across coding, email workflows and internal operations.
The growing demand is putting more pressure on chief information security officers, who are being asked to govern a rapidly expanding web of access permissions that no longer belongs only to employees. In many organisations, the challenge is no longer simply identity management. It is about controlling machine-driven access at scale, across increasingly complex infrastructure.
This is where Oasis sees its opening. Rather than treating machine identities as a side issue, it is positioning them as a central problem of modern enterprise security, particularly as more automated software becomes embedded into day-to-day operations.
A fast-growing blind spot inside enterprise systems
Oasis is focused on what the industry calls non-human identities. As businesses adopt more connected applications and increasingly rely on autonomous software to carry out tasks, the number of these identities has surged. Oasis says they now outnumber human identities by 50 to 1, while other figures cited around the market place the ratio even higher. Either way, the imbalance is large enough to create a major new attack surface.
It matters because these accounts often operate quietly in the background, yet they can hold deep permissions across cloud infrastructure, internal tools and customer-facing systems. If they are poorly managed, forgotten or over-privileged, they can become an easy route for malicious actors to exploit.
Oasis says its platform addresses that problem by automatically discovering non-human identities across environments, giving security teams visibility into what exists, assessing risk, helping with remediation of vulnerabilities and simplifying secret-management compliance. The aim is to replace fragmented oversight with a clearer map of who, or what, has access to critical systems.
What’s next?
Enterprise systems are becoming more automated, more interconnected and harder to secure with older access models. Oasis Security is trying to solve that gap before it becomes standard breach territory. With the new funding and a customer base anchored by large corporations, it is positioning itself at the centre of one of cybersecurity’s fastest-emerging problem areas.