Data security powerhouse Cyera has taken a monumental step toward defining the next generation of cloud and artificial intelligence defense, entering into a definitive letter of intent to acquire non-human identity security pioneer Oasis Security in a transaction valued at approximately $1 billion. The high-stakes deal, structured predominantly as a cash payout supplemented by Cyera equity, represents one of the most significant strategic consolidations in the cybersecurity sector this year. The acquisition directly addresses the explosive proliferation of synthetic credentials, programmatic access keys, and autonomous software agents across enterprise environments.
The acquisition brings together two rapidly growing forces in the cybersecurity ecosystem. Oasis Security, founded in 2022, established itself as a category leader in Non-Human Identity Management (NHIM)—a specialized discipline that governs the lifecycle, permissions, and security posture of API keys, service accounts, secrets, and autonomous software modules. By absorbing Oasis into its expansive security platform, Cyera aims to deliver an end-to-end architecture capable of mapping sensitive enterprise data while simultaneously governing the non-human entities authorized to interact with it.
The Non-Human Identity Crisis in the Age of Agentic AI
The transaction highlights a fundamental shift in the enterprise threat landscape. For decades, Identity and Access Management (IAM) centered almost entirely on human users—managing password policies, multi-factor authentication, and user access rights for employees and contractors. However, the rapid adoption of cloud-native infrastructure, microservices architectures, continuous integration/continuous deployment (CI/CD) pipelines, and, most critically, generative artificial intelligence has inverted this operational model.
Today, non-human identities outnumber human identities in standard enterprise environments by a ratio often exceeding ten to one. As organizations deploy autonomous AI agents to execute multi-step workflows—ranging from querying internal databases and synthesizing financial forecasts to triggering automated software updates—these digital entities require elevated credentials to interact with underlying cloud software, internal APIs, and third-party SaaS platforms.
Unlike human workers, AI agents operate at high velocity, possess persistent access, and frequently create secondary processes that generate their own credentials. Left unmonitored, these non-human identities become prime targets for malicious actors. Cybercriminals increasingly bypass traditional endpoint controls by hijacking unrotated API tokens, exploiting over-privileged service accounts, or manipulating autonomous agents into exfiltrating corporate intellectual property.
Oasis Security emerged specifically to dismantle this attack vector. The company’s technology automatically discovers all non-human identities operating across hybrid and multi-cloud environments, assesses their risk posture, identifies excessive privileges, and orchestrates automated remediation. By bringing this capability in-house, Cyera is tackling what many Chief Information Security Officers (CISOs) consider the single most complex blind spot in modern IT governance.
Convergence of Data Security Posture Management and Identity Intelligence
Historically, data security and identity management functioned in operational silos. Data Security Posture Management (DSPM) solutions—a category Cyera helped popularize—focused on discovering where sensitive data resides across public clouds, SaaS environments, and on-premises data lakes, classifying that information, and identifying security misconfigurations. Conversely, identity platforms managed authorization and authentication controls without deep context regarding the actual business sensitivity of the data being accessed.
The integration of Oasis Security into Cyera’s portfolio eliminates this boundary, creating a unified Data and Identity Security Platform. Under the integrated architecture, security operations teams will no longer have to cross-reference disparate dashboards to understand whether an autonomous AI agent possesses dangerous privileges.
Instead, the combined platform will offer real-time contextual awareness:
- Data Context: Precisely identifying where regulated data (e.g., PII, financial records, proprietary source code) is stored and used.
- Identity Context: Mapping every human and non-human entity that holds permission to read, modify, or export that specific dataset.
- Behavioral Monitoring: Continuously auditing the operational telemetry of AI agents and automated scripts to detect unauthorized lateral movement, anomalous data queries, or credential misuse.
- Policy Enforcement: Enforcing least-privilege models dynamically, ensuring synthetic identities are granted access strictly for the duration of a task before credentials are systematically revoked or rotated.
This unified approach reflects a broader industry movement toward platformization, where enterprise buyers actively sunset fragmented point solutions in favor of cohesive security suites capable of reducing operational overhead and accelerating incident response times.
Cyera’s Aggressive Inorganic Growth Strategy
The purchase of Oasis Security marks the latest move in an aggressive M&A spree by Cyera, which has moved rapidly to consolidate complementary technology stacks and maintain its hyper-growth trajectory.

Valued at $12 billion following a landmark $600 million funding round, Cyera has accumulated roughly $2.3 billion in total venture capital funding since its inception five years ago. Rather than relying solely on internal research and development, the company has leveraged its capital reserves to execute strategic acquisitions.
Prior to signing the letter of intent with Oasis, Cyera expanded its technical capabilities through the acquisition of Ryft, an Index Ventures-backed startup specializing in real-time data discovery and telemetry analysis, as well as Genie Security, an early-stage security firm focused on AI-native threat analysis.
While Cyera recently crossed the threshold of $150 million in Annual Recurring Revenue (ARR), the company continues to operate at a net loss—a common profile for high-growth software vendors prioritizing rapid market capture over immediate profitability. With an ARR valuation multiple hovering around 80x, Cyera’s strategy depends on expanding its Total Addressable Market (TAM) as quickly as possible. Integrating Oasis’s non-human identity capabilities directly into Cyera’s core platform allows the company to land larger enterprise software contracts and upsell existing clients on holistic AI governance modules.
Venture Capital Dynamics and Portfolio Synergies
The acquisition also sheds light on the close-knit network of elite Silicon Valley and international venture capital firms driving the current wave of cybersecurity M&A. Oasis Security had raised approximately $195 million in venture funding prior to the agreement, securing backing from prominent investment firms including Accel, Craft Ventures, and Cyberstarts.
Notably, Cyera and Oasis share key venture backers, including Accel and Cyberstarts. In the venture ecosystem, shared capitalization tables frequently act as a catalyst for strategic M&A. Institutional investors with stakes in both target and acquirer are uniquely positioned to facilitate discussions, align strategic visions, and streamline transaction terms. For Oasis investors, a $1 billion exit represents a strong return on $195 million of invested capital, while providing Cyera with proven engineering talent and enterprise-grade technology without the friction of prolonged competitive bidding wars.
Re-engineering Zero Trust for Autonomous Enterprise Operations
As enterprise reliance on generative AI transforms from internal experimentation to core operational infrastructure, existing Zero Trust architectures are proving inadequate. Traditional Zero Trust principles rely on continuous verification: "never trust, always verify." However, when thousands of autonomous AI sub-agents execute micro-tasks every second, manual or step-up authentication checks become impossible without crippling operational performance.
The convergence of data protection and non-human identity governance lays the blueprint for what security experts term "Synthetic Zero Trust." Under this model:
- Identities are Ephemeral: Credentials for AI agents are generated on-demand, cryptographically tied to specific workloads, and terminated upon task completion.
- Access is Scoped by Data Sensitivity: Permissions are not granted globally across applications; instead, an agent’s access is dynamically restricted based on the risk classification of the specific data payload it requires.
- Automated Containment is Native: If an AI agent exhibits anomalous behavior—such as attempting to download high-volumes of restricted data or connecting to unapproved external endpoints—the security platform immediately revokes its underlying tokens, isolating the process before a breach can materialize.
By positioning itself at the intersection of data protection and synthetic identity management, Cyera is betting that the defining cybersecurity challenge of the next decade will not merely be keeping attackers out of the network, but governing the complex web of autonomous software agents operating inside it.
Looking Ahead: The Future of Enterprise AI Governance
The deal between Cyera and Oasis Security serves as a bellwether for the broader software market. As corporate boards demand rapid deployment of AI-driven automation to gain operational efficiencies, CISOs face immense pressure to implement guardrails that prevent data leaks, regulatory non-compliance, and security breaches.
Assuming the transaction completes following final regulatory approvals and customary closing conditions, Cyera will begin integrating Oasis’s platform into its primary enterprise suite immediately. The combined offering will likely force competing security platforms to pursue their own identity and data protection M&A targets, accelerating consolidation across the cybersecurity startup ecosystem.
For enterprise organizations navigating the shift toward agentic AI, the message is clear: the traditional enterprise perimeter has vanished. In its place lies a complex network of algorithms, cloud repositories, and synthetic personas. As Cyera’s billion-dollar bet demonstrates, securing that new landscape requires tools engineered specifically for a world where code, not human fingers, drives the majority of business operations.
