Identity Security Tools
Compare the best Identity tools and vendors. Expert reviews, pricing, and feature comparisons on Latio.
Wiz is the leader in having an all-in-one cloud security platform by expanding into CTEM, ASPM, and Runtime capabilities all within a single dashboard. Their posture and vulnerability capabilities remain the strongest, while there are better standalone code and runtime vendors out there.
Sysdig created the first runtime cloud protection tool with the open source project Falco, and has since built a trusted, enterprise ready, runtime oriented CNAPP platform. The tool is strongest at runtime protection, but offers the standard suite of CNAPP features, and is especially a good choice for regulated industries.
The core of Sweet Security is powerful incident detection and response capabilities for cloud environments. They have since created a larger CNAPP platform expanding more into vulnerability management, posture, and identity capabilities
Lumos is fascinating for the breadth of use cases they cover - general SaaS contract management, user audit logs, and request flows for Okta apps - all from a single platform. From what I've seen, Lumos seems like a dream come true for most corporate IT teams, where managing Okta has turned into a team sized job.
Formal is a complete PAM solution based on deploying flexible binaries that allow complete control of data access. They offer unique data aliasing to make them especially strong at controlling sensitive data access.
Astrix doesn't go to market as a SaaS security company, but their ability to protect OAuth credentials is incredibly unique and powerful security for an area that's traditionally been a blind spot for many teams. They've expanded to general NHI protection.
Teleport works by giving end users certificates that allow them to enforce access policies across numerous cloud resources that are typically difficult to manage. The user experience is better than any alternatives I've seen.
P0 has built a fully featured identity solution for developer access. They support posture scanning for misconfiguration, but go beyond by also providing ways for developers to connect to those workloads in the first place.
Veza has created a unique graph querying tool associating users to the data they have access to - this extends beyond basic Okta user assignments to include things like sensitive S3 buckets or databases. Alerting can also be configured based on the searches. They also include onboarding/offboarding automations.
Tenable offers a robust ecosystem of vulnerability scanning solutions, most recently consolidated with their Tenable One Exposure Management platform. Tenable offers scanning from cloud to DAST to network scanning, and is widely deployed across enterprises in order to consolidate different scanners. Their exposure management platform has done a great job bringing together their various data points, creating a more unified experience that the platform had been missing.
Andromeda has built a promising solution for making least privileged identity enforcement a reality. They do some discovery, sensitive permission scanning, blast radius building, looking for unused permissions, and JIT access. What makes them unique is AI approval workflows for JIT, and a rich checking for unused permissions.
Turbot's Guardrails allow enforcement of cloud security controls, while Pipes enables querying across your cloud data.
Doppler provides tools for sharing, managing, and securing application secrets across local, dev, staging, and production environments.
Aembit provides the most secure way I've seen of delivering machine to machines credentials to your workloads. They uniquely validate asset identity via contextual properties and integrations, and then inject the approved credentials into the workload.
GitGuardian is the best paid provider for this tool and is a great solution for deploying secret detection at scale. On the one hand, secret scanning is a very narrow function, but on the other, a leak is extremely costly. While Arnica does the workflow, GitGuardian has more robust detection.
Cloudfence has focused on creating a more actionable CSPM for specifically managing network and identity security in the cloud. Their network visibility allows them to do some cool things like limiting security groups based on observed traffic.
Oasis security discovers identities across cloud, on prem, and SaaS, graphs them, and points out potential violations and security issues. It shows what the roles, or NHIs if you want to get marketing with it, are accessing, their likely owner, and what it should be accessing
Acquired by Cloudflare. Kivera is not strictly speaking a CSPM, but provides granular controls over what cloud API calls are permissible within your environment. This allows instant enforcement of custom rules and policies, giving the same outcomes as CSPMs without the alert explosion. The downside of using them as a sole CSPM would be missing out on more holistic CNAPP features and visibility, but they run well alongside other providers.
Entro watches for API key generation and usage across tools, alerting you to both unused permissions, as well as potential malicious activity. An example use case is detecting when a secret is shared on Slack.
Vorlon monitors connections between cloud and application environments for anomolous and malicious activity, enabling both posture and threat detection response outcomes. They've expanded into additional posture and AI capabilities.
ClearVector has built identity focused runtime defense across workloads and clouds.
Apono enables you define access policies to cloud and workload resources, creating JIT workflows for accessing different environments. One standout feature is kubernetes RBAC visualization, combined with JIT access roles.
Raito gets the details of database access right - they've managed to standardize controlling access to databases across different architectures and providers. Data owners can be assigned and manage who has access to what data, and risk assessments can be done for access. They have an amazing foundation for the future of managing DB access.
Abbey allows you to define grant kits in code, which are custom pre-defined terraform for different access scenarios. Developers can then request access via Abbey, and open a PR subject to defined approval workflows.
CloudSploit is a great tool to run a quick scan to check your permissions at a high level.
Push Security created a browser plugin that monitors SaaS applications being used by employees, and can alert on risky identity controls such as re-using weak passwords or lack of MFA. They've since focused on broader browser security and phishing prevention.
BalkanID is a platform for SaaS access management. They have the standard features of detecting overpermissioned users and creating workflows for adding and removing users automatically, but they have a surprisingly robust playbook functionality for creating custom workflows.
ConductorOne provides a management platform for okta user assignments and PAM.
Cortex Cloud is an evolution of Prisma into being a part of Palo's broader security operations stack. The runtime offering integrates Twistlock alerts into the larger platform, but the posture capabilities seem weak still.
Lumeus offers a powerful combination of developer access with session monitoring, SaaS access control, AI based JIT privilege escalation, and runtime detection capabilities.
Clutch has a very strong NHI product with robust discovery and mapping of access from users to API tokens and roles. They also offer IP whitelisting to help and put some guardrails around the use of the tokens.
Permiso is creating incident response for identities. They bridge the gap between "SaaS Security" and "IAM security" by tracking identities across IaaS and SaaS, while baselining and firing alerts for suspected misbehavior, along with session tracking.
Token connects into your cloud and SaaS identities, with some support for workloads like Postgres and K8s, and looks for identity issues like over-permissioned accounts or a lack of rotation or MFA.
Sonrai has built a simple deployment for securing numerous cloud identities with as little complexity as possible by focusing on deploying permissions boundaries through SCPs and removing unused resources.
At their core, Garantir offers a solution for public and private key storage, but that description sells them short of numerous use cases they support with elegance. They can be used as a PAM, for SSH management, to accomplish HSM with ease, and can run just about anywhere a private key is needed with their agent on user endpoints.
Axiom provides standard scanning and remediation for least privileged access, but also grant least privileged roles on demand for just in time access. Their approach is to reduce permissions while providing temporary roles when major changes are needed.
Entitle.io is focused on the specific use case of granting break glass permissions in AWS, and rolling back changes when they're not needed. They also support more general permission scanning.
AWS Access Analyzer looks at your users and policies and suggests changes. It is a great built in tool, but doesn't offer easy organization level management.
Breez provides identity based threat detections, primarily for cloud resources.
ScoutSuite is another useful tool to run a quick scan of your cloud environment to check for any issues.
Grip Security provides SaaS posture management and identity management
Acquired by Ping Identity. Procyon provides JIT access for cloud workloads
InstaSecure uniquely flips the paradigm of identity management by helping you set robust IAM boundaries and SCPs instead of focusing on the endless tweaking of individual users and roles. The approach is a great way to get high impact low effort results.
Basic built in analysis for GCP policies and users. Also provides role recommendations. At a high level, GCP is the easiest of cloud providers to manage permissions in.
Blueflag offers identity centric ASPM. They allow users to create policies for detection and enforcement of privileges, as well as JIT for repo access.
Komo provides user access request flows for Okta and AWS SSO, allowing users to easily request and be assigned permissions. They uniquely allow the creation of attribute based rules, creating workflows around users as their attributes change.
WhiteSwan has built a robust access solution for workloads, files, and applications. They deploy similarly to a VPN and can be used for session tracking, file access, and give a lot of visibility and access control. Primarily for non-containerized environments.
StackIdentity provides a platform that excels in diving deep into your IAM environment and assessing over permissive and high risk resources. They provide a data lake that allows you to really see and maintain proper access controls across tools.
Axiad has their roots in certificates and MFA, but have launched a new product in the posture management space, giving security teams tools for dicovering identity relationships and securing them.
Opal provides a management platform for okta user assignments. I haven't met with them.