Identity Security Tools
Compare the best Identity tools and vendors. Expert reviews, pricing, and feature comparisons on Latio.
Astrix doesn't go to market as a SaaS security company, but their ability to protect OAuth credentials is incredibly unique and powerful security for an area that's traditionally been a blind spot for many teams. They've expanded to general NHI protection.
Aembit provides the most secure way I've seen of delivering machine to machines credentials to your workloads. They uniquely validate asset identity via contextual properties and integrations, and then inject the approved credentials into the workload.
GitGuardian is the best paid provider for this tool and is a great solution for deploying secret detection at scale. On the one hand, secret scanning is a very narrow function, but on the other, a leak is extremely costly. While Arnica does the workflow, GitGuardian has more robust detection.
Entro watches for API key generation and usage across tools, alerting you to both unused permissions, as well as potential malicious activity. An example use case is detecting when a secret is shared on Slack.
Token connects into your cloud and SaaS identities, with some support for workloads like Postgres and K8s, and looks for identity issues like over-permissioned accounts or a lack of rotation or MFA.
Entitle.io is focused on the specific use case of granting break glass permissions in AWS, and rolling back changes when they're not needed. They also support more general permission scanning.