Cyera has signed a letter of intent to acquire Oasis Security, combining data security with non-human identity and access management to build a unified platform for securing AI agents across enterprise environments. The proposed transaction is moving through the completion process.
Cyera provides technology that helps organizations discover, classify and protect sensitive data across cloud and enterprise systems. Oasis Security focuses on managing non-human identities, including service accounts, software workloads, applications, credentials and autonomous AI agents. The combination is based on the view that enterprises cannot secure agentic AI by managing data and identity separately.
An AI agent’s risk depends on both the information it can access and the authority it has to perform actions. A system may understand that a dataset is highly sensitive but still fail to recognize that an agent has excessive permissions.
Conversely, an identity platform may understand an agent’s credentials without knowing the sensitivity or business importance of the information those credentials can reach.
Cyera and Oasis plan to connect these capabilities so organizations can continuously determine which human users, machines, and AI agents are acting, what information they can access, what actions they are authorized to perform, and what business consequences could result from an incorrect decision.
Cyera CEO and co-founder Yotam Segev said autonomous agents are rapidly joining enterprise workforces and that conventional access controls were primarily designed for human users rather than for software acting independently.
The company said non-human identities within Fortune 500 organizations increased by nearly 500% over the previous six months, making them the fastest-growing category of enterprise identity. The figure was presented by Cyera and was not independently detailed in the announcement.
Non-human identities allow applications, cloud services, automated workflows and machines to communicate with other systems. Examples include API keys, service accounts, digital certificates, tokens and software identities.
These credentials are essential to modern technology environments, but they can become security risks when organizations lose track of who owns them, why they exist or which systems and data they can access.
AI agents add another layer of complexity because they may reason, make decisions, and carry out multistep tasks without a person approving every individual action.
An agent does not necessarily need to be compromised by an attacker to create damage. A legitimate agent with valid credentials could expose sensitive information, delete data or disrupt a critical process after interpreting an objective incorrectly.
Oasis was founded in 2022 by Danny Brickman and Amit Zimerman to address the growth of non-human identities. Its platform helps organizations inventory machine and agent identities, identify their owners, understand their permissions and apply policy-driven access controls.
The company has expanded its approach to include agentic access management, which is designed to control when agents receive access, which resources they can access, and how long their permissions remain active.
Traditional identity systems frequently rely on standing permissions that remain available until someone manually changes or removes them. Oasis instead emphasizes continuous, contextual access decisions that can change as an agent’s task, environment or risk level changes.
Cyera contributes information about the data on the other side of an access request. Its platform identifies where information is stored, determines how sensitive it is, and maps which users or systems can reach it.
By bringing these functions together, the combined platform would be able to evaluate an access request using information about the identity, requested permissions, underlying data, and associated business process.
For example, an enterprise could authorize an AI agent to analyze customer service records while preventing it from accessing financial information or unrelated employee data.
The system could also limit the agent’s access to the duration of a particular task and revoke the permissions after the work is completed.
This approach is intended to create a continuous trust layer rather than relying on a one-time identity verification or static access policy.
Cyera said every human, machine and agent identity represents a potential point of exposure and must be tracked, understood and controlled.
The company plans to provide one platform through which enterprises can govern what each identity can see and do.
Oasis will continue operating its platform during the transaction process. The company said customers will continue working with their current teams, and the non-human identity and agentic access roadmap will continue with additional resources from Cyera.
The acquisition would also allow Cyera to expand beyond identifying and protecting sensitive data into directly governing the identities requesting access to that information.
Oasis would gain access to Cyera’s data classification, security context and enterprise distribution capabilities.
Together, the companies plan to support agents developed internally by customers as well as agents supplied through third-party applications and AI platforms.
This flexibility is becoming more important as enterprises adopt agents from multiple vendors. Organizations need consistent identity, data and access policies regardless of which model or software provider created a particular agent.
The proposed combination reflects a broader shift in enterprise security toward managing AI systems as members of the digital workforce.
Unlike traditional applications, agents may appear quickly, receive temporary credentials and perform actions across several systems before their task ends. Static identity inventories and manually maintained access policies may not be able to govern this activity at machine speed.
Cyera and Oasis are seeking to establish an architecture in which every agent’s access is continuously evaluated against the sensitivity of the data, the business context and the organization’s security policies.
The companies believe this model will help enterprises use AI for critical workflows without surrendering control over sensitive information and operational systems.
Cyera plans to provide additional information about its agent security strategy during Black Hat USA.
KEY QUOTES:
“This is the next chapter for Cyera, and the next step toward the most complete security platform for the agentic enterprise.”
Yotam Segev, Co-Founder and CEO of Cyera
“Joining Cyera is the most ambitious way to pursue the mission we started.”
Danny Brickman, Co-Founder and CEO of Oasis Security

