Cyera's $1B Oasis deal: agent identity tools consolidate
Cyera signed a letter of intent to buy Oasis Security for about $1B, mostly cash. AI agent identity is consolidating — keep the controls in your own stack.
Cyera signed a letter of intent on July 28 to acquire Oasis Security for roughly $1 billion — about $700 million in cash with the rest in Cyera shares. Oasis governs non-human identity: the service accounts, tokens, keys, and AI agents that now outnumber your employees in every system you run. Read the sentence carefully, though. This is a letter of intent, not a closed deal, and the category you're being sold on is consolidating fast enough that whoever you pick this quarter may be somebody else's product line by Christmas.
What actually happened
Per TechCrunch, Oasis was founded in 2022, raised about $195 million from Accel, Craft Ventures, and Cyberstarts, and monitors agent behavior while granting permission for software access. Cyera itself just raised $600 million at a $12 billion valuation, runs north of $150 million ARR, is not profitable, and has now made three acquisitions this year — Ryft, Genie Security, and Oasis. Accel and Cyberstarts sat on both cap tables.
SecurityWeek called it the second-largest cybersecurity M&A deal of 2026, and quoted Cyera's rationale plainly: knowing your data isn't enough if you can't govern what touches it. That's a real observation. It's also a platform vendor explaining why it needs to own the layer above the one it already sells you.
Why AI agent identity consolidation matters for your business
The technical problem is legitimate and we've written about it twice this month — dormant permissions your agents inherit, and grants you can't revoke. Three billion-dollar-adjacent moves in one category in one year tells you the market agrees.
Here's the trap for a ten-person company. You buy the point tool that solves agent identity today. Eighteen months later it's a module inside a $12 billion data-security platform with a floor price built for the Fortune 500, your renewal quote triples, and the migration path out runs through a config format nobody documented.
So put the durable controls where a vendor change can't reach them. Scoped credentials issued per agent by your cloud provider's IAM. Secrets in a manager you control — Vault, AWS Secrets Manager, whatever — never in the agent's prompt or repo. Every agent action logged to your own sink, not just the vendor console. Then a governance product becomes something you layer on for reporting, and swapping it is a Tuesday, not a quarter.
Key takeaways
- Cyera signed a letter of intent — not a closed deal — to buy Oasis Security for ~$1B, roughly $700M in cash plus stock
- Oasis raised ~$195M since 2022 and governs non-human identities: service accounts, tokens, keys, AI agents
- Cyera's third acquisition of 2026, weeks after raising $600M at a $12B valuation on $150M+ ARR
- Reported as the second-largest cybersecurity M&A of 2026 — the agent-identity category is consolidating, not settling
- Operator move: keep IAM, secrets, and audit logging in infrastructure you own so a vendor swap is a config change
We build agent identity into your stack, not into a vendor's. Scoped IAM roles, secrets in a manager you control, action logs in your own sink — so the governance tool on top is replaceable and the controls underneath aren't. See how we scope AI agents or have us audit what yours can reach.
Sources: TechCrunch, SecurityWeek.
- #ai-agents
- #non-human-identity
- #security
- #vendor-risk
- #acquisitions
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Qualcomm's price increase hits your hardware budget
Qualcomm told customers of a double-digit price increase on chips shipped after September 1. The AI buildout is now repricing hardware that has nothing to do with AI.
Read it24,000 exposed BMCs leak hashes: close your IPMI port
A 2004 protocol flaw with no patch is handing out password hashes from 24,000 internet-exposed server BMCs. The fix is network exposure, not a firmware update.
Read it