Identity control plane
Every identity in your organization. One control plane.
VeraID is the identity provider and the governance layer above it. Single sign-on for your workforce, and full lifecycle control over the service accounts, API keys, CI/CD tokens, and AI agents they leave behind.
Pre-GA · onboarding a limited number of design partners
Staff Engineer, Platform · MFA enforced · federated via Okta
- aws svc-payments-prod prod
- aws svc-etl-batch
- aws ci-deploy-runner 214d
- gcp sa-analytics-reader
- gcp key-bq-export 190d
- agent support-triage-agent budgeted
- agent pr-review-bot
- ci github-actions-deploy prod
The gap
Your IdP offboards the person. It does not offboard what they built.
SSO covers the workforce login. The service accounts, API keys, and agents that person created never touch it.
The directory says the user is deactivated. Their machine identities keep authenticating across every cloud.
You pay for an IdP, a vault, and a CNAPP — and still cannot answer "what does this person have access to?"
Industry estimates put machine identities at roughly 45 for every human one. Almost none of them are governed by the directory that governs the human.
Detection and response
A compromised login becomes a contained incident in 92 seconds.
Conventional ITDR watches human accounts. VeraID joins the human signal to the machine identities that person owns — so the response reaches everything they could have touched, not just the login that tripped the alert.
- Detected
Impossible travel on the federated directory
jane.doe@acme.com authenticated from New York and Singapore within 20 minutes.
- Correlated
Ownership graph resolved — 8 machine identities
3 AWS service accounts, 2 GCP keys, 2 AI agents, 1 CI/CD token. Two credentials unrotated past 180 days.
- Contained
All 8 identities suspended, credentials rotated
Rotation synced to GitHub Actions and AWS. PagerDuty incident opened, #security notified.
- Resolved
Blast radius report generated
No lateral movement. Two production paths closed. Full action trail written to the audit log.
The platform
Authenticate. Govern. Contain.
One control plane covering the whole lifecycle — from a workforce login to the decommissioning of an AI agent nobody remembered creating.
Authenticate
A full identity provider for your workforce — or federation with the one you already run.
- OIDC and SAML 2.0 single sign-on
- SCIM 2.0 provisioning and directory sync
- Passkeys, adaptive MFA, and step-up auth
- Conditional access on IP, device, geo, and risk
- Federation with Okta, Entra ID, Google Workspace
Govern
Every non-human identity discovered, owned by a real person, and retired on schedule.
- Discovery across AWS, GCP, and Azure
- Human-to-machine ownership mapping
- Automated offboarding cascades
- Credential rotation with downstream sync
- Access reviews, attestation, and SoD checks
Contain
Detection that spans both worlds, and a response that fires before the damage spreads.
- Correlated human and machine threat signals
- Blast radius and attack path analysis
- Auto-suspend on owner compromise
- AI agent budget and prompt-injection controls
- Append-only, queryable audit trail
Standards and connections
Built on the protocols your stack already speaks.
AES-256-GCM encryption at rest and in transit · every identity action written to an append-only audit log.
SOC 2 Type II and ISO 27001 are in progress, not yet certified. Current controls documentation is available on request.
See your own identity graph.
Thirty minutes. Connect one cloud account and one directory, and we will show you every machine identity your offboarding process has been missing.
Book a design partner callNo deck · a working environment · your data stays yours