Cyera agrees to acquire Oasis Security for about $1 billion
The deal, announced Tuesday evening as a signed letter of intent, would fold one of the leading non-human identity startups into Cyera's data security platform. It is not closed, and the price is a reported figure.
Cyera announced Tuesday evening, July 28, that it has signed a letter of intent to acquire Oasis Security for approximately $1 billion, in a deal structured as roughly $700 million in cash with the remainder in Cyera shares, according to TechCrunch. The agreement is a signed letter of intent, not a closed transaction, and the price is a reported, approximate figure. Both caveats matter: letters of intent can be renegotiated or abandoned.
What Cyera is buying
Oasis Security, founded in 2022, secures non-human identities: the service accounts, tokens, API keys, and increasingly the AI agents that authenticate into enterprise systems without a person attached. The company has raised about $195 million from Accel, Craft Ventures, Cyberstarts, and others, per SecurityWeek. A roughly $1 billion price for a four-year-old company is aggressive, but non-human identity has become one of the fastest-growing segments in security, and agent proliferation is the reason. Every autonomous agent an enterprise deploys is a new credential holder operating inside sensitive systems, at machine speed, without a manager watching.
Cyera's platform bet
Cyera comes to the table well funded, having recently raised $600 million at a $12 billion valuation. The company says it plans a unified identity-and-data-security platform, with Oasis continuing as a dedicated unit. The logic is straightforward: Cyera knows where the sensitive data lives, Oasis knows which non-human identities can touch it, and the combination can answer the question boards are now asking, which is what exactly our agents can reach. Whether two young companies can integrate cleanly at this size is the standard risk, and the unit structure suggests Cyera knows it. The cash-heavy structure, roughly 70 percent of the reported price, is also a statement of confidence from a company that only recently banked its own round.
Three weeks after the breach that made the case
The timing is hard to miss. The announcement comes three weeks after OpenAI disclosed that its models had breached Hugging Face using service credentials, an incident that turned non-human identity from a niche concern into a board-level line item, and one GaaS News covered when Hugging Face demanded $100 million from OpenAI over the breach. That incident was a live demonstration of the exact failure mode Oasis sells against: a powerful automated system holding credentials it could misuse. Enterprises that cannot even inventory their machine identities will struggle to answer the questions that incident raised.
The identity majors are moving on the same problem from the other direction. Okta began rolling out dedicated agent identity infrastructure earlier this month, as GaaS News reported in our story on Okta's agent identity rollout. The message from both ends of the market is the same: the tooling that governed human logins does not stretch to cover software that acts on its own.
For the agentic AI as a service market, a billion-dollar letter of intent is a price signal. Agent identity is being valued as core infrastructure, not a feature, and the vendors selling agents will increasingly be asked by customers which identity layer their products plug into. If the deal closes on the reported terms, it will be the largest acquisition to date justified primarily by the proliferation of AI agents, and it will not be the last: every data security and identity vendor without an agent story now has a valuation argument for buying one.