
Application SecurityAI Security
Obsidian Security Platform
Agentless SSPM and ITDR across SaaS apps, OAuth integrations, and AI agents.
Obsidian Security Platform Overview
What it does
Obsidian Security Platform is a SaaS Security Posture Management (SSPM) and identity threat detection platform covering third-party enterprise applications and the AI agents acting inside them. Its core mechanism is the Obsidian Knowledge Graph, which unifies identity, permission, and activity data reached through a single API connection per application into one model, so weak MFA, inactive accounts, shadow admins, and overly broad OAuth scopes surface as connected risk across the estate rather than as isolated per-application findings, human or non-human.
How it works
One API connection per application surfaces both managed and unmanaged apps tied to corporate identity, and a browser extension extends discovery to shadow apps and AI tools the API path misses while blocking credential submission to adversary-in-the-middle phishing sites. Configuration findings are scored for criticality against built-in or custom policies and mapped to SOC 2, ISO 27001, CIS, and NIST controls for audit evidence. Detection ships as out-of-the-box rules aligned to MITRE ATT&CK alongside machine-learning behavioural baselines, and runtime guardrails intercept policy-violating AI agent executions. Snowflake, T-Mobile, Wyndham Hotels & Resorts, Algolia, and Upwork are named customers.
Credentials and traction
SOC 2 Type II, ISO 27001, ISO 27701, and ISO/IEC 42001 certified, with an IRAP assessment to the PROTECTED classification for the Australian sovereign instance. Named a Strong Performer in The Forrester Wave: SaaS Security Posture Management, Q4 2023, and a Sample Vendor for SSPM in the 2026 Gartner Hype Cycle for Cyber-Risk Management. Received the SINET16 Innovator Award in 2023 and ranked No. 95 on the 2025 Deloitte Technology Fast 500. Sold to Fortune 1000 and Global 2000 enterprises.
Key Capabilities
mapped to solution categoriesDetects sensitive content shared publicly or externally from connected SaaS apps, such as world-readable files, anonymous share links, and over-shared folders, so exposure can be revoked before it leaks.
Maps SaaS configuration findings to CIS SaaS Benchmarks, NIST 800-53, and SOC 2 control requirements, generating evidence for auditors from automated assessment.
Automatically corrects specific SaaS misconfigurations or revokes excessive permissions without manual intervention.
Integrates with enterprise SaaS applications through native admin APIs to assess tenant configuration, identity, and third-party connections, including Microsoft 365, Google Workspace, Salesforce, Slack, GitHub, ServiceNow, and Okta. Breadth and depth of coverage vary by product.
Discovers OAuth-connected third-party applications with access to core SaaS environments, maps their granted permissions, and flags high-risk or unused authorizations for revocation.
Identifies over-privileged users, dormant accounts, and excessive license assignments within SaaS applications, producing a right-sizing recommendation per application.
Maps integration connections between SaaS applications (API keys, webhooks, shared credentials) to surface unmanaged data flows and integration attack surface.
Inspects prompts, uploads, and AI-generated responses for sensitive data across modalities, preventing exposure of regulated or proprietary information to third-party AI services.
Assesses and scores the risk of discovered AI services and embedded AI features (data handling, training-use terms, hosting, vendor posture) to drive sanction/block decisions.
Discovers and categorizes the organization's use of third-party AI, whether consumed as a service, installed locally, or embedded inside other applications, building a continuously updated inventory of AI usage including shadow AI.
Enforces AI usage controls through multiple local inspection points - browser, endpoint, and network - coordinated from a cloud-delivered control plane, so coverage does not depend on a single interception path.
Defines organizational AI usage policies and enforces them at the point of use - allowing, blocking, redirecting, or constraining specific AI services, models, and features per user, group, or data context.
Analyzes identity telemetry (authentication events, access patterns, privilege use) in real time with behavioral baselines and risk scoring; leading implementations detect identity attacks in sub-second time.
Reconstructs an identity incident end to end (authentications, token issuance, MFA events, privilege and group changes, directory and policy modifications) into an identity-centric timeline with blast-radius context, so analysts can scope a compromise and choose the right remediation quickly. Distinct from generic SIEM case management: the pivot is the identity and the IAM objects it touched.
Detects named identity attack techniques with purpose-built detection content: password spraying, credential stuffing, pass-the-hash and pass-the-ticket, Kerberoasting, DCSync and DCShadow, golden and silver tickets, and consent phishing of OAuth applications, each mapped to MITRE ATT&CK so technique coverage can be verified against known identity attack scenarios. Complements Identity Behavioral Analytics (anomaly-based) and Identity Infrastructure Attack Detection (attacks on the IAM control plane).
Detects attacks on the IAM infrastructure itself: misuse of directory and identity provider administrator credentials, changes to token-signing certificates and federation trust, tampering with conditional access, MFA, and admin role configuration, and other signs that an identity tool has been compromised, continuously monitoring root and global administrator accounts and their configuration changes.
Exchanges identity risk signals with identity providers, IGA, PAM, endpoint, and SIEM or SOAR platforms through bidirectional integrations and the Shared Signals Framework (CAEP, RISC), so a detection can revoke a session or force step-up in the identity provider within seconds and lands in the SOC as an enriched, correlated alert instead of a siloed one.
Detects credential-abuse techniques that defeat authentication controls, including MFA circumvention, session hijacking, and forged or replayed tokens.
Assesses the identities and service accounts that AI models, pipelines, and agents use, flagging over-permissioned non-human identities and access paths that violate least privilege. Reports identity risk as a posture finding, distinct from enforcing access policies at the model API at runtime.
Maps data lineage and provenance across AI training and inference pipelines, tracing how PII, PHI, and IP move into models and external services.
Automatically discovers AI models, LLM API connections, ML pipelines, and AI-enabled SaaS applications in use across the organization, including those deployed without IT authorization.
Discovers and enforces least-privilege access for non-human and AI-agent identities across systems and data.
Discovers AI model and inference endpoints and flags public exposure, weak authentication, default credentials, or excessive permissions as posture misconfigurations.
Monitors AI-agent behavior at runtime to detect anomalous or malicious actions and policy violations.
Detects sensitive or regulated data in AI training, fine-tuning, or third-party LLM flows without appropriate controls, such as unencrypted PII in inputs or PHI sent to external APIs.
Integrates identity data, activity, relationships, and configuration from directories, identity providers, IGA, PAM, cloud platforms, and SaaS applications, including applications not yet connected to any IAM tool, into one correlated inventory of every human and non-human actor with its accounts and entitlements, the single view on which posture assessment and analytics run.
Flags identity-object hygiene problems: dormant and orphaned accounts, accounts without MFA enrolled, shared or generic accounts, weak or non-expiring passwords, and risky discretionary permissions, so they are cleaned up before attackers use them. Configuration of the identity providers and access policies themselves is covered by IAM Policy and Configuration Assessment.
Discovers service accounts, OAuth apps, API keys, JWT tokens, and Kubernetes service accounts alongside human accounts, mapping the complete identity population.
Fixes identity posture findings instead of only reporting them: revokes unused or excessive entitlements, enforces MFA, disables dormant accounts, and corrects policy drift, either directly or through IGA, PAM, and identity provider connectors, with approval workflows for higher-risk changes. Distinct from ITDR response actions, which act on active attacks.
Continuously assesses the security configuration of identity providers, directories, and access policies themselves (conditional access rules, federation and token-signing settings, MFA enforcement scope, admin role assignments, password and session policies) against baselines and best practices, flagging drift, gaps, and inconsistencies in the policies that decide who or what can access resources, when, and under which conditions.
Compares granted permissions against observed usage to identify entitlements that exceed what an identity actually needs, candidates for right-sizing or revocation.
Surfaces indicators of identity compromise from posture and activity telemetry (anomalous login sequences, MFA fatigue patterns, impossible travel, sudden privilege changes) and routes them for response, so posture findings and active-attack signals sit in one risk view. This is the posture-layer signal: real-time detection, response playbooks, and recovery are the Identity Threat Detection and Response (ITDR) niche vocabulary, and EDR identity detection covers endpoint-side behavior.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on September 7, 2026
Buyers
See how Obsidian Security Platform fits your stack
Add Obsidian Security Platform to your shortlist and unlock all evaluation tools.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.