Security Stack Logo
Obsidian Security Platform logo

Application SecurityAI Security

Obsidian Security Platform

Agentless SSPM and ITDR across SaaS apps, OAuth integrations, and AI agents.

Obsidian Security Platform Overview

What it does

Obsidian Security Platform is a SaaS Security Posture Management (SSPM) and identity threat detection platform covering third-party enterprise applications and the AI agents acting inside them. Its core mechanism is the Obsidian Knowledge Graph, which unifies identity, permission, and activity data reached through a single API connection per application into one model, so weak MFA, inactive accounts, shadow admins, and overly broad OAuth scopes surface as connected risk across the estate rather than as isolated per-application findings, human or non-human.

How it works

One API connection per application surfaces both managed and unmanaged apps tied to corporate identity, and a browser extension extends discovery to shadow apps and AI tools the API path misses while blocking credential submission to adversary-in-the-middle phishing sites. Configuration findings are scored for criticality against built-in or custom policies and mapped to SOC 2, ISO 27001, CIS, and NIST controls for audit evidence. Detection ships as out-of-the-box rules aligned to MITRE ATT&CK alongside machine-learning behavioural baselines, and runtime guardrails intercept policy-violating AI agent executions. Snowflake, T-Mobile, Wyndham Hotels & Resorts, Algolia, and Upwork are named customers.

Credentials and traction

SOC 2 Type II, ISO 27001, ISO 27701, and ISO/IEC 42001 certified, with an IRAP assessment to the PROTECTED classification for the Australian sovereign instance. Named a Strong Performer in The Forrester Wave: SaaS Security Posture Management, Q4 2023, and a Sample Vendor for SSPM in the 2026 Gartner Hype Cycle for Cyber-Risk Management. Received the SINET16 Innovator Award in 2023 and ranked No. 95 on the 2025 Deloitte Technology Fast 500. Sold to Fortune 1000 and Global 2000 enterprises.

Key Capabilities

mapped to solution categories
SaaS Security Posture Management (SSPM)

Detects sensitive content shared publicly or externally from connected SaaS apps, such as world-readable files, anonymous share links, and over-shared folders, so exposure can be revoked before it leaks.

Maps SaaS configuration findings to CIS SaaS Benchmarks, NIST 800-53, and SOC 2 control requirements, generating evidence for auditors from automated assessment.

Automatically corrects specific SaaS misconfigurations or revokes excessive permissions without manual intervention.

Integrates with enterprise SaaS applications through native admin APIs to assess tenant configuration, identity, and third-party connections, including Microsoft 365, Google Workspace, Salesforce, Slack, GitHub, ServiceNow, and Okta. Breadth and depth of coverage vary by product.

Discovers OAuth-connected third-party applications with access to core SaaS environments, maps their granted permissions, and flags high-risk or unused authorizations for revocation.

Identifies over-privileged users, dormant accounts, and excessive license assignments within SaaS applications, producing a right-sizing recommendation per application.

Maps integration connections between SaaS applications (API keys, webhooks, shared credentials) to surface unmanaged data flows and integration attack surface.

AI Usage Control

Inspects prompts, uploads, and AI-generated responses for sensitive data across modalities, preventing exposure of regulated or proprietary information to third-party AI services.

Assesses and scores the risk of discovered AI services and embedded AI features (data handling, training-use terms, hosting, vendor posture) to drive sanction/block decisions.

Discovers and categorizes the organization's use of third-party AI, whether consumed as a service, installed locally, or embedded inside other applications, building a continuously updated inventory of AI usage including shadow AI.

Enforces AI usage controls through multiple local inspection points - browser, endpoint, and network - coordinated from a cloud-delivered control plane, so coverage does not depend on a single interception path.

Defines organizational AI usage policies and enforces them at the point of use - allowing, blocking, redirecting, or constraining specific AI services, models, and features per user, group, or data context.

Identity Threat Detection and Response (ITDR)

Analyzes identity telemetry (authentication events, access patterns, privilege use) in real time with behavioral baselines and risk scoring; leading implementations detect identity attacks in sub-second time.

Reconstructs an identity incident end to end (authentications, token issuance, MFA events, privilege and group changes, directory and policy modifications) into an identity-centric timeline with blast-radius context, so analysts can scope a compromise and choose the right remediation quickly. Distinct from generic SIEM case management: the pivot is the identity and the IAM objects it touched.

Detects named identity attack techniques with purpose-built detection content: password spraying, credential stuffing, pass-the-hash and pass-the-ticket, Kerberoasting, DCSync and DCShadow, golden and silver tickets, and consent phishing of OAuth applications, each mapped to MITRE ATT&CK so technique coverage can be verified against known identity attack scenarios. Complements Identity Behavioral Analytics (anomaly-based) and Identity Infrastructure Attack Detection (attacks on the IAM control plane).

Detects attacks on the IAM infrastructure itself: misuse of directory and identity provider administrator credentials, changes to token-signing certificates and federation trust, tampering with conditional access, MFA, and admin role configuration, and other signs that an identity tool has been compromised, continuously monitoring root and global administrator accounts and their configuration changes.

Exchanges identity risk signals with identity providers, IGA, PAM, endpoint, and SIEM or SOAR platforms through bidirectional integrations and the Shared Signals Framework (CAEP, RISC), so a detection can revoke a session or force step-up in the identity provider within seconds and lands in the SOC as an enriched, correlated alert instead of a siloed one.

Detects credential-abuse techniques that defeat authentication controls, including MFA circumvention, session hijacking, and forged or replayed tokens.

AI Security Posture Management (AISPM)

Assesses the identities and service accounts that AI models, pipelines, and agents use, flagging over-permissioned non-human identities and access paths that violate least privilege. Reports identity risk as a posture finding, distinct from enforcing access policies at the model API at runtime.

Maps data lineage and provenance across AI training and inference pipelines, tracing how PII, PHI, and IP move into models and external services.

Automatically discovers AI models, LLM API connections, ML pipelines, and AI-enabled SaaS applications in use across the organization, including those deployed without IT authorization.

Discovers and enforces least-privilege access for non-human and AI-agent identities across systems and data.

Discovers AI model and inference endpoints and flags public exposure, weak authentication, default credentials, or excessive permissions as posture misconfigurations.

Monitors AI-agent behavior at runtime to detect anomalous or malicious actions and policy violations.

Detects sensitive or regulated data in AI training, fine-tuning, or third-party LLM flows without appropriate controls, such as unencrypted PII in inputs or PHI sent to external APIs.

Identity Security Posture Management (ISPM)

Integrates identity data, activity, relationships, and configuration from directories, identity providers, IGA, PAM, cloud platforms, and SaaS applications, including applications not yet connected to any IAM tool, into one correlated inventory of every human and non-human actor with its accounts and entitlements, the single view on which posture assessment and analytics run.

Flags identity-object hygiene problems: dormant and orphaned accounts, accounts without MFA enrolled, shared or generic accounts, weak or non-expiring passwords, and risky discretionary permissions, so they are cleaned up before attackers use them. Configuration of the identity providers and access policies themselves is covered by IAM Policy and Configuration Assessment.

Discovers service accounts, OAuth apps, API keys, JWT tokens, and Kubernetes service accounts alongside human accounts, mapping the complete identity population.

Fixes identity posture findings instead of only reporting them: revokes unused or excessive entitlements, enforces MFA, disables dormant accounts, and corrects policy drift, either directly or through IGA, PAM, and identity provider connectors, with approval workflows for higher-risk changes. Distinct from ITDR response actions, which act on active attacks.

Continuously assesses the security configuration of identity providers, directories, and access policies themselves (conditional access rules, federation and token-signing settings, MFA enforcement scope, admin role assignments, password and session policies) against baselines and best practices, flagging drift, gaps, and inconsistencies in the policies that decide who or what can access resources, when, and under which conditions.

Compares granted permissions against observed usage to identify entitlements that exceed what an identity actually needs, candidates for right-sizing or revocation.

Surfaces indicators of identity compromise from posture and activity telemetry (anomalous login sequences, MFA fatigue patterns, impossible travel, sudden privilege changes) and routes them for response, so posture findings and active-attack signals sit in one risk view. This is the posture-layer signal: real-time detection, response playbooks, and recovery are the Identity Threat Detection and Response (ITDR) niche vocabulary, and EDR identity detection covers endpoint-side behavior.

Compliance

certifications
IRAPISO 27001ISO 27701ISO/IEC 42001SOC 2 Type II

Integrations

compatible tools
Amazon BedrockAnthropic ClaudeAtlassianBoxDatabricksGitHubGoogle Vertex AIGoogle WorkspaceMicrosoft 365Microsoft CopilotMicrosoft EntraOktaOpenAISalesforceSalesforce AgentforceServiceNowSlackSnowflakeSplunkWorkday

Implementation & support

Deployment model
Agentless (API Integration)Browser ExtensionSaaS
Support channels
DocumentationEmail Support

Info last updated on September 7, 2026

Buyers

See how Obsidian Security Platform fits your stack

Add Obsidian Security Platform to your shortlist and unlock all evaluation tools.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.