For founders and GTM leaders
Know your category. Know how buyers read you.
See how crowded your category is, track what rivals do week by week, and see how an enterprise security buyer reads your positioning. Built on 3,777 cybersecurity companies and 37,000+ dated moves on file.
How buyers read you
Dashboard
Explorer
Radars
Competition
Intel Reports
NIST Profiler
Overview
Market map
Momentum
Funding
Valuations
M&A
Exit Readiness
Hiring
Products
Alert Center
MCP & API
How Oasis Security reads to a CISO buyer
Verdict
Oasis sells to the person who signs. The homepage puts Fortune 500 logos and quantified business outcomes above the fold, five industry pages speak to regulated buyers, and the published SLA and DPA give procurement something real to read. The Agentic Access Management page is the strongest asset on the site and the easiest to miss: real product screenshots, a 2:29 walkthrough, the AI platforms it brokers access to named one by one, and a chain of custody that names its own links.
Two things hold the score at 6.5. The hero still leads with a category Oasis invented, so a buyer searching for non-human identity security meets that phrase only in the browser tab and the nav dropdown. And the answer to "why not Microsoft, why not the IGA and PAM we already own" is written, but it is in the blog, while Why Oasis leads with "Superior Insights" and "best in class".
Read this as a re-score. The number has not moved since 29 August because the site has not moved. Measured on 8 September, the product and Why Oasis pages are identical to their 27 August versions, and the homepage changed by exactly one line: the banner now reads "Oasis has been acquired by Cyera", where on 27 August it read "Oasis + Cyera: Building the Next-Generation AI Security Platform". The Cyera deal is closed. Every fix the last score asked for is still open.
The homepage H1 is still "Agentic Access Management", the category Oasis trademarks as AAM. The subhead does real work: "Access control that understands intent, not just static roles and permissions." But "non-human identity" never appears in the hero a visitor reads. It sits in the browser tab title and the Product nav dropdown. The plain sentence, "Oasis secures AI agents and non-human identities across IaaS, SaaS, PaaS, and on-prem", is a full scroll down.
Claims a rival could not honestly copy do exist: Oasis Scout with AuthPrint threat-actor fingerprinting on /product, and on /agentic-access-management a chain of custody that names its own links, "Prompt, Intent, Policy, Session, Action", plus a short-lived identity per session. But Why Oasis, where a buyer goes for "why not them", still leads with "Breadth of integrations" and "Superior Insights ... best in class". No named rival on any page, and none answers Microsoft Agent 365.
Checkable and strong: readable Fortune 500 logos in the homepage hero (Citizens Financial, BlueCross BlueShield, Chipotle, Mars), a five-line Business Impact strip of quantified outcomes, seven award badges, and original vulnerability research on the Cursor autorun flaw. Two gaps hold it here. Measured 8 September: G2 shows 0 reviews, Gartner Peer Insights 1 review at 5.0. Both customer quotes are anonymous roles, and SOC 2 and ISO 27001 are footer images with no trust centre behind them.
The homepage Business Impact strip is board language: a Fortune-50 healthcare provider avoiding a $3 to 5M HIPAA fine, a Fortune-500 logistics firm cutting secret-rotation effort by 35%, an F300 CPG cutting attack surface 60% during a POV. Procurement gets a published SLA with 99.9% uptime, service credits and severity response times, plus a DPA. Five industry pages address regulated buyers. Short of the top band: framework mapping is asserted on the governance page, never shown.
Integrations are named, not implied: Okta, Ping, HashiCorp Vault, Azure Key Vault and AWS KMS on /product, and on /agentic-access-management the AI platforms themselves, Claude, OpenAI, Microsoft Copilot, Cursor, Gemini and Glean. That page carries real product screenshots of a Cursor session escalating into Databricks and a 2:29 walkthrough video, the strongest architect-facing proof on the site. Still missing: public docs, an API reference, a stated deployment model and a data-handling page.
Two registers on one site. The AAM page is the good one: "No standing privilege, no long-lived tokens, no hard-coded secrets." The product page is where it slips, and none of it moved in ten days. Inventory still promises "a consolidated single pane of glass", the opening strip still says "Leverage AI-powered insights", and Context still reads "The system goes beyond raw data by furnishing essential contextual information." The lifecycle strip still misspells "Decomission".
Measured against the full sitemap on 8 September: 264 URLs, no pricing page. No page names an edition, a tier, or a unit of pricing, and every route is Request a Demo or Chat with Us. What is public is the contract, not the packaging: the SLA states 99.9% uptime, a service-credit table and severity response times, and a DPA and subscription agreement are published. The nav does name two products, NHI Security Cloud and Agentic Access Management, and that is the only shape a buyer gets.
Fix these first
- 1Put the searched category in the H1. Lead with non-human identity and AI agent access, and keep Agentic Access Management as the sub-line. Today "non-human identity" appears only in the browser tab and the nav dropdown.
- 2Promote the Agentic Access Management page. It carries the site's best proof and its clearest copy, but it sits one nav item deep and nothing on the homepage links to it. The homepage banner points at the Cyera post instead.
- 3Move the "why not them" answer onto Why Oasis. The IGA, PAM, CSPM and Microsoft Agent 365 comparisons already exist as blog posts. Put them on the page, and replace "Superior Insights" with the Scout and AuthPrint claims.
- 4Publish packaging without publishing prices. Name the editions, state the unit (per non-human identity, per environment, or per workload) and any minimum, so a CISO can build a budget line before booking a demo.
- 5Stand the trust signals up. Link the SOC 2 and ISO 27001 footer badges to a trust centre, and ask three reference customers for Gartner Peer Insights reviews. Measured 8 September: G2 shows 0, Gartner shows 1.

Stop losing enterprise deals on your homepage.
Generic positioning loses enterprise deals. I score your homepage, sales deck and funding deck against the seven checks above, then rewrite what fails. Buyers and investors get your value in 30 seconds.
See what you getReviewed by a security leader, not by a model.
It rates a vendor's positioning on the seven dimensions a security buyer works through before they take a call. Every mark carries the evidence behind it, and a written verdict names the two things holding the number down.
- Seven dimensions, the real ones
- Value Proposition Clarity, Competitive Differentiation, Trust Signals & Social Proof, CISO Buyer Fit, Technical Credibility, Website Copy Quality, and Pricing & Packaging Clarity.
- That is a real score, not a sample
- The screen above is Oasis Security's published score, out of ten, exactly as it reads on their profile. Re-run it tomorrow and this page changes with it.
How crowded your category is
Dashboard
Explorer
Radars
Competition
Intel Reports
NIST Profiler
Overview
Market map
Momentum
Funding
Valuations
M&A
Exit Readiness
Hiring
Products
Alert Center
MCP & API
Icon size = total capital raised. Axes split on the median. Companies with no disclosed funding are left out of the average — an unknown is not a zero.
Every category, placed by how crowded and how well funded.
Each mark is a category: how many companies are in it, against how much capital each one raised. The crosshairs are the market medians, so your quadrant tells you whether you are in a crowd, in a land grab, or somewhere nobody has funded yet.
- Four quadrants, not a ranking
- Few players and big cheques reads very differently from many players and small ones. A league table hides that; a map does not.
- An unknown is not a zero
- Companies with no disclosed funding are left out of the average rather than counted as nothing. The chart says so on its face.
What your rivals just did
Dashboard
Explorer
Radars
Competition
Intel Reports
NIST Profiler
Overview
Market map
Momentum
Funding
Valuations
M&A
Exit Readiness
Hiring
Products
Alert Center
MCP & API
Sep 19, 2026
Acunetix announced the release of Acunetix Version 13, introducing the SmartScan engine, malware detection functionality, comprehensive network scanning, proof-of-exploit, incremental scanning, and an improved user interface.
TrendAI announced a strategic partnership with Anthropic to embed Claude models across its platform to power agentic workflows, automation, AI-native security operations, and threat research. The partnership spans vulnerability discovery, platform innovation, and go-to-market execution.
Kura has appointed Acumen Cyber to provide 24/7 cyber defence services across its UK and South Africa operations.
Censys announced record growth metrics for the first half of 2026, including 115% growth in Platform customers, 400% increase in customers generating $1M+ in ARR, global expansion into Japan and the Middle East, and partner ecosystem growth to 200+ partners. The company is actively hiring across the board.
Anchore published a LinkedIn post highlighting how SBOM-powered security enables historical vulnerability analysis across the entire software lifecycle, allowing organizations to determine if previously shipped software is vulnerable today without re-scanning archived artifacts.
Picus Security published threat research on LinkedIn analyzing SprySOCKS, a Windows backdoor variant used by Aquatic Panda (also tracked as Earth Lusca and FishMonger) that uses a kernel driver to hide its files, processes, and network connections. The analysis covers the group's campaigns, malware capabilities, MITRE ATT&CK techniques, and how to test controls using Aquatic Panda threats in Picus.
The US Secret Service issued an RFP for ZeroFox software licenses with a due date of September 21, 2026. The bid was posted on September 12, 2026 on GovDirections.
Ectacom's events listing page showcasing upcoming cybersecurity events and conferences where ectacom presents solutions from its partner vendors including Aikido, Cofense, Nozomi, and iVerify.
UpGuard published security rating and vendor risk assessment pages for multiple third-party vendors (Status.io, 6clicks, Cornerstone OnDemand, Everbridge, GBG), showcasing UpGuard's Trust Exchange and security assessment capabilities for vendor evaluation.
Notice.co provides a market snapshot of Claroty's valuation, funding history, and investor information. The page shows Claroty's current $3B valuation (as of January 2026 Series F round), total funding of $882M across 6 rounds, and lists major investors including Bessemer, Temasek, SoftBank, and Schneider Electric.
News every four hours. Websites every week.
Stop opening fifteen tabs every Monday. One dated feed of competitor website rewrites, product launches, executive changes, customer wins, partnerships and M&A — filtered down to the moves that are actually moves.
- Filter by what happened
- Funding, product and feature launches, executive changes, customer wins, partnerships, positioning shifts, acquisitions and IPOs each file as their own type.
- Typed, dated, sourced
- Each move carries its type, its date and a link back to the page or article it came from, where we have one.
One rival, their whole record
Dashboard
Explorer
Radars
Competition
Intel Reports
NIST Profiler
Overview
Market map
Momentum
Funding
Valuations
M&A
Exit Readiness
Hiring
Products
Alert Center
MCP & API
Sep 17, 2026
Cyera publishes a comprehensive security guide on Model Context Protocol (MCP) vulnerabilities and mitigation strategies, drawing on the company's research into real-world incidents including OpenClaw and postmark-mcp. The guide covers four key security pillars (identity/authentication, network/transport, supply chain, runtime data access) and outlines common MCP attack patterns and defenses.
Sep 16, 2026
Cyera announced a partnership with Snowflake to secure AI agents accessing Snowflake environments. The partnership demonstrates how Cyera surfaces every agent with access to Snowflake, shows what each agent can reach, and remediates access to exposed or sensitive data using dynamic masking and least-privilege enforcement. Cyera and Snowflake are hosting a joint webinar on October 20 featuring Cyera's Gal Pollak and Snowflake's Navnit Shukla.
Sep 10, 2026
Cyera publishes a case study demonstrating how it used its own platform to audit Snowflake access before deploying Claude Cowork agents to 1,500 employees. The article describes discovering hidden access through nested roles, identifying dormant accounts, and mapping privileged access to ACCOUNTADMIN, positioning Cyera's DSPM and identity capabilities as essential for agent security.
Sep 9, 2026
Cyera announces a unified integration between its Data Security Posture Management (DSPM) and Data Loss Prevention (DLP) capabilities, enabling shared data intelligence to flow between discovery and enforcement. The integration allows DSPM classifications to inform DLP policies and enables direct remediation actions like triggering backups from DLP findings.
Cyera publishes thought leadership on AI agent security risks, analyzing two real-world incidents where AI agents bypassed read-only restrictions to communicate with each other. The article frames Cyera's Agent Guardian platform as a solution for detecting and preventing intent drift across three dimensions: agent-user, agent-organization, and user-organization.
Sep 8, 2026
Cyera publishes thought leadership on 2026 cybersecurity trends, emphasizing how AI adoption, agentic systems, and data fragmentation will test enterprise resilience. The article features insights from Cyera's Office of the CSO on cybercrime acceleration, CISO strategy shifts toward precision, and the emergence of agentic AI as an inflection point enterprises are unprepared for.
Their history is a lookup, not a research project.
When a rival ships a feature or quietly changes its story, open its timeline: website rewrites, LinkedIn posts, press, hiring and funding on one spine, newest first, each row linked to its source.
- The depth is printed, not promised
- Every profile prints how many moves are on file and how many days carry one. Depth differs company by company, so we show the number rather than promise one.
- Positioning shifts are their own move
- A homepage rewrite, a new target buyer, a changed category claim — each is typed and dated like a funding round, not buried in a diff.
What changed this week
Dashboard
Explorer
Radars
Competition
Intel Reports
NIST Profiler
Overview
Market map
Momentum
Funding
Valuations
M&A
Exit Readiness
Hiring
Products
Alert Center
MCP & API
The week's market on one screen.
See which companies are accelerating, read what actually moved this week, and take numbers to a board that trace back to dated events instead of a static analyst PDF.
- Momentum, and what feeds it
- Three pillars — growth, market presence and financial strength — built from headcount growth, hiring rate, news volume, LinkedIn activity and funding.
- Every number opens
- A score on the dashboard is a door: click it and you are in the dated events it was computed from.
See your category in Mandos today.
3,777 companies tracked · 37,000+ dated moves on file