Opal Security
Opal Security is an AI-native access governance platform that builds a unified access graph across 250+ systems and uses autonomous AI agents, policy-as-code, and natural-language queries to enforce least-privilege access for enterprise security engineering, IAM, and AI-platform teams.
- Company typePrivate
- Founded2020
- HeadquartersSan Francisco, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Opal Security does
Opal Security, legally Perma Security Incorporated (DBA Opal), is a San Francisco-based identity and access governance vendor founded in 2020. The company operates an AI-native platform that builds a unified access graph across 250+ systems — spanning identity providers (Okta, Azure AD/Entra ID, Google Workspace), cloud infrastructure (AWS, GCP, Azure with granular resource-level coverage), SaaS applications, databases, ITSM, and AI platforms (Anthropic, OpenAI, Cursor, Devin AI). On top of this access graph, Opal delivers three proprietary AI capabilities: Paladin, an AI agent that autonomously evaluates access requests and revokes entitlements; OpalQuery, a natural-language interface for surfacing risk and entitlement questions; and OpalScript, a policy-as-code language that can be generated by AI from natural-language descriptions. Adjacent workflow modules include Just-In-Time Access, AI-Guided Access Reviews, and Security for AI Agents. Deployment options cover hosted SaaS on AWS, customer VM, Kubernetes, or AWS ALB, with US/EU data residency, SOC 2 Type II, GDPR, CCPA, and FedRAMP High configurations.
The platform is sold via a sales-led enterprise GTM with quote-based annual subscriptions executed through an Order Form under the Opal SaaS Agreement, supported by Forward Deployed Engineers, Solutions Engineers, and Technical Customer Success Managers. Customer segments are primarily security engineering and IAM/IGA leaders at regulated enterprises and AI-forward platform teams, with strong traction in fintech (Blend, Valon, Merge, Mercari, CoinList), cloud-native and AI infrastructure (Databricks, Cloudflare, CoreWeave, Scale AI, Figma), and cybersecurity buyers (Palo Alto Networks, Sophos, Elastic, Obsidian). Total disclosed funding is $59M across a 2021 seed ($1.8M, Greylock), a 2023 Series B ($22M, Battery Ventures led), and a June 2026 round ($23M, Greylock and Battery Ventures co-led, Cambium Capital participating). Opal is a privately held, venture-backed company with no parent entity; its most recent CEO appointment (Howard Ting, December 2025) and a June 2026 leadership expansion including CPO Sameer Mehta from Veza coincide with the AI-native product launches.
Opal Security firmographics
Firmographics- Name
- Opal Security
- Legal name
- Perma Security Incorporated
- Website
- https://opal.dev
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Opal Security is an AI-native access governance platform that builds a unified access graph across 250+ systems and uses autonomous AI agents, policy-as-code, and natural-language queries to enforce least-privilege access for enterprise security engineering, IAM, and AI-platform teams.
- Ownership category
- akta.pro rank
Opal Security industry classification
Industry- Product category
- Identity and Access Governance
- NAICS
- Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Privileged Access Management (PAM) (HDADAAAC)
- akta.pro secondary industries
- Identity Orchestration & Policy (Zero Trust Access, Conditional Access) (HDADAAAL), Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII) (HDAEANAG)
Keywords
Where Opal Security is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices4 records
Markets served
Opal Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure
Revenue model
- Opal Security SaaS Subscription: Recurring SaaS subscription paid under an Order Form governed by the Opal Security SaaS Agreement (Perma Security Incorporated dba Opal). Customers access the hosted Opal product and documentation. Initial terms renew automatically in 12-month increments unless 60 business days' notice is given. Includes optional self-hosted deployment under an Opal license. Fees paid within 30 days of invoice; 1.5% per month finance charges on overdue balances. Includes professional services-style deployment support (Forward Deployed Engineer function evidenced by hiring and customer case studies).
- Professional Services / Deployment Engineering: Forward Deployed Engineer, Solutions Engineer, and Technical Customer Success Manager roles are staffed to deliver hands-on deployment, integration, and ongoing customer success — supporting implementation-heavy enterprise rollouts alongside the core subscription.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Quote-based enterprise subscription via demo / sales engagement (no public list price) |
Go-to-market motion5 records
Opal Security product offering
Product offeringCore offering
Opal Security provides an AI-native access governance platform that models an organization's permissions as a real-time access graph across 250+ systems (cloud, identity, SaaS, databases, AI platforms). It enforces fine-grained access policies through a policy-as-code engine (OpalScript), a natural-language query interface (OpalQuery), and an autonomous AI agent (Paladin) that makes access decisions, automates access reviews, and governs human, service, and AI agent identities.
Product overview
Opal Security offers a single unified identity security and access governance platform that combines a real-time access graph, a policy-as-code engine (OpalScript), a natural-language query interface (OpalQuery), and an autonomous AI agent (Paladin) for access decisions. Built on this core platform are workflow modules including AI-Guided Access Reviews, Just-In-Time Access, Security for AI Agents, and Programmable Governance, which extend the platform into certification, time-bound provisioning, AI-agent identity governance, and code-driven automation respectively.
Differentiator
Problem solved
Functional benefit
Brands
- Paladin: AI agent that evaluates access requests, applies policy, evaluates risk, approves safe requests, and escalates to humans when needed; branded as part of the Opal product line.
- OpalScript
- OpalQuery
Companies that use Opal Security
Customer profileNamed customers17 records
Segments6 records
Ideal customer profiles3 records
Opal Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration57 records
AI capability9 records
Feature9 records
Opal Security partnerships and signals
Strategic signalScale indicators10 records
Recent moves6 records
Expansion highlights6 records
Opal Security competitors and assessment
Company assessmentDirect peers
- Veza: AI-native identity security and access governance platform that maps permissions across cloud and SaaS systems. Most direct comparable given shared AI-native positioning and overlapping customer base (Opal's CPO Sameer Mehta joined from Veza).
- ConductorOne: Cloud-native identity governance and access automation platform offering just-in-time access, access reviews, and provisioning across SaaS and infrastructure. Closely comparable in target buyer, use cases (JIT, reviews, least-privilege), and stage.
Broad incumbents
- SailPoint: Legacy IGA market leader offering identity governance, access certifications, and provisioning across enterprise environments. Represents the established incumbent Opal positions against with its AI-native, API-first approach.
- Saviynt: Cloud-native IGA platform focused on identity governance, privileged access management, and access reviews for large enterprises. Competes head-to-head with Opal in regulated, multi-cloud identity governance deals.
- Okta: Identity and access management platform whose IGA, privileged access, and governance capabilities increasingly overlap with Opal. Functions both as Opal's primary identity source (via Okta integration) and as a competitor for the same enterprise IAM budget.
- CyberArk: Privileged access management leader that has expanded into identity governance and just-in-time access. Directly competes in the privileged-access and least-privilege enforcement use cases that anchor Opal's product.
- Microsoft Entra ID (Azure AD) Governance: Microsoft's cloud identity governance and access management suite bundled into the broader Microsoft security platform. Competes on enterprise access reviews and lifecycle workflows, often displacing point-tool purchases in Microsoft-heavy estates.
- BeyondTrust: Privileged access management and identity security vendor covering password vaulting, session management, and just-in-time elevation. Overlaps with Opal's privileged access and JIT capabilities for enterprise security buyers.
Emerging players
- Pomerium: Open-core zero trust access proxy focused on identity-aware proxying and context-based access policy. Adjacent to Opal on the access enforcement layer, particularly for engineering-forward buyers who prefer code-first policy.
- StrongDM: Infrastructure access platform providing just-in-time, audited access to databases, servers, and cloud resources. Competes with Opal's JIT and break-glass capabilities for engineering and SRE personas in mid-market and enterprise.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Opal Security social profiles
Digital presenceOpal Security compliance and trust
Trust signalCompliance5 records
Opal Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Opal Security leadership team
Management profileNumber of profiles
Profiles2 records
Opal Security funding detail
Funding detailFunding overview
Funding rounds4 records
Investors5 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Opal Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Opal Security
What does Opal Security do?
Opal Security provides an AI-native access governance platform that models an organization's permissions as a real-time access graph across 250+ systems (cloud, identity, SaaS, databases, AI platforms). It enforces fine-grained access policies through a policy-as-code engine (OpalScript), a natural-language query interface (OpalQuery), and an autonomous AI agent (Paladin) that makes access decisions, automates access reviews, and governs human, service, and AI agent identities.
Is Opal Security a public or private company?
Opal Security is a private company. It is classified as venture growth investor backed and is currently operating.
When was Opal Security founded?
Opal Security was founded in 2020. It employs 11 to 50 people.
Where is Opal Security based?
Opal Security is headquartered in San Francisco, United States, in the North America region.
How does Opal Security make money?
Two revenue lines are on record. Opal Security SaaS Subscription is the primary driver. The others are professional Services / Deployment Engineering.
Who are Opal Security's main competitors?
Direct peers on record are Veza and ConductorOne. Broad incumbents are SailPoint, Saviynt, Okta, CyberArk, Microsoft Entra ID (Azure AD) Governance and BeyondTrust. Emerging players are Pomerium and StrongDM.
Does Opal Security have an API?
Yes. Opal Security offers public APIs and a hosted MCP (Model Context Protocol) server, enabling developers and partners to programmatically manage access policies, integrate governance with infrastructure resources, and automate identity-aware workflows. Developers can leverage the API and MCP server to extend Opal's access decisioning and policy enforcement into external tools. Developer documentation is at docs.opal.dev.
What industry is Opal Security in?
Opal Security's product category is Identity and Access Governance. Its primary akta.pro industry code is HDADAAAC, Privileged Access Management (PAM), with a secondary code of HDADAAAL, Identity Orchestration & Policy (Zero Trust Access, Conditional Access). Its NAICS code is 561621 and its SIC code is 7370.