Aserto
Aserto built a cloud-native, fine-grained authorization-as-a-service platform for SaaS application developers, combining its open-source Topaz authorizer (OPA + Zanzibar-inspired directory) with a hosted control plane and multi-language SDKs; the Seattle-based company ceased commercial operations on May 31, 2025.
- Company typePrivate
- Founded2020
- HeadquartersSeattle, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Aserto does
Aserto was a Seattle-headquartered, venture-backed private company that built a cloud-native authorization-as-a-service platform for SaaS application developers. Founded in 2020 by Omri Gazitt (CEO) and Gert Drapers (CTO) — veterans of developer-facing products at Microsoft, HP Cloud, Splunk, Hulu, NEON, and Puppet — the company targeted engineering teams that needed fine-grained, real-time authorization but lacked the distributed-systems expertise to build and operate one in-house. Its core offering combined the open-source Topaz authorizer (which itself wraps the CNCF Open Policy Agent decision engine and a Google Zanzibar-inspired graph directory) with a hosted control plane that synchronized policies, users, and authorization data to local edge authorizers deployed as sidecars or microservices, delivering sub-millisecond authorization decisions. The platform supported RBAC, ABAC, and ReBAC models and exposed SDKs in Node.js, Go, Python, Java, .NET, and Ruby alongside gRPC, REST, and GraphQL APIs; Aserto also co-authored the OpenID AuthZEN specification and implemented it natively.
The company monetized through a tiered SaaS subscription: a free Starter tier, an Essentials tier at $0.20 per user/month, and Pro and Enterprise tiers sold via direct sales contact with features such as VPC deployment, self-hosted IDP gateways, signed policy images, and 24x7 support. Go-to-market was a hybrid developer-led growth motion — free tier, quickstarts, multi-language SDKs, community Slack, and Topaz open-source community — supplemented by enterprise field sales for Pro/Enterprise deals. Named customers included Spreetail and Metrikus. Aserto raised a single $5.1 million seed round in June 2021 led by Costanoa Ventures with HeavyBit and TGM Ventures, achieved SOC 2 Type II certification, and was recognized as Outstanding in Innovation by KuppingerCole Analysts in 2024. The company announced it would wind down in April 2025 and ceased commercial operations on May 31, 2025, with the open-source Topaz project continuing under community maintainers.
Aserto firmographics
Firmographics- Name
- Aserto
- Legal name
- Aserto, Inc.
- Website
- https://aserto.com
- Company type
- Private
- Founded year
- 2020
- Operating status
- Closed
- Headcount range
- 11–50 employees
- Short description
- Aserto built a cloud-native, fine-grained authorization-as-a-service platform for SaaS application developers, combining its open-source Topaz authorizer (OPA + Zanzibar-inspired directory) with a hosted control plane and multi-language SDKs; the Seattle-based company ceased commercial operations on May 31, 2025.
- Ownership category
- akta.pro rank
Aserto industry classification
Industry- Product category
- Identity and Access Management
- NAICS
- Computer Systems Design Services (541512)
- SIC
- Services-Computer Programming Services (7371), Services-Prepackaged Software (7372)
- akta.pro primary industry
- Single Sign-On (SSO) & Federation (SAML/OIDC, Identity Providers) (HDAEAJAB)
Keywords
Where Aserto is headquartered
LocationHeadquarters
- HQ city
- Seattle
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Aserto business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Infrastructure, Marketing or Sales, Operations
Revenue model
- SaaS Subscription (Per-User): Tiered subscription model with per-user pricing. Starter tier is free, Essentials at $0.20/user/month, Pro and Enterprise offered via sales contact.
- Enterprise Licensing: Enterprise tier includes features like self-hosted IDP gateway, VPC deployment, 180-day log retention, and 24x7 support.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Free tier for personal projects, OSS, and commercial evaluation |
| Subscription | Monthly | For small teams or early-stage startups using Auth0 |
| Subscription | Annual | For SaaS vendors needing enterprise-ready authorization |
| Subscription | Annual | For enterprises creating authorization control plane for all internal applications |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels8 records
Aserto product offering
Product offeringCore offering
Aserto provides a fine-grained authorization-as-a-service platform for SaaS applications and APIs, built on the open-source Topaz authorizer, Open Policy Agent (OPA) decision engine, and a Google Zanzibar-inspired directory. The platform enables centralized policy management with edge-deployed authorizers that return access decisions in approximately 1 millisecond with 100% availability, supporting RBAC, ABAC, and ReBAC models.
Product overview
Aserto is an authorization-as-a-service platform that ceased operations on May 31, 2025. The company's product portfolio centered on Topaz, an open-source cloud-native authorizer that combines Open Policy Agent (OPA) and Google Zanzibar concepts for fine-grained authorization. Topaz serves as the core engine, while the Aserto Control Plane provides centralized management with real-time synchronization to Edge Authorizers deployed near applications. The platform offered solutions for Multi-tenant SaaS Authorization, Enterprise Customer Authorization, Internal Application Authorization, API Authorization, and Access Control for GenAI. The Aserto Directory provides graph-based relationship modeling, and the platform supports RBAC, ABAC, and ReBAC authorization models with policy-as-code workflows. Aserto also championed the OpenID AuthZEN specification for authorization standardization. The open-source Topaz project continues with community support after Aserto's commercial entity wind-down.
Differentiator
Problem solved
Functional benefit
Products and services
- Topaz Topaz is an open-source, cloud-native authorizer that combines Open Policy Agent (OPA) and Google Zanzibar concepts to enable fine-grained authorization with support for RBAC, ABAC, and ReBAC models. It is targeted at developers and platform engineers who need a distributed, high-performance open-source authorization engine. The project continues to be maintained by community maintainers after Aserto's commercial wind-down.
- Aserto Control Plane The Aserto Control Plane is the central management platform for Aserto authorization, providing a hub for managing policies, users, authorizers, and authorization data across all applications with real-time synchronization to edge authorizers. It is targeted at engineering teams that need centralized governance of distributed authorization deployments.
- Aserto API Authorization Aserto API Authorization delivers fine-grained, gateway-enforced API authorization that enables teams to go from OpenAPI spec to gateway-enforced authorization with automated API onboarding and entitlement management. It is targeted at platform engineering teams that need consistent externalized authorization across many APIs without changing API code.
- Aserto Access Control for GenAI Aserto Access Control for GenAI is a permission-aware authorization solution for enterprise chatbots and RAG applications that captures document permissions during indexing and filters retrieved results based on user access during the retrieval phase. It is targeted at enterprise AI/ML teams building chatbots and RAG applications that must respect existing document permissions and access controls.
Quantifiable outcome
- ~1 millisecond authorization decisions
- +1 more outcomes
Companies that use Aserto
Customer profileNamed customers2 records
Segments5 records
Ideal customer profiles5 records
Aserto technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration13 records
AI capability4 records
Feature8 records
Aserto partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered core and strategic.
- Topaz (Open Source Project)coreAserto created and maintains the Topaz open-source authorizer project. Topaz implements OPA decision engine with Zanzibar-inspired directory. Maintainers continue supporting Topaz after Aserto ceased operations.
- ZuplostrategicFirst-class integration between Aserto authorization and Zuplo API gateway. Demonstrated at joint webinar. Allows gateway-enforced API authorization without changes to API code.
- OpenID FoundationcoreAserto co-proposed the AuthZEN working group in October 2023. Serving as co-chair of WG and co-editor of PEP-PDP spec. Primary authors of AuthZEN interop scenario demonstrated by 12 implementations at Identiverse 2024.
- Auth0coreNative integration with Auth0 for identity provider functionality. Aserto SDKs designed to look familiar to Auth0 users.
- OktacoreNative integration with Okta for enterprise identity provider functionality.
- Microsoft Azure Active DirectorycoreNative integration with Azure AD (Entra ID) for enterprise identity provider functionality.
- GitHubcoreNative integration with GitHub for source code repository and container registry functionality.
- GitLabcoreNative integration with GitLab for source code repository and container registry functionality.
- Open Policy Agent (CNCF)coreBuilt on top of OPA, a CNCF graduated project. Uses Rego policy language for authorization policies.
- Open Policy Containers (CNCF Sandbox)strategicCNCF Sandbox project that secures software supply chain for OPA policies. Enables immutable policy images that can be signed and verified.
Scale indicators3 records
Recent moves7 records
Expansion highlights5 records
Aserto competitors and assessment
Company assessmentMarket position
Weaknesses5 records
Competitive moat4 records
Customer concentration
Aserto social profiles
Digital presenceAserto compliance and trust
Trust signalCompliance1 record
Aserto financial estimates
Financial estimateRevenue estimate
Valuation estimate
Aserto leadership team
Management profileNumber of profiles
Aserto funding detail
Funding detailFunding overview
Funding rounds1 record
Investors3 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Aserto M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Aserto
What does Aserto do?
Aserto provides a fine-grained authorization-as-a-service platform for SaaS applications and APIs, built on the open-source Topaz authorizer, Open Policy Agent (OPA) decision engine, and a Google Zanzibar-inspired directory. The platform enables centralized policy management with edge-deployed authorizers that return access decisions in approximately 1 millisecond with 100% availability, supporting RBAC, ABAC, and ReBAC models.
Is Aserto a public or private company?
Aserto is a private company. It is classified as venture growth investor backed and is currently closed.
When was Aserto founded?
Aserto was founded in 2020. It employs 11 to 50 people.
Where is Aserto based?
Aserto is headquartered in Seattle, United States, in the North America region.
How does Aserto make money?
Two revenue lines are on record. SaaS Subscription (Per-User) is the primary driver. The others are enterprise Licensing.
Does Aserto have an API?
Yes. Aserto provides gRPC, REST, and GraphQL APIs for developers to integrate authorization into their applications. The APIs enable developers to add fine-grained authorization using SDKs for Node.js, Python, Java, .NET, Ruby, and Go. Aserto also implements the OpenID AuthZEN specification with native endpoints supporting both HTTP REST and gRPC bindings. Developer documentation is at docs.aserto.com/docs.
What industry is Aserto in?
Aserto's product category is Identity and Access Management. Its primary akta.pro industry code is HDAEAJAB, Single Sign-On (SSO) & Federation (SAML/OIDC, Identity Providers). Its NAICS code is 541512 and its SIC code is 7371.