Open Policy Agent
Open Policy Agent is an open-source CNCF Graduated policy engine that uses the Rego declarative language to unify policy enforcement across Kubernetes, CI/CD, API gateways, and AI agents for enterprise platform, security, and DevOps teams.
- Company typePrivate
- Founded2016
- HeadquartersSan Francisco, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Open Policy Agent does
Open Policy Agent (OPA) is an open-source, general-purpose policy engine stewarded by the Cloud Native Computing Foundation (CNCF) as a Graduated project and maintained by community contributors under the Apache License 2.0. OPA provides a high-level declarative policy language called Rego, purpose-built for expressing policies over complex hierarchical data structures, and evaluates queries against pre-loaded in-memory data to deliver fast policy decisions. The engine accepts arbitrary structured data as input and can generate arbitrary structured data as output, going beyond simple allow/deny decisions to support context-aware policy enforcement. Native integrations span Envoy External Authorization, Kubernetes admission control (via the OPA Gatekeeper sub-project), CI/CD pipelines, Terraform plan validation, AWS CloudFormation Hooks, Kafka, Docker, GraphQL, HTTP APIs, SSH/sudo, and AI agent tool-calling governance, with developer access through a Go SDK, a REST API, and an interactive Rego Playground.
The OPA ecosystem includes OPA Gatekeeper (Kubernetes admission controller), Regal (Rego linter and analysis tool), and Conftest (configuration testing utility). Distribution is entirely self-serve via downloadable binaries for macOS, Linux, and Windows, Docker Hub, Homebrew, and community-maintained packages across Arch Linux, NixOS, Wolfi, FreeBSD, and NetBSD. Marketing and adoption run through community-led channels: documentation portal, Slack community, GitHub repository, KubeCon Maintainer Track sessions, and an official blog. The project does not sell software or charge licensing fees; commercial support is offered by independent third-party providers (including Policy-as-Code Laboratories and DepKeep), and monetization adjacent to OPA occurs through partner products such as Harness Policy as Code (powered by OPA).
Adopters named in public materials span financial services (Goldman Sachs, Bloomberg, Capital One, BNY Mellon, BankData, Intuit), technology (Atlassian, Cisco, Pinterest, SugarCRM), insurance (Allstate), professional services (Marsh McLennan), telecommunications (T-Mobile, Vodafone), retail (Zalando), and travel (Tripadvisor). OPA serves platform and DevOps teams, Kubernetes operators, CI/CD engineers, API gateway owners, application developers, and increasingly AI/ML platform teams that need fine-grained governance over autonomous agents. The organization operates with a 1-10 person maintainer team based in San Francisco, has no venture funding, and is structurally a non-profit community project rather than a revenue-generating company.
Open Policy Agent firmographics
Firmographics- Name
- Open Policy Agent
- Legal name
- Open Policy Agent contributors
- Website
- https://openpolicyagent.org
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Open Policy Agent is an open-source CNCF Graduated policy engine that uses the Rego declarative language to unify policy enforcement across Kubernetes, CI/CD, API gateways, and AI agents for enterprise platform, security, and DevOps teams.
- Ownership category
- akta.pro rank
Open Policy Agent industry classification
Industry- Product category
- Policy-as-Code Engine
- NAICS
- Software Publishers (5132)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Identity Orchestration & Policy (Zero Trust Access, Conditional Access) (HDADAAAL)
- akta.pro secondary industry
- Access Management & Policy Enforcement (Zero Trust) (BPAMAEAH)
Keywords
Where Open Policy Agent is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Markets served
Open Policy Agent business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Infrastructure
Revenue model
- Open Source Distribution: OPA is distributed as open source under Apache License 2.0. No direct revenue from software licensing. The project is maintained by the open source community and supported by third-party commercial providers.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Open Source - Free |
Go-to-market motion2 records
Distribution channels5 records
Marketing channels6 records
Open Policy Agent product offering
Product offeringCore offering
Open Policy Agent (OPA) is a general-purpose, open-source policy engine that unifies policy enforcement across the technology stack via the Rego declarative policy language. It allows software, platform, and security teams to decouple policy decision-making from application code by querying OPA through REST APIs, the Go SDK, or native integrations such as Envoy and Kubernetes. The project also ships ecosystem tooling including OPA Gatekeeper (Kubernetes admission control), Conftest (configuration testing), and Regal (Rego linting), all distributed under Apache License 2.0.
Product overview
Open Policy Agent (OPA) is a general-purpose policy engine that provides unified policy enforcement across the technology stack. The core product is the OPA policy engine itself, which uses the Rego declarative language for expressing policies. The ecosystem includes the Rego Playground for interactive policy development, OPA Gatekeeper for Kubernetes admission control, Regal for policy linting, and Conftest for configuration testing. Developers can integrate OPA via the Go SDK, REST API, or Envoy native integration. OPA is designed to decouple policy decision-making from application logic, enabling security teams to centrally manage policies while applications query OPA for authorization decisions.
Differentiator
Problem solved
Functional benefit
Brands
- OPA Gatekeeper: A sub-project for Kubernetes policy enforcement using OPA
- Regal
- Conftest
Products and services
- Open Policy Agent (OPA) A general-purpose, open-source policy engine that unifies policy enforcement across the stack, providing a high-level declarative language (Rego) for specifying policies and APIs to offload policy decision-making from application code. Targeted at platform, security, and application teams in enterprises.
- Rego Playground An interactive online environment where developers can write and test Rego policies against sample input data and see real-time evaluation results, usable without local installation.
- OPA Gatekeeper A sub-project that integrates OPA as a Kubernetes admission controller, enabling custom policy enforcement on cluster resources through declarative Rego policies.
- Regal A linter and analysis tool for Rego that helps developers write higher-quality policy code by enforcing style and correctness rules.
- Conftest A utility for writing tests against structured configuration files using the Rego policy language, enabling policy-as-code testing of configuration artifacts.
- OPA Go SDK A Go library that allows OPA to be embedded inside Go programs as a library, enabling in-process policy evaluation without a separate network call.
- OPA REST API An HTTP API exposing OPA policy decisions to any language or system over standard web requests, enabling cross-stack integration.
Quantifiable outcome
- Comprehensive audit trails generated for every policy decision
- +1 more outcomes
Companies that use Open Policy Agent
Customer profileNamed customers16 records
Segments5 records
Ideal customer profiles5 records
Open Policy Agent technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration11 records
AI capability3 records
Feature6 records
Open Policy Agent partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- HarnessnotableHarness released 'Harness Policy as Code' powered by Open Policy Agent, enabling enterprises to define and enforce compliance and security policies across CI, CD, and Feature Flags pipelines with automatic policy enforcement and audit trails for regulated industries (SOC2, PCI, FedRamp).
Scale indicators1 record
Recent moves6 records
Expansion highlights5 records
Open Policy Agent competitors and assessment
Company assessmentDirect peers
- Cerbos: Open-source authorization layer for application permissions, providing policy decision and enforcement services analogous to OPA for microservices and API authorization.
- Kyverno: Kubernetes-native policy engine that competes directly with OPA Gatekeeper, using a simpler YAML-based policy style for cluster admission control and configuration validation.
- Styra: Commercial venture founded by the original creators of OPA, providing enterprise products (including enterprise OPA distributions and Dashboards) that wrap and operationalize OPA for production authorization use cases.
- HashiCorp Sentinel: Policy-as-code framework embedded in HashiCorp Terraform and other products, offering a competing declarative policy language for infrastructure and application authorization decisions.
- Casbin: General-purpose open-source authorization library and policy engine that, like OPA, decouples policy from application code and supports multiple model formats for access control.
- AWS Cedar: AWS-developed policy language and evaluation engine for authorization, positioned as a cloud-native alternative to OPA for permissions and policy decision-making.
Emerging players
- Kubewarden: Kubernetes policy engine leveraging WebAssembly for policy execution; competes with OPA Gatekeeper specifically on admission control and cluster admission workflows.
Broad incumbents
- AWS IAM (Identity and Access Management): Hyperscaler-scale identity and policy service from AWS that addresses authorization use cases overlapping with OPA, especially for cloud-native workloads and externalized authorization via Cedar.
- Google Cloud IAM: Cloud-provider identity and access management suite with policy components that overlap with OPA's authorization and access enforcement capabilities for Google Cloud workloads.
- Microsoft Azure Policy: Microsoft's governance service for enforcing organizational standards and policies on Azure resources, offering an integrated alternative to OPA-style external policy engines.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
Open Policy Agent social profiles
Digital presenceOpen Policy Agent compliance and trust
Trust signalCompliance1 record
Open Policy Agent financial estimates
Financial estimateRevenue estimate
Valuation estimate
Open Policy Agent leadership team
Management profileNumber of profiles
Open Policy Agent funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Open Policy Agent M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Open Policy Agent
What does Open Policy Agent do?
Open Policy Agent (OPA) is a general-purpose, open-source policy engine that unifies policy enforcement across the technology stack via the Rego declarative policy language. It allows software, platform, and security teams to decouple policy decision-making from application code by querying OPA through REST APIs, the Go SDK, or native integrations such as Envoy and Kubernetes. The project also ships ecosystem tooling including OPA Gatekeeper (Kubernetes admission control), Conftest (configuration testing), and Regal (Rego linting), all distributed under Apache License 2.0.
Is Open Policy Agent a public or private company?
Open Policy Agent is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Open Policy Agent founded?
Open Policy Agent was founded in 2016. It employs 1 to 10 people.
Where is Open Policy Agent based?
Open Policy Agent is headquartered in San Francisco, United States, in the North America region.
How does Open Policy Agent make money?
One revenue line is on record: open Source Distribution.
Who are Open Policy Agent's main competitors?
Direct peers on record are Cerbos, Kyverno, Styra, HashiCorp Sentinel, Casbin and AWS Cedar. Kubewarden is listed as an emerging player. Broad incumbents are AWS IAM (Identity and Access Management), Google Cloud IAM and Microsoft Azure Policy.
Does Open Policy Agent have an API?
Yes. OPA provides a REST API that allows applications to query policy decisions. Applications can integrate directly using the SDKs (Go library) or REST API to make domain-specific runtime decisions. OPA accepts arbitrary structured data as input and generates policy decisions by evaluating queries against policies and data. The API listens on localhost:8181 by default when running as a server. Developer documentation is at www.openpolicyagent.org/docs/rest-api.
What industry is Open Policy Agent in?
Open Policy Agent's product category is Policy-as-Code Engine. Its primary akta.pro industry code is HDADAAAL, Identity Orchestration & Policy (Zero Trust Access, Conditional Access), with a secondary code of BPAMAEAH, Access Management & Policy Enforcement (Zero Trust). Its NAICS code is 5132 and its SIC code is 7372.