NEWS · JULY 29, 2026 · ARTIFICIAL INTELLIGENCE

Cyera moves to buy Oasis Security, the company that governs agent identities

Data security company Cyera announced on July 28, 2026 that it had signed a letter of intent to acquire Oasis Security for roughly $1 billion. Oasis governs non-human identities: service accounts, tokens, bots and AI agents. The deal makes a point clear for every company deploying agents, that the real question is not what an agent can do but what it can reach.

01 · WHAT HAPPENED?

A billion-dollar letter of intent

Cyera signed a letter of intent to acquire Oasis Security, a company working on non-human identity security, for approximately $1 billion. The news was reported on July 28, 2026 by TechCrunch and SiliconANGLE. Most of the payment is expected to be cash with the remainder in Cyera shares; figures reported by Israeli outlets put the cash portion at around $700 million. One detail matters here: the transaction has not closed. What exists today is a signed letter of intent, and Oasis is expected to run as a separate unit after closing.

02 · DETAILS

What a non-human identity actually is

Oasis Security was founded in 2022 and focuses on a single question: how many non-human identities exist inside an organisation, and what can each of them reach? Those identities are service accounts, API keys, tokens, digital keys, bots, workloads and, increasingly, AI agents. The platform inventories them, flags dormant or over-permissioned accounts, and can rotate credentials automatically or retire them outright. On the agent side, the emphasis is on watching behaviour and governing the access permissions granted to other software.

The company has raised more than $190 million to date, including a $120 million Series B led by Craft Ventures in March 2026. On the buying side, Cyera works in data security, recently raised $600 million at a $12 billion valuation and passed $150 million in annual recurring revenue. This is its third acquisition of the year, after Ryft and Genie Security. Cyera's plan is to fold the Oasis technology into its own data security work and build a single identity and data security platform. The five-year-old company has raised roughly $2.3 billion in total and is not yet profitable.

03 · WHY IT MATTERS

Agents arrive faster than teams can govern them

The framing Cyera co-founder and chief executive Yotam Segev used to explain the deal captures the point: knowing where your data sits is not enough if you cannot govern who or what touches it. Segev stresses that agents are spreading faster than teams can govern them, and that an agent does not need to be exploited by an attacker to cause damage. A well-intentioned agent with the wrong permissions can leak data on its own.

This is one of the more concrete structural shifts of the past two years. Headcount in a company grows slowly. Service accounts, integrations and agents can double inside a single sprint. Classic identity tooling was designed for people: onboarding, offboarding, passwords, two-step verification. Agents have neither a start date nor an HR record. A key that lives quietly inside a system with no owner is an attacker's favourite door. A billion dollars flowing towards that problem is a fair measure of how large it has grown on the enterprise side.

04 · TÜRKİYE

What it means for businesses in Türkiye

Businesses in Türkiye are adopting agents quickly: an agent drafting replies in customer support, a connection updating stock and prices on the e-commerce side, a service account feeding reporting spreadsheets. Each of those is an API key, and those keys usually live on an employee's laptop, in a spreadsheet, or in the settings of a project that closed months ago. If nobody holds the list, nobody holds the responsibility to switch them off either.

The work itself is plain. First, inventory: which agent, which integration, which key, connecting to which system. Second, least privilege: an agent that needs to read orders does not need to see the entire customer record. Third, lifetime and rotation: keys should not live forever and should be renewed on a schedule. Fourth, logging: it should be possible to see when an agent reached what. That last item matters under KVKK as well, because an agent touching personal data should have a documented, traceable basis and purpose. Closing a departing employee's account while leaving five integrations built under their name running is the most common gap we see.

The UNALSOFT take

The first question asked when building an agent is usually what it can do, when the critical question is what it can reach. In our agentic AI work we write the access boundary before the agent goes live: which data source, which operation, for how long. Scope starts narrow and widens as the need is proven. That does not slow the agent down. It simply makes it obvious where to start if the thing ever has to be pulled back.

Define what the agent may reach and speed stops producing risk.

Let's map the access list of the integrations and agents you already run.

Message on WhatsApp