Veza
Identity security platform built around an authorization graph that maps who and what can actually access data and systems, beyond what IAM roles claim.
Visit Website ↗Overview
Veza, founded in 2020 and headquartered in Los Gatos, California, built its platform around what it calls the authorization graph — pulling raw permission and entitlement metadata from disparate systems (cloud IAM, data warehouses, SaaS apps, on-prem directories) and normalizing it into a single schema that shows actual effective access, not just the roles and groups an admin thinks are in place. That distinction matters because in most environments the nominal role structure and the real, computed effective permissions diverge significantly, especially in cloud IAM systems like AWS where policy inheritance is complex.
The company raised a $108 million Series D in April 2025 at an $808 million valuation, led by New Enterprise Associates with participation from Atlassian Ventures, Workday Ventures, and Snowflake Ventures — notably including strategic investment from companies whose own platforms are common Veza data sources — bringing total funding to $235 million.
Veza positions itself less as a replacement for identity governance tools like SailPoint and more as the authorization layer underneath them: a query-able graph of who can do what, used to power least-privilege enforcement, access reviews, and non-human identity governance across cloud, SaaS, and data infrastructure.
Innovation Matrix Assessment
Expanded from cloud-entitlement visibility into full access-review, least-privilege automation, and non-human identity governance within roughly five years of founding.
Computing actual effective permissions rather than relying on nominal role assignments directly addresses a well-documented cause of over-privileged access that manual reviews routinely miss.
An $808M valuation and strategic investment from Atlassian, Workday, and Snowflake — companies whose platforms are common data sources for Veza — is a strong momentum signal, though it remains a private, sub-scale company relative to incumbents.
Modeling authorization as a queryable graph of effective permissions, rather than a static list of role assignments, is a structurally different approach to the access-visibility problem than traditional IGA.
Strong investor validation and named strategic partners, but independent, third-party efficacy evidence at large production scale is limited in public sources given the company's relative youth.
As access sprawls across cloud, SaaS, data platforms, and non-human identities, a normalized authorization graph is likely to become more, not less, necessary.
Why CISOs Should Care
Veza answers the question access reviews are supposed to answer but usually can't — exactly what a given identity can actually do across cloud, data, and SaaS systems — replacing spreadsheet-based certification with a queryable graph.
What Makes It Different
Rather than governing static role assignments like traditional IGA tools, Veza computes and normalizes actual effective permissions across heterogeneous systems into one graph, closing the gap between assigned and real access.
The Matrix Verdict
77/100 — MEANINGFUL INNOVATOR
A structurally different, well-funded approach to a genuine and worsening problem — permission sprawl and effective-access blindness — with strong strategic investor validation. A strong Meaningful-to-Transformational Innovator among smaller category-creators.
Editorial Note: Claims vs. Verified Findings
Funding and investor details are independently corroborated (BusinessWire, Yahoo Finance); the technical claim of computing effective permissions is describable from Veza's own product documentation and is architecturally distinct, but independent third-party production benchmarks are limited.
Sources
- Veza Raises $108 Million Series D — https://veza.com/company/press-room/series-d-announcement/
- BusinessWire — https://www.businesswire.com/news/home/20250428090240/en/Veza-Raises-$108-Million-in-Series-D-at-$808-Million-Valuation-to-Meet-Global-Demand-for-its-Pioneering-Identity-Security-Platform
- Veza emerges from stealth — https://veza.com/company/press-room/veza-the-data-security-company-built-on-the-power-of-authorization-emerges-from-stealth-and-announces-110-million-in-funding/
Alternatives to Veza
Silverfort
Agentless unified identity protection platform that extends MFA, ITDR, and access policy to legacy and unmanaged systems traditional…
Oasis Security
Non-human identity management platform discovering, classifying, and governing service accounts, API keys, and machine credentials, now extending to…
Semperis
Identity resilience platform specializing in Active Directory security posture, attack-path discovery, threat detection, and disaster recovery.
Astrix Security
Non-human identity security platform that discovers and governs API keys, OAuth tokens, service accounts, and AI-agent credentials across…
Microsoft Entra ID
Microsoft's cloud identity and access platform (formerly Azure AD) providing SSO, conditional access, MFA, and identity governance across…
CyberArk
The market-leading privileged access management vendor, extending from vaulted human credentials into machine identity and secrets management.