Styra
The creator of Open Policy Agent, Styra sells the commercial control plane and enterprise tooling for policy-as-code authorization across cloud-native applications, APIs, and Kubernetes.
Visit Website ↗ + Add to CompareOverview
Styra is the company behind Open Policy Agent (OPA), an open-source policy engine that lets developers express authorization and access-control rules as code and enforce them consistently across microservices, APIs, Kubernetes admission control, and infrastructure configuration. Rather than each application or platform team hand-rolling its own authorization logic, OPA centralizes policy decisions behind a common declarative language (Rego), which Styra donated to the Cloud Native Computing Foundation in 2018; OPA reached CNCF graduated status in 2021 and has accumulated more than 75 million downloads.
Founded in 2015 and headquartered in Redwood City, California, Styra monetizes the open-source project through Styra DAS (Declarative Authorization Service) and Enterprise OPA, commercial control-plane products that give organizations centralized policy management, testing, and observability on top of the free OPA engine — a classic open-core model where the underlying technology is freely adoptable and the commercial product is management and governance at scale.
Styra raised a $40 million Series B in 2021 (Battery Ventures-led, with Capital One Ventures and Citi Ventures among new participants), bringing total disclosed funding to roughly $67.5 million. OPA’s independently documented adoption by companies including Netflix, Capital One, Atlassian, and Pinterest for internal authorization is a genuine, verifiable signal of technical traction that goes well beyond Styra’s own commercial customer base.
Innovation Matrix Assessment
Policy-as-code with a declarative language (Rego) lets teams update authorization rules without redeploying application code, and OPA's broad ecosystem of pre-built integrations (Kubernetes, Envoy, Terraform, Kafka, etc.) meaningfully shortens time-to-enforcement versus hand-coded authorization logic.
OPA's CNCF graduated status (2021) required demonstrating production-grade maturity, governance, and multi-vendor adoption to CNCF's technical oversight committee, which is a genuinely independent bar to clear, not a vendor self-assessment.
A $40M Series B in 2021 with new strategic investors (Capital One Ventures, Citi Ventures) is a solid but not explosive funding signal, and no larger or more recent round was found, suggesting steady rather than accelerating momentum.
Centralizing authorization as a separate, declarative policy layer decoupled from application code is a meaningful architectural shift from the prior norm of authorization logic embedded ad hoc in each service, and Styra pioneered this pattern at meaningful scale rather than following an existing standard.
OPA's independently documented production use at Netflix, Capital One, Atlassian, and Pinterest for real internal authorization decisions is strong, verifiable third-party evidence of technical efficacy that does not depend on Styra's own marketing claims.
Consistent, auditable authorization across microservices, APIs, and Kubernetes is a persistent and growing need as organizations decompose monoliths into distributed systems, keeping policy-as-code highly relevant to modern application security programs.
Why CISOs Should Care
CISOs get a way to enforce and audit consistent authorization policy across a sprawling microservices and Kubernetes estate from one control plane, instead of trusting each engineering team's ad hoc access-control code.
What Makes It Different
Styra's differentiation is having created and stewarded the de facto open standard (OPA) for policy-as-code, giving its commercial product an adoption funnel and ecosystem breadth that authorization competitors built purely as closed commercial products lack.
The Matrix Verdict
67/100 — INCREMENTAL INNOVATOR
A rare case in this batch where the core technology's effectiveness is independently, publicly verifiable through well-known companies' real production use rather than vendor claims; Styra's commercial upsell (centralized management on top of free OPA) is a reasonable and fairly proven open-core business model, making this one of the stronger-evidenced profiles in the batch.
Editorial Note: Claims vs. Verified Findings
Vendor-sourced: Styra's specific claims about ease of migration and time savings versus hand-coded authorization are company-provided. Independently verified: OPA's CNCF graduated status, its 75M+ download count, and its production use at Netflix, Capital One, Atlassian, and Pinterest are documented by CNCF and independent trade press, not solely by Styra.
Sources
Alternatives to Styra
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…