Skip to content

Cerbos

Open-source, policy-as-code authorization engine that lets engineering teams externalize fine-grained access-control decisions from their application code.

Visit Website ↗ + Add to Compare
53/100Incremental Innovator

Overview

Cerbos was founded in 2021 by Emre Baran, Alex Olivier, and Charith Ellawala to address a gap most IAM platforms leave unsolved: after a user authenticates, applications still need to decide what that user is allowed to do, and that authorization logic is typically hardcoded, inconsistent across services, and hard to audit. Cerbos externalizes this into a standalone, open-source policy decision point that development teams query via API, using YAML-based policies rather than a proprietary DSL.

The company is fully remote and headquartered in London, and closed a $7.5 million extended seed round in March 2023 led by OMERS Ventures, bringing total funding to roughly $11 million. Cerbos later added a hosted cloud offering (Cerbos Hub) for teams that don’t want to self-host the open-source policy decision point, giving it a bottom-up open-source-to-commercial adoption path similar to companies like HashiCorp or Snyk.

It competes with Open Policy Agent (OPA)-based approaches, AWS Cedar, and commercial authorization platforms like Permit.io and Styra, differentiating mainly through developer ergonomics and a schema-driven policy model designed to be testable in CI/CD.

Innovation Matrix Assessment

Innovation Velocity 6/10

Expanded from an open-source policy engine to a hosted Cerbos Hub product within roughly two years of founding, showing reasonably fast iteration for a small team.

Operational Value 6/10

Centralizing authorization logic outside application code materially improves auditability and consistency for security teams reviewing access-control decisions.

Market Momentum 4/10

A $7.5M extended seed round is modest relative to well-funded authorization competitors like Styra or Permit.io, indicating early but not yet proven market pull.

Category Disruption 5/10

Policy-as-code authorization is a meaningful architectural shift from hardcoded access checks, though it builds on prior art (OPA, XACML) rather than inventing the category.

Real-World Efficacy 5/10

As an open-source project with public GitHub activity, its code is inspectable, but no independent production-security case study was found beyond vendor testimonials.

Enduring Relevance 6/10

Fine-grained, externalized authorization becomes more important as applications fragment into microservices and as AI agents require scoped, auditable permissions.

Why CISOs Should Care

Cerbos gives security and platform teams a single, auditable place to define and change authorization logic across microservices, rather than relying on scattered if/else access checks buried in application code that are difficult to review or prove compliant.

What Makes It Different

It is open-source and self-hostable by default, letting security-conscious teams keep policy decisions and sensitive data entirely within their own infrastructure rather than routing every authorization check through a third-party SaaS.

The Matrix Verdict

53/100 — INCREMENTAL INNOVATOR

A well-regarded, developer-first authorization engine addressing a genuine architectural gap (fine-grained authorization) with real open-source traction, but it remains an early-stage company competing in a category with several credible alternatives (OPA, Styra, Permit.io). An Emerging Innovator worth tracking.

Editorial Note: Claims vs. Verified Findings

Funding and founding details are sourced from GlobeNewswire's funding announcement and Cerbos's own about page; adoption and usage-scale figures are vendor-reported and were not independently benchmarked.

Sources