Cerbos
Open-source, policy-as-code authorization engine that lets engineering teams externalize fine-grained access-control decisions from their application code.
Visit Website ↗ + Add to CompareOverview
Cerbos was founded in 2021 by Emre Baran, Alex Olivier, and Charith Ellawala to address a gap most IAM platforms leave unsolved: after a user authenticates, applications still need to decide what that user is allowed to do, and that authorization logic is typically hardcoded, inconsistent across services, and hard to audit. Cerbos externalizes this into a standalone, open-source policy decision point that development teams query via API, using YAML-based policies rather than a proprietary DSL.
The company is fully remote and headquartered in London, and closed a $7.5 million extended seed round in March 2023 led by OMERS Ventures, bringing total funding to roughly $11 million. Cerbos later added a hosted cloud offering (Cerbos Hub) for teams that don’t want to self-host the open-source policy decision point, giving it a bottom-up open-source-to-commercial adoption path similar to companies like HashiCorp or Snyk.
It competes with Open Policy Agent (OPA)-based approaches, AWS Cedar, and commercial authorization platforms like Permit.io and Styra, differentiating mainly through developer ergonomics and a schema-driven policy model designed to be testable in CI/CD.
Innovation Matrix Assessment
Expanded from an open-source policy engine to a hosted Cerbos Hub product within roughly two years of founding, showing reasonably fast iteration for a small team.
Centralizing authorization logic outside application code materially improves auditability and consistency for security teams reviewing access-control decisions.
A $7.5M extended seed round is modest relative to well-funded authorization competitors like Styra or Permit.io, indicating early but not yet proven market pull.
Policy-as-code authorization is a meaningful architectural shift from hardcoded access checks, though it builds on prior art (OPA, XACML) rather than inventing the category.
As an open-source project with public GitHub activity, its code is inspectable, but no independent production-security case study was found beyond vendor testimonials.
Fine-grained, externalized authorization becomes more important as applications fragment into microservices and as AI agents require scoped, auditable permissions.
Why CISOs Should Care
Cerbos gives security and platform teams a single, auditable place to define and change authorization logic across microservices, rather than relying on scattered if/else access checks buried in application code that are difficult to review or prove compliant.
What Makes It Different
It is open-source and self-hostable by default, letting security-conscious teams keep policy decisions and sensitive data entirely within their own infrastructure rather than routing every authorization check through a third-party SaaS.
The Matrix Verdict
53/100 — INCREMENTAL INNOVATOR
A well-regarded, developer-first authorization engine addressing a genuine architectural gap (fine-grained authorization) with real open-source traction, but it remains an early-stage company competing in a category with several credible alternatives (OPA, Styra, Permit.io). An Emerging Innovator worth tracking.
Editorial Note: Claims vs. Verified Findings
Funding and founding details are sourced from GlobeNewswire's funding announcement and Cerbos's own about page; adoption and usage-scale figures are vendor-reported and were not independently benchmarked.
Sources
Alternatives to Cerbos
Teleport
An identity-based infrastructure access platform issuing short-lived cryptographic identities for humans, machines, and AI agents in place of…
SpecterOps
Identity attack-path security specialist behind BloodHound, the widely used open-source tool for mapping Active Directory and Entra ID…
Astrix Security
Non-human identity security platform that discovers and governs API keys, OAuth tokens, service accounts, and AI-agent credentials across…
Socure
AI-driven identity verification and fraud platform used by banks, fintechs, and government agencies to validate identities during digital…
Keyfactor
Machine identity and PKI management platform helping enterprises secure certificates, keys, and post-quantum cryptography readiness at scale.
Silverfort
Agentless unified identity protection platform that extends MFA, ITDR, and access policy to legacy and unmanaged systems traditional…