Platform

Customers

Resources

Platform

Customers

Resources

See. Encode.

→ Enforce.

Opal is the access control plane for every identity. Our AI understands the CISO's context with a security engineer's precision.

→ Enforce.

Trusted by leading companies

Built for every identity.

Humans

Employees, contractors, and external partners

Humans

Employees, contractors, and external partners

Non-human identities

Service accounts, CI/CD pipelines, and API tokens

Non-human identities

Service accounts, CI/CD pipelines, and API tokens

AI agents

Agents, sub-agents, and coding agents

AI agents

Agents, sub-agents, and coding agents

See every identity, relationship, 

and access path.

OpalQuery

Query your entire stack in plain English to surface risk, over-provisioned access, separation-of-duties conflicts, and hidden privilege escalation paths.

Encode access policy into reusable logic.

OpalScript

Turn approval rules into version-controlled workflows that scale across every team and environment. Write it in code, or describe what you need and let AI generate it.

Enforce least privilege continuously.

Paladin

Our AI agent evaluates every request, approves what's safe on its own, escalates only what needs a human, and revokes access the moment it's no longer needed.

1

2

3

of 3

In production.

Chronosphere

0%

reduction in standing access

Permissions expire by default, so the attack surface shrinks on its own.

Security engineering

Databricks

0K

just-in-time access requests

Every request handled by policy, 
no ticket queue required.

Identity & access

Superhuman

0+

apps under governance

Lower access risk without slowing anyone down.

Platform

Mercari

0

Okta entitlements governed

Automated reviews that surface real risk, not rubber-stamps.

Compliance

In production.

Chronosphere

0%

reduction in standing access

Permissions expire by default, so the attack surface shrinks on its own.

Security engineering

Databricks

0K

just-in-time access requests

Every request handled by policy, 
no ticket queue required.

Identity & access

Superhuman

0+

apps under governance

Lower access risk without slowing anyone down.

Platform

Mercari

0

Okta entitlements governed

Automated reviews that surface real risk, not rubber-stamps.

Compliance

In production.

  • Chronosphere

    0%

    reduction in standing access

    Eliminate standing access across 
cloud and SaaS

    Security engineering

  • Databricks

    0K

    request resolution time

    Resolve access requests in minutes, not days

    Identity & access

  • Superhuman

    0+

    identities under governance

    Govern human and agent identities side-by-side

    Platform

  • Mercari

    0

    fewer audit findings

    Pass SOC 2, ISO, and PCI without burning a quarter

    Compliance

Opal helps us protect more of our attack surface, with a small but mighty team.”

Mandy Andress

CISO, Elastic

As we scale, our security scales with us, and access controls aren't something we worry about.”

Gil Feig

CTO, Merge

Opal secures every identity in modern infrastructure, from employees to AI agents

Opal helps us protect more of our attack surface, with a small but mighty team.”

Mandy Andress

CISO, Elastic

As we scale, our security scales with us, and access controls aren't something we worry about.”

Gil Feig

CTO, Merge

Opal secures every identity in modern infrastructure, from employees to AI agents

Opal helps us protect more of our attack surface, with a small but mighty team.”

Mandy Andress

CISO, Elastic

As we scale, our security scales with us, and access controls aren't something we worry about.”

Gil Feig

CTO, Merge

Opal secures every identity in modern infrastructure, from employees to AI agents

Use Cases

Identity governance for every 

access decision.

Apply identity controls across human users, AI agents, applications, and infrastructure from a single governance layer.

AI-Powered Access Reviews

Surface the riskiest access with explainable recommendations, so reviews stop being stamps.

Just-In-Time Access

Grant privileged access only when it's needed, and revoke it automatically when the work is done.

Access Intelligence

Ask who has access to what, and why, in plain English. Answers in seconds, not a quarterly report.

Security for AI Agents

Define what AI agents can see, access, and execute before they touch your systems.

Programmable Governance

Build access logic into workflows and approvals as version-controlled, testable code.

  • Passing a SOC 2 audit

  • Killing standing access

  • Rolling out AI agents

  • Recertifying access

  • Offboarding at scale

  • A wave of new hires

  • Responding to a breach

  • Onboarding contractors and vendors

  • Preparing for an IPO

  • A merger or acquisition

Built on a complete view of your environment.

Opal connects to 250+ systems across cloud, identity, SaaS, databases, and AI platforms to build a complete access graph and enforce governance where it matters.

  • Workday

  • Twingate

  • Tines

  • Terraform

  • Teleport

  • Tailscale

  • Snowflake

  • Slack

  • ServiceNow

  • Salesforce

  • RunReveal

  • Rootly

  • PagerDuty

  • Oracle Fusion Cloud

  • Opsgenie

  • OpenAI

  • Okta

  • Notion

  • Linear

  • LDAP

  • Jira SM

  • Jira

  • Internal Tools

  • incident.io

  • Google Workspace

  • Google Groups

  • GCP

  • Google Chat

  • GitLab

  • GitHub

  • GCP Project

  • GCP GKE

  • GCP Folder

  • GCP Compute

  • GCP Cloud SQL

  • GCP Bucket

  • Fresh Service

  • Entra ID

  • Email

  • Duo

  • Devin AI

  • Datastax Astra

  • Databricks

  • Cursor

  • Coupa

  • Azure VM

  • Azure SQL

  • Azure Blob Storage

  • Azure AD

  • AWS SSO

  • AWS IAM Role

  • Anthropic Platform

  • AWS

  • Amazon EKS

  • Amazon EC2

  • Amazon Aurora

  • Active Directory

ENTERPRISE READY

Built for regulated environments.

SOC 2 Type 2 certified and independently penetration-tested every year. Run Opal in our cloud or your own environment, with every access change logged and searchable, so audit evidence is a byproduct of how you operate.

/1

SOC 2 Type 2

Independently audited security controls. Full report available under NDA.

/2

Self-hosted or on-prem

Deploy in our cloud, your own VM, or Kubernetes, for the most tightly controlled environments.

/3

Encryption everywhere

TLS 1.2+ in transit, AWS KMS at rest, daily encrypted backups.

See how Opal secures enterprise environments at scale.

/4

Searchable audit log

Every access change and admin action logged, attributable, and exportable to your SIEM or S3.

/5

Tested continuously

Independent penetration testing at least annually, plus monthly vulnerability scans.

/6

Data residency and transfers

US or EU hosting, GDPR and CCPA support, and EU Standard Contractual Clauses for cross-border data.

ENTERPRISE READY

Built for regulated environments.

SOC 2 Type 2 certified and independently penetration-tested every year. Run Opal in our cloud or your own environment, with every access change logged and searchable, so audit evidence is a byproduct of how you operate.

/1

SOC 2 Type 2

Independently audited security controls. Full report available under NDA.

/2

Self-hosted or on-prem

Deploy in our cloud, your own VM, or Kubernetes, for the most tightly controlled environments.

/3

Encryption everywhere

TLS 1.2+ in transit, AWS KMS at rest, daily encrypted backups.

See how Opal secures enterprise environments at scale.

/4

Searchable audit log

Every access change and admin action logged, attributable, and exportable to your SIEM or S3.

/5

Tested continuously

Independent penetration testing at least annually, plus monthly vulnerability scans.

/6

Data residency and transfers

US or EU hosting, GDPR and CCPA support, and EU Standard Contractual Clauses for cross-border data.

ENTERPRISE READY

Built for regulated environments.

SOC 2 Type 2 certified and independently penetration-tested every year. Run Opal in our cloud or your own environment, with every access change logged and searchable, so audit evidence is a byproduct of how you operate.

/1

SOC 2 Type 2

Independently audited security controls. Full report available under NDA.

/2

Self-hosted or on-prem

Deploy in our cloud, your own VM, or Kubernetes, for the most tightly controlled environments.

/3

Encryption everywhere

TLS 1.2+ in transit, AWS KMS at rest, daily encrypted backups.

See how Opal secures enterprise environments at scale.

/4

Searchable audit log

Every access change and admin action logged, attributable, and exportable to your SIEM or S3.

/5

Tested continuously

Independent penetration testing at least annually, plus monthly vulnerability scans.

/6

Data residency and transfers

US or EU hosting, GDPR and CCPA support, and EU Standard Contractual Clauses for cross-border data.

AI that makes continuous access decisions, with you on the dial.

AI that makes continuous access decisions, with you on the dial.

AI that makes continuous access decisions, with you on the dial.

Everything you need to know about Opal

What is Opal Security and what does it do?

What systems does Opal integrate with?

How is Opal different from traditional IGA and IAM tools?

Can Opal govern AI agents and non-human identities?

Does Opal replace my existing identity stack?

How fast can Opal be deployed?

Who is Opal's leadership?

FAQ

Everything you need to know about Opal

What is Opal Security and what does it do?

What systems does Opal integrate with?

How is Opal different from traditional IGA and IAM tools?

Can Opal govern AI agents and non-human identities?

Does Opal replace my existing identity stack?

How fast can Opal be deployed?

Who is Opal's leadership?

FAQ

Everything you need to know about Opal

What is Opal Security and what does it do?

What systems does Opal integrate with?

How is Opal different from traditional IGA and IAM tools?

Can Opal govern AI agents and non-human identities?

Does Opal replace my existing identity stack?

How fast can Opal be deployed?

Who is Opal's leadership?

FAQ

See. Encode.

→ Enforce.

© 2026

See. Encode.

→ Enforce.

© 2026

See.

→ Enforce.

Encode.

© 2026