Cerbos

Cerbos Competitive Intelligence & Landscape

cerbos.dev ·

Overview

Cerbos Overview

Cerbos (cerbos.dev) is an enterprise authorization management platform designed to secure access across complex, distributed environments, SaaS products, AI systems, and regulated industries [cerbos.dev/about]. The company's core offering focuses on externalizing authorization logic from application code, providing a consistent and centrally managed approach to access control across applications, gateways, workloads, and AI agents [cerbos.dev, cerbos.dev/about, cerbos.dev/faq]. This allows for fine-grained, contextual, and continuous authorization, enabling full visibility into access decisions, defining AI agent boundaries, and proving compliance for standards like SOC 2, ISO 27001, HIPAA, and GDPR [cerbos.dev].

Cerbos addresses the challenge of scattered authorization logic, which can create blind spots and make it difficult to manage permissions. By centralizing policy definition, approval, and updates, it allows for the deployment of roles and permissions without code changes, supporting various models such as RBAC, ABAC, ReBAC, and PBAC out of the box [cerbos.dev, cerbos.dev/features-benefits-and-use-cases]. The platform is built to scale, handling millions of authorization decisions per second across distributed systems and AI agents, and can be deployed in cloud, on-premise, or air-gapped environments [cerbos.dev].

The company's mission is to make the implementation of access control in modern, cloud-native applications as painless as possible, freeing developers to focus on product development rather than custom permissions implementations [cerbos.dev/join-us].

Cerbos is particularly focused on securing AI agents by defining their access boundaries before deployment and allowing rapid revocation of access through policy [cerbos.dev]. It also bridges the gap in existing IAM stacks by controlling what identities actually do at the resource level at runtime, complementing authentication by IdPs and provisioning by IGAs [cerbos.dev].

Cerbos operates under Zenauth Ltd [cerbos.dev/tos]. While specific details regarding founding year, headquarters, and company size are not explicitly stated on the provided homepage or "About Us" sections, the "Join Us" page indicates that it is a well-funded startup working with world-class investors, offering competitive salaries and perks, and supporting remote work [cerbos.dev/join-us]. The company continually shares insights and news, including demonstrations of how its GitOps-based workflow for authorization policies enhances security and streamlines developer workflows [cerbos.dev/news].

Cerbos

Cerbos Weekly Intel Updates

Receive weekly intel updates about Cerbos straight to your inbox.

Competitors

Cerbos Competitors

Several companies offer solutions that compete with Cerbos's authorization management platform.

Permit.io is a notable alternative that provides authorization as a service, aiming to fit into various tech stacks and offering a visual policy experience. While Cerbos focuses on enterprise software and AI authorization with support for RBAC, ABAC, ReBAC, and PBAC out of the box, Permit.io also provides a comprehensive authorization solution for developers looking for fine-grained control.

Oso is another significant competitor, distinguishing itself as an AI Agent Security & Control Platform. Unlike Cerbos, which emphasizes an end-to-end authorization platform for enterprise software and AI, Oso specifically targets securing and controlling AI agents within an organization, offering visibility and controls to manage AI traffic and shut down unsanctioned AI. Both companies address the authorization challenges posed by AI, but Oso's market positioning is more specialized in AI agent security.

AuthZed, creators of SpiceDB, offers permissions systems as a service, inspired by Google's Zanzibar. This positions AuthZed as a strong competitor in managing permissions and authorizations, particularly for those seeking a robust, scalable, and open-source-inspired solution. While Cerbos is an authorization layer that integrates into application code and provides a comprehensive authorization management platform, AuthZed focuses on the core permissioning infrastructure.

Aserto is a commercial identity governance and administration tool that provides fine-grained, scalable authorization. Similar to Cerbos, Aserto aims to deliver efficient authorization. However, Aserto's broader categorization as an identity governance and administration (IGA) tool suggests it might offer a wider suite of identity-related features beyond just authorization, while Cerbos is hyper-focused on authorization management across various identity types and use cases.

Alternatives

Cerbos Alternatives

Product & Pricing

Cerbos Product and Pricing Intelligence

Cerbos (cerbos.dev) offers a comprehensive authorization management platform with distinct product packages: the open-source Cerbos PDP and the commercial Cerbos Hub + Synapse. The Cerbos PDP provides an externalized authorization layer, allowing for distributed policy decision points and policy enforcement via SDK and ORM integrations. It supports YAML-based policy definition, audit logs, CI/CD and IDE tooling, various storage options, and community support, deployable on-premise or in the cloud [https://www.cerbos.dev/pricing][https://www.cerbos.dev/product-cerbos-pdp]. This open-source component is designed for developers to implement scalable access control by separating authorization logic from application code [https://www.cerbos.dev/for-developers].

Cerbos Hub is positioned as an end-to-end authorization platform, encompassing a policy control plane, a data enrichment layer, and the distributed policy engine. It manages the full authorization lifecycle, including authoring, testing, versioning, distribution, data enrichment, decision evaluation, and auditing [https://docs.cerbos.dev/cerbos-hub/]. It allows for centralized policy management to enforce fine-grained, contextual, and continuous authorization across applications, APIs, AI agents, and workloads [https://www.cerbos.dev/product-cerbos-hub]. This enables companies to control product packaging and feature gating using authorization policies, managing trials, tiers, custom bundles, and enterprise contracts without hardcoding [https://www.cerbos.dev/features-benefits-and-use-cases/product-packaging].

The pricing structure for Cerbos Hub is based on a "Growth Plan" with a per-principal model. For example, a monthly plan starts at $25 per month for up to 100 monthly principals, with a rate of $0.25 per principal [https://www.cerbos.dev/pricing-build-your-plan]. Users can also opt for yearly billing to save 15%.

Cerbos offers a 3-month free trial for Cerbos Hub without requiring a credit card [https://www.cerbos.dev/pricing-build-your-plan]. Details on "Product Packages & Usage Limits" are available on their legal page, with previous versions also accessible [https://www.cerbos.dev/legal/product-packages].

Hiring & Layoffs

Cerbos Hiring and Layoffs

Cerbos maintains a dedicated "Join Us" section on its website, indicating an active interest in expanding its team [cerbos.dev/join-us]. The company is seeking passionate individuals to contribute to its journey, emphasizing growth and development within the organization [cerbos.dev/join-us]. While specific numbers on recent hiring trends or any layoffs are not publicly detailed, the presence of open roles signals a strategic focus on scaling operations and enhancing capabilities.

Currently, Cerbos has a notable job opening for a B2B Growth Marketer (Enterprise & Developer Audience) [cerbos.dev/join-us]. This role is described as a "rare, high-impact" opportunity, targeting an experienced T-shaped marketer with a background in B2B/B2D enterprise marketing. The emphasis on hands-on execution across multiple marketing channels and B2B tactics suggests a push to expand market reach and engagement, particularly within enterprise and developer communities.

The focus on a B2B Growth Marketer signals Cerbos's strategic intent to drive market penetration and customer acquisition within its target audience. This hiring pattern indicates a company in a growth phase, prioritizing marketing and sales efforts to bring its authorization management platform to a wider range of enterprises, SaaS products, and AI systems [cerbos.dev/about]. The company's continuous news and insights section further highlights its commitment to thought leadership and industry engagement, which a growth marketer would support [cerbos.dev/news].

Leadership

Cerbos Management and Leadership Team

Cerbos is led by its co-founders, Emre Baran and Alex Olivier. Emre Baran serves as the CEO and Co-Founder of Cerbos [cerbos.dev/news/front-end-happy-hour-podcast-leadership-startups-and-gtm-with-emre-baran], having previously co-founded Yonja, Turkey's largest social network [cerbos.dev/news/the-cloud-gambit-podcast-cerbos-ceo-emre-baran-talks-startup-growth-and-shares-cerbos-insights]. His expertise includes insights into scaling businesses, externalized authorization, and navigating the evolving role of a CEO [cerbos.dev/news/front-end-happy-hour-podcast-leadership-startups-and-gtm-with-emre-baran]. Baran frequently shares his insights on startup growth and software development at industry events and podcasts [cerbos.dev/blog/techstrong-tv-decoupling-in-software-development-emre-baran-kube-con-cloud-native-con-europe-2023].

Alex Olivier, also a co-founder, recently advanced to the role of Chief Product Officer (CPO) at Cerbos [cerbos.dev/news/cerbos-appoints-alex-olivier-to-the-role-of-chief-product-officer]. Olivier has been instrumental in leading product development since the company's inception, from its initial open-source authorization layer to the current offering of Cerbos Hub [cerbos.dev/news/cerbos-appoints-alex-olivier-to-the-role-of-chief-product-officer]. Together, Baran and Olivier are available for direct consultations to discuss authorization strategies [cerbos.dev/talk-to-the-founders].

Both co-founders have been actively involved in public discussions and interviews, detailing Cerbos's mission, its approach to authorization, and its focus on developer experience [cerbos.dev/news/the-cube-simplifying-authorization-for-a-seamless-developer-experience]. They emphasize the company's commitment to simplifying authorization for enterprise software and AI systems [cerbos.dev/news/revolutionizing-access-control-with-cerbos]. Their combined leadership guides Cerbos in providing an authorization management platform designed for complex, distributed environments and regulated industries [cerbos.dev/about].

Financials

Cerbos Financial Performance, Fundraising, M&A

Cerbos (cerbos.dev) has demonstrated strong financial growth and successful fundraising efforts since its inception. The company launched in 2021 with a mission to simplify authorization for developers and has since secured a total of $11 million in funding. This includes an initial seed funding round announced in November 2021 [https://www.cerbos.dev/news/announcement-cerbos-seed-funding-round] and an extended seed funding round of $7.5 million in April 2023, coinciding with the launch of Cerbos Cloud in private beta [https://www.cerbos.dev/news/cerbos-cloud-launch-cerbos-secures-7-5-million-extended-seed-funding].

Cerbos offers a tiered pricing model for its Cerbos Hub service, starting from $25 per month and extending to $933 per month for more comprehensive plans [https://www.cerbos.dev/pricing]. The pricing is based on the number of Monthly Active Principals requiring authorization decisions. The company's business model leverages its open-source foundation, providing value-added services and operational streamlining for enterprises that choose to utilize their managed solutions rather than self-hosting [https://www.cerbos.dev/news/the-business-of-open-source-podcast-from-open-source-to-enterprise-alex-olivier-on-cerbos-evolution].

In terms of financial health and growth indicators, Cerbos experienced a significant fourfold increase in demand for its authorization management platform in 2025. This growth is further validated by its recognition by Gartner as an authorization management platform vendor [https://www.cerbos.dev/blog/year-in-review-2025]. The company has consistently emphasized its commitment to enterprise and regulated environments, focusing on extending its authorization foundation to meet the needs of these demanding sectors.

Partnerships

Cerbos Partnerships, Clients and Vendors

Cerbos has established itself as a key partner for enterprises seeking robust authorization solutions, serving a diverse clientele that includes notable organizations. For instance, Utility Warehouse, an FTSE 250 Index company, successfully replaced a cumbersome in-house authorization system with Cerbos, gaining enhanced reliability and transparency across 4,500 services and millions of non-human identities (NHIs) in a move towards a Zero Trust model cerbos.dev/customers/utility-warehouse, cerbos.dev/customers/utility-warehouse/non-human-identities. Another significant client, 4G Capital, a digital bank, achieved substantial cost savings, replacing their legacy authorization service and saving a quarter-million dollars annually cerbos.dev/customers/4g-capital. Additionally, BarrierSystems integrated Cerbos into their smart vehicle access gates, improving user experience and cutting internal costs by 15% cerbos.dev/customers/barriersystems, while Nook leveraged Cerbos to build a scalable, secure, and extensible roles and permissions system, empowering business owners to manage authorization without developer intervention www.cerbos.dev/blog/how-cerbos-helped-nook-build-secure-extensible-roles-permissions.

Cerbos extends its reach through strategic technology integrations, particularly in the burgeoning field of AI. A significant partnership is with Tailscale for fine-grained authorization of AI agents through Aperture by Tailscale www.cerbos.dev/blog/fine-grained-authorization-for-ai-agents-with-cerbos-and-aperture-by-tailscale. This integration allows Aperture, Tailscale's AI gateway, to intercept AI agent tool calls, extract identity and parameters, and forward them to a Cerbos PDP for policy-driven authorization before reaching the Large Language Model (LLM) docs.cerbos.dev/cerbos-hub/integrations-aperture. This collaboration addresses the critical need for defining and revoking AI agent access with policies in seconds, preventing over-permissioned access and ensuring compliance.

Beyond AI, Cerbos offers a robust ecosystem of integrations with essential identity and access management (IAM) components. It provides authorization for Thales SafeNet Trusted Access for fine-grained access control www.cerbos.dev/ecosystem/cerbos-thales. The platform also supports integrations with various identity providers (IdPs), including mapping Auth0 Actions, Organizations, and roles to Cerbos policy inputs, utilizing Authentik property mappings to shape token claims for policies, and leveraging AWS Cognito user pool groups and custom attributes as policy inputs www.cerbos.dev/ecosystem/cerbos-thales. These integrations enable seamless operation within existing enterprise IAM stacks, complementing authentication and provisioning services by governing actual resource-level actions at runtime.

Further enhancing its ecosystem, Cerbos integrates with Agent Gateway, an open-source proxy for AI agent communication. This integration allows the enforcement of fine-grained Cerbos authorization policies on MCP, A2A, and LLM traffic flowing through Agent Gateway, which natively supports the Envoy `ext_authz` protocol via its `extAuthz` policy www.cerbos.dev/ecosystem/agent-gateway. This comprehensive approach solidifies Cerbos's position as a versatile authorization management platform, capable of securing diverse identity types, from users and service accounts to non-human identities and AI agents, across varied architectural deployments including cloud, on-premise, or air-gapped environments.

Events

Cerbos Event Participations

Cerbos regularly participates in and hosts various events to advance the discussion around authorization. They hosted a webinar on “How to Choose the Right AuthZ and AuthN Deployment Model” on April 17, 2025, guiding attendees through deployment model selection for security and control [https://cerbos.dev/ebooks-webinars/choosing-the-right-authentication-and-authorization-deployment]. Another webinar, “Mastering Authorization in Fintech,” took place on May 6, 2025, focusing on building dynamic and regulation-compliant access control at scale in the FinTech sector [https://cerbos.dev/ebooks-webinars/mastering-authorization-in-fintech]. Additionally, Cerbos held a webinar to "Simplify Access Control in Your Apps With Cerbos Hub," addressing technical debt and security vulnerabilities associated with managing authorization policies [https://www.cerbos.dev/news/join-our-upcoming-webinar-simplify-access-control-in-your-apps-with-cerbos-hub-eliminate-months-of-coding].

Cerbos maintains an active presence at industry conferences. At Identiverse 2026, a Cerbos representative had a booth, ran a raffle, and spoke three times, including as a co-chair of the OpenID AuthZEN working group [https://www.cerbos.dev/blog/identiverse-2026]. They also participated in a panel at an OpenID Foundation workshop discussing how enterprise specifications like AuthZEN, Shared Signals, SCIM Events, and IPSIE integrate as a stack [https://www.cerbos.dev/blog/authzen-shared-signals-scim-events-ipsie]. Earlier, in 2025, a Cerbos CPO and Co-Founder, Alex Olivier, and Senior DevRel Manager, Dan Maher, delivered a webinar on the “Business Case for Externalized Authorization,” exploring challenges businesses face with authorization as they expand [https://cerbos.dev/blog/recap-of-webinar-business-case-for-externalized-authorization].

Cerbos also engages with the Cloud Native community. Alex Olivier, Cerbos Product Lead, presented insights into modernizing authorization in a Cloud Native Computing Foundation (CNCF) live demo, comparing traditional RBAC with modern approaches [http://cerbos.dev/news/cloud-native-live-modernizing-authorization]. Furthermore, at ISC2 Security Congress 2025 in Nashville, a Cerbos representative joined a panel to discuss automating IAM for compliance, security, and business agility, alongside experts from Apple and Google [https://www.cerbos.dev/blog/automating-iam-for-compliance-security-and-business-agility]. Their commitment to industry standards and collaboration was further demonstrated at the European Identity Conference 2025, where they co-presented on the lack of common approaches to authorization compared to the standardized nature of authentication [https://www.cerbos.dev/blog/authzen-standards-based-authorization-for-enterprises].

Frequently Asked Questions

What is Cerbos's core product strategy, given its dual offering of Cerbos PDP and Cerbos Hub?

Cerbos employs a freemium strategy, offering the open-source Cerbos PDP for developers to implement authorization logic, while monetizing through Cerbos Hub. Cerbos Hub provides an end-to-end authorization platform with centralized policy management, data enrichment, and advanced features for enterprises requiring comprehensive authorization lifecycle management and operational streamlining.

How does Cerbos position itself in the evolving landscape of AI agent security and control?

Cerbos is strategically positioning itself as a critical enabler for securing AI agents. Its platform defines access boundaries before deployment and allows rapid revocation of access through policy, as demonstrated by its integration with Tailscale's Aperture for fine-grained authorization of AI agents and its support for Agent Gateway.

What does the recent hiring focus on a B2B Growth Marketer indicate about Cerbos's strategic priorities?

The hiring of a B2B Growth Marketer (Enterprise & Developer Audience) signals Cerbos's strategic intent to expand market penetration and customer acquisition within enterprise and developer communities. This role emphasizes hands-on execution across multiple marketing channels, indicating a push to scale operations and enhance capabilities for its authorization management platform.

What financial indicators suggest Cerbos is in a growth phase?

Cerbos has secured a total of $11 million in funding, including an extended seed round of $7.5 million in April 2023. The company experienced a fourfold increase in demand for its platform in 2025 and was recognized by Gartner, indicating strong financial growth and market validation.

How does Cerbos differentiate its authorization platform from competitors like AuthZed (SpiceDB) and Open Policy Agent (OPA)?

Cerbos provides a more opinionated and complete authorization solution specifically built for modern applications, offering an authorization layer that integrates into application code with support for various models like RBAC, ABAC, ReBAC, and PBAC. While AuthZed focuses on relationship-based access control (ReBAC) inspired by Google Zanzibar, and OPA is a general-purpose policy engine, Cerbos positions itself as a streamlined alternative for scaled authorization needs.

What is the strategic significance of Cerbos's frequent participation in industry events and its co-chair role in the OpenID AuthZEN working group?

Cerbos's active presence at industry conferences like Identiverse and its leadership in the OpenID AuthZEN working group demonstrate its commitment to thought leadership, industry standards, and collaboration. This engagement helps shape the future of authorization, builds credibility, and expands its influence within the security and identity communities.

What does the shift of Alex Olivier to Chief Product Officer signify for Cerbos's product direction?

Alex Olivier's promotion to Chief Product Officer signifies a continued focus on product innovation and development, particularly for Cerbos Hub. Having led product development since inception, his leadership ensures the platform evolves to meet the needs of complex, distributed environments and regulated industries, extending from the open-source authorization layer to the comprehensive Hub offering.

How does Cerbos's customer base, including Utility Warehouse and 4G Capital, reflect its target market and value proposition?

Cerbos's customer base, including FTSE 250 company Utility Warehouse and digital bank 4G Capital, reflects its focus on large enterprises and regulated industries with complex authorization requirements. These case studies highlight its value proposition in replacing cumbersome in-house systems, achieving significant cost savings, enhancing reliability, and enabling moves towards Zero Trust models.

What is Cerbos's strategy for integrating with existing enterprise IAM stacks?

Cerbos integrates with essential identity and access management (IAM) components such as Thales SafeNet Trusted Access and various identity providers like Auth0, Authentik, and AWS Cognito. This strategy allows Cerbos to complement existing authentication and provisioning services by providing fine-grained, resource-level authorization at runtime, fitting seamlessly into diverse enterprise environments.

How does Cerbos's pricing model for Cerbos Hub align with its target audience and growth strategy?

Cerbos Hub's tiered pricing, based on Monthly Active Principals and ranging from $25 to $933 per month, aligns with its target audience of enterprises and SaaS products. This usage-based model makes the service accessible for smaller operations while scaling up for larger, more complex deployments, supporting Cerbos's growth strategy by offering both value-added services and operational streamlining.

Powered by ForesightIQ · Competitive intelligence from digital exhaust