SailPoint to Buy Entro Security for a Reported $200 Million

The acquisition adds non-human identity and secrets management to SailPoint's governance platform, a gap that's become increasingly hard to ignore.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 2 min read
SailPoint to Buy Entro Security for a Reported $200 Million
Share

Key points

  • SailPoint has agreed to acquire Israel-based Entro Security for a reported $200 million.
  • Entro specialises in non-human identity (NHI) and credential security, covering API keys, service account tokens and OAuth tokens.
  • Neither company has confirmed financial terms; both declined to comment on the reported figure.
  • SailPoint has historically focused on human identity governance; Entro extends that to machine credentials.
  • Whether the integration runs deep or stays cosmetic depends on engineering decisions still to come.

What is Entro and why does SailPoint want it?

Entro, founded in 2021 and backed by Cerca Partners and Microsoft's venture arm M12, maps credential sprawl across code repositories and cloud providers, then flags hardcoded secrets and overprivileged tokens. SailPoint built its name on human identity governance: provisioning, access reviews, role management. Entro fills the machine-credential side, which most governance platforms have quietly left blank.

Non-human identities outnumber human ones inside most enterprise environments by an order of magnitude. They rotate less often, get audited less rigorously, and turn up in breach post-mortems with depressing regularity. Our 28 May story on a Nightwing contractor who left AWS GovCloud keys on GitHub is a clean example of what unmanaged secrets cost in practice.

Should you worry about stolen machine credentials?

Stolen API keys and service account tokens need no phishing and no social engineering. They just work, until someone notices they shouldn't. That simplicity is exactly why attackers hit them first.

The deal fits a pattern: vendors built on human IAM are buying into secrets management rather than building it. Cloud-native architectures have multiplied machine credentials across CI/CD pipelines and container workloads faster than internal teams can track. Our 4 June story on Offroad's $7 million bet on autonomous identity management showed how acute the gap has become.

What does this mean for SailPoint customers?

For existing SailPoint customers the practical upside is visibility into a credential class that most identity governance tools ignore entirely. That visibility is worth having. How much it's worth depends on how tightly SailPoint folds Entro's detection into its core workflows after the deal closes, and no close date has been announced.

Financial terms remain unconfirmed by either company. No regulatory filings surfaced before publication.

© 2026 Threat Vectr