SailPoint to Buy Entro Security for a Reported $200 Million
The acquisition adds non-human identity and secrets management to SailPoint's governance platform — a gap that's become increasingly hard to ignore.

SailPoint has agreed to acquire Entro Security, an Israel-based firm focused on non-human identity (NHI) and credential security. The reported price tag: $200 million.
Non-human identities — service accounts, API keys, OAuth tokens, machine credentials — now outnumber human ones inside most enterprise environments by an order of magnitude. They also rotate less often, get audited less rigorously, and show up in breach post-mortems with depressing regularity. Entro's platform is built to discover, classify, and monitor exactly these assets.
SailPoint has historically anchored its identity governance portfolio around human users: provisioning, access reviews, role management. Bringing Entro in extends that perimeter to the credential types that attackers increasingly target first. Stolen API keys and service account tokens require no phishing, no malware, and no social engineering. They just work — until someone notices they shouldn't.
The deal fits a clear pattern in the identity security market. Vendors that built their names on human IAM are acquiring their way into secrets management and NHI coverage rather than building from scratch. That makes sense given the speed at which cloud-native architectures have multiplied machine credentials across CI/CD pipelines, container workloads, and SaaS integrations.
Financial terms have not been confirmed by either company in an official statement at time of publication. No regulatory filings surfaced in time for this story. Both SailPoint and Entro declined to comment on the reported figure.
Entro was founded in 2021 and had raised funding from investors including Cerca Partners and Microsoft's venture arm M12. Its core product maps secrets sprawl across vaults, code repositories, and cloud providers, then flags risky exposures — hardcoded credentials, overprivileged tokens, secrets shared across environments.
For SailPoint customers, the practical upside is visibility into a credential class that most identity governance tools simply ignore. Whether integration is tight or cosmetic will depend on how SailPoint handles the engineering work post-close.
No close date has been announced.



