Picture your first day as a software engineer at a company with 5,000 employees. Someone in IT creates your account. From then on, every application you open asks the same question: is this really you, and are you allowed in here? The company has to answer that question for every employee and every contractor. More and more, it also has to answer it for every piece of software that talks to another piece of software. This is the identity business. The industry calls it identity and access management, or IAM.
You have used its products every day without naming them:
- the single login that opens many apps, called single sign-on (SSO)
- the code on your phone that you type after your password, called multi-factor authentication (MFA)
- the certificate that lets your browser trust your bank's website, part of what is called public key infrastructure (PKI)
This Market Segment is about the companies that sell these products. Their buyers are the IT and security teams of other companies, protecting their own staff and systems. Proving who a customer is, rather than an employee, is covered in Market Segment 4.3, KYC, identity verification and fraud prevention.
Every company named here has posted software engineering jobs in India. Famous companies that don't actively hire software engineers in India are left out.
This Market Segment runs from the front door inwards, in five sub-segments:
The login: who you are, and how you prove it.
The rights behind the login: which of the company's thousand systems you may use. Access is granted when you join and, which is harder, taken away when you leave.
The keys to the kingdom: the accounts that can do anything, used by administrators and by machines. This is where a break-in does its damage.
Certificates and keys: how machines trust each other without a person present.
The password on your own laptop: the password manager, the consumer version of everything above.
Identity from the front door inwards: the login (Okta, Ping Identity), the rights behind it (SailPoint, Saviynt), the accounts that can do anything (CyberArk), and the certificates and keys that let machines trust each other (DigiCert, Sectigo). The password manager on your own laptop (Enpass, SplashData) is the consumer version of all of it.
The login
Access management: single sign-on (SSO), multi-factor authentication (MFA), and login services for the apps a company builds
Back to your first day at the company from the start of this Market Segment. You open your email, then the HR portal, then the code repository, and you sign in only once. That works because of one system that every application trusts, called an identity provider. You sign in to it, and it vouches for you everywhere else. This is single sign-on.
Single sign-on. You sign in once to an identity provider such as Okta or Ping Identity, and it vouches for you to every other application: email, the HR portal and the code repository. A code from your phone is the second proof, called multi-factor authentication, so a stolen password alone is no longer enough.
Then it asks for a code from your phone, a second proof on top of your password. This is multi-factor authentication. A password stolen by a phishing email is no longer enough on its own. (More on those emails in Market Segment 4.1, Email security and anti-phishing.) In time, the phone may replace the password altogether.
Oktaturned the identity provider into a product category of its own. It is by far the largest company in this Market Segment. It has engineers in Bengaluru.
Okta for Developersis Okta's other business. It sells login APIs that developers build into their own apps, so they don't have to build a login system themselves. Okta bought this business as a company called Auth0.
Ping Identityis the alternative built for large enterprises. It has merged with ForgeRock, and the two now have one owner. It has engineering in Bengaluru.
RSA Securityis the oldest name here. For a generation of banks and governments, its SecurID token defined the second factor. The token is a small key-ring device that shows a new code every minute. RSA now sells the software version.
OneSpanin Delhi NCR, still makes the hardware devices that banks hand to customers to generate login codes. It also sells cloud-based authentication and electronic signatures.
WatchGuardis here for AuthPoint, the multi-factor product it sells with its network equipment. (More on it in Market Segment 4.5, Network security, firewalls and SASE.)
Two companies here prove identity, but not for an employer. They mark the border with Market Segment 4.3, KYC, identity verification and fraud prevention.
SentiLinkscores whether a new account belongs to a real person or to a synthetic identity. A synthetic identity is a fake person, stitched together from pieces of real people's stolen details. (More on it in Market Segment 19.2, Fraud prevention, AML and regtech, in Industry Vertical 19, Banking and regtech.)
Meazure Learningchecks that the person sitting an online exam is the candidate who registered for it. (More on it in Market Segment 42.1, Test prep and exam coaching platforms, in Industry Vertical 42, Edtech.)
The rights behind the login
Identity governance and administration: joiners, movers, leavers, access reviews, and the directory underneath
Back to your first day. Signing in is the easy half. The hard half is deciding what you may open once you are in. A company with 5,000 people and 1,000 applications has millions of separate permissions. They were granted one by one over years, and nobody knows who still needs which.
Identity governance is the software that answers this. The HR system tells it who has joined, moved or left.
- When you join, it creates your accounts.
- When you move to another team, it changes your access.
- When you leave, it removes your access.
Joiners, movers and leavers. The HR system tells identity governance software, such as SailPoint or Saviynt, who has joined, moved or left, and it creates, changes or removes that person's access. Every quarter it also makes managers confirm who still needs which access, in an access review.
The industry calls these joiners, movers and leavers. Every quarter, the software also makes managers confirm that each person still needs their access, because the auditors will ask. This is called an access review. (More on the audit in Market Segment 4.14, Governance, risk and compliance (GRC).)
SailPointis the specialist that leads this category. Its Indian engineering is in Pune.
Saviyntis a newer rival built for the cloud, with its own centre in Bengaluru.
One Identitysells the same governance, with privileged access and single sign-on alongside it. (Privileged access is the next sub-segment.) One Identity is the identity business of Quest Software.
Quest Softwareis here for its own tools for the thing underneath all of this: Microsoft's Active Directory. Active Directory is the directory, the master list of users, computers and permissions, that most large companies still run their identities on. Quest's tools protect it, move it to new systems, and recover it after an attack.
Two newer companies attack the same problem with a graph of who can reach what:
Vezanow part of ServiceNow, maps every permission across every system. So the question "what can this account actually do?" finally has an answer. (More on ServiceNow in Market Segment 16.1, IT service management (ITSM) and IT operations software, in Industry Vertical 16, IT management and workplace tools.)
Oleriaautomates granting and removing access.
Two more companies each work in their own way:
Simeioruns identity programmes for other companies as a managed service. Its own staff run the work for the client, rather than only selling the client software.
Exostarsells identity and access for the defence and aerospace supply chain. A prime contractor is the large company that builds the aircraft and hires the suppliers. When a supplier's engineer logs in to a prime contractor's systems, the rules require that login to be controlled and recorded. (More on this industry in Market Segment 39.1, Aircraft and aerospace systems makers, in Industry Vertical 39, Aerospace, defence and space.)
The identity that is not a person.
For every employee, a company now has dozens of identities that belong to software: service accounts, API keys and, lately, AI agents acting on someone's behalf. A service account is an account used by a program, not a person. None of these joins, moves or leaves the way a person does. Governing them is the newest problem in this Market Segment. Veza, Oleria, Saviynt and SailPoint all sell products for it.
You're reading as a guest. Sign in free to follow links for five minutes, once an hour.
Sign in
The keys to the kingdom
Privileged access management, secrets, and the identities of machines
Back to you, a year after your first day. A problem on the production database needs fixing, and for that you need an account that can change anything. Such accounts are called privileged accounts. Other examples are the root login on a server, and the service account that runs the payroll job.
An attacker who gets past the login goes looking for these accounts first. So a separate product exists, called privileged access management, or PAM. It locks these accounts in a vault and hands them out for one session at a time. It records what was done with them. Afterwards, it changes the password, so nothing written down still works.
Privileged access management. An engineer who needs an account that can change anything asks the vault, such as CyberArk's, which hands the account out for one session. Every action is recorded, and the password is changed afterwards, so nothing written down still works.
CyberArkbuilt this product and still defines it. It has been part of Palo Alto Networks since 2026, and has engineers in Hyderabad. It has also bought its way into machine identity, the certificates and keys of the next sub-segment. So the same vault now holds secrets for software as well as for people. Secrets are the passwords and API keys that programs use to log in to each other. (More on Palo Alto Networks in Market Segment 4.5, Network security, firewalls and SASE.)
Unosecuris a young company doing the cloud version. It watches every identity, human and non-human, across AWS, Microsoft Azure and Google Cloud. It looks for any permission that is wider than it needs to be.
One company here does the same job for a different kind of key:
Liminalholds the cryptographic keys to institutions' crypto wallets. Whoever holds such a key can move the money. So Liminal splits each key between several parties, and no one person can move the money alone. It is privileged access for an asset that is nothing but a key. (More on it in Market Segment 17.7, Crypto and digital assets, in Industry Vertical 17, Payments.)
Certificates and keys
Public key infrastructure (PKI) and certificate lifecycle management
Every secure website, every device that proves to a network what it is, and every piece of signed software rests on a certificate. A certificate is a digital file that proves a machine or a program is what it claims to be. It is issued by a certificate authority, a company that browsers and operating systems have agreed to trust. The whole system of certificates, keys and authorities is called public key infrastructure, or PKI.
Back to the company from the start of this Market Segment. It has hundreds of thousands of certificates, and each one expires. When one expires, it takes a website or a service down with it. So finding and renewing them all has become a product of its own, called certificate lifecycle management.
DigiCertis one of the largest certificate authorities in the world. Bengaluru is its largest engineering site outside the United States. Its business has shifted from selling certificates to selling the platform that finds, renews and manages them.
Sectigoits rival, is a certificate authority in its own right, with engineers in Chennai. It sells the same lifecycle management for certificates from any authority.
One company here comes from physical security:
HIDmakes the badges and readers on office doors. It also runs public key infrastructure, multi-factor authentication and identity verification. It has engineers in Chennai and Bengaluru. It is the clearest case of the door badge and the login becoming one credential. (More on it in Market Segment 4.15, Physical security, surveillance and trust and safety.)
The certificate that lasts forty-seven days.
Public certificates used to last about a year. Under rules agreed by the browser makers and the certificate authorities, that limit is shrinking in steps, down to 47 days by 2029. Renewal turns from a yearly chore into something no person can do by hand. Automation is now the whole product, and DigiCert and Sectigo are the two companies in this Market Segment built for it. Further ahead, today's encryption will have to be replaced with quantum-safe algorithms, designed so that future quantum computers cannot break them. That change also runs through the same companies.
The password on your own laptop
Consumer password managers
Back to you, at home this time, on your own laptop. The person's version of everything above is the password manager. It keeps one vault, locked with one master password, and creates a different password for every site.
Two small ones are covered here:
Enpassfrom Delhi NCR, keeps the vault on the user's own device and storage, not on Enpass's own servers.
SplashDatafrom California with engineers in Pune, makes SplashID, one of the oldest names in this category.
The large consumer names in this business are not covered in this Market Segment.
That is the whole life of your identity at work, from the account created on your first day to the access removed on your last. In between, the most powerful accounts stay locked in a vault, and certificates prove who the machines are.