Back

The NHI Iceberg: Veza NHI Security brings visibility and actionability of the hidden risks across the enterprise

In today’s complex IT environments, security is no longer just about managing human access. A new and rapidly growing population of non-human identities (NHIs)—such as service accounts, agents, API keys, and machine identities—now outnumbers human users. These NHIs are the backbone of modern applications, but what most organizations see is just the tip of the iceberg. The vast majority of these identities, along with their permissions and potential risks, lie hidden below the surface, creating a massive and dangerous blind spot.

At Veza, we are on a mission to illuminate the full picture, and we’re excited to share our progress.

Enterprise to Understand the Entire Iceberg

We are proud to announce that Veza now supports over 90 different types of NHI entities across all our integrations. This broad coverage gives you a comprehensive view of your entire NHI landscape, from the visible tip to the depths below. But we’re not stopping there. By the end of this year, we plan to support over 150 NHI entities, ensuring you have the visibility you need to secure your entire environment.

Here’s a summary of the NHIs we support across some of our most popular integrations:

Cloud Platforms

  • AWS: Our comprehensive AWS support includes a wide range of NHIs, such as AwsIamUser, EC2Instance, LambdaFunction, and many more, giving you a complete picture of your cloud security posture.
  • Azure: We offer extensive coverage for Azure, including AzureADEnterpriseApplication, AzureVirtualMachine, AzureManagedIdentity, and other NHIs, to help you secure your Microsoft cloud environment.
  • GCP: We offer extensive coverage for Google Cloud Platform, including key NHIs from GoogleCloudServiceAccount and GoogleCloudRun to GoogleCloudComputeVirtualMachine.

SaaS & DevOps

  • Salesforce: We provide visibility into SalesforceConnectedApplication and SalesforceUser NHIs, helping you secure your critical customer data.
  • Github: Veza helps you secure your source code and development pipelines with support for GithubApp, GithubDeployKey, GithubPersonalAccessToken, and more.
  • Additional NHIs across Microsoft ecosystem (SharePoint, etc.), Linux Servers, Windows Servers, Oracle, etc.

Databases

  • Snowflake: Veza helps you manage your data security with support for SnowflakeSecret and SnowflakeUser NHIs.
  • SQL Server: Secure your Microsoft databases with visibility into NHIs like SqlServerLogin and SqlServerDatabaseUser.
  • PostgreSQL: Manage access in your open-source databases with support for PostgreSQLLogin and PostgreSQLUser.
  • Oracle DB: Get a handle on your critical enterprise data by managing OracleUser identities and their permissions in Veza.

Powerful Features to Chart the Depths

Beyond simple discovery, Veza offers a suite of powerful features designed to help you manage and control your NHIs:

  • Human-to-NHI owner: Easily identify the human owner of any NHI, establishing clear lines of responsibility and accountability.
  • NHI age: Track the age of your NHIs to identify and retire old or unused identities that could be a security risk.
  • NHI span (blast radius): Understand the full scope of an NHI’s permissions and potential impact in the event of a compromise.
  • UARs for NHIs: Conduct user access reviews for NHIs to ensure that they have the appropriate level of access.
  • Time Range: Analyze new NHIs over the last 90 days or 45 days or just 15 days to detect anomalies and potential threats.
  • Native NHI Product Designs across all our products : Instantly find and investigate NHIs directly from Access AI Search, the first step in your security workflows.

Looking Ahead

The world of NHIs is constantly evolving, and so is Veza. We have a bold and exciting roadmap for NHI, with a host of new features and updates planned to roll out throughout our weekly releases this year. Stay tuned for more announcements as we continue to enhance our NHI capabilities.

The Future of Identity Security is Here

NHIs are inherent to AI Agents and are a critical part of the modern IT landscape, and they require a new approach to security. With Veza, you can finally see the full NHI iceberg and protect your organization from the hidden threats that lie beneath the surface.Ready to learn more? Request a demo today and see how Veza can help you reveal and secure your entire non-human identity landscape.

Table of Contents