Spera Security
Last updated: Jul 31, 2026
Israeli identity-security company that developed Identity Security Posture Management (ISPM) for discovering, prioritizing, and reducing identity risk across identity providers, SaaS, cloud, and infrastructure applications. Spera was acquired by Okta in February 2024 and its technology is now associated with Okta Identity Security Posture Management.
Visit WebsiteCompany Overview
Spera Security built an identity-security posture management platform for organizations whose users, contractors, service accounts, permissions, and authentication controls span multiple identity providers, SaaS applications, and cloud environments. The product was designed to create a consolidated view of the identity attack surface rather than treating each IAM, IGA, PAM, or SaaS security tool as a separate silo. Its value proposition was to identify risky identities and configurations, add context about permissions and activity, prioritize issues by likely impact, and help security teams remediate gaps such as dormant accounts, excessive access, incomplete offboarding, or administrators without appropriate multifactor authentication.
The technology matters because identity has become a control plane for cloud and enterprise operations. Spera's approach sat between conventional identity administration and security operations: it used integrations and analytics across Okta and third-party identity providers, SaaS systems, and infrastructure applications to measure posture and expose attack paths that are difficult to see from a single directory. That is distinct from simply issuing credentials or logging authentication events. The relevant capability set includes identity inventory, permission and entitlement analysis, identity attack-surface management, posture scoring, risk prioritization, and remediation workflow. Public product material also positioned the platform as complementary to existing IAM and IGA investments rather than a replacement for every underlying control.
Commercially, Spera entered a crowded but expanding identity-security market. The company announced a $10 million seed round led by YL Ventures in 2023 and described early customer results, including a claim that partners resolved a large share of critical identity issues within weeks; that outcome is company-reported and should not be treated as independently verified traction. The acquisition is the strongest public commercialization signal: Okta announced the transaction in December 2023, completed it on February 1, 2024, and disclosed $58 million in acquisition-date cash consideration in its SEC filing. Okta subsequently described the service as Identity Security Posture Management, formerly Spera, indicating that the product survived as a defined capability inside a larger enterprise platform.
Competitive pressure comes from established identity platforms expanding into posture, threat detection, and entitlement analytics, as well as specialist vendors such as Veza, Silverfort, Saviynt, SailPoint, and Zscaler. Spera's defensible advantage was therefore less likely to be a unique security primitive than a focused cross-platform identity graph, fast time to useful risk findings, and a product narrative that connected visibility to remediation. Okta ownership supplied distribution, integrations, and enterprise trust, but also reduced Spera's independence and makes current product scope, roadmap, customer retention, and engineering continuity questions for diligence.
The dual-use case is credible but bounded. The same identity inventory, least-privilege analysis, MFA and offboarding checks, and cross-cloud posture visibility can protect defense contractors, government suppliers, and mission-support systems from account takeover and privilege abuse. Identity compromise is relevant to national-security environments, but the public record does not establish classified deployments, government contracts, or defense-specific certifications. The appropriate strategic conclusion is that Spera represents a useful identity-security capability with defense adjacency, not a proven defense platform. Its primary current relevance is as an acquired component of Okta's identity-security portfolio and as a case study in Israeli cybersecurity commercialization.
Dual-Use Assessment
Spera's identity-security posture capabilities have substantive commercial and security-sector applicability: inventorying identities and entitlements, detecting excessive privilege, checking MFA and offboarding controls, and prioritizing identity attack paths are relevant to enterprises and to defense contractors or government suppliers. The defense case is adjacent rather than proven because public sources do not establish classified deployments, government contracts, or defense certifications.
Strategic Fit Assessment
Spera is not an independent strategically relevant startup-screening signal because Okta completed its acquisition in February 2024. The acquisition and Okta's continued ISPM product labeling validate the problem area and provide evidence of strategic value, but they do not justify treating Spera as an available standalone strategic-screening signal. Diligence should focus on product continuity, adoption inside Okta, competitive differentiation, and whether the acquired technology produces measurable identity-risk reduction.
Strategic Value to U.S.-Israel Alliance
Spera is strategically relevant as an identity-security capability that links fragmented IAM, SaaS, and cloud telemetry to prioritized remediation. That visibility can support zero-trust and least-privilege programs in commercially important and security-sensitive environments. Its strongest evidence is Okta's completed acquisition and subsequent use of the Spera name for ISPM; public evidence does not support stronger claims about classified or government deployment.
Key Technologies
- Identity Security Posture Management (ISPM)
- Identity attack-surface management
- Cross-platform identity and entitlement inventory
- Permission and least-privilege risk analytics
- Identity-provider, SaaS, and cloud integrations
- Identity Threat Detection and Response (ITDR) support
Use Cases & Applications
- Discovering users, service accounts, permissions, and actions across identity silos
- Prioritizing excessive privilege and risky entitlement combinations
- Finding dormant accounts and incomplete contractor or employee offboarding
- Checking MFA coverage and risky administrator configurations
- Reducing identity attack surface across AWS, GCP, Salesforce, GitHub, and related applications
- Supporting identity-security audits and remediation programs
- Assessing identity controls in defense contractors and other high-consequence environments
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.
This record lists 6 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- Spera company page Official company page describing ISPM, identity-risk reduction, Tel Aviv headquarters, founders, and the company's integration into Okta.
- Okta acquisition announcement Okta announced and later updated the completed acquisition; it describes Spera's identity security posture and attack-surface-management focus.
- Okta fiscal 2025 Form 10-K SEC filing states that Okta completed the Spera acquisition on February 1, 2024 and discloses $58 million of acquisition-date cash consideration.
- Spera seed announcement Official Spera material describing the identity-security problem, product positioning, and company-reported early customer outcomes.
- Okta ISPM support documentation Okta documentation identifies ISPM as formerly Spera and describes its identity-posture and risk-prioritization scope.
- Official website
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Investor Lens
What this entry is
Acquired asset
Why it may matter
Spera Security may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.
How an independent investor should read this
Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify technical claims
- Verify regulatory/export-control issues
Main investor questions
- Is this entry a benchmark, buyer, ecosystem node, acquired asset, or strategic reference rather than a live startup opportunity?
- What does this reference clarify about buyers, sector structure, public-market context, or strategic demand?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Spera Security's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- Is the company a live venture opportunity, a mature strategic reference, an acquired asset, or primarily a market-mapping entry?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.