Start with Identity
IGA

Saviynt

Founded 2010El Segundo, CA, USAPrivateScore 4.4/5Evaluated 2026-09-20Website ↗

Capability scores

Methodology →
Authentication
3.0
SSO & Federation
3.0
Authorization
4.0
Lifecycle & Provisioning
4.5
MFA & Passwordless
2.5
Governance & Audit
4.5
Developer Experience
3.5
Deployment Flexibility
3.5
Pricing Transparency
2.5
Support & Ecosystem
4.0

Scored 0–5 against a published rubric. Independent analysis, no vendor sponsorship.

Overview

Saviynt is a cloud-native identity governance (IGA) platform and one of the two names, alongside SailPoint, on most enterprise governance shortlists. Its Identity Cloud spans IGA, Application Access Governance, privileged access, non-human identity, just-in-time access and identity security posture management in one SaaS platform rather than a suite of acquired parts.

It is well capitalised. In December 2025 it raised 700 million dollars in a KKR-led Series B at roughly a 3 billion dollar valuation, and reports 600 or more enterprise customers, over 20 percent of the Fortune 100, and 100 million identities secured.

What it is good at

Depth of governance in a single platform. Application Access Governance handles fine-grained separation-of-duties analysis inside ERP systems, which is where generalist IGA tools usually stop, and the cross-application risk model is genuinely strong for SAP-heavy and regulated environments. The AI agent work is ahead of the category: Identity Security for AI shipped in March 2026 with agent discovery and registration, followed in June by Intent-Aware Runtime Authorization, which evaluates what an agent is trying to do rather than only who it is.

The security record is a quiet strength. Two CVEs in the vendor's entire NVD history, both from 2022 and both on the legacy self-managed line, with nothing in CISA KEV.

Where it falls short

Pricing is opaque even by enterprise IGA standards: three named tiers with no figures, no licensing basis, no minimums.

The FedRAMP picture needs care. Saviynt holds Moderate authorization dating to 2019 with five agency reuses, while a separate High package has been in process since August 2026 with zero authorizations. Several marketing pages claim DoD Impact Level 5 readiness, which the marketplace record does not support. Federal buyers should verify against the package they will actually consume.

Deployment is SaaS only, so air-gapped and strict on-premises requirements rule it out, and implementations remain substantial projects.

Pricing

Quote-only, via sales or an AWS Marketplace private offer, across Essentials, Pro and Premium. Model the all-in cost with our TCO calculator, and budget for implementation.

Best for, and who should look elsewhere

Choose Saviynt for large regulated enterprises needing deep application-level governance, especially with ERP separation-of-duties requirements, or where agentic AI governance is a near-term need. Compare SailPoint vs Saviynt before deciding. Look at ConductorOne or Lumos for faster, lighter deployments, or Veza if the problem is visibility rather than lifecycle.

Bottom line

The strongest cloud-native IGA platform for complex regulated enterprises, now heavily funded and ahead of peers on AI agent governance, let down by pricing opacity and an overstated federal posture.

Saviynt: frequently asked questions

How much does Saviynt cost?
Saviynt publishes no list pricing. Its pricing page names three tiers, Essentials, Pro and Premium, with no dollar figures, no stated licensing basis, no minimums and no free trial for the core platform. The AWS Marketplace listing for Saviynt Identity Cloud is custom-priced and directs buyers to request a private offer. Per-seat figures circulating on procurement and comparison sites have no disclosed methodology and contradict each other, so we do not repeat them. A free trial does exist, but only for the Identity Security for AI product, not the core platform.
Is Saviynt FedRAMP authorized?
Yes at Moderate, and this is more nuanced than most reviews state. Saviynt Enterprise Identity Cloud has been FedRAMP Authorized at Moderate impact since 1 March 2019, via the agency path, with five agency reuses, currently in continuous monitoring. Separately, a package called Saviynt High Security Identity Platform has been FedRAMP In Process at High impact since 4 August 2026, still in initial implementation with zero authorizations. So Saviynt is not FedRAMP High authorized today. Note also that several Saviynt marketing pages claim the platform meets DoD Impact Level 5 requirements, which the FedRAMP Marketplace record does not support.
What certifications does Saviynt hold?
Its trust page lists ISO 27001:2022, ISO 27017:2015, SOC 1 Type II, SOC 2 Type II, FedRAMP Moderate, PCI-DSS, and Cyber Essentials plus Cyber Essentials Plus. It has also achieved an IRAP assessment at PROTECTED level for Australian government work, though the assessment date is not published. No NIST CMVP certificate for FIPS 140-2 or 140-3 could be located, and no StateRAMP listing exists.
Does Saviynt have security vulnerabilities?
Its record is unusually clean. The National Vulnerability Database contains exactly two Saviynt CVEs, both from January 2022: CVE-2022-23855 (CVSS 9.8, an authentication bypass allowing unauthenticated password reset on any local account) and CVE-2022-23856 (5.3, user enumeration). Both affect the self-managed Enterprise Identity Cloud 5.5 SP2.x line rather than the current SaaS platform. Zero CVEs were published in 2023, 2024, 2025 or 2026, and no Saviynt entry appears in the CISA KEV catalog. No breach disclosure was found.
Who owns Saviynt and how well funded is it?
Saviynt is privately held. In December 2025 it raised 700 million dollars in a Series B growth equity round led by KKR, with Sixth Street Growth, TenEleven and existing investor Carrick Capital Partners participating, at a valuation of roughly 3 billion dollars. Founder Sachin Nayyar returned as CEO in 2023. No SEC registration or IPO filing exists, and no acquisitions by or of Saviynt have been announced.
How big is Saviynt?
The company reports more than 600 global enterprise customers including over 20 percent of the Fortune 100, and states it secures more than 100 million identities. Revenue, ARR and employee counts are not disclosed in any primary source.
What does Saviynt do for AI agent identity?
More than most IGA vendors. In March 2026 it launched Identity Security for AI, a control plane for governing autonomous agents with discovery, registration and real-time monitoring, an Agent Access Gateway, and posture management for shadow AI. In June 2026 it added Intent-Aware Runtime Authorization, evaluating agent actions at runtime against identity, context, policy and intent. Named integrations span Amazon Bedrock, Microsoft Copilot Studio, Google Vertex AI, ServiceNow AI, Salesforce Agentforce, Microsoft Foundry and Snowflake Cortex.
What are the best Saviynt alternatives?
SailPoint is the closest competitor and the other half of most enterprise IGA shortlists, generally with deeper analyst recognition. One Identity suits Microsoft-heavy enterprises wanting IGA, PAM and Active Directory management from one vendor, though it is mid-spin-out. ConductorOne and Lumos are the modern cloud-first choices for faster deployment. Veza is the pick when access visibility rather than lifecycle governance is the real problem.
Last reviewed By SWI Community TeamSuggest a correctionHow we research

By SWI Community Team · Last evaluated 2026-09-20

Independent, community-driven analysis. No vendor sponsorship. Compiled from public research and community input and verified on a best-effort basis, so details may be incomplete or out of date. Scores are opinions, not advice. Trademarks belong to their owners; mention does not imply affiliation or endorsement. See the full disclaimer, or send corrections to [email protected].