Curity

Receive weekly intel updates about Curity straight to your inbox.

Curity

Curity Competitive Intelligence & Landscape

curity.io ·

Overview

Curity Overview

Curity (curity.io) is an identity and access management (IAM) company that provides a platform to secure authentication and authorization for humans, AI agents, and APIs. The company's core offering, the Curity Identity Server, is designed to manage every access decision across various digital experiences, from customer login (CIAM) to partner access (B2B IAM) and machine-to-machine workflows. Its value proposition centers on providing a robust, standards-based, and deployable-in-your-environment solution that allows organizations to maintain control over their data and comply with regulations.

Curity also offers Access Intelligence, which provides real-time authorization specifically for AI agents and automated systems, ensuring that AI investments do not become audit liabilities. The platform is built on open standards and emphasizes deployment in the customer's environment to prevent vendor lock-in. Their target market includes organizations in sectors such as financial services, government, healthcare, tech & SaaS, and telecom, particularly those that require secure access at scale and cannot afford errors in their identity infrastructure.

Founded in 2015 [source], Curity operates with a remote-first approach, though its headquarters are located in Stockholm [source]. The company aims to empower organizations to secure millions of users through its API-driven identity and access management solutions [source]. While specific company size isn't detailed, job postings and customer testimonials suggest a growing team and a global reach, serving thousands of enterprise customers and impacting billions of end-users.

Curity's mission is to provide the access layer that businesses run on, securing APIs, AI agents, and human interactions. They differentiate themselves by building their platform around the access decision itself, rather than solely users, making it suitable for modern, complex digital environments. The company emphasizes reducing identity debt and allowing customers to stay in control of their data and infrastructure.

Competitors

Curity Competitors

Curity (curity.io) faces competition from various identity and access management (IAM) providers. One key competitor is Okta, known for its extensive suite of cloud-based identity products, including single sign-on (SSO), multi-factor authentication (MFA), and API access management. While Okta offers broad functionality and a large market share, Curity differentiates itself by focusing on the access decision itself, securing APIs, AI agents, and machine-to-machine workflows, and allowing deployment in the customer's environment for greater control, contrasting with Okta's predominantly cloud-native approach.

ForgeRock Identity Management is another significant competitor, providing a comprehensive IAM platform that covers authentication, authorization, and identity lifecycle management. Similar to Curity, ForgeRock supports open standards and offers deployment flexibility. However, Curity emphasizes securing AI agents and complex API access decisions as a core strength, positioning itself as a platform built specifically for the "agentic era," where AI agents continuously call APIs.

Ping Identity also competes with Curity in the CIAM and API security space.

Ping Identity offers a robust platform with fine-grained authorization (Zanzibar-style), strong compliance features like ISO 27018, user management with progressive profiling, and bot detection, areas where Curity may have partial or no comparable features. Conversely, Curity is noted for its local emulator for development, which can be an advantage for developers. While both leverage open standards like OAuth 2.0 and OpenID Connect, Curity highlights its focus on securing AI agents and providing an access layer for the modern business.

Saviynt is another competitor that offers a converged platform for Identity Governance and Administration (IGA), Cloud Privileged Access Management (PAM), and Application GRC. While Saviynt provides a broader governance-focused IAM solution, Curity maintains its specialized focus on the core access layer for authentication, authorization, and federation across diverse infrastructure, including securing AI and API interactions, with an emphasis on customer control through on-premise deployment options. This specialized focus on access decisions for humans, AI, and APIs sets Curity apart from the more generalized IGA approach of Saviynt.

TrustBuilder also operates in the IAM sector, offering an access management platform that includes MFA and CIAM solutions. Like Curity, TrustBuilder aims to provide robust access control. However, Curity's unique selling proposition lies in its "Access Intelligence" for real-time authorization for AI agents and automated systems, and its platform being built specifically around the access decision itself rather than solely user-centric models. This positions Curity as a more specialized solution for organizations dealing with complex API ecosystems and the emerging demands of AI agent security.

Alternatives

Curity Alternatives

Product & Pricing

Curity Product and Pricing Intelligence

Curity (curity.io) offers the Curity Identity Server as its core product, designed to provide authentication, authorization, and federation across an organization's infrastructure. This platform is built to secure applications, APIs, and AI agents, with a focus on access decisions rather than solely user-centric models. Key use cases include CIAM (Customer Identity and Access Management), B2B IAM, and modernizing identity infrastructure by consolidating fragmented systems into a single, standards-based platform [curity.io/product/]. The platform also features Token Intelligence, which helps enterprises manage fine-grained access as their API ecosystems grow, preventing risk by controlling what each token can access [curity.io/product/token-intelligence/].

Curity offers a Community Edition of its Identity Server, which functions as a free OAuth server [curity.io/product/community/]. This edition helps organizations secure humans, AI agents, and the APIs connecting them, with a focus on controlling access for AI agents. While specific pricing tiers for paid versions are not explicitly detailed as fixed packages, Curity highlights a pricing philosophy that stands in contrast to common industry models. They emphasize that their approach avoids per-user or per-authentication billing, which can penalize product growth and increase costs with every new customer, login, or API call [curity.io/solutions/tech-saas/], [curity.io/solutions/financial-services/]. This suggests a more predictable cost structure for enterprise customers, often crucial for industries like financial services and government [curity.io/solutions/government/].

Recent product developments include the release of Curity Identity Server 11.3, which introduced new features such as a built-in React login app and expanded Token Intelligence [curity.io/product/plans/]. The Curity Identity Server is designed for flexible deployment, working in any environment and fitting into CI/CD pipelines with ready-made Docker images and Kubernetes Helm charts for easy setup and linear auto-scalability [www.curity.io/product/deployment/]. This emphasis on deployment control and predictable costs is a significant part of Curity's value proposition for market leaders who cannot afford to get their access decisions wrong.

Hiring & Layoffs

Curity Hiring and Layoffs

Curity (curity.io) is actively seeking skilled professionals to join its team, with a consistent focus on expanding its expertise in identity and access management. The company has no indication of layoffs; instead, its hiring patterns suggest a strategic emphasis on growth and enhancing its core product offerings.

Recent job openings at Curity include a Product Marketing Engineer, a Professional Services Engineer, and a Java Software Engineer [curity.io/company/careers/]. The Product Marketing Engineer role is critical for articulating the complex value proposition of Curity's solutions, while the Professional Services Engineer position is designed to empower organizations in securing their users through API-driven identity and access management [curity.io/company/careers/job/professional-services-engineer/]. The demand for an experienced Java Software Engineer with over five years of experience highlights Curity's continuous investment in developing its production-class code and core identity server [curity.io/company/careers/job/java-software-engineer/].

These hiring trends signal Curity's commitment to both product development and market outreach, indicating a strategy to strengthen its technological foundation and improve its ability to communicate its advanced identity solutions. The company's "remote-first approach," despite its Stockholm headquarters, further demonstrates a flexible and inclusive strategy to attract top talent globally [curity.io/company/careers/working-at-curity/]. This approach allows Curity to tap into a wider talent pool, ensuring it can bring in the best individuals to "solve complex identity problems" and make the internet safer [curity.io/company/careers/].

Overall, Curity's hiring activities reflect a healthy and expanding company that is investing in key roles to support its growth in the competitive identity and access management sector. The focus on engineering and product marketing roles suggests a balanced strategy of innovation and market penetration, aiming to secure humans, AI agents, and the APIs that connect them, especially as AI agents increasingly call APIs and access data [curity.io].

Leadership

Curity Management and Leadership Team

Curity (curity.io) has recently strengthened its leadership team with several key appointments. In a significant change, Gustaf Sahlman was appointed CEO, bringing extensive experience in leading the growth of B2B software companies. This appointment was supported by Merete Søby, who joined the Curity board of directors as the new chairperson in March 2024, emphasizing Sahlman's track record in accelerating global expansion curity.io/news/gustaf-sahlman-new-ceo/. Sahlman will deliver a keynote at Nordic FinTech Week 2025, titled "Identity, the Digital Kill Switch – Why Digital Sovereignty Is More Critical Than Ever" curity.io/news/nfw-2025/.

The executive team also saw the addition of Johanna Alvemur as Chief Human Resources Officer (CHRO) and Sutton Maxwell as Chief Revenue Officer (CRO). Alvemur is expected to be instrumental in fostering innovation and global growth, while Maxwell will lead revenue generation efforts curity.io/news/curity-welcomes-johanna-alvemur-and-sutton-maxwell/.

Supporting the executive team, Jacob Ideskog serves as Curity's CTO and an Identity Specialist, regularly contributing to discussions on security solutions in the API and Web space and speaking at industry events like "Modern Business, Secured" in London curity.io/author/jacob-ideskog/. Additionally, Andrew Hindle is a non-executive member of the board, contributing his expertise in digital identity, privacy, cyber security, and corporate governance, alongside his roles as Identiverse Conference Chair and co-founder of The Identity Salon curity.io/author/andrew-hindle/. Travis Spencer, a former member, was accepted into the Forbes Technology Council curity.io/news/2/.

Financials

Curity Financial Performance, Fundraising, M&A

Curity, a company specializing in identity and access management, secured an investment led by Fairpoint Capital to accelerate its growth. Fairpoint Capital, an offshoot of a major Swedish bank, was chosen for its B2B tech focus and shared vision, with the investment earmarked to expand Curity's engineering efforts [curity.io/news/curity-accelerates-growth-with-fairpoint%20capital/]. This strategic funding aims to meet increasing customer demands and scale the business effectively.

While specific revenue figures and valuations are not publicly disclosed, Curity offers a tiered pricing model for its Curity Identity Server, featuring a free Community plan for individuals and startups, and a Standard plan for more comprehensive business needs, both with flat annual subscriptions and unlimited users [curity.io/pricing/]. This pricing structure suggests a focus on scalability and accessibility for various business sizes.

There is no publicly available information regarding Curity's acquisitions or any M&A activities. However, the company's financial health is bolstered by its continuous product development, such as the Curity Identity Server, and its strategic leadership appointments, including a new CEO, CHRO, and CRO, to support global expansion and operational excellence [curity.io/news/2/, curity.io/news/curity-welcomes-johanna-alvemur-and-sutton-maxwell/]. These developments indicate a focus on internal growth and market penetration rather than external M&A activities.

Curity is recognized as a leading vendor in the identity and access management space, with recognition from firms like Liminal, which ranked Curity among the top authentication providers for its strong product execution [curity.io/news/curity-leading-ciam-vendor-by-liminal/]. Additionally, Curity is frequently mentioned in Gartner research documents and has been named an Overall Leader, Product Leader, Innovation Leader, and Technology Leader in the KuppingerCole Leadership Compass for API Security and Management [curity.io/what-analysts-say/]. These accolades suggest a strong competitive position and positive financial outlook within its market segment.

Partnerships

Curity Partnerships, Clients and Vendors

Curity (curity.io) actively cultivates a robust network of partners to deliver secure digital solutions. Notable technology partners include Microsoft, leveraging platforms like Azure to build and scale modern digital services, and Yubico. Curity also partners with CASQUE (Distributed Management Systems Ltd) to enhance identity assurance. Additionally, Curity integrates with other technologies such as the Tyk API Gateway and its Enterprise Developer Portal for dynamic client registration.

Curity is trusted by a diverse range of enterprise clients across various sectors, including financial services, telecom, retail, and healthcare, who rely on the Curity Identity Server for secure access at scale. These organizations deploy Curity's solutions within their own environments, maintaining control over their infrastructure and data.

Key clients include If Insurance, a leading property and casualty insurer in the Nordic region with over 4.5 million customers, which built a secure and scalable identity platform with Curity. Scandic Hotels also selected Curity for its modern identity and access management needs, unifying authentication for its website and mobile apps and facilitating growth.

Santander has also strengthened its API security with Curity [source].

Events

Curity Event Participations

Curity actively participates in and hosts a variety of events, including conferences, webinars, and exclusive customer gatherings, to engage with the industry and its user base. They will be hosting the Curity Customer User Group 2025 in Stockholm, providing a platform for customers to influence the product roadmap and connect with peers. Additionally, Curity will celebrate their new book, "Cloud Native Data Security with OAuth," at a launch event in Stockholm, offering attendees the chance to meet the authors and discuss the book's themes.

Curity maintains a significant presence at major industry conferences. They will be attending the Gartner Identity & Access Management Summit in London in both 2025 and 2026, where they will discuss how identity needs to evolve with autonomous services and intelligent agents, focusing on maximizing investment and modernizing identity and API access. In 2026, Curity will also be at the AI & Big Data Expo in London, showcasing their application-centric, identity-first approach to securing APIs and AI-driven workloads.

Curity also partners with other industry leaders for specialized events. They are collaborating with Nordic APIs and Akamai for an event in Stockholm to explore securing APIs in the age of AI-driven interactions. Furthermore, Curity will participate in the inaugural API Security Unconference, held in association with Nordic APIs’ Platform Summit, fostering a participant-driven discussion on API security challenges.

Webinars are another key channel for Curity to share expertise. Their on-demand and live webinars cover critical topics such as "When AI Agents Meet Customers: Getting Security Right" and "MCP and AI Agents: Identity Strategies for Safe API Access." Curity is also partnering with KuppingerCole for a webinar on "AI Rewrites the Rules of B2B Identity Access," exploring how AI and modern identity architecture are reshaping third-party access management and API security.

Frequently Asked Questions

What is Curity's strategic focus in its hiring efforts?

Curity's hiring patterns indicate a strategic focus on growth and enhancing core product offerings, specifically in identity and access management. Recent job openings for a Product Marketing Engineer, Professional Services Engineer, and Java Software Engineer highlight investments in both product development and market outreach to strengthen its technological foundation and communicate advanced identity solutions.

What is Curity's approach to securing emerging technologies like AI agents?

Curity is proactively addressing the security challenges posed by AI agents, as evidenced by their 'Access Intelligence' offering for real-time authorization for AI and automated systems. Their participation in events like the AI & Big Data Expo and webinars on 'When AI Agents Meet Customers: Getting Security Right' further demonstrate their commitment to securing AI-driven workloads and API interactions.

What does Curity's participation in major industry events signal about its strategic priorities?

Curity's active participation in and hosting of major industry events, such as the Gartner Identity & Access Management Summit and the AI & Big Data Expo, signals a strategic priority on thought leadership and market presence. They use these platforms to discuss the evolution of identity for autonomous services and AI, and to showcase their application-centric, identity-first approach to securing APIs and AI workloads.

What is the significance of Curity's recent leadership appointments?

Curity's recent leadership appointments, including Gustaf Sahlman as CEO, Merete Søby as Board Chairperson, Johanna Alvemur as CHRO, and Sutton Maxwell as CRO, signal a strategic push for global expansion, operational excellence, and accelerated growth. These appointments aim to strengthen the executive team's expertise in leading B2B software companies and driving revenue generation.

How does Curity differentiate its pricing model from competitors?

Curity differentiates its pricing model by avoiding per-user or per-authentication billing, which commonly penalizes product growth in the industry. Instead, Curity offers a Community plan and a Standard plan for its Identity Server with flat annual subscriptions and unlimited users, suggesting a focus on predictable costs for enterprise customers, especially in high-scale environments.

What is Curity's core value proposition in the identity and access management market?

Curity's core value proposition is providing an identity and access management platform that secures authentication and authorization for humans, AI agents, and APIs by focusing on the access decision itself, rather than solely users. This approach enables organizations to maintain control over their data, comply with regulations, and prevent vendor lock-in through standards-based, deployable-in-your-environment solutions.

How does Curity position itself against broad IAM platforms like Okta and ForgeRock?

Curity positions itself against broad IAM platforms like Okta and ForgeRock by specializing in securing APIs, AI agents, and machine-to-machine workflows, with an emphasis on deployment in the customer's environment for greater control. While competitors offer extensive features and cloud-native approaches, Curity highlights its 'agentic era' readiness and platform built around the access decision itself.

What kind of strategic partnerships does Curity prioritize?

Curity prioritizes strategic partnerships with technology providers like Microsoft and Yubico to build and scale secure digital services, and with security firms like CASQUE to enhance identity assurance. They also integrate with API gateways like Tyk, demonstrating a focus on enabling secure, modern digital infrastructure for enterprise clients in sectors such as financial services, telecom, and healthcare.

What does Curity's investment from Fairpoint Capital indicate about its growth strategy?

Curity's investment from Fairpoint Capital indicates a strategy to accelerate growth, particularly by expanding its engineering efforts to meet increasing customer demands and scale the business effectively. This strategic funding signals a focus on internal growth and market penetration rather than external M&A activities, aiming to strengthen its position in the identity and access management sector.

What is Curity's stance on deployment flexibility and data control?

Curity strongly emphasizes deployment flexibility and customer control over data. Its core offering, the Curity Identity Server, is designed to be deployed in the customer's environment, preventing vendor lock-in and ensuring compliance with regulations. This is supported by ready-made Docker images and Kubernetes Helm charts for integration into CI/CD pipelines.

What is the significance of Curity's focus on Open Standards?

Curity's focus on open standards ensures interoperability and avoids vendor lock-in, providing customers with greater control over their identity infrastructure. The platform's foundation on these standards enables robust, secure, and flexible integration, particularly crucial for modernizing identity systems and managing complex API ecosystems in regulated industries.

Powered by ForesightIQ · Competitive intelligence from digital exhaust