# Orchid Security > Orchid Security is an identity-first security platform that brings clarity to the complexity of identity. It discovers, analyzes, governs, and proves identity controls across all applications — making "identity dark matter" (hidden access, credentials, and authentication logic that standard security tools cannot see) visible and manageable. Orchid was founded by Roy Katmor, Robert Wiseman, and Ido Kelson — veterans of enSilo (acquired by Fortinet), Team8, and Imperva — and is backed by Team8 and Intel Capital. The platform uses Large Language Models (LLMs) to interpret application code and configuration, revealing identity-related context and reasoning that traditional IAM tools cannot access. ## Core Concept: Identity Dark Matter Identity dark matter refers to access, credentials, and authentication logic that exists inside applications but is invisible to centralized IAM, PAM, and IGA systems. This includes: - Shadow authentication paths (users logging in via alternate flows that bypass SSO) - Local user accounts and in-app access that never appear in IAM logs - Hardcoded credentials embedded in code, configs, and scripts - Privilege drift (permissions that accumulate long after the original need is gone) - Application-level authorization logic that IAM cannot inspect ## Platform Capabilities ### See Everything (Discover) Orchid continuously inventories every application — SaaS, cloud, on-premises, legacy, home-grown, and shadow — and discovers every identity within them: human, machine, and agentic AI. Built-in risk analysis uncovers and prioritizes exposures automatically. ### Analyze Anything (Analyze) Orchid's AI engine analyzes authentication and authorization logic inside each application. It identifies weak encryption, hardcoded credentials, missing controls, and shadow auth paths. Findings are mapped against compliance frameworks including NIST, ISO 27001, SOX, GDPR, HIPAA, PCI-DSS, and NIS2. Output includes a visual identity graph of every authentication and authorization flow, and continuous posture trend tracking. ### Govern Everywhere (Orchestrate) Orchid integrates with existing IAM, PAM, and IGA systems (e.g., Microsoft, Saviynt, CyberArk, SentinelOne) to enforce policies, automate remediation, and maintain least-privilege access. It bridges unmanaged applications back into IAM control without replacing existing tooling. ### Prove Everything (Audit) Every discovery, policy, and remediation action is recorded in a continuous, exportable audit trail. Orchid delivers real-time evidence aligned to SOX, PCI, HIPAA, GDPR, and NIS2 — replacing periodic manual evidence collection with always-on compliance posture. ## Use Cases - **Identity & Access Management Programs**: Accelerate application onboarding and eliminate identity blind spots at scale. Reduces onboarding time by up to 90% and identity professional services cost by up to 75%. - **GRC & Audit**: Maintain continuous audit readiness with framework-aligned reporting. Eliminates fire-drill evidence collection. - **Incident Response Teams**: Surface identity-related exposures and compromised authentication paths at the speed of an attack. - **M&A / Growth Events**: Rapidly baseline and govern identity sprawl introduced through mergers, acquisitions, and rapid expansion. ## Key Differentiators - Uses LLMs to parse application source code and configuration to extract identity behavior — not just log analysis - Discovers identity context that no IAM scanner or SIEM can access - Does not replace IAM/PAM/IGA — augments and feeds them with application-level telemetry - Automates what previously required months of manual application onboarding work - Supports regulated industries (financial services, healthcare, critical infrastructure) under heavy audit pressure ## Reported Customer Outcomes - 75–90% reduction in application onboarding time (from ~4 weeks to ~1 week on average) - 97% reduction in professional services cost per application (from ~$15,000 to ~$500) - 275% improvement in regulatory compliance coverage - 83% improvement in security outcomes through automated actions ## Integrations Orchid integrates with the broader enterprise IAM stack, including: - **IGA**: Saviynt - **PAM**: CyberArk - **Identity Platform**: Microsoft (Azure AD / Entra ID) - **EDR/XDR**: SentinelOne ## Compliance & Certifications Orchid Security holds the following certifications: - SOC 2 - ISO 27001 - ISO 27701 - HIPAA - GDPR - CSA STAR Level 1 ## Company - **Website**: https://www.orchid.security - **Founded**: ~2022 (incubated at Team8) - **Headquarters**: Israel, with US presence - **Investors**: Team8, Intel Capital - **Trust Center**: https://trust.orchid.security ## Key Pages - [Home](https://www.orchid.security/) — Overview of identity dark matter problem and platform summary - [Platform](https://www.orchid.security/platform) — Detailed description of Discover, Analyze, Govern, Prove capabilities - [About / Company](https://www.orchid.security/company) — Founding story, leadership team, investor information - [IAM Programs Use Case](https://www.orchid.security/use-case/identity-access-management-programs) — Accelerating identity program velocity - [GRC & Audit Use Case](https://www.orchid.security/use-case/grc-audit) — Continuous audit readiness - [Incident Response Use Case](https://www.orchid.security/use-case/incident-response-teams) — Identity threat response - [M&A Use Case](https://www.orchid.security/use-case/m-a-growth-events) — Identity consolidation post-acquisition - [Customer Stories](https://www.orchid.security/customer-stories) — Case studies and testimonials - [Blog](https://www.orchid.security/resources/blog) — Research, thought leadership, product updates - [Reports & Papers](https://www.orchid.security/resources/reports-papers) — Whitepapers and industry research - [ROI Calculator](https://www.orchid.security/calculator) — Estimate cost savings from deploying Orchid - [Book a Demo](https://www.orchid.security/book-a-demo) — Schedule a live product demonstration - [Careers](https://www.orchid.security/careers) — Open positions - [Privacy Policy](https://www.orchid.security/privacy-policy) - [Terms of Service](https://www.orchid.security/terms-of-use)