Vendor dossier // okta.com
Also known as Okta
San Francisco, California, United States · Est. 2009 · 6,366 employees
Key people
Last updated: Aug 12, 2026, 06:32 PM · Partial / limited public data
Proceed with caution
Historical security incidents, including a 2023 support system breach and a 2024 sign-on policy bypass, have been addressed through forensic investigations and… Limited public data — verify before relying.
Risk Tier
Risk Score
Confidence
partial
Material Incidents
Okta, Inc. is a publicly traded identity and access management company headquartered in San Francisco, California. Founded in 2009, the enterprise technology firm employs approximately 6,366 individuals and reported roughly $2.9 billion in revenue for the 2025 fiscal period. Operating globally, Okta provides cloud-based identity solutions designed to secure workforce and customer identities across diverse organizational environments. The company maintains a strong market presence in the IT software and services sector, focusing on scalable identity infrastructure that supports modern enterprise security requirements and digital transformation initiatives worldwide.
Okta’s core offering is a cloud-based identity and access management platform that functions as a centralized hub for user identities. The service delivers single sign-on, multi-factor authentication, and automated user provisioning capabilities for both workforce and customer identity use cases. By integrating with hundreds of third-party applications, the platform enables organizations to enforce least-privilege access controls and streamline secure login workflows. Enterprise buyers utilize the solution to reduce administrative overhead while maintaining robust authentication standards across hybrid and cloud-native environments globally.
Okta maintains a dedicated Security Trust Center and publishes regular security advisories to communicate threat intelligence to its customer base. In October 2023, attackers compromised a customer support management system containing session tokens, impacting support users; an independent forensic investigation by Stroz Friedberg concluded with no evidence of further malicious activity. Additionally, a sign-on policy bypass vulnerability in the Classic application was identified in mid-2024 and patched by October 4, 2024. The company advises customers to monitor authentication logs and implement defense-in-depth strategies to mitigate identity provider risks effectively.
Evidence class: observed by us
Deterministic outside-in checks run directly against the vendor's domain - not inferred from press or marketing pages.
Last observed: Aug 12, 2026, 06:32 PM
TLS certificate
Certificate expires in 112 days
Security headers
4/6 security headers present
Email authentication (SPF / DMARC)
DNS presence
[breach] 2024 Sign-on Policy Bypass Vulnerability
A bug in the Okta Classic app allowed attackers to bypass strict sign-on policies between July and October 2024. The vulnerability was patched by October 4, 2024.
Oct 4, 2024, 12:00 AM · Source
[breach] October 2023 Security Incident
Attackers accessed a support system containing session tokens, impacting customer support users. Independent forensic investigation concluded with no further malicious activity.
Oct 13, 2023, 12:00 AM · Source
[breach] October 2023 Customer Support System Incident
Okta announced a cybersecurity incident affecting its customer support management system. Forensic firm Stroz Friedberg concluded the investigation with no evidence of further malicious activity.
Oct 1, 2023, 12:00 AM · Source
[legal] $60M Shareholder Settlement
Okta reached a $60 million settlement regarding shareholder claims related to cybersecurity controls and incident disclosures.
- · Source
Vendors offering a similar product or service - for side-by-side comparison, not a ranking.
Ping Identity
Enterprise-grade flexibility and identity governance.
Microsoft Entra
Comprehensive identity and access management suite.
OneLogin
Cloud identity platform focused on simplicity and faster rollout.
CyberArk
Privileged account security and credential vaulting.
Recent corporate updates highlight financial initiatives, including a $1 billion share repurchase program and expanded partnerships such as an agreement with the PGA of America to secure golf professionals’ identities globally. Okta also announced enhanced disaster recovery and data residency capabilities for the Indian market. However, public discourse remains heavily influenced by historical security incidents, with ongoing shareholder litigation and a $60 million settlement addressing allegations of inadequate cybersecurity controls. The company continues to emphasize transparency and long-term strategic growth amid these legal and operational developments.
Content in this section is vendor-supplied and does not alter Vendorisk.ai's risk tier or evaluation.
32 sources · Generated Aug 12, 2026, 06:32 PM
Every verdict stores the public sources retrieved for this run. Read our methodology.
Input sources · retrieved Aug 12, 2026, 06:32 PM
Okta Inc Company Profile
Company
Okta, Inc.
Company
Okta | OKTA Stock Price, Company Overview & News
Company
AI-generated assessment based on publicly available sources. Verify critical findings before contractual reliance. Analysis is advisory, not a compliance attestation, and is subject to data availability.
Years in Business
17 yrs
Historical security incidents, including a 2023 support system breach and a 2024 sign-on policy bypass, have been addressed through forensic investigations and patches. However, material legal exposure persists via a $60 million shareholder settlement and class-action complaints regarding cybersecurity control disclosures. While Okta maintains a coherent public security posture with a dedicated trust center, its critical role in identity management amplifies the impact of past incidents, warranting a moderate risk classification.
Certificate transparency exposure
crt.sh unavailable
Breach database (HIBP)
HIBP_API_KEY not configured
Public status page
Public status page reachable
[legal] Class Action Lawsuit on Cybersecurity Controls
Plaintiffs allege Okta failed to disclose inadequate cybersecurity controls, leading to vulnerabilities that impacted hundreds of customers.
- · Source
Leadership - CEO Todd McKinnon
Company
Okta
Company
Okta for Good: Our Commitment to Social Impact | Okta
Company
Careers - Jobs at the Leader in Identity and Access ...
Company
404
Company
Okta Competitors & Alternatives A Comprehensive 2024 Guide | metacto
Product
Top 9 Okta alternatives and competitors | Scalefusion
Product
The Top 8 Okta Competitors for Identity Management in 2026
Product
Okta Platform reviews 2026
Product
10+ Best Okta Competitors & Alternatives in 2026
Product
Top Okta Competitors & Alternatives 2026
Product
Okta Data Breach: What Happened, Impact, and Security ...
Security & risk
The butterfly effect: Analyzing Okta's data breach
Security & risk
Okta Security Trust Center | Powered by SafeBase
Security & risk
Accessing Okta's Security Trust Center
Security & risk
How the Okta Customer Support Hack Exposed Sensitive ...
Security & risk
Okta security breach affected all customer support system ...
Security & risk
Okta October 2023 Security Incident Investigation Closure
Security & risk
Okta Trust
Security & risk
News & Events - News Releases - Okta Inc. - Investor Relations
News
Okta, Inc. - Rosen Law Firm
News
Okta Data Breach: What It Means For Your Security
News
Unpacking the Okta Data Breach
News
Okta Data Breach: What Happened, Impact, and Security ...
News
Okta (OKTA) $60M Shareholder Settlement
News
Investigation of Okta, Inc.
News
okta-20230430 - SEC.gov
News
Okta Inc. - Investor Relations
News
Okta October 2023 Security Incident Investigation Closure
News