OneLogin

United States · www.onelogin.com · 39 vendors

OneLogin develops a cloud-based identity and access management (IAM) platform. It provides solutions such as single sign-on (SSO), multi-factor authentication (MFA), and user provisioning. The company aims to simplify and secure access to applications and data for enterprises.

Resilience scores

Disruption prediction

OneLogin has an estimated 11% probability of disruption in the next 6 months.

17 of OneLogin's 39 vendors monitored for disruptions.

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 39 sub-vendors.

Insights

Last updated 2026-08-14 · revision 2

39 direct vendors, 292 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

OneLogin exhibits very high migration readiness, scoring 92. This is largely due to its highly modern, cloud-native, and containerized internal tech stack. The extensive use of Amazon Web Services (AWS), Kubernetes, Docker, and Terraform, along with distributed system components like Kafka and Redis, signifies a microservices-oriented architecture and strong infrastructure-as-code practices. These technologies inherently provide high portability and flexibility for potential migrations. While 'Total Vendors: 0' is stated, implying minimal external vendor dependencies, the 'Vendor Lock-in Risk' is explicitly noted as 'Unknown', which could present a challenge if significant external services are indeed in use. Furthermore, the absence of specified data residency requirements, regulatory environment details, and financial stability information means these factors cannot be fully assessed, but the underlying technology foundation is exceptionally strong for migration.

Compliance

11 in-scope frameworks identified; showing 3.

CPRA — Compliant

OneLogin is headquartered in San Francisco, California, making CCPA/CPRA directly applicable. As a cloud service provider processing personal data of California residents (both as a business and as a service provider to other businesses), OneLogin must comply with CCPA/CPRA requirements. Risk is Medium because OneLogin processes significant volumes of personal data (authentication data, behavioral data, user profiles) and the CPRA introduced enhanced obligations including data minimization, purpose limitation, and sensitive personal information protections. The California Privacy Protection Agency (CPPA) has increased enforcement activity since 2023.

Evidence: https://www.onelogin.com/trust/privacy, https://www.onelogin.com/legal/privacy-policy

GDPR (source) — Compliant

OneLogin is a US-headquartered cloud IAM provider that processes personal data of EU/EEA residents on behalf of its global enterprise customers, making GDPR directly applicable. OneLogin acts as both a Data Controller (for its own customer account data) and a Data Processor (for end-user identity data managed through its platform). The risk is Medium rather than High because OneLogin has publicly documented GDPR compliance measures including a Data Processing Agreement (DPA), Privacy Shield successor mechanisms (Standard Contractual Clauses), and a published Privacy Policy addressing EU data subject rights. However, residual risk exists due to the 2017 security breach, ongoing Schrems II cross-border transfer complexity, and the inherent sensitivity of identity/authentication data processed at scale. Enforcement by EU DPAs of IAM providers has increased since 2021.

Evidence: https://www.onelogin.com/trust/privacy, https://www.onelogin.com/trust/gdpr, https://www.onelogin.com/legal/data-processing-addendum

HIPAA (source) — Compliant

OneLogin explicitly markets its platform to healthcare organizations and positions itself as a HIPAA-compliant Business Associate. The risk is Medium because while OneLogin offers HIPAA-compliant configurations and signs Business Associate Agreements (BAAs), the actual compliance posture depends on how individual healthcare customers configure and deploy the platform. OneLogin as an IAM provider does not directly store PHI in most deployments, but authentication logs and user identity data in healthcare contexts may constitute PHI-adjacent data. Misconfiguration by healthcare customers or OneLogin's own handling of healthcare customer data creates residual risk. The 2017 breach, though not specifically involving PHI, underscores the sensitivity of the platform.

Evidence: https://www.onelogin.com/trust/compliance, https://www.onelogin.com/solutions/industries/healthcare

Financials

Three-year financials

Financial Resilience Score: 6/10

OneLogin's financial resilience is difficult to assess precisely due to its private status and lack of disclosed audited financials. However, the company benefits significantly from being a subsidiary of One Identity (Quest Software), which is ultimately backed by Clearlake Capital Group, a large private equity firm. This ownership structure provides access to substantial capital resources and integration into a broader IAM product portfolio including privileged access, identity governance, and Active Directory management. The company operates in the IAM/SaaS space, which typically features high gross margins (70-80%+) and strong net retention due to switching costs. OneLogin has an established customer base of thousands of enterprises across 40+ countries, including notable references like Airbus, Steelcase, and Pandora. Its product breadth spanning workforce identity and customer identity (CIAM) provides revenue diversification. However, significant risks temper this assessment. OneLogin faces intense competition from much larger players including Okta, Microsoft Entra ID, Ping Identity, ForgeRock, CyberArk, and JumpCloud. As a mid-tier competitor, it lacks the scale of market leaders. The 2017 data breach remains reputationally damaging for an identity vendor. Additionally, PE-owned software companies often carry meaningful debt loads, and the opacity of financials prevents verification of profitability or cash burn.

Key strengths: Backed by well-capitalized parent (Clearlake Capital via Quest Software/One Identity), Sticky SaaS/subscription model with typically high gross margins (70-80%+), Established customer base of thousands of enterprises across 40+ countries, Product breadth across workforce identity and CIAM, Raised ~US$170M in funding before acquisition, Reported ~US$1B valuation at 2019 funding round

Risk factors: Intense competition from Okta, Microsoft Entra ID, Ping Identity, ForgeRock, CyberArk, JumpCloud, Historical 2017 data breach damaged reputation as identity vendor, Financial opacity prevents verification of profitability, cash burn, or leverage, PE-owned software companies often carry meaningful debt loads, Product overlap risk post-acquisition with sister One Identity products, Macro pressure on SaaS spend and IAM market consolidation into platform vendors (especially Microsoft)

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report