Aserto is an authorization-as-a-service platform that simplifies adding fine-grained, policy-based, real-time access control to cloud applications and APIs. It enables developers to implement role-based access control (RBAC), attribute-based access control (ABAC), and relationship-based access control (ReBAC) models. Aserto's core offering is Topaz, an open-source authorizer built on top of the Cloud Native Computing Foundation's Open Policy Agent (OPA) decision engine and Google's Zanzibar ReBAC model.
Topaz follows a distributed architecture with local authorizers running alongside applications and a central control plane for managing policies, users, groups, objects, relations, and decision logs. This architecture ensures low-latency authorization decisions using cached data while providing centralized management and real-time syncing of changes across all authorizers. Aserto treats authorization policies as code, allowing developers to version, tag, and sign them like application artifacts.
By integrating established open-source technologies like OPA, Zanzibar, and Open Containers Initiative (OCI), Aserto aims to democratize fine-grained access control capabilities previously available only to large organizations. It offers comprehensive developer resources, including quickstarts, SDKs, and APIs for popular languages and frameworks, saving engineering teams months of development time.
Key customers and partnerships
Aserto partners with organizations like Replicated, which serves 50% of Fortune 100 companies, to provide enterprise-grade authorization solutions.
By using this site, you agree to allow SPEEDA Edge and our partners to use cookies for analytics and personalization. Visit our privacy policy for more information about our data collection practices.