
Overview
Zilla Security delivers an identity security solution focused on comprehensive security and compliance that is automated and easy to use. The platform combines identity governance with cloud security to deliver access visibility, compliance reviews, user lifecycle management, segregation of duties, and policy-based security remediation.
Zilla's no-code integration with SaaS applications like Salesforce, cloud infrastructure like AWS, and cloud databases like Databricks, is unparalleled. Robotic automation enables the platform to monitor and configure all web-based applications, even those that don't have security APIs.
Zilla's self-learning, intelligent automation easily handles cloud scale and dramatically reduces the cost of ownership via a simple user experience that enables collaboration between app owners, IT, security teams, and auditors.
Zilla delivers:
Extensive library of out-of-the-box app Integrations Fast onboarding of any app - no coding or scripting - including custom and legacy apps without APIs Fully automated access reviews campaigns and compliance assessments for multiple reviewer types Simple user experience for frictionless collaboration between stakeholders Continuous and audit-ready compliance with all the supporting evidence in one place Advanced search and reporting for the compliance audit purposes Complete visibility into who has access to what
Highlights
- Automated monitoring and remediation of access - who has access to what and any access risks. Zilla enables organizations to easily monitor all permissions, infrastructure entitlements, and security settings that give users, machines, and APIs access. We deliver insight into critical access risk and then remediate inappropriate access via integration with an organization's ITSM systems for ticketing workflows.
- Comprehensive integrations with Zilla Universal Sync (ZUS) - we haven't met an app we can't support. Zilla makes it easy to integrate the tools, systems, and platforms organizations use every day. The platform includes robotic automation that enables customers to integrate with all applications, including legacy and homegrown apps, and ones that offer no security APIs or file exports for security data.
- Simple, automated User Access Reviews (UAR) - go from months to days for reviews and audits. Zilla automates the entire UAR process and delivers an auditable system of record. The platform generates permissions relevant to a campaign, invites reviewers to complete work, and enables administrators to track reviewer progress. Reviewers can maintain, revoke, change, re-assign, or delegate permissions, while campaign administrators have complete control over the review process.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
Comply 500/25 | Zilla Security - Comply for 500 Identities and 25 applications | $45,000.00 |
Comply 2500/100 | Zilla Security - Comply for 2500 identities and 100 applications | $90,000.00 |
Comply additional app | Zilla Security - Comply Additional App | $1,000.00 |
Vendor refund policy
No refunds are available
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
The Zilla Customer Support Team is dedicated to providing you with a best-in-class support experience. Our goal is to exceed your expectations and make you successful. Support@ZillaSecurity.com address
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

FedRAMP
GDPR
HIPAA
ISO/IEC 27001
PCI DSS
SOC 2 Type 2
Standard contract
Customer reviews
Automation has streamlined identity workflows and saves significant time in access management
What is our primary use case?
I have known Idira IGA for about three years now. I work with Idira IGA as a consultant for a system integrator company. I am both a consultant and a system integrator. My clients mainly handle Privileged Access Management (PAM) use cases for Idira IGA. I handle PAM for the banking sector and also for manufacturers.
What is most valuable?
The biggest advantage of this tool is that it is a Gartner leader, making it easier to propose to customers. I find the implementation phase easier compared to other products.
The automation part of Idira IGA is what we love the most because it simplifies the use of the application. With automation, we save a lot of time because it cuts our effort in half. If we need one hour, with automation, we can cut it to half an hour.
The features I appreciate most in Idira IGA are the simplified dashboard and the automation configuration, which other brands cannot offer. It saves time and effort for my team.
What needs improvement?
I do not see any areas for improvement at this time.
In the future, I think they could add new functionalities. I am from Indonesia and we lack local consultants for discussions and brainstorming on potential features. We do not have local support here.
What do I think about the stability of the solution?
I find Idira IGA to be quite stable and reliable.
What do I think about the scalability of the solution?
Scaling Idira IGA is easy. If I want to scale up, I just add more licensing and storage as needed, as it is VM-based.
How are customer service and support?
If I had to rate my experience with Idira IGA's support, I would give it an 8 to 8.5 out of 10. The absence of local support is the only reason for this rating.
How was the initial setup?
I do not see any problems with deployment, as I find it easy to install. Deployment for Idira IGA depends on customer needs. For banking, they prefer on-premises, while for those requiring cloud solutions, we propose cloud for easier maintenance and accessibility. Deployment usually takes around three weeks to one month, as we first need to source the asset and access permissions.
What was our ROI?
It is easy to notice a return on investment (ROI) and I do see value for money. For the ROI from the customer's perspective, especially in banking, using Idira IGA for identity management brings ROI mostly if they use it for about two or three years.
What's my experience with pricing, setup cost, and licensing?
Pricing for Idira IGA varies. It is essential to consider it from different perspectives, but for the features Idira IGA offers, I find it affordable.
Which other solutions did I evaluate?
I can compare Idira IGA to similar products, such as Delinea. While Delinea may be less expensive, Idira IGA's licensing and all-inclusive features stand out. I would say Idira IGA is more advanced, particularly with its integration from the Palo Alto database, which is significantly more powerful than other brands.
What other advice do I have?
Regarding access reviews and evidence collection, I find it more feasible due to the improved dashboard and asset management. I would rate this review an 8.5 out of 10.
Privileged access has improved compliance and accountability but still needs smoother onboarding
What is our primary use case?
My main use case for Idira IGA is related to CyberArk at Truist Bank, where I owned the end-to-end delivery of a CyberArk Application Access Manager implementation. I specifically managed the scope and sequencing, Splunk integration, and shared accounts and service accounts remediation, as well as disaster recovery testing. My CyberArk experience is primarily at the program delivery and integration level.
How has it helped my organization?
Idira IGA has positively impacted my organization in terms of security posture, compliance and audit impact, and operational impact. For the security posture impact, before the CyberArk implementation, privileged access at Truist was a huge risk, with service accounts using hardcoded credentials in configuration files. After implementation, those accounts retrieve credentials dynamically from Idira IGA vault at runtime.
Regarding compliance and audit impact, the program had a direct SOX audit requirement. A good percentage of privileged accounts were onboarded into CyberArk within a specific timeframe to meet the bank's compliance application. For operational impact, I had over 500 shared accounts and service accounts retired and replaced with individual CyberArk manager accounts. This change alone brought significant operational consequences, such as accountability improvements and enhanced stability, given our pre-onboarding validation process.
In summary, the CyberArk implementation at Truist eliminated static credential exposure across over 200 plus enterprise applications, and my team and I brought over 500 privileged accounts under active vault management.
What is most valuable?
While discussing the best features Idira IGA offers, I mentioned the challenges, including application owner pushback on the onboarding timeline, particularly for their production systems. Furthermore, the shared account or service account remediation was particularly complex because we often did not have complete visibility into which systems depended on a given shared account. For features, I appreciate the end-to-end ownership, not just a piece. Most people who touch a CyberArk program own slices of it, but I owned the end-to-end implementation. The features of zero service disruption across 500 plus environments are among the strongest, along with proactive risk identification, compliance outcomes under a hard audit deadline, and creative dependency mapping using Splunk. Additionally, the disaster recovery validation that tested the failure scenario is crucial.
I took over a million-dollar CyberArk program from scope definition to a clean audit close, remediating over 500 accounts across legacy banking applications and catching a critical credential rotation risk before it reached production, delivering real-time privileged access visibility to the SOC environment with almost zero service disruption and zero audit findings.
What needs improvement?
Idira IGA could improve in the way access is provisioned for different users. My perspective on this improvement comes from the program delivery and implementation side. The application onboarding complexity needs to be simpler. Idira IGA could improve by providing a lighter-weight integration option that does not require application code changes. Additionally, while automatic credential rotation is one of Idira IGA's most prominent security features, it can be dangerous for large enterprises if not done properly. A rotation event that was carried out in the test environment caused an application to lose its database connection because it cached the old credential instead of calling Idira IGA dynamically. Therefore, Idira IGA could improve by incorporating an automated application impact assessment into the onboarding workflow.
Visibility into account sprawl before onboarding could also enhance usability, as the strongest problems for shared accounts or service account remediation were our lack of visibility into which systems depended on a given shared account. Idira IGA itself does not discover that dependency map, managing only the accounts it is programmed to report. Additionally, the native reporting in Idira IGA is functional but not executive-ready.
For how long have I used the solution?
I have used Idira IGA since 2025, and it has been about two years.
What other advice do I have?
An example of how I used Idira IGA was when I implemented it in the form of CyberArk with privileged access management, or PAM.
I mentioned the SOX compliance at the bank as the primary regulatory driver behind the CyberArk program. The SOX Act requires financial institutions to maintain strict control over access to financial systems, knowing who has access, what they did, and whether the access is properly managed and audited. The ISO/IEC 27001 compliance requires organizations to implement and maintain an information security management system with documented controls across access management, logging, monitoring, and incident response. Several of these controls were mapped directly to what the CyberArk program delivered.
I would rate Idira IGA a six out of ten overall. I chose this rating because of the areas where I see improvements could be made. My observations about operational friction points and the challenges slowing down adoption during implementation have led to this rating.
Regarding Idira IGA's AI capabilities, I believe there could be improvements in prioritizing features that reduce implementation friction and increase adoption.
The AI-driven anomaly detection and improvements represent a long-term opportunity for Idira IGA. This is where the platform needs to head to stay ahead of the threat landscape. Simpler legacy application onboarding, smarter rotation readiness checks, and native dependency discovery will make a significant difference for organizations.
Idira IGA is deployed in the cloud across the two organizations I have experience with.
Improvements needed for Idira IGA that I have not mentioned yet include alignment with banking regulations and compliance as well as enhancements according to the national NIST framework.
At Truist Bank, it took us about six months to deploy our previous IGA solution, primarily because we had to conduct compliance checks with various teams. Deploying CyberArk Modern IGA took three months. Compared to past solutions, the CyberArk deployment was pretty fast due to strong support from account managers and the many out-of-the-box configurations CyberArk offered.
My team spends less time on access reviews and evidence collection compared to before, taking about two to three hours of work with two technical people, depending on the subject matter experts available. Automation has made access reviews faster and more accurate.
My advice for others looking into using Idira IGA would be to prioritize improvements that reduce implementation friction and increase adoption. The gap between what CyberArk can do and what an organization achieves is not due to platform capability, but rather the difficulty of achieving effective implementation. Simpler legacy application onboarding, smarter rotation readiness checks, and native dependency discovery will differentiate organizations that achieve full privileged access coverage from those that stall at 60 percent and stop. My insights come from leading delivery and identifying operational friction points rather than from a product engineering perspective.
Idira IGA is a very good solution for privileged access management and stands out against the rest. I hope it continues to improve. My overall rating for this review is six out of ten.
Secure password rotations and monitored sessions have strengthened our daily banking operations
What is our primary use case?
In our day-to-day activities, we use Idira IGA for storing passwords, rotating passwords, and securing connections.
We support users and onboard user accounts, elevated accounts, privileged accounts, and all accounts on Idira IGA. On a daily basis, we rotate them according to company policies.
Apart from password rotations, we store passwords on the web application. According to user requirements, we provide access to users and approvers. Once a user requests a password, the manager must approve it. Then, the user can access the password. We have implemented policies according to Idira IGA policies.
What is most valuable?
The best feature is the secure logins and secure connections. Whenever a user needs to connect to the target machine, they must log in to the web application. From the web application, the user can connect to the target machine with the help of the PSM component. This is a very valuable feature in Idira IGA.
Not only my team, but the entire organization stores recordings with the help of this PSM. Whenever a user wants to connect to the target machine, they must log in to Idira IGA, which is CyberArk. Later, from the web application, the user can connect to the target machine. This allows for secure connection instead of a user directly connecting through RDP.
Apart from this, whenever a user tries to access the target machine and does something wrong, the manager can monitor what the user is doing and has permissions to stop the session whenever needed. Idira IGA has many features in the PSM component.
In my organization, with the help of Idira IGA, we secure our passwords and rotate passwords. This is very helpful for our organization to maintain secure growth.
What needs improvement?
Currently, they are improving significantly, and whenever vulnerabilities arrive, they notify customers. Whenever they upgrade versions, they notify customers. This is very good. Whenever we contact customer support, they provide prompt responses. Everything is good on their end.
For how long have I used the solution?
I have been working in my current field for around ten years, and I have been working in my current organization for three years.
How are customer service and support?
Whenever we contact customer support, they provide prompt responses. Everything is good on their end.
What other advice do I have?
On a daily basis, we rotate passwords automatically. Whenever the user retrieves the password, after settings such as twelve hours or eight hours, the password expires. This means that the user cannot use the same password again. This is very secure. The organization, as I work in the banking sector, finds this very helpful for us and our clients to maintain all applications securely.
I would suggest to them that whenever an issue occurs, with the help of logs, we need to go to Idira IGA community portal and validate that.
Identity governance has strengthened automation and now delivers holistic security insights
What is our primary use case?
My main use case for Idira IGA is mostly for the governance and administration point of view. Normally, we are using a UAR facilities and joiner mover leaver part.
One specific example of how I use Idira IGA for governance and administration is that we align the policy and procedure based on the access request approval workflow, user access review, SOD policies, and provisioning engine.
What is most valuable?
Idira IGA is integrated with privileged access management, and it gives us broader identity security capabilities in a single platform, which is an added advantage.
The best features Idira IGA offers include especially the provisioning engine, which gave us a broader scope and broader identification for security prospects.
Multiple features worth highlighting include adding an identity security platform with PAM, then ITDR capabilities, and Microsoft Entra suite, and how it will integrate with the CyberArk PAM.
Idira IGA has positively impacted my organization by providing good governance and giving us more depth information as an SOC and NOC provisioning, especially since we are already using Office 365, Entra ID, Intune, and Microsoft Defender.
The depth of information has helped my team by integrating with PAM and giving us a holistic view based on the access management, identity threat detections, and identity governance, providing a very broad umbrella to solve things based on security layers.
The impact of automation on our access reviews is significant, as it reduces the manual work. For example, automation has reduced time and effort for our team, as it correlates with Idira IGA, PAM, and other SOC environments, giving a complete holistic view for troubleshooting and identifying the operation model and security posture compliance, ultimately providing cost structure-wise business agility. The great value comes when moving forward to relative operations in a policy-driven manner, giving us a good output.
What needs improvement?
Idira IGA can be improved in addressing our core pain point of joiner, leaver, and remover, which we identify with SSO, MFA, read admin access, PAM request, and the process holistic view and hierarchy, particularly in the model and the integration part based on the HRM module or JD Edward module.
Integration with JD Edwards, especially with SAML authentication, would be beneficial.
Improvements are needed on the reporting side and integration with the ITSM module for smoother automation and intelligence graph based on department-wise organization. The automated response needs to revoke token, force MFA, and disable accounts more proactively in the reporting side.
Idira IGA's scalability still needs to mature more; over time, it will mature and provide us with a more holistic view and details about the correlation and integration into a single umbrella.
For how long have I used the solution?
I have been using Idira IGA for the past two years.
What do I think about the stability of the solution?
Idira IGA is stable and has been reliable for us so far.
What do I think about the scalability of the solution?
Idira IGA's scalability still needs to mature more; over time, it will mature and provide us with a more holistic view and details about the correlation and integration into a single umbrella.
How are customer service and support?
We have not interacted much with the AI capabilities, but it has very good machine learning behavior analytics and provides good risk scoring, giving us proper graph analytics. However, we want more proactive reporting if it is integrated with multiple solutions such as IGA, PAM, and ITDR, providing us a more holistic view.
Which solution did I use previously and why did I switch?
I did not previously use a different solution; earlier we only used PAM, which is CyberArk, and now we have integrated with the same.
How was the initial setup?
It took five months to deploy Idira IGA from setup to initial go-live as a maturity part. Compared to the past solutions, there is not much difference; I noticed no major differences since the organization level structure designing took almost the same time.
What was our ROI?
I have seen a little return on investment, which is a bit early, but it is time saved and employee savings that one can note.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that it is costly compared to other marketplaces, but based on the utilization, I will see if it is really worthwhile or not.
Which other solutions did I evaluate?
Before choosing Idira IGA, we evaluated other options based on governance and marketplace validation.
What other advice do I have?
My advice to others looking into using Idira IGA is that the correlation and the integration are the added benefits and holistic view, but it needs to work more on the reporting side, and once matured more, we will be able to know because the good features are joiner, mover, and leaver, role mining, access review, and PAM integration, which are key points.
Idira IGA needs to focus on identity maturity and the visibility life cycle, especially with governance automations and business transformation. As I am transforming from on-premises to cloud, I want to see the benefits and level of governance automation we can fetch. I rate this product an eight overall.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Unified identity governance has streamlined automation, compliance, and audit readiness
What is our primary use case?
Idira IGA serves as a unified platform combining IAM, PAM, IGA, and machine identity security within HP. One example of how I use Idira IGA in my day-to-day work is through the PAM capability, where we utilize something called digital workforce within HP. These are Bot IDs used for automations. Whenever we request any new automation to be created, we request a Bot ID with the IGA team within HP, and then it gets onboarded to the PAM solution for automatic credential rotation management on the platform.
Other use cases for Idira IGA include management of specific types of accounts, such as supplemental accounts and service accounts. We also use IGA for onboarding users into many other applications within our organization and providing user access, attaching the roles and permissions necessary. Using this platform, we are able to drive our SOX activities, including segregation of duties and other SOX controls which can occur on any application. Those activities are tracked and maintained on this platform.
What is most valuable?
Idira IGA offers several good features, including integration capabilities that allow it to integrate with many SaaS apps, on-premises apps, and cloud platforms. It also has APIs, which make it useful for integration with different types of downstream and upstream applications. Additionally, it provides a unified identity security platform that functions as a single platform for IGA, PAM, and IAM security, serving as a single control plane for all these platforms and capabilities. It also has native governance for most of these capabilities and inbuilt compliance integrated into the workflows, making it easy for us to meet our regulatory frameworks for SOX.
We rely mostly on the integration features of Idira IGA. For example, PAM is one of the tools we use most from Idira IGA, where we are connecting to privileged accounts and utilizing them for our automations across the organization. This is one of the most heavily used features. We also rely on this platform for our SOX activities to gather all audit-based evidence collections.
My favorite feature is the integration with PAM and the audit governance that it provides, making it truly helpful for us in driving our automations and SOX compliance activities. In terms of agentic capabilities and AI capabilities, it has some, but I believe it could improve in that area. We have not used that feature much, but I believe the combination of integration with agentic capabilities or autonomous agents within the platform could help increase the productivity of the platform.
Governance security on Idira IGA is very tight, providing all necessary requirements to keep data and transactions closely monitored. It has all the logging mechanisms within the platform. In terms of compliance, it aligns with most of the industry standard certifications and can be tightly integrated within our company network for setup. I believe AI readiness is present, with good governance and security measures in place.
Automation has significantly reduced both manual efforts and improved accuracy in our access reviews, which has changed how quickly we complete these processes. For example, we previously onboarded users through a different tool, which took considerable time due to back and forth emails and manual approvals for requests. Now, with this platform, everything is automated, requiring just one form and one approval, making the process much more efficient. What used to take about seven or eight days can now be accomplished within a couple of working days.
What needs improvement?
Idira IGA platform itself is somewhat complex to understand initially, so the UI and user interface could be simplified. This is one pain point I see. Additionally, an agentic layer could be improved on the platform. Instead of filling many forms to onboard any account or get access permissions, we could use the agent, invoke it, and through conversing naturally with the agent, we could get the access and onboarding completed quickly. This would simplify processes for most of our teams, so these two are the primary improvements I feel should be made.
Support is not an issue; however, performance-wise, the application feels somewhat heavyweight. It could possibly be made lighter by improving the underlying backend technology. Adding an additional agentic layer would also help simplify how we interact with the application.
The AI capabilities of Idira IGA are not extensively used by us, but I believe the accuracy of the responses we have utilized is good. However, regarding agentic actions, I think there is room for improvement overall on the platform.
For how long have I used the solution?
I have been working in my current field for almost thirteen years.
What do I think about the stability of the solution?
Idira IGA is quite stable.
How are customer service and support?
Customer support for Idira IGA is good. They are responsive and provide a first response within a few hours, with most issues resolved within a couple of days.
Which solution did I use previously and why did I switch?
We did not have any centralized IGA solution previously, but we had some tools around PAM such as CyberArk. Idira IGA now serves as a comprehensive solution that suits all of our needs.
How was the initial setup?
I believe it took somewhere around six months to go live with our previous IGA solution. Idira IGA deployment took less than a quarter. Compared to past solutions, our Idira deployment was at least 50 percent faster.
What was our ROI?
Currently, the return on investment is mostly reflected in time and effort reductions. We have indeed saved some headcounts as part of this deployment, but the metrics primarily highlight time-saving and accuracy improvements.
What's my experience with pricing, setup cost, and licensing?
Pricing-wise, I find Idira IGA very competitive compared to other IGA tools available in the market.
Which other solutions did I evaluate?
We evaluated options from other vendors, such as BeyondTrust, but Idira IGA suited us better.
What other advice do I have?
I would definitely recommend customers use Idira IGA as a single platform for all governance around PAM, application, and user provisioning. It is definitely recommended for large organization deployments. I provided this review with a rating of nine.
