TRACK: BUYING
How to read a vendor's security page
SHORT ANSWER
Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29
3 min read
Identity security vendors publish a lot, and very little of it is written to be compared. Product pages mix what the product does today with what it is designed to do, what is planned and what is possible with partners. The useful skill is reading each sentence for what it actually commits to.
Stated, implied, missing
A stated capability names the thing and how it works. Silverfort's ITDR page, for example, names the attacks it detects, from password spraying to DCSync, and says it can block, challenge with MFA or end a session inline. An implied capability rests on a general phrase, such as covering every identity, without saying how. A missing capability is not mentioned at all. On this site, a cell whose reason says the public material does not describe something carries a Gap in public material tag and scores low.
Dates and status words
Read every date and every status word. Generally available, preview, planned and coming soon mean very different things for a buyer. Okta's September 2026 announcement listed Agent SSO as generally available and Agent Gateway, announced on 22 September 2026 as planned for Q3 2026 (https://www.okta.com/newsroom/press-releases/ai-innovations-oktane-2026/). Docker lists its Docker-managed cloud option as coming soon. Ping noted that availability of its May 2026 agent features varies by product, region or deployment model.
Prices and minimums
Where a price is published, read the basis: per user or per workload, per month or per year, billed monthly or annually, and any minimum. Okta's published plans carry a $1,500 annual minimum. Ping's published prices assume an annual contract with a 5,000-user minimum. JumpCloud shows different prices for annual and monthly billing. Where no price is published, the only accurate statement is that it is not published.
Certifications and ownership
Certifications such as SOC 2 Type II and ISO 27001 are stated facts that can be checked. Changes of ownership are too. Oasis Security is now part of Cyera, and Astrix Security, now part of Cisco, ended standalone sales of new licenses on 30 June 2026. Both change the questions a buyer should ask about roadmap and support.
Turning gaps into questions
- List the criteria that matter to you before reading any vendor page.
- For each vendor, mark each criterion as stated, implied or missing.
- Ask the vendor to show the stated items in a demo, and to document the implied and missing ones in writing.
- Re-score once you have the answers. A vendor that publishes the detail later deserves the higher score.
Related pages
Sources
- Silverfort: ITDR: https://www.silverfort.com/platform/identity-threat-detection-and-response/
- Okta newsroom, 22 Sep 2026: https://www.okta.com/newsroom/press-releases/ai-innovations-oktane-2026/
- Docker MCP Enterprise Gateway: https://www.docker.com/products/mcp-enterprise-gateway/
- Ping Identity press, 27 May 2026: https://press.pingidentity.com/2026-05-27-Ping-Identity-Redefines-the-Identity-Control-Plane-for-the-Agentic-Enterprise
- Okta pricing: https://www.okta.com/pricing/
- Ping Identity pricing: https://www.pingidentity.com/en/platform/pricing.html
- JumpCloud pricing: https://jumpcloud.com/pricing
- Oasis Security: https://www.oasis.security/
- Astrix Security: https://astrix.security/
NEXT LESSON
What an identity provider does, and what it signs
3 min read