BeyondTrust

Primary category: secrets-management. Also listed in identity-access.

One-liner — A top-tier privileged access management vendor — credential vaulting, privileged remote access and endpoint privilege management — consistently ranked alongside CyberArk and Delinea, and reportedly up for sale.

What it does — Three product lines. Password Safe is the privileged-credential vault with discovery, rotation, session management and recording. Privileged Remote Access (the Bomgar heritage) brokers vendor and administrator access to internal systems without VPN or shared credentials — genuinely strong, and the piece most directly relevant to a firm managing third-party administrator access to its trading and back-office systems. Endpoint Privilege Management removes standing local admin rights while permitting specific elevated actions. Newer work sits under identity-security posture: finding the privileged paths and standing entitlements that exist across an estate.

Naming / provenance — Long and tangled: the current company is the result of Bomgar (backed by Francisco Partners) acquiring BeyondTrust in 2018 and adopting the BeyondTrust name; earlier lineage runs through Symark and eEye Digital Security. Founding dates cited for it range from 1985 onward depending on which predecessor is counted — treat the founding year on this page as approximate.

Ownership & viabilitype-owned. Francisco Partners has held the majority since 2018; Clearlake Capital took a minority position closing August 2021. The live issue: Francisco Partners has been reported to be exploring a multi-billion-dollar sale, with roughly $500M ARR cited. No transaction has been announced as of 2026-08-26. Eight years is a long PE hold, so a sale is more likely than not — and for a product line that holds a firm’s privileged credentials, an ownership change is a genuine planning input, not gossip. verify_after: 2027-02-26.

Positioning & differentiators

  • Privileged Remote Access is the standout. Brokering third-party and vendor administrator access with full session recording is a specific, well-executed capability, and vendor access is a recurring finding in financial-services examinations and a repeated root cause in real breaches.
  • Analyst standing is genuinely top-tier — Leader in the 2025 Gartner MQ for PAM, and Overall Leader in the 2026 KuppingerCole Leadership Compass for a sixth consecutive year. Among the strongest independent validation of any vendor in this category. (Sourced here via a secondary aggregator, not the reports themselves — see confidence note.)
  • Versus cyberark: the closest peer. CyberArk is broader in identity security overall; BeyondTrust is at least its equal on remote/vendor privileged access.
  • Versus delinea: similar tier, similar PE dynamics. Delinea leans mid-market via Secret Server; BeyondTrust leans enterprise.

Who should choose them / anti-fit — Fits an enterprise-scale firm with substantial third-party administrator access — outsourced IT, managed service providers, fund-administration and market-data vendors touching internal systems. That describes a great many alternative managers, and it is the clearest reason for this page. Anti-fit: a small firm that needs a vault and nothing more (keeper, 1password); a cloud-native platform team (hashicorp-vault).

Known weaknesses / gotchas — Sale overhang per above. Deployment weight and cost are enterprise-grade. Most important history: in December 2024 BeyondTrust disclosed a compromise of its Remote Support SaaS instances via a stolen API key, an incident that was subsequently linked publicly to intrusions at the US Treasury Department. For a vendor whose product is privileged remote access, this is material and must be raised explicitly in diligence — what changed, and what the current key-management and tenancy-isolation model is.

Deployment & data handling — SaaS, on-prem and hybrid; on-prem remains fully supported and is the conservative choice for the vault given the incident above. SaaS key-management and isolation specifics are unverified.

Integrations & partnerships — IdP/directory, ITSM, SIEM, vulnerability management. MCP support unverified.

Compliance & FS tractionUnverified in specifics. Large regulated-industry install base including financial services is presumed; no named references confirmed. Certifications not confirmed here.

Commercial — Not public. Enterprise licensing by user/asset; among the more expensive options in the category.

Open questions

  • Sale status — recheck by 2027-02-26.
  • Post-December-2024 changes to SaaS key management, tenancy isolation and monitoring for Remote Support.
  • Verify the Gartner and KuppingerCole placements against the reports directly rather than the aggregator cited here.
  • Certifications held (FedRAMP status).
  • Named FS customers.

Sources

History

  • [2026-08-26] Page created via wiki-create + researched same day. Found by diffing the live SurveyMonkey instrument against the wiki.