§50 · Lane 8 — Agent Infrastructure Standards & Toolchain

Oso (Polar + Oso Cloud) the commercial policy-engine alternative to Cedar and OPA

Oso Security, Inc. (2026) · Oso Cloud + Polar

Policy Engine Tier 1 Lane 8 Commercial / Apache-2.0
Read on publisher · Commercial / Apache-2.0

Bibliographic data

Title
Oso — Polar authorisation language and Oso Cloud platform
Authors / Issuing body
Oso Security, Inc. (osohq)
Venue / Publisher
Oso Security, Inc.
Year
2026
Designation
Policy Engine
Licence
Oso Cloud is a commercial hosted product (proprietary terms); Polar and the open-source Oso client libraries are Apache-2.0

How to cite

Oso Security, Inc. (2026). Oso — Polar authorisation language and Oso Cloud platform. Oso Security, Inc.. https://www.osohq.com/docs.

Authorisation platform built on the Polar declarative policy language, delivered as the hosted Oso Cloud service with open-source Polar client libraries.

Why it matters for NETEVO

Oso models application authorisation in the Polar declarative language and answers questions such as whether a given actor may take a given action on a given resource, and which resources an actor may access. The current product is the hosted Oso Cloud service; the Polar language and the Oso client libraries are open source under Apache-2.0. Among policy engines, Oso is the commercial managed-service alternative to the open-source engines Cedar and OPA.

Oso Cloud is commercial with proprietary terms; only the Polar language and the client libraries are Apache-2.0. Any evaluation of Oso therefore needs to distinguish the hosted platform from the open-source language. For an organisation weighing policy-engine adoption, the choice is between self-hosting an open-source engine and procuring a managed service — both legitimate, with the familiar infrastructure trade-off between operational overhead and vendor concentration.

The maintained path is Oso Cloud. Current documentation is published at osohq.com/docs.

The product surface has broadened beyond application authorisation. The documentation now leads with agent-oriented capabilities — an agent-authorisation product, shadow-AI discovery, connectors, identity synchronisation, session monitoring, alerts and content tags — alongside deployment models spanning an edge proxy, a browser extension and a network overlay. The Polar reference documentation is unchanged and still resolves. For an organisation evaluating policy engines, the point of interest is the deployment models: an enforcement point that sits in the request path is the piece that a machine-readable policy statement, on its own, does not supply.

Where NETEVO applies this

Who acts on this

Reading this usually means something has forced the question — a listing, an audit finding, a procurement questionnaire, a regulator's letter. The role pages below set out what NETEVO does about it, including where we would tell you not to engage.