Vendor hubIGA · Certification · SoDTechBag Intel Hub

SailPoint

The identity governance category leader — ranked #1 by revenue in IGA by Gartner’s 2024 market-share research — running in the AWS Mumbai region since November 2024. This hub is your complete intel file, including the cost reality most buyers discover late: implementation typically runs 2–3× the licence.

Data residency & processing

SailPoint has run on AWS Asia Pacific (Mumbai) since 27 November 2024 — its ninth point of presence globally. SailPoint’s own words: a highly available multi-tenant SaaS environment “completely isolated from other AWS Regions—no data will be replicated, backed up, or stored in any other AWS Region.” That is the strongest documented India data-storage position of any IGA vendor we carry. It is a statement about STORAGE. SailPoint does not separately document where data is processed, and we are not going to infer it — if processing location is part of your obligation rather than storage, ask SailPoint directly and get it in writing.

On CERT-In: the 180-day ICT log duty applies to you as the regulated entity, not to SailPoint. CERT-In’s own FAQ permits storage outside India provided logs are producible to the authorities in reasonable time — but if you are IRDAI-regulated, the 2023 audit annexure asks as a plain yes/no whether ICT logs are stored in India, and that is where an offshore region actually costs you.

5 intel pages insideAWS Mumbai region since Nov 2024Pune office since 2011

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

The company, at a glance

ListedNasdaq: SAIL · re-listed Feb 2025
LeadershipMark McClain — CEO & Founder
Scale$1.125B ARR · up 28% (FY2026)
Market position#1 by revenue in IGA (Gartner 2024)
PricingQUOTE-ONLY — and services are 2–3× licence

Quick answer

SailPoint is the identity governance category leader, and for an Indian buyer the most important fact about it is not the market position but the Mumbai data region. Gartner's Market Share: Security Software, Worldwide 2024 ranks SailPoint first by revenue in identity governance and administration, and the company reported $1.125 billion in annual recurring revenue for its 2026 fiscal year, up 28 percent, with SaaS ARR of $746 million growing 38 percent. It is public again on the Nasdaq as SAIL, having re-listed in February 2025 at $23 a share and raised $1.38 billion, three years after Thoma Bravo took it private for around $6.9 billion. Thoma Bravo retained roughly 88 percent, which makes SailPoint a controlled company — a governance fact worth knowing if you are committing to a platform for a decade. The product is Identity Security Cloud, built on a core the company calls Atlas, covering the questions every access review has to answer: who has access to what, should they, and can you prove it. Around it sit Non-Employee Risk Management for contractors and partners, Data Access Security for the files themselves, cloud infrastructure entitlement management, and IdentityIQ, the on-premises product that still runs in thousands of enterprises. Now the two things we would rather tell you before a sales cycle than after. First, the India position is genuinely strong and specific: SailPoint has run on AWS Asia Pacific (Mumbai) since November 2024, its ninth point of presence globally, in an environment it describes as completely isolated from other AWS regions with no data replicated, backed up or stored elsewhere. That is a documented statement about storage, and we are not going to stretch it into a claim about processing, which SailPoint does not separately document. Second, the honest cost warning: the licence is not the expensive part. Third-party reporting consistently puts implementation at two to three times licence cost, and that ratio is the single most common complaint from buyers who felt surprised. SailPoint is an enterprise product with an enterprise implementation, and below roughly a thousand identities it is difficult to justify. There is also no Gartner Magic Quadrant for IGA — the current research is a Market Guide, which names representative vendors rather than leaders, so anyone claiming an MQ Leader position in this category is misreading it. TechBag scopes SailPoint honestly against Saviynt and the lighter alternatives, and invoices in INR with GST. Read more ↓ Show less ↑
The portfolio

Three intel pages. One agent underneath.

Devices, identity and security — three products sharing one agent. Each intel page is a full decision file.

The platformIntel page →

Identity Security Cloud

Who has access to what, should they, and can you prove it.

The flagship, built on the core SailPoint calls Atlas: joiner-mover-leaver automation, access certification campaigns, role modelling and mining, segregation-of-duties policy, and the evidence trail an auditor actually asks for. This is the product that makes SailPoint the category leader, and it is the one to evaluate if your driver is an access review you cannot currently produce. Runs in the AWS Mumbai region for Indian customers.

#1 by revenue in IGAExplore
On-premisesIntel page →

IdentityIQ

The on-prem line — and the migration question, answered honestly.

The on-premises product that still runs in thousands of enterprises, and the reason a lot of Indian buyers first met SailPoint. Its rules and workflow engine is more flexible than the cloud platform's, which is exactly why complex legacy estates stay on it. The honest position on migration, because the industry overstates it: there is no announced end-of-life for IdentityIQ, and a typical move to Identity Security Cloud takes two to three years with both platforms running in parallel. Anyone telling you to migrate this quarter is selling you a project.

No announced end-of-lifeExplore
The blind spotIntel page →

Non-Employee Risk Management

Contractors, vendors and partners — the identities HR never sees.

Your HR system knows about employees. It does not know about the contractor onboarded by a project manager, the vendor engineer with a support login, or the partner who still has access two years after the engagement ended. Non-Employee Risk Management gives those identities a lifecycle, an owner and an expiry, with centralised visibility over business-partner access. Since September 2025 it integrates with Microsoft Entra Verified ID for faster onboarding and biometric verification. For an Indian enterprise running a large contractor base, this is frequently the gap an auditor finds first.

Entra Verified ID integrationExplore
Beyond applicationsIntel page →

Data Access Security

Govern access to the data itself, not just the app that opens it.

Access certification usually stops at the application. Data Access Security goes to the files: automatically classifying sensitive data across cloud, on-premises and SaaS, applying consistent tagging and sensitivity labels, identifying over-privileged access, detecting externally shared sensitive content, and enabling fine-grained access reviews of data assets themselves. For DPDP Act obligations, where the question is about personal data rather than about an application, that distinction is the whole point.

Cloud, on-prem and SaaSExplore
Multi-cloudIntel page →

Cloud Infrastructure Entitlement Management

Cloud entitlements, discovered and right-sized.

Cloud infrastructure generates entitlements faster than anyone governs them, and most of them are over-privileged by default. CIEM gives unified visibility into cloud access from one console, discovers human and non-human identities across multi-cloud environments, right-sizes permissions toward least privilege with AI-driven insights, produces audit-ready reports on who has access to what, and runs cloud-specific certification campaigns. The non-human half matters more each year — service accounts and workload identities now outnumber people in most cloud estates.

Human AND non-humanExplore

Machine Identity Security

Platform layer

Discovery, classification and ownership of machine accounts — service accounts, bots, shared accounts

Access Risk Management

Platform layer

SAP-focused access risk and segregation-of-duties analysis

Agentic Fabric

Platform layer

SailPoint's framing for AI-agent identity — marketed as a fabric rather than sold as a discrete SKU

Harbor Pilot

Platform layer

AI assistance across the platform

SailPoint is one of 16 identity governance products TechBag carries. The Identity Governance guide shows how the category splits and which part is yours. →

The thesis

The two things buyers find out late

SailPoint genuinely leads this category — Gartner’s 2024 market-share research puts it #1 by revenue in IGA, and the AWS Mumbai region gives it the strongest documented India data-storage position of any vendor here. Two things are worth knowing before the sales cycle rather than during it. The licence is not your budget — third-party reporting puts implementation at two to three times licence cost, and below roughly a thousand identities the economics are hard to justify at all. And there is no Gartner Magic Quadrant for IGA, so any vendor claiming to lead one is misreading a document that does not exist in that form.

01
The India fact

The Mumbai region — and exactly what it does say

SailPoint has run on AWS Asia Pacific (Mumbai) since 27 November 2024, its ninth point of presence globally. The company's own description is specific: a highly available multi-tenant SaaS environment, completely isolated from other AWS regions, with no data replicated, backed up or stored in any other AWS region. That is a documented statement about where data is STORED, and it is a strong one — stronger than most competitors can offer. We are not going to stretch it into a claim about where data is PROCESSED, because SailPoint does not separately document that. If processing location is in your obligation rather than storage, get it in writing before you sign.

02
Market position

Category leadership that is real, stated precisely

Gartner's Market Share: Security Software, Worldwide 2024 ranks SailPoint first by revenue in identity governance and administration. That is a citable, meaningful position. What it is NOT is a Magic Quadrant placement, because there is no Gartner Magic Quadrant for IGA — the current research is a Market Guide, published 2 October 2025, and Market Guides name representative vendors rather than leaders. Any vendor page claiming to be an 'IGA MQ Leader' is misreading a document that does not exist in that form. We would rather be precise than impressive.

03
⚠️ Budget honestly

The cost warning we would rather give you early

The licence is not the expensive part. Third-party reporting consistently puts SailPoint implementation at two to three times licence cost, and that ratio is the most common source of buyer surprise in this category. It is not a criticism of the product — enterprise IGA is genuinely hard, connectors take work, and role modelling is a real project — but a budget that covers licence and treats services as a rounding error will be wrong by a multiple. Below roughly a thousand identities, the economics are difficult to justify at all, and we will tell you so rather than take the order.

04
The migration truth

IdentityIQ is not being switched off

There is no announced end-of-life for IdentityIQ, and a typical migration to Identity Security Cloud takes two to three years with both platforms running in parallel. The on-premises rules and workflow engine remains more flexible than the cloud platform's, which is precisely why complex estates stay on it. SailPoint runs an upgrade programme with a free assessment for customers who do want to move, and configured connectors, objects and rules can carry across. But the decision is yours to time, and anyone presenting it as urgent is selling a project rather than answering a requirement.

05
The company

Public, profitable-scale, and 88 percent controlled

SailPoint re-listed on the Nasdaq as SAIL in February 2025 at $23 a share, raising $1.38 billion, three years after Thoma Bravo took it private for around $6.9 billion. FY2026 ARR was $1.125 billion, up 28 percent, with SaaS ARR at $746 million growing 38 percent and customers above $1 million ARR up 62 percent year on year. Being public means the numbers are disclosed rather than asserted. The counterweight worth stating: Thoma Bravo retained roughly 88 percent, which makes SailPoint a controlled company with its private-equity owner holding final say on board decisions.

Start where the pain is; the other two products attach to the same agent — never a second operational world.

The trophy wall

Peer & market recognition

Every claim on this hub traces to one of these public signals.

Gartner

#1 by revenue in IGA

Market Share: Security Software, Worldwide 2024

Nasdaq

SAIL — public again

Re-listed Feb 2025, $1.38B raised

27 Nov 2024

AWS Mumbai region

9th point of presence — isolated, India-stored

FY2026

$1.125B ARR, +28%

SaaS ARR $746M, +38%

Pune

India office since 2011

200+ staff as of 2023

⚠️ Ownership

~88% Thoma Bravo

A controlled company

⚠️ The real cost

2–3× licence

Typical implementation, third-party reported

Analyst standing

No IGA MQ exists

It is a Market Guide — representative vendors

By the numbers

The company in six figures

$1125M ARR
FY2026, up 28% year on year
SailPoint
$746M SaaS ARR
Up 38% — the faster-growing half
SailPoint
#1 by revenue in IGA
Gartner Market Share: Security Software, Worldwide 2024
Gartner
9th point of presence
AWS Mumbai, live since 27 November 2024
SailPoint
+62%
Growth in customers above $1M ARR
SailPoint
up to 3× licence
⚠️ What implementation typically costs
Third-party reported

See the platform, hear the pitch

SailPoint (official)·Overview

SailPoint Identity Security Cloud Overview

The platform, introduced by SailPoint.

SailPoint (official)·Guide

A guide to SailPoint Identity Security Cloud

A product-marketing walkthrough of the suites.

SailPoint (official)·NERM

SailPoint Non-Employee Risk Management Overview

The contractor and partner blind spot.

The market maps

Where SailPoint sits — the grids

Two company-level views you won’t find on any vendor site — tap any dot for the rationale. The category-level grid lives on the product page.

Grid 01 · The portfolio

SailPoint Across Its Portfolio

Each dot is a SailPoint product: competitive position vs category momentum.

Emerging betsCrown jewelsSteady nicheAnchor strengths
Identity Security CloudSailPoint

The flagship platform on the Atlas core.

Grid 02 · The industry

The Convergence Map

Who genuinely converges devices, identity and security — and who staples products together.

Runnable nichesConverged & runnablePoint playersBroad but heavy
SailPointSailPoint

Category leader by revenue. Documented Mumbai region. Enterprise-priced.

Positions are TechBag’s illustrative synthesis of public review-platform standings and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Track 01 · Beginner guides

New to this? Learn it properly.

Zero-jargon starting points, in reading order. Each links into the deep education on the product page.

Interactive · 30 seconds

Which SailPoint product answers your problem?

Answer three questions; we’ll point you at the right starting product. No email required — this isn’t that kind of quiz.

1. What actually triggered this project?

2. Where does your identity estate live?

3. How big is the identity population?

Start here4 min

What IGA actually is, and what it is not

Identity governance answers three questions: who has access to what, should they have it, and can you prove it to someone who asks. That third question is what separates governance from provisioning. Plenty of products create and remove accounts — that is joiner-mover-leaver automation, and it is genuinely useful. Governance adds the review campaign, the segregation-of-duties rule, and the evidence trail. If your driver is an auditor's finding rather than an onboarding delay, you need the second thing, and a lot of buyers discover that distinction after they have bought the first.

Read →
Commercials3 min

Why the licence is not your budget

SailPoint is quote-only, and the number you eventually get is not the number that matters. Third-party reporting consistently puts implementation at two to three times licence cost. That is not padding: connectors to legacy applications take real work, role modelling is a genuine analytical project, and certification campaigns need designing before they need running. Budget for the programme, not the software, and be sceptical of any proposal where services look cheap relative to licence — it usually means the scope has not been thought through.

Read →
Compliance3 min

Storage, processing, and why they are different questions

SailPoint runs in the AWS Mumbai region and describes it as completely isolated from other AWS regions, with no data replicated, backed up or stored elsewhere. That is a documented statement about STORAGE. Where data is PROCESSED is a separate question with a separate answer, and SailPoint does not document it separately. For most buyers storage is what the obligation covers; for some — particularly IRDAI-regulated insurers — it is not. Establish which one your compliance team actually means before you shortlist, because the answer changes which vendors qualify.

Read →
Planning3 min

Should you migrate off IdentityIQ?

Probably not on anyone else's timetable. There is no announced end-of-life for IdentityIQ, thousands of enterprises still run it, and a typical migration to Identity Security Cloud takes two to three years with both platforms running in parallel. The on-premises rules and workflow engine is more flexible than the cloud platform's, which is why complex estates stay. SailPoint offers a free upgrade assessment and configured connectors, objects and rules can carry across — so the path exists when you want it. The decision is about your roadmap, not a deadline.

Read →

The acronym decoder

Every term on these pages, in one place
IGA
Identity governance and administration — who has access to what, should they, and can you prove it.
JML
Joiner-mover-leaver — automating access as people arrive, change role and leave. Provisioning, not governance.
Certification
An access review campaign: managers or owners confirm that the access their people hold is still appropriate.
Attestation
The evidence produced by a certification — the artefact an auditor asks for.
SoD
Segregation of duties — rules preventing one person holding combinations of access that enable fraud.
Role mining
Deriving roles from actual entitlement data rather than designing them on a whiteboard first.
Entitlement
A specific permission inside an application — the granular unit governance actually reviews.
Non-employee identity
Contractors, vendors and partners — identities the HR system does not own, and the usual audit gap.
CIEM
Cloud infrastructure entitlement management — governing permissions across cloud platforms.
Atlas
SailPoint's name for the core the Identity Security Cloud platform is built on.
Track 02 · Buying guides

Buy it like you’ve done this before

The procurement playbook TechBag runs with IT buyers — steps, licensing cheat-sheet, and the pitfalls that cost quarters.

01

Decide what your obligation actually says

Is the requirement an access review you must evidence, or account provisioning that is too slow? Those are different products, and the second is far cheaper. Separately: does your compliance obligation speak about data STORAGE or data PROCESSING? SailPoint documents the Mumbai region for storage and does not separately document processing — for most buyers that is fine, for some it is decisive.

02

Size it honestly, then budget for the programme

Below roughly a thousand identities, enterprise IGA is difficult to justify and we will say so. Above it, build the budget around implementation rather than licence: third-party reporting puts services at two to three times licence cost, and a proposal where services look cheap usually means the scope is not understood yet.

03

Scope the connectors before anything else

The work in an IGA programme is the applications. List every system that must be governed, identify which have supported connectors and which need custom work, and get that list priced. This single exercise predicts your timeline better than any other part of the evaluation.

04

Get the Mumbai region confirmed in writing

The AWS Asia Pacific (Mumbai) region is documented and the isolation language is specific, but get it in your contract along with the sub-processor list. If you are IRDAI-regulated, ask the processing question explicitly rather than assuming storage answers it.

05

Compare against Saviynt, and against doing less

Saviynt is the main alternative in most enterprise bake-offs and has the larger India engineering presence. And if the real requirement is joiner-mover-leaver rather than certification, a lighter product may genuinely be the right answer. TechBag scopes all three positions rather than defending the largest one.

The licensing cheat-sheet

ProductLicensing modelHow you enterBest for
Identity Security CloudPer identity, QUOTE-ONLYNo published rate cardCertification, SoD and the audit evidence trail
The real costServices, not licenceImplementation commonly 2–3× licenceBudget the programme, not the software
Navigators (Dec 2025)Digital Identity Flex · Premier FlexShift allocation between machine and agent identitiesStill quote-based
IdentityIQOn-premises licensingQuote-only; no announced end-of-lifeComplex legacy estates that need the rules engine
Minimum viable sizeNot a published floorBelow ~1,000 identities the economics are hardWe will tell you when it does not fit

Per-device and per-user pricing across the trio — TechBag negotiates the converged bundle against the vendors you’ll retire.

Five pitfalls that cost buyers quarters

1

Budgeting the licence and forgetting the programme

The most common and most expensive mistake in this category. Implementation typically runs two to three times licence cost. Connectors to legacy applications, role modelling and certification design are all real work, and a proposal that prices services thinly has usually not scoped them.

2

Buying governance when you needed provisioning

If the actual pain is that new joiners wait a week for access, that is joiner-mover-leaver automation and there are much cheaper answers. Governance earns its cost when someone has to prove access is appropriate. Establish which problem you have before shortlisting.

3

Assuming the Mumbai region answers a processing question

SailPoint's documented statement covers replication, backup and storage. Processing location is not separately documented. For most buyers storage is the obligation; for IRDAI-regulated insurers, whose audit annexure asks a direct question, it may not be. Ask explicitly.

4

Believing IdentityIQ is about to be switched off

There is no announced end-of-life, and migrations take two to three years with both platforms running in parallel. Treat a migration as a roadmap decision you time, not a deadline someone else set for you.

5

Reading '#1 in IGA' as a Magic Quadrant position

SailPoint is first by revenue in Gartner's 2024 market-share research, which is a real and citable position. It is not an MQ Leader placement, because there is no Gartner Magic Quadrant for IGA — the current research is a Market Guide naming representative vendors. Precision matters when an auditor reads your business case.

The evaluation kit

The flagship intel page carries an 8-question vendor checklist and an automation-savings calculator:

Skip the homework entirely

Bring your device counts and current tool bills — a TechBag advisor models the whole decision for you.

Book a discovery call →
FAQ

Questions buyers ask about SailPoint

No — and neither is anyone else, because there is no Gartner Magic Quadrant for identity governance and administration. The current Gartner research in this category is the Market Guide for Identity Governance and Administration, published 2 October 2025, and Market Guides name representative vendors rather than positioning them as Leaders, Challengers, Visionaries or Niche Players. The last IGA Magic Quadrant appears to have been published in 2019. So any vendor page claiming an 'IGA MQ Leader' position today is misreading a document that no longer exists in that form, and you should treat the rest of that page's claims with corresponding caution. What SailPoint can legitimately claim, and what we cite on these pages, is a different Gartner document: Market Share: Security Software, Worldwide 2024 ranks SailPoint first by revenue in IGA. That is a real, meaningful and checkable position — it says the market spends more with SailPoint than with anyone else in this category. It is not the same thing as a quadrant placement, and we would rather be precise than impressive. Worth noting as corroboration: SailPoint's own accolades page, which would certainly advertise an MQ Leader slot if one existed, cites no IGA Magic Quadrant at all.

Ready to shortlist SailPoint?

Open a product intel page for the deep dive, or bring your device and user counts and let a TechBag advisor build the converged case with you — quotes, trials, GST invoicing and lifecycle support included.

Stats, positions and figures are illustrative syntheses of public materials; verify before purchase.