# Oso Financial Model

Developer-first authorization library (open-source) that replaces hand-rolled authZ code with an embedded policy engine.

- Canonical: https://finamodel.com/startups/oso
- Excel download: https://finamodel.com/startup-models/oso.xlsx
- Category: Dev Tools
- Model type: SaaS ARR / Valuation
- Funding round: Series A
- Funding: $8.2M
- Founded: 2021
- Geography: US (team in NYC/SF area implied by MongoDB/Cornell pedigree; customers appear US-based).
- Customer: B2B

## About the company

Oso is an embedded authorisation policy engine built on Rust, with language bindings. Developers declare access rules in Polar instead of scattering role checks throughout application code. Unlike external policy engines, Oso runs inside the application process, keeping policy decisions close to application data.

At the deck stage Oso was open-source only, with no commercial product. The planned developer-led motion starts with community adoption and is expected to lead to paid enterprise controls such as support, service levels, SSO, and audit logs. The research does not disclose pricing, ARR, or customer count.

The product had been live 14 weeks with almost no marketing investment. First Resonance reached production with one engineer in three weeks, and Dhi said Oso accelerated its authorisation roadmap fourfold. The model should forecast downloads, active projects, qualified teams, enterprise conversion, ACV, expansion, churn, and advocacy.

## What's included

- 5-year monthly revenue build with stage-appropriate growth assumptions
- Full P&L, headcount plan, and operating-expense schedule
- Cash-flow statement, runway, and burn-rate tracking
- Valuation via exit multiple with a DCF cross-check
- Returns analysis with MOIC and IRR
- Unit economics including CAC, LTV, payback, and cohort retention

## Product & value proposition

- Oso is an embedded authorization policy engine built on a Rust core with bindings across languages/frameworks.
- Developers declare authorization rules in Polar (a Prolog-inspired, natural-language-like policy language), instead of hand-coding role checks scattered across the codebase.
- Key differentiator vs. OPA/Styra: policy engine runs embedded inside the application process (data co-located), removing the need for a separate deployment and the round-trip data-shuttling OPA requires.
- Addresses both greenfield (net-new authZ) and brownfield (migrating legacy RBAC) use cases.
- Tagline: "We put security in the hands of the makers."

## Market

- Related market (Gartner, cited in deck):
  - IAM: $10B
  - AppSec: $3B
  - Infrastructure Protection: $17B
  - All three markets growing at 6% per year
- App Authorization project spend per enterprise (proxy for per-customer ACV potential):
  - Gusto: $1M
  - Financial Planning SaaS Co: $1.2M
  - Endpoint Security Co: $1.8M
  - Infra Tech Co: $1.8M

## Revenue model

- Current: Open-source library; no commercial product yet at time of deck.
- Planned: Bottom-up / developer-led GTM (PLG) - developers adopt open-source, commercial product follows. Headcount plan is 3x, engineering-focused.
- Likely commercial model (implied by comp set and enterprise spend data): seat-based or usage-based SaaS subscription on top of OSS core; enterprise tier with SLAs, SSO, audit logs.
- Channels: Community/open-source self-serve; direct developer evangelism.

## Traction & metrics

- Product live for ~14 weeks at time of deck with "~no marketing investment."
- Qualitative engagement signals: positive community interaction shown (Slack, Twitter/social posts).
- Named design partner / early customer testimonials:
  - First Resonance (CEO Karan Talati): "1 engineer in 3 weeks" to production; planning to expand.
  - Dhi (CTO Gaurub Pandey): "Sped up our authZ roadmap 4x."
- Named companies with Oso in production (greenfield / brownfield slide): redacted names across Insurance Co, HR SaaS Co, Credit Card Co, Digital Pharma Co, Life Science & Research Co, Sales Forecast SaaS Co, Securities Mgt Co, Endpoint Security Co, Customer Data Platform Co, Financial Planning SaaS Co - suggesting 10+ early adopters.
- Customer count: Not explicitly stated.

## Unit economics

- Proxy data: enterprise app authZ project spend of $1M–$1.8M per company per project suggests high ACV potential once commercial.

## Competition / moat

Competitive landscape:
- DIY (dominant today): hand-rolled RBAC/ABAC; fragmented, repeated across every company.
- OPA / Styra: traction in Kubernetes infra access; architectural weakness for app authZ (data segregation, separate deployment, cited as complex).
- Legacy InfoSec tools (Active Directory, AXOMATICS, Authress, IONIC, Visual Guard): optimized for security teams, not developers; legacy / complex.
- Auth0 / Okta: handle authentication, punt authZ work back to developer.
- Open-source (e.g., Pundit): limited features, quality varies.

Moat claims:
- Embedded architecture (data lives in-process) - technical differentiation vs. OPA.
- Rust core = cross-language, cross-platform portability.
- Policy language built over 100+ iterations.
- Developer-experience positioning analogous to Stripe/Twilio for payments/comms.
- Team moat: CEO from MongoDB (bottom-up GTM playbook); CTO PhD Cornell Tech; angel investors include MongoDB CEO Dev Ittycheria, Honeycomb co-founder Charity Majors.

## Team & funding ask / use of funds

Team:
- Graham Neray - CEO; prior MongoDB.
- Sam Scott - CTO, PhD Cornell Tech.
- Engineers: Alex Plotnick (PhD), Leina McDermott, David Hatch, Steve Olsen, Gabe Jackson.
- Community: Stephie Glaser.
- Advisors/angels: Dev Ittycheria (CEO MongoDB), Charity Majors (CTO Honeycomb), Jared Rosoff (VMware Project Tanzu), Meghan Gill (VP SalesOps, MongoDB employee #8).

Funding ask: Not explicitly stated in deck. Deck implies a raise is in progress (it is a pitch deck; use-of-funds slide is absent).

Use of funds:
- Product: more "batteries" / integrations (frameworks, ORMs), developer experience (IDEs, testing), continued core work.
- Commercial product buildout.
- Education, documentation, evangelism.
- Headcount: 3x growth, engineering-focused.

---

## Recommended financial model

**Archetype + why:**
OSS-led PLG SaaS - open-source flywheel driving enterprise commercial conversion. Closest analogs: HashiCorp, Teleport, OPA/Styra. Model should track OSS adoption (GitHub stars/downloads as leading indicator) converting to paid seats/contracts. Given pre-revenue stage, model needs to project the OSS → commercial ramp, not current revenue.

**Forecast horizon & granularity:**
- 5 years (Year 1–5); monthly for Year 1–2, quarterly for Year 3–5.
- Year 1–2 focus: OSS growth, design partner conversion, first commercial contracts.
- Year 3–5 focus: enterprise ACV scale, land-and-expand, net revenue retention.

**Key drivers & assumptions:**

OSS / Top of Funnel
- OSS user base growth (GitHub installs / active developers): start at ~500 active OSS users at deck date (14-week-old product with ~10 known adopters); grow 15–20% MoM early, tapering to 8% MoM by Year 2 - typical early PLG.
- Self-serve signups from OSS base: 5–10% of OSS users evaluate commercial when launched.

Commercial Conversion
- OSS → paid conversion rate: 2–5% of active OSS users convert to paid on commercial launch (industry benchmark for OSS-led SaaS: 1–5%).
- Time to commercial launch: 12–18 months post-deck (deck lists commercial product as roadmap item).
- Pilot / design partner ACV: $30–60K/yr for early SMB; $150–500K for mid-market; potential $1M+ enterprise (validated by per-project spend data).

Land-and-Expand
- Initial ACV per customer: $50K average (blended); skewed by enterprise potential.
- Net Revenue Retention (NRR): 120–140% - authZ expands with use-cases (slide 13 explicitly shows multiple use-case expansions per customer).
- Logo churn: 5–8% annually - embedded infrastructure tools are sticky once in production.

Cost Structure
- Headcount plan: 3x current team; current team ~9 people; 3x = ~27 by end of Year 1 of raise.
- Fully-loaded engineer cost: $200K/yr (NYC/SF market).
- Sales / CS headcount: first enterprise AE hire in Month 9–12; CS from Month 12.
- Gross margin: 75–80% at scale (typical for embedded software/SaaS; low COGS - mostly support + hosting).
- Burn: $400–600K/month at 27 headcount; implies ~$5–7M/yr cash burn.

Market sizing (bottom-up)
- Addressable developers writing authZ code: ~2M globally (web/API developers at companies >50 employees).
- Target enterprise accounts (>500 engineers): 5,000 accounts globally.
- Penetration in Year 5: 1–2% of enterprise accounts = 50–100 logos; at $200K avg ACV = $10–20M ARR base case.

**Scenarios (Base / Bull / Bear - which variables flex):**
- Base: Commercial launch Month 15; OSS grows 12% MoM; 3% OSS→paid conversion; $50K initial ACV; 120% NRR.
- Bull: Commercial launch Month 12; OSS grows 20% MoM; 5% conversion; $100K ACV; 140% NRR; enterprise deals ($500K+) arrive Year 3.
- Bear: Commercial launch Month 18; OSS growth stalls at 6% MoM; 1.5% conversion; $30K ACV; 110% NRR; longer sales cycles.

**Required sheets / outputs:**
1. Assumptions - all drivers in one place, clearly tagged.
2. OSS funnel - installs / active users / commercial-eligible users over time.
3. ARR bridge - new ARR, expansion ARR, churn ARR, net new ARR; ending ARR by cohort.
4. P&L (Income Statement) - revenue, COGS, gross profit, OpEx by function (R&D, S&M, G&A), EBITDA, net loss.
5. Headcount plan - by function, hire dates, fully-loaded cost.
6. Cash flow & runway - cash burn, fundraise timing, months of runway.
7. Dashboard - ARR, NRR, LTV/CAC, gross margin, headcount, burn/runway.

## Frequently asked questions

### Is the Oso financial model free?

Yes. The Oso model is a free Excel download with live formulas.

### Can I change the assumptions?

Yes. The workbook is editable and its live formulas recalculate when assumptions change.
