Secure Privileged Access. Simplify Identity Security.

The AIC Enterprise Privilege Suite™ discovers, rotates, and propagates privileged credentials across Microsoft Windows, Linux, Unix, macOS, network devices, databases, cloud, and Operational Technology (OT).

Request a demoReview the Requirements Checklist

From the Blog

Overcoming CMMC Chaos, Failure, and Fines

Cybersecurity Maturity Model Certification (CMMC) defines requirements. Turning those requirements into a working, maintainable security environment is a separate challenge, especially for smaller organizations with limited staff and resources.

Read the article

Scattered documents, keys, and disconnected security controls on the left transition through a blue arrow to an organized, connected security system on the right.

For defense suppliers: AIC CMMC Complete™

AIC CMMC Complete™ is a packaged product for subcontractors in the Defense Industrial Base preparing for Cybersecurity Maturity Model Certification (CMMC). Each level is a ready-made secure enclave appliance on Microsoft Azure that runs the controls, trains your workforce, and keeps the records your assessor asks to see.

One-time startup fees and terms are on CMMC pricing.

Explore AIC CMMC Complete™

Explore AIC CMMC Complete™ for Defense Suppliers

One Platform, Four Connected Workflows

Manage credentials, control their use, and review the result through the AIC Enterprise Privilege Suite™. The modules share one roster, one policy engine, and one audit trail.

Coverage Across Privileged Access and Identity Security

Privileged Access Management (PAM), Privileged Identity Management (PIM), Privileged Account and Session Management (PASM), Privilege Elevation and Delegation Management (PEDM), Endpoint Privilege Management (EPM), secrets management, and Remote Privileged Access Management (RPAM) connect the core workflows.

Just-in-Time (JIT) elevation and Zero Standing Privileges (ZSP) apply to enrolled-system elevation. Service and machine credentials cover Non-Human Identities (NHIs). Identity Governance and Administration (IGA) covers suite-managed accounts. Conditional access and Identity Threat Detection and Response (ITDR) connect sign-in controls, alerts, and response; configuration findings and rescans support Identity Security Posture Management (ISPM).

Cloud Infrastructure Entitlement Management (CIEM), broader application governance, and certificate lifecycle management are planned extensions.

See Which Modules Perform Each Function · Review Terminology and Capability Scope

Built for the RFP

Review 127 requirements across eleven Request for Proposal (RFP) categories, from discovery and credential management to integrations, recovery, and support. The checklist describes each requirement and identifies planned extensions.

See the privileged access RFP, row by row

Where AIC Enterprise Privilege Suite™ wins

Air-gapped operation

AIC Enterprise Privilege Suite™ runs on networks with no internet connection, including classified enclaves.

FIPS 140-3 validated cryptography

Cryptography runs through Federal Information Processing Standards (FIPS) 140-3 validated modules.

Hardware Security Module key custody

Master keys can stay in your Hardware Security Module (HSM).

Recorded sessions with command control

Privileged sessions are recorded, and commands can be allowed or blocked per policy.

One product

One platform built as one product, rather than a set of acquired products.

See air-gapped operation

Replace your current PAM product

The AIC migration program moves vaulted accounts, policies, and session rules from your current PAM product into AIC Enterprise Privilege Suite™, with an implementation partner if you want one.

See the migration program | Talk to us about migration

See the controls in action

A live SSH command line, recorded, with a dangerous command blocked as it is typed.

Runs on and connects to

AIC Enterprise Privilege Suite™ runs on the operating systems, hypervisors, containers, and clouds below, and connects to the identity, monitoring, ticket, key, and notice systems listed in the Request for Proposal (RFP) checklist.

Area Integrations
Host platforms Microsoft Windows, Linux (Red Hat Enterprise Linux, Ubuntu), macOS, Hyper-V, VMware, Proxmox, KVM, Nutanix, XenServer, Docker, Podman, Kubernetes, OpenShift, and virtual machines on Azure, Amazon Web Services (AWS), Google Cloud, and Oracle Cloud Infrastructure
Identity and federation Microsoft Active Directory, Microsoft Entra ID, Lightweight Directory Access Protocol (LDAP), Okta, Ping Identity, OpenID Connect, Security Assertion Markup Language (SAML) 2.0, SailPoint, YubiKey, and RADIUS
Security monitoring Security Information and Event Management (SIEM): Splunk, Microsoft Sentinel, Datadog, Amazon CloudWatch, Google Cloud Logging, Windows Event Log, and syslog
Service management ServiceNow, Jira, and other trouble-ticket systems
Key custody Hardware Security Module (HSM) profiles for Thales, Entrust, Utimaco, Futurex, IBM, YubiHSM, and PKCS#11, plus cloud Key Management Service (KMS)
Notices Short Message Service (SMS) through Twilio, Vonage, Plivo, Amazon Simple Notification Service (SNS), Telnyx, and MessageBird

The AIC Enterprise Privilege Management Suite™ and AIC CMMC Complete™ run on the operating systems, hypervisors, containers, and clouds below, and connect to the identity, monitoring, ticket, key, and notice systems shown below.

Runs On

  • Microsoft Windows
  • Linux
  • Red Hat Enterprise Linux
  • Ubuntu
  • Apple macOS
  • Microsoft Hyper-V
  • VMware vSphere
  • Proxmox Virtual Environment
  • QEMU and Kernel-based Virtual Machine
  • Nutanix AHV
  • Citrix XenServer
  • Microsoft Azure
  • Amazon Web Services
  • Google Cloud
  • Oracle Cloud Infrastructure
  • Docker
  • Podman
  • Kubernetes
  • Red Hat OpenShift
  • Oracle VirtualBox

Connects To

  • Microsoft Active Directory
  • Microsoft Entra ID
  • Lightweight Directory Access Protocol
  • Okta
  • Ping Identity
  • OpenID Connect
  • SailPoint
  • Yubico YubiKey
  • RADIUS
  • ServiceNow
  • Atlassian Jira
  • Splunk
  • Microsoft Sentinel
  • Datadog
  • Amazon CloudWatch
  • Google Cloud Logging
  • Thales
  • Entrust
  • Utimaco
  • Futurex
  • IBM Cloud HSM
  • PKCS#11
  • Twilio
  • Vonage
  • Plivo
  • Telnyx
  • MessageBird

All logos and trademarks are the property of their respective owners. Their use does not imply endorsement.

Experience since 1993

Founded by Philip Lieberman, who is widely credited with creating the field of privileged identity management. Building cybersecurity software since 1993.

Cybersecurity engineering experience dating to 1993, with pioneering work in privileged identity management.

Meet Our Staff

See AIC Enterprise Privilege Suite™ on your use case

Try AIC Enterprise Privilege Suite™ in the free cloud demo environment, or evaluate it on site for 30 days.

Request a demo