View the full capability list

Integrated Identity Security and Privileged Access

Analog Informatics Corporation (AIC) builds privileged access, identity, audit, and compliance evidence into one set of kits. The modules are built into the Level 1, Level 2, and Level 3 kits. They are not sold as separate products. The Level 2 kit includes the Level 1 kit. The Level 3 kit includes the Level 2 kit. The kits run in the cloud or on premises, in a secure enclave, and on air-gapped systems.

The kits receive constant feeds, generate alerts, mitigate issues, and constantly monitor configuration compliance where a feed path exists. That makes continuous compliance possible instead of a point-in-time check. Training is free. We work with the reseller, Managed Service Provider, or service provider the customer already uses.

Capability List

Privileged Access

CapabilityWhat It Does
Privileged Identity Management (PIM)Vault, check out, and rotate privileged and service account credentials, including local administrator passwords.
Privileged Access Management (PAM)Live SSH, RDP, and VNC sessions in the browser through a broker, approvals, and command restriction that blocks dangerous commands as they are typed.
JumpManaged access path for privileged sessions. The Level 3 kit isolates Jump and records sessions.
Privileged User Management (PUM)Privilege elevation and delegation management: endpoint elevation, delegation, least privilege, application and command control, just-in-time elevation, and privileged activity auditing. Windows is the most complete today. Apple Mac and Unix/Linux are expanding.
Secure Application LaunchStart an application with credentials the user never sees.
Known default credential detectionScan networks, match systems and devices to licensed public default-password dictionaries, and flag dangerous defaults still in use. See Known Default Credentials.

Identity Security

CapabilityWhat It Does
Identity Governance and Administration (IGA)Account lifecycle and periodic access review for kit accounts. Governance across other applications is planned.
Data classificationCMMC, US government, NATO, and national markings with clearances, mandatory access control, and audited formal release. See Data Classification.
Conditional accessAllow, step up, or deny sign-in by country, network address, multifactor authentication, and session policy. See Conditional Access and Threat Defense.
Threat intelligence and attack reportDeny sign-in from addresses on threat feeds, and report blocked and failed attempts mapped to MITRE ATT&CK.

Compliance and Operations

CapabilityWhat It Does
Session recordingRecorded SSH, RDP, and VNC sessions with replay on the Level 3 kit.
Document sharing vaultStore and share sensitive files with classification marking.
AuditPrivileged-action and session records, Windows Event Log, and syslog for a security information and event management system.
Assessment BinderLiving evidence package shared by the assessor, the Managed Service Provider, and the customer.
Current State ComplianceLedger of control findings with rescan.
Configuration complianceCheck workstations and servers against STIG-oriented baselines, repair known settings with Fix-It, flag what needs IT, and optionally block a system until it complies. See Configuration Compliance.
VM power schedulingPower off idle workstations and session capacity on a schedule or after idle time, and start them on demand, to cut cloud cost and shrink the attack surface. See VM Power Scheduling.
Incident ResponseIncident records, detectors, and email or text alerts when a messaging path is configured.
Training and attestationAssign documents to named people and collect a signed attestation.
Governed mailMail for Federal Contract Information or Controlled Unclassified Information inside the kit.
Cryptography and key custodyAWS-LC cryptography with a FIPS 140-3 certificate on server cryptographic paths. Keys in software, in a PKCS#11 HSM, or in a customer-owned AWS KMS, Azure Key Vault Managed HSM, or Google Cloud KMS key. Separate key sets per system group, with rotation and re-encryption. See Key Management.
Directory sign-inActive Directory and LDAP sign-in, and Microsoft Entra ID, Okta, Ping Identity, and other OpenID Connect and Security Assertion Markup Language (SAML) 2.0 providers, with another step beyond a password.
High availabilityAutomatic database failover on customer-supplied hosts.
Air-gapped operationThe kits run on systems that are not generally connected.
Managed Service Provider operationA Managed Service Provider can administer inside the customer boundary.
LocalizationThe operator console ships with 18 language packs. See Localization.
Evidence feedsRecords can feed Competitors and other compliance packages through export and syslog.
Certificate lifecycle managementDiscovery, renewal, and governance of certificates across certificate authorities.
Cloud infrastructure entitlement managementAnalysis of cloud account permissions.
Vulnerability analysisAnalysis of discovered systems for known vulnerabilities. Planned as an add-on module.
Universal host logon bannerOne banner pushed to every system.

The industry terms for these capabilities are on Industry Functions.

Screenshots

A live SSH command line, recorded, with a dangerous command blocked as it is typed.
A live, recorded RDP desktop session to a Windows workstation, in the browser.
Endpoint privilege elevation and delegation covers Windows, Unix, approvals, policy, and air-gapped tokens in one place.
Failed sign-ins are mapped to MITRE ATT&CK technique T1110 Brute Force, with top sources and most-tried usernames.

More on Product Screenshots.

Industry Functions

Analog Informatics Corporation (AIC) Level 2 and Level 3 kits perform privileged account and session management (PASM), privilege elevation and delegation management (PEDM), secrets management, remote privileged access management (RPAM), just-in-time (JIT) privilege management, zero standing privileges (ZSP) for elevation, identity governance and administration (IGA) for kit accounts, identity threat detection and response (ITDR), and machine identity for service accounts. Cloud infrastructure entitlement management (CIEM) is planned. Identity security posture management (ISPM) is built into the Level 1, Level 2, and Level 3 kits. The modules are not separate products. The Level 2 kit includes the Level 1 kit. The Level 3 kit includes the Level 2 kit.

Which Industry Functions Do the AIC Modules Perform?

Each function is built into the AIC kit named in the answer.

Does AIC perform privileged account and session management?

Yes. Analog Informatics Corporation (AIC) performs privileged account and session management (PASM) in the AIC Level 2 and Level 3 kits through Privileged Identity Management, Privileged Access Management, Audit, Secure Application Launch, and Jump.

Does AIC perform privilege elevation and delegation management?

Yes. Analog Informatics Corporation (AIC) performs privilege elevation and delegation management (PEDM) in the AIC Level 2 and Level 3 kits through Privileged User Management. It covers endpoint privilege elevation, delegation, least-privilege enforcement, application and command control, just-in-time elevation, and privileged activity auditing. Windows coverage is the most complete today. Apple Mac and Unix/Linux coverage is expanding.

Does AIC perform secrets management?

Yes. Analog Informatics Corporation (AIC) performs secrets management in the AIC Level 2 and Level 3 kits through Privileged Identity Management and Secure Application Launch.

Does AIC perform cloud infrastructure entitlement management?

Planned. Cloud infrastructure entitlement management (CIEM), the analysis of cloud permissions across cloud accounts, is on the Analog Informatics Corporation (AIC) roadmap. Today the kits control privileged access to the systems they manage.

Does AIC perform remote privileged access management?

Yes. Analog Informatics Corporation (AIC) performs remote privileged access management (RPAM) in the AIC Level 2 and Level 3 kits through Privileged Access Management and Jump. The Level 3 kit adds session recording on Jump.

Does AIC perform just-in-time privilege management?

Yes. Analog Informatics Corporation (AIC) performs just-in-time (JIT) privilege management in the AIC Level 2 and Level 3 kits through Privileged User Management.

Does AIC perform zero standing privileges?

Yes, for elevation. Analog Informatics Corporation (AIC) removes standing administrator rights on enrolled systems and grants time-bound elevation through Privileged User Management in the AIC Level 2 and Level 3 kits. Creating short-lived accounts on demand is planned.

Does AIC perform identity governance and administration?

Yes, for kit accounts. Analog Informatics Corporation (AIC) performs identity governance and administration (IGA) for accounts the kit manages in the AIC Level 2 and Level 3 kits: account lifecycle and periodic access review. Governance across other business applications is planned.

Does AIC perform identity threat detection and response?

Yes. Analog Informatics Corporation (AIC) performs identity threat detection and response (ITDR) in the AIC Level 2 and Level 3 kits through Audit and Incident Response. The kit receives constant feeds, generates alerts, and mitigates issues.

Does AIC perform identity security posture management?

Yes. Analog Informatics Corporation (AIC) performs identity security posture management (ISPM) in the AIC Level 1, Level 2, and Level 3 kits through Current State Compliance and configuration compliance. The kit constantly monitors configuration compliance.

Does AIC perform machine identity management?

Yes, for service and machine accounts. Analog Informatics Corporation (AIC) vaults and rotates service and machine account credentials through Privileged Identity Management in the AIC Level 2 and Level 3 kits. Certificate lifecycle management is planned.

These are the industry terms for privileged access and identity. Privileged account and session management (PASM), privilege elevation and delegation management (PEDM), secrets management, cloud infrastructure entitlement management (CIEM), and remote privileged access management (RPAM) are the privileged-access tool categories. Just-in-time (JIT) privilege management and zero standing privileges (ZSP) are functions in that scope. Identity governance and administration (IGA), identity threat detection and response (ITDR), and identity security posture management (ISPM) are adjacent identity terms.

Capability (AIC Module)What It DoesIndustry Function PerformedBuilt Into
Assessment BinderLiving evidence package an assessor can readShared audit record for the C3PAO, the MSP, and the customerAIC Level 1, Level 2, and Level 3 kits
Current State ComplianceLedger of control-oriented findings, with rescanIdentity security posture management (ISPM)AIC Level 1, Level 2, and Level 3 kits
Privileged Identity Management (PIM)Credential lifecycle and vaulted identitiesPrivileged account and session management (PASM); secrets management; machine identityAIC Level 2 and Level 3 kits
Privileged Access Management (PAM)Session connect and open, Jump, command restriction, and session recording on Level 3Privileged account and session management (PASM); remote privileged access management (RPAM)AIC Level 2 and Level 3 kits
Privileged User Management (PUM)Privilege Elevation and Delegation Management (PEDM): endpoint privilege elevation, delegation, least-privilege enforcement, application and command control, just-in-time (JIT) elevation, and privileged activity auditing on Windows, Apple Mac, and Unix/LinuxPrivilege elevation and delegation management (PEDM); just-in-time (JIT) privilege management; zero standing privileges (ZSP)AIC Level 2 and Level 3 kits
Identity Governance and Administration (IGA)Account lifecycle and periodic access reviewIdentity governance and administration (IGA) for kit accounts. Cloud infrastructure entitlement management (CIEM) is plannedAIC Level 2 and Level 3 kits
AuditPrivileged-action and session records on product paths, and Windows Event Log or syslog when configuredPrivileged account and session management (PASM) session audit; identity threat detection and response (ITDR)AIC Level 2 and Level 3 kits
Document sharing vaultStore and share FCI and Controlled Unclassified Information (CUI)Protected information sharing. Not a privileged-access tool categoryAIC Level 1, Level 2, and Level 3 kits
Training and attestationAssign documents and collect a signed attestationWorkforce attestation. Not a privileged-access tool categoryAIC Level 2 and Level 3 kits
Secure Application LaunchStart an application with credentials the user does not seeSecrets management; privileged account and session management (PASM)AIC Level 2 and Level 3 kits
JumpManaged access path for sessions. The Level 3 kit adds session recordingRemote privileged access management (RPAM); privileged account and session management (PASM)AIC Level 2 and Level 3 kits
Incident ResponseIncident records and notificationIdentity threat detection and response (ITDR)AIC Level 2 and Level 3 kits
Federal Information Processing Standards (FIPS) cryptographyCryptography on product pathsCryptographic protection of kit paths. Not a privileged-access tool categoryAIC Level 2 and Level 3 kits
Configuration complianceCheck system configuration against an approved baseline, with an optional block, when workstations connectIdentity security posture management (ISPM)AIC Level 1, Level 2, and Level 3 kits
Governed mailMail for FCI or CUIMail for FCI and CUI. Not a privileged-access tool categoryOptional on the AIC Level 1 kit. Built into the AIC Level 2 and Level 3 kits

Screenshots

Privileged User Management applies application control packs across Windows, Linux, and macOS, with live counts.
Command restriction allows or denies SSH commands by rule, with a default deny and a test tool.

More on Product Screenshots.

An assessment organization, certification body, or regulator decides whether a requirement is satisfied.

Connected Privilege Workflows

  1. Discover & Analyze

    Understand identity exposure and configuration findings

  2. Protect & Respond

    Control privilege and act on findings

  3. Verify & Prove

    Confirm remediation and retain evidence

Platform Questions

What does fewer vendors mean in practice?

Bring identity and privilege security, security assurance, and audit evidence into one consistent package. This reduces separate product handoffs and integration work across these functions while retaining connections to your existing security and IT systems.

Which capabilities are still planned?

Governance across other business applications, certificate lifecycle management, and cloud infrastructure entitlement management are planned. Identity governance for platform-managed accounts is available today.

CMMC solutions by level and use case

Frequently Asked Questions

Which protocols do privileged sessions support?

Secure Shell (SSH), Remote Desktop Protocol (RDP), and Virtual Network Computing (VNC). Every brokered session is recorded, encrypted, and listed for review, and playback requires a case or review reason.

Can AIC block commands during a session?

Yes. Command restriction allows or denies SSH commands by rule, with a default deny and a tool to test a command before it runs.

Where are encryption keys kept?

In software, in a PKCS#11 hardware security module (HSM), or in a customer-owned cloud key management service (KMS) key, on premises, in the cloud, or hybrid. Stored secrets are protected using AWS-LC cryptography with a FIPS 140-3 certificate.

Does AIC send security events to my SIEM?

Yes. Security events forward to your Security Information and Event Management (SIEM) system over RFC 5424 syslog, using UDP, TCP, or TLS.

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.