Analog Informatics

Privileged Access and Credential Management

AIC Enterprise Privilege Management Suite™One product for privileged access and identity security Privileged Identity ManagementVault and rotate privileged credentials Privileged Access ManagementControl and record privileged sessions Privileged User ManagementManage privilege elevation and delegation Secure Remote AccessConnect to systems through controlled sessions Credential VaultingProtect credentials and secrets Identity GovernanceGovern platform-managed accounts Conditional Access and Threat DefenseApply access policy and investigate threats Deployment and IntegrationsHosting environments and identity providersMigration ProgramMove from legacy systems on your terms

Governance, Risk, and Compliance (GRC)

Current State ComplianceCheck configuration compliance and retain evidence Data ClassificationApply classification and access rules Key ManagementManage cryptographic keys and custody Detect, Respond, and RemediateConnect detection to response and verification Industry TermsCapabilities mapped to industry terminology

AIC CMMC Complete™

AIC CMMC Complete™Tools and evidence for CMMC Levels 1–3 Secure EnclavesCustomer-controlled secure environments FrameworksRegulatory requirements and control mappings
Explore all capabilities →

By Need

AIC CMMC Complete™An integrated offering for Levels 1, 2, and 3 Secure EnclavesProtect systems within a controlled boundary Air-Gapped EnvironmentsOperate inside isolated environments Operational TechnologyControl access and evidence for operationsCMMC SolutionsBy level, stage, and use case

By Industry

Defense Industrial BaseRequirements for contractors and suppliers GovernmentIdentity, access, and evidence for government Health CareHealth information safeguards and evidence PaymentsPayment security control mappings EnterpriseSecurity across enterprise environments

By Framework

CMMCLevel 1, Level 2, and Level 3 mappings NIST SP 800-171Controlled information requirements NIST SP 800-53Security and privacy controls ISO/IEC 27001Information security management mappings All FrameworksBrowse the frameworks library
AIC CMMC Complete™ PricingLevel 1, Level 2, and Level 3 pricing All Product PricingProduct families and quote requests
Partner BenefitsMargins, support, training, and NFR demosDeal RegistrationRegister a customer opportunity Managed Service ProvidersOperate the platform for your customers ResellersQuote and sell the integrated platform Technology PartnersConnect products and workflows Service ProvidersImplementation and migration International PartnersDeliver in your local market
BlogSecurity articles and practical guidanceEventsMeet us at upcoming industry events Product ScreenshotsExplore real product workflows Frameworks LibraryBrowse control mappings GlossarySecurity terms explained Languages18 language packs
Blog
AboutWhat we build and how we work StaffMeet Our Leadership and TeamAccessibility and VPAT ReportsWebsite testing and conformance documentation ContactTalk to Analog Informatics
Request a demo
Home / Product screenshots

Product screenshots

These screenshots show the Analog Informatics Corporation (AIC) console doing the work described on this site. The modules are built into the AIC CMMC Complete™ Level 1, Level 2, and Level 3 kits.

Proof index by industry function

Each row names an industry function and the screenshots that show it working. Jump to a section below to see the images.

Industry functionWhat the screenshots showSection
Privileged account and session management (PASM)Live SSH, RDP, and VNC sessions in the browser, vaulted credentials, recordings with reason-gated playback, and session controlPrivileged access and sessions
Secrets managementCredential vault with rotation, and application launch with credentials the user never seesPrivileged access and sessions
Remote privileged access management (RPAM)Entitlements to SSH, RDP, and VNC targets, and clipboard and file transfer limitsIdentities and entitlements
Command controlDangerous commands blocked in a live SSH session, and the list of blocked commands in the recordingPrivileged access and sessions
Default credential detectionNetwork scan results, the default credential catalog, and its licensed public sourcesDiscovery and default credentials
Configuration complianceBaseline configuration checks, Fix-It repair settings, and application control packsConfiguration compliance
Key managementAWS-LC, which holds a FIPS 140-3 certificate, key sets per zone with rotation and re-encryption, and PKCS#11 HSM vendor profilesKey management and HSMs
Cloud cost and attack surfaceScheduled power off and on-demand start for workstations and session capacityVM power scheduling
Privilege elevation and delegation management (PEDM)Windows, Linux, and macOS elevation policy and application control packsPrivilege elevation and delegation
Just-in-time (JIT) privilege and zero standing privileges (ZSP)One-time elevation codes, time-bound group membership, and just-in-time entitlementsPrivilege elevation and delegation
Identity governance and administration (IGA)Account discovery, role catalog mapped to CMMC and NIST, and identity providersIdentities and entitlements
Machine identityDiscovered service and administrator accounts on Linux and WindowsIdentities and entitlements
Conditional accessCountry policy, network rules, multifactor authentication, passkeys, and session timeoutsConditional access and threat defense
Identity threat detection and response (ITDR)Attack / Threat Report mapped to MITRE ATT&CK, logon audit, threat intelligence, live events, and incident alertsConditional access and threat defense
Identity security posture management (ISPM)Current State Compliance, control coverage, and control drift historyContinuous compliance and evidence
Data classification and mandatory access controlCMMC, US government, NATO, and national markings with enforcement and formal releaseData classification
Continuous compliance and auditAssessment Binder, frameworks crosswalk, POA&M, risk register, and reportsContinuous compliance and evidence
Workforce training and attestationTraining packs and workforce rosterWorkforce training and attestation
LocalizationThe console in German and Spanish, and language pack settingsMultilingual console

Why MSPs pick the AIC kits

A Managed Service Provider (MSP) gets the tools a customer needs in one console: privileged access, session recording, command restriction, privilege elevation, incident alerts, continuous compliance, the Assessment Binder, workforce training, a document vault, reports, and SIEM forwarding. There is no second product to buy for each job. The same console works in German, Spanish, and other languages.

Screenshots

Privileged access and sessions
A live SSH command line, recorded, with a dangerous command blocked as it is typed.
A live, recorded RDP desktop session to a Windows workstation, in the browser.
A live, recorded VNC desktop session to a Linux workstation, in the browser.
Every blocked command is listed with the rule that refused it, and links to that moment in the recording.
Every brokered SSH, RDP, and VNC session is recorded, encrypted, and listed for review.
Playback of a recorded SSH session requires a case or review reason, and every attempt is audited.
RDP sessions are recorded as encrypted video, with the same reason-gated, audited playback.
Session Control lets an operator approve, deny, watch, or terminate privileged sessions.
Command restriction allows or denies SSH commands by rule, with a default deny and a test tool.
Privileged credentials are vaulted and rotated. Operators never see the secret.
Secure Application Launch starts common admin tools with injected credentials the user never sees.
Privilege elevation and delegation
Endpoint privilege elevation and delegation covers Windows, Unix, approvals, policy, and air-gapped tokens in one place.
Privileged User Management applies application control packs across Windows, Linux, and macOS, with live counts.
Just-in-time elevation works with an agent, without an agent, and on air-gapped systems through one-time codes.
One elevation policy covers Windows, Linux, and macOS, including offline challenge and response.
Time-bound group membership grants privilege for a set time, then removes it.
Identities and entitlements
Account discovery finds privileged and standard accounts on every system, managed or not.
Entitlements decide who may reach which target, with standing or just-in-time access and deny-wins rules.
Clipboard and file transfer can be blocked or limited for each privileged session.
45 built-in roles map permissions to CMMC and NIST controls for least privilege.
Sign in with local accounts, OpenID Connect, Windows Integrated, or Active Directory.
Conditional access and threat defense
The Attack / Threat Report counts blocked and failed attempts and maps them to MITRE ATT&CK.
Failed sign-ins are mapped to MITRE ATT&CK technique T1110 Brute Force, with top sources and most-tried usernames.
Every sign-in attempt is logged append-only, with outcome, source, and reason, and exports to CSV or JSON.
Conditional access by country: allow, require extra verification, or deny sign-in by source country.
Ordered network rules allow or deny sign-in by address range before any password check.
Threat intelligence feeds block known-bad addresses at sign-in, and load offline on air-gapped systems.
Sign-in policy covers multifactor authentication, passkeys, password rules, and lockout.
Session timeouts and forced logoff limit the risk of an unattended or stolen session.

The failed sign-ins in the threat report were made for this demonstration against accounts that do not exist. More on Conditional access and threat defense.

Discovery and default credentials
The built-in scanner finds hosts and open management ports across IPv4 and IPv6 ranges.
Default credential dictionaries come from licensed public sources, with the license shown for each.

More on Known default credentials.

Configuration compliance
Every workstation and server shows its posture and open findings, with rescan and Fix-It actions.
Fix-It repairs known settings with operator confirmation, and logs every attempt.

More on Configuration compliance.

Key management and HSMs
Encryption runs in AWS-LC and can move to an HSM.
Each key set can be rotated, and stored data re-encrypted after a preview.
Built-in PKCS#11 profiles cover on-premises and cloud HSMs from the major vendors.

More on Key management.

VM power scheduling
Each hypervisor connection sets when idle machines power off.
Unused workstations and jump capacity power off on a schedule and start on demand.

More on VM power scheduling.

Attack detection and response
A live security event feed shows sign-ins, configuration changes, and vault activity as they happen.
Incident Response follows a six-step process and sends email and text alerts to named groups.
The kit checks for dangerous vendor default passwords, including on operational technology devices.
Security events forward to your SIEM over RFC 5424 syslog.
Continuous compliance and evidence
Measurement and Mitigation checks the environment against the selected framework and level.
Control coverage shows which controls have live evidence and which still need work.
Control state history records drift over time, the core of continuous compliance.
The Assessment Binder builds a living evidence package for each framework, shared by the assessor, the MSP, and the customer.
Auditor playbooks load reusable binder text and steps for each assessment.
77 frameworks and 722 requirement rows are crosswalked to NIST SP 800-53 in the product.
The control catalog lists every practice with its CMMC identifier and NIST SP 800-53 crosswalk.
Findings flow into a plan of action and milestones with status and risk.
The risk register tracks each risk from identification to acceptance, with overdue review alerts.
Physical and offline evidence is recorded with a timestamp and a SHA-256 hash.
GDPR records of processing are kept in the product and exported on demand.
Built-in reports cover crosswalks, access, account assurance, and assessment evidence.
Workforce training and attestation
53 training templates are built in and mapped to the clauses they address.
The workforce roster tracks who must train, including contractors, and records exclusions.
Data classification
One marking catalog ranks CMMC, US government, and NATO markings by sensitivity.
National markings for the United Kingdom, Canada, Australia, and more are built into the catalog.
Preview any access decision, and lower a marking only through an audited formal release.
Mandatory access control policies apply marking defaults for a framework in one step.
Choose a classification mode, and carry markings into audit logs and SIEM events.

More on Data classification.

Systems, vault, and security
One inventory of every system, with or without an agent, filtered by scope and classification.
The document sharing vault stores and shares FCI and CUI with classification markings.
Cryptography runs in AWS-LC, with hardware security module support.
Classification marking, login notice, and session notice appear on every page, as organizations configure them.
Built-in messaging sends templated email and text notifications.
Multilingual console
Administrators turn language packs on and off. 18 packs ship with the product.
The console in German. The language is chosen per person.
Training packs in German.
Privileged User Management in German.
The Assessment Binder in Spanish.
Built-in manuals and guides
Operator manuals are built into the console and export to PDF.
A built-in guide walks MSPs and assessors through the kit.

See it on your use case

Request a demo
Analog Informatics

Integrated privileged access, identity security, and compliance evidence for regulated organizations.

Product

  • All capabilities
  • Privileged Identity Management
  • Privileged Access Management
  • Privileged User Management
  • Identity Governance
  • Configuration Compliance
  • Key Management
  • Product Screenshots
  • Deployment and Integrations
  • Migration Program
  • Industry Terms

Solutions

  • AIC CMMC Complete™
  • Secure Enclaves
  • Air-Gapped Environments
  • Operational Technology
  • Defense Industrial Base
  • Government

Resources

  • Blog
  • Frameworks Library
  • NIST SP 800-171
  • NIST SP 800-53
  • Glossary
  • Languages

Partners

  • Managed Service Providers
  • Resellers
  • Technology Partners
  • International Partners
  • Deal Registration

Company

  • About
  • Staff
  • Pricing
  • Accessibility and VPAT Reports
  • Contact
Analog Informatics Corporation
3626 North Hall Street, Suite 610
Dallas, TX 75219, USA
+1 (214) 210-2260 sales@analoginfo.comsupport@analoginfo.com

Analog Informatics Corporation has submitted an entity registration in the System for Award Management (SAM.gov). Commercial and Government Entity (CAGE) code issuance is in progress.

  • Microsoft Azure
  • Amazon Web Services
  • Google Cloud
  • Oracle Cloud Infrastructure

All logos and trademarks are the property of their respective owners. Their use does not imply endorsement.

© 2026 Analog Informatics Corporation. All rights reserved.

  • Terms and Conditions
  • Privacy Policy
  • Accessibility
  • Security
  • Intended use