AIC Enterprise Privilege Suite™

Bring credential management, privileged sessions, endpoint elevation, and evidence into one operating platform. The AIC Enterprise Privilege Suite™ connects those controls through a shared account roster, policy engine, and audit trail.

Choose the modules your organization needs, then evaluate them against the systems, tasks, and records in your requirements list.

AIC Enterprise Privilege Suite™ receives constant feeds, generates alerts, mitigates issues, and constantly checks each system against its baseline configuration where a feed path exists. That makes continuous compliance possible instead of a point-in-time check. Training is free. We work with the reseller, Managed Service Provider, or service provider the customer already uses.

Capability List

View the full capability list

Privileged Access

CapabilityWhat It Does
Privileged Identity Management (PIM)Discover systems, accounts, privileged group membership, password age, SSH keys, and cloud access keys. Find where each credential is used, change it, and push the new value to every service, task, application pool, COM+ and DCOM application, connection string, and configuration file that uses it. Covers Windows, macOS, Linux and Unix, Active Directory and LDAP, databases, cloud accounts, network and hardware devices, and applications. Extend to any other platform with SSH and Telnet scripts, browser automation, or the REST API (OpenAPI). Vault and check out credentials. See Privileged Identity Management.
Privileged Access Management (PAM)Live SSH, RDP, and VNC sessions in the browser through a broker, approvals, and Command Restriction that blocks dangerous commands as they are typed.
JumpManaged access path for privileged sessions. AIC Enterprise Privilege Suite™ isolates Jump and records sessions.
Privileged User Management (PUM)Privilege Elevation and Delegation Management: endpoint elevation, delegation, Least Privilege, application and command control, Just-in-Time elevation, and privileged activity auditing. Elevate through the Agent on the system or by remote control from the AIC Server, with one-time activation codes, challenge and response, signed grants, or agentless WinRM and SSH. Windows is the most complete today. macOS and Unix/Linux are expanding. See Privileged User Management.
Secure Application LaunchStart an application with credentials the user never sees.
Known default credential detectionScan networks, match systems and devices to licensed public default-password dictionaries, and flag dangerous defaults still in use. See Known default credentials.

Identity Security

CapabilityWhat It Does
Identity Governance and Administration (IGA)Account lifecycle and periodic access review for suite accounts. Governance across other applications is planned.
Data classificationUS government, NATO, and national markings with clearances, mandatory access control, and audited formal release. See Data classification.
Conditional AccessAllow, step up, or deny sign-in by country, network address, Multi-Factor Authentication, and session policy. See Conditional Access and threat defense.
Threat intelligence and attack reportDeny sign-in from addresses on threat feeds, and report blocked and failed attempts mapped to MITRE ATT&CK.

Compliance and Operations

CapabilityWhat It Does
Session RecordingRecorded SSH, RDP, and VNC sessions with replay.
Document sharing vaultStore and share sensitive files with classification marking.
AuditPrivileged-action and session records, Windows Event Log, and syslog in RFC 5424, CEF, or LEEF. Route each event type to its own destinations: Splunk, Microsoft Sentinel, Azure Monitor, Datadog, Amazon CloudWatch, Google Cloud Logging, any web service, another AIC Server, email, and ServiceNow or Jira tickets. Text message notices through seven providers. See Logging, SIEM, and event forwarding.
Assessment BinderLiving evidence package shared by the assessor, the Managed Service Provider, and the Customer.
Current State ComplianceLedger of control findings with rescan.
Configuration ComplianceCheck workstations and servers against STIG-oriented baselines, repair known settings with Fix-It, flag what needs IT, and optionally block a system until it complies. See Configuration Compliance.
VM power schedulingPower off idle workstations and session capacity on a schedule or after idle time, and start them on demand, to cut cloud cost and shrink the attack surface. See VM power scheduling.
Incident ResponseIncident records, detectors, and email or text alerts when a messaging path is configured.
Training and attestationAssign documents to named people and collect a signed attestation.
Governed mailGoverned mail for sensitive information inside the suite.
Cryptography and key custodyAWS-LC, which holds a FIPS 140-3 certificate, on server cryptographic paths. Keys in software, in a PKCS#11 HSM, or in a customer-owned AWS KMS, Azure Key Vault Managed HSM, or Google Cloud KMS key. Separate key sets per system group, with rotation and re-encryption. See Key Management.
Directory sign-inActive Directory and LDAP sign-in, and Microsoft Entra ID, Okta, Ping Identity, and other OpenID Connect and Security Assertion Markup Language (SAML) 2.0 providers, with another step beyond a password.
High availabilityAutomatic database failover on customer-supplied hosts.
Air-gapped operationAIC Enterprise Privilege Suite™ runs on connected and fully air-gapped systems on Windows, Linux, and macOS, in the cloud or on premises. The Agent rotates passwords on schedule from a shared seed with local propagation and no server connection, and handles elevation on the system itself. See Air-gapped systems.
Managed Service Provider operationA Managed Service Provider can administer inside the customer boundary.
LocalizationThe operator console ships with 18 language packs. See Localization.
Evidence feedsRecords can feed compliance automation platforms through export and syslog.
Certificate Lifecycle ManagementDiscovery, renewal, and governance of certificates across certificate authorities. This capability is planned.
Cloud Infrastructure Entitlement ManagementAnalysis of cloud account permissions. This capability is planned.
Vulnerability analysisAnalysis of discovered systems for known vulnerabilities. Planned as an add-on module.
Universal host logon bannerOne banner pushed to every system. This capability is planned.

The industry terms for these capabilities are on Industry Functions.

Screenshots

A live SSH command line, recorded, with a dangerous command blocked as it is typed.
A live, recorded RDP desktop session to a Windows workstation, in the browser.
Endpoint privilege elevation and delegation covers Windows, Unix, approvals, policy, and air-gapped tokens in one place.
Failed sign-ins are mapped to MITRE ATT&CK technique T1110 Brute Force, with top sources and most-tried usernames.

More on Product Screenshots.

Industry Functions

Analog Informatics Corporation (AIC) builds the AIC Enterprise Privilege Suite™. AIC Enterprise Privilege Suite™ performs Privileged Account and Session Management (PASM), Privilege Elevation and Delegation Management (PEDM), Secrets Management, Remote Privileged Access Management (RPAM), Just-in-Time (JIT) privilege management, Zero Standing Privileges (ZSP) for elevation, Identity Governance and Administration (IGA) for suite accounts, Identity Threat Detection and Response (ITDR), Identity Security Posture Management (ISPM), and machine identity for service accounts. Cloud Infrastructure Entitlement Management (CIEM) is planned. Each function is performed by a module of the suite.

Which Industry Functions Do the AIC Modules Perform?

Each function is performed by the AIC Enterprise Privilege Suite™ module named in the answer.

Does AIC perform Privileged Account and Session Management?

Yes. AIC Enterprise Privilege Suite™ performs Privileged Account and Session Management (PASM) through Privileged Identity Management, Privileged Access Management, Audit, Secure Application Launch, and Jump.

Does AIC perform Privilege Elevation and Delegation Management?

Yes. AIC Enterprise Privilege Suite™ performs Privilege Elevation and Delegation Management (PEDM) through Privileged User Management. It covers endpoint privilege elevation, delegation, least-privilege enforcement, application and command control, Just-in-Time elevation, and privileged activity auditing. Windows coverage is the most complete today. macOS and Unix/Linux coverage is expanding.

Does AIC perform Secrets Management?

Yes. AIC Enterprise Privilege Suite™ performs Secrets Management through Privileged Identity Management and Secure Application Launch.

Does AIC perform Cloud Infrastructure Entitlement Management?

Planned. Cloud Infrastructure Entitlement Management (CIEM), the analysis of cloud permissions across cloud accounts, is on the Analog Informatics Corporation (AIC) roadmap. Today the suite controls privileged access to the systems it manages.

Does AIC perform Remote Privileged Access Management?

Yes. AIC Enterprise Privilege Suite™ performs Remote Privileged Access Management (RPAM) through Privileged Access Management and Jump, with Session Recording on Jump.

Does AIC perform Just-in-Time privilege management?

Yes. AIC Enterprise Privilege Suite™ performs Just-in-Time (JIT) privilege management through Privileged User Management.

Does AIC perform Zero Standing Privileges?

Yes, for elevation. AIC Enterprise Privilege Suite™ removes standing administrator rights on enrolled systems and grants time-bound elevation through Privileged User Management. Creating short-lived accounts on demand is planned.

Does AIC perform Identity Governance and Administration?

Yes, for suite accounts. AIC Enterprise Privilege Suite™ performs Identity Governance and Administration (IGA) for accounts the suite manages: account lifecycle and periodic access review. Governance across other business applications is planned.

Does AIC perform Identity Threat Detection and Response?

Yes. AIC Enterprise Privilege Suite™ performs Identity Threat Detection and Response (ITDR) through Audit and Incident Response. The suite receives constant feeds, generates alerts, and mitigates issues.

Does AIC perform Identity Security Posture Management?

Yes. AIC Enterprise Privilege Suite™ performs Identity Security Posture Management (ISPM) through Current State Compliance and Configuration Compliance. The suite constantly monitors system posture.

Does AIC perform machine identity management?

Yes, for service and machine accounts. AIC Enterprise Privilege Suite™ vaults and rotates service and machine account credentials through Privileged Identity Management. Certificate Lifecycle Management is planned.

These are the industry terms for privileged access and identity. Privileged Account and Session Management (PASM), Privilege Elevation and Delegation Management (PEDM), Secrets Management, Cloud Infrastructure Entitlement Management (CIEM), and Remote Privileged Access Management (RPAM) are the privileged-access tool categories. Just-in-Time (JIT) privilege management and Zero Standing Privileges (ZSP) are functions in that scope. Identity Governance and Administration (IGA), Identity Threat Detection and Response (ITDR), and Identity Security Posture Management (ISPM) are adjacent identity terms.

Capability (AIC Module)What It DoesIndustry Function PerformedBuilt Into
Assessment BinderLiving evidence package an assessor can readShared audit record for the assessor, the Managed Service Provider (MSP), and the CustomerAIC Enterprise Privilege Suite™
Current State ComplianceLedger of control-oriented findings, with rescanIdentity Security Posture Management (ISPM)AIC Enterprise Privilege Suite™
Privileged Identity Management (PIM)Credential lifecycle and vaulted identitiesPrivileged Account and Session Management (PASM); Secrets Management; machine identityAIC Enterprise Privilege Suite™
Privileged Access Management (PAM)Session connect and open, Jump, Command Restriction, and Session RecordingPrivileged Account and Session Management (PASM); Remote Privileged Access Management (RPAM)AIC Enterprise Privilege Suite™
Privileged User Management (PUM)Privilege Elevation and Delegation Management (PEDM): endpoint privilege elevation, delegation, least-privilege enforcement, application and command control, Just-in-Time (JIT) elevation, and privileged activity auditing on Windows, macOS, and Unix/LinuxPrivilege Elevation and Delegation Management (PEDM); Just-in-Time (JIT) privilege management; Zero Standing Privileges (ZSP)AIC Enterprise Privilege Suite™
Identity Governance and Administration (IGA)Account lifecycle and periodic access reviewIdentity Governance and Administration (IGA) for suite accounts. Cloud Infrastructure Entitlement Management (CIEM) is plannedAIC Enterprise Privilege Suite™
AuditPrivileged-action and session records on product paths, and Windows Event Log or syslog when configuredPrivileged Account and Session Management (PASM) session audit; Identity Threat Detection and Response (ITDR)AIC Enterprise Privilege Suite™
Document sharing vaultStore and share sensitive files with classification markingProtected information sharing. Not a privileged-access tool categoryAIC Enterprise Privilege Suite™
Training and attestationAssign documents and collect a signed attestationWorkforce attestation. Not a privileged-access tool categoryAIC Enterprise Privilege Suite™
Secure Application LaunchStart an application with credentials the user does not seeSecrets Management; Privileged Account and Session Management (PASM)AIC Enterprise Privilege Suite™
JumpManaged access path for sessions, with Session RecordingRemote Privileged Access Management (RPAM); Privileged Account and Session Management (PASM)AIC Enterprise Privilege Suite™
Incident ResponseIncident records and notificationIdentity Threat Detection and Response (ITDR)AIC Enterprise Privilege Suite™
Federal Information Processing Standards (FIPS) cryptographyCryptography on product pathsCryptographic protection of product paths. Not a privileged-access tool categoryAIC Enterprise Privilege Suite™
Configuration ComplianceCheck system configuration against an approved baseline, with an optional block, when workstations connectIdentity Security Posture Management (ISPM)AIC Enterprise Privilege Suite™
Governed mailGoverned mail for sensitive informationProtected email communicationAIC Enterprise Privilege Suite™

Screenshots

Privileged User Management applies application control packs across Windows, Linux, and macOS, with live counts.
Command Restriction allows or denies SSH commands by rule, with a default deny and a test tool.

More on Product Screenshots.

Connected Privilege Workflows

  1. Discover & Analyze

    Understand identity exposure and configuration findings

  2. Protect & Respond

    Control privilege and act on findings

  3. Verify & Prove

    Confirm remediation and retain evidence

Platform Questions

What does fewer vendors mean in practice?

Bring identity and privilege security, security assurance, and Audit Evidence into one consistent platform. This reduces separate product handoffs and integration work across these functions while retaining connections to your existing security and IT systems.

Which capabilities are still planned?

Governance across other business applications, Certificate Lifecycle Management, and Cloud Infrastructure Entitlement Management are planned. Identity Governance for platform-managed accounts is available today.

Evaluate the Workflow, Not Just the Feature Name

  1. Discover a test account and the services or tasks that use it.
  2. Rotate the credential, open an approved recorded session, and review the associated activity.
  3. Match the observed result to your requirements using the RFP checklist and evaluation guide.

Frequently Asked Questions

Which protocols do privileged sessions support?

Secure Shell (SSH), Remote Desktop Protocol (RDP), and Virtual Network Computing (VNC). Every brokered session is recorded, encrypted, and listed for review, and playback requires a case or review reason.

Can AIC block commands during a session?

Yes. Command Restriction allows or denies SSH commands by rule, with a default deny and a tool to test a command before it runs.

Where are encryption keys kept?

In software, in a PKCS#11 hardware security module (HSM), or in a customer-owned cloud Key Management Service (KMS) key, on premises, in the cloud, or hybrid. Stored secrets are protected using AWS-LC cryptography with a FIPS 140-3 certificate.

Does AIC send security events to my SIEM?

Yes. Security events forward to your Security Information and Event Management (SIEM) system over RFC 5424 syslog, using UDP, TCP, or TLS.

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.