AIC Enterprise Privilege Suite™
Bring credential management, privileged sessions, endpoint elevation, and evidence into one operating platform. The AIC Enterprise Privilege Suite™ connects those controls through a shared account roster, policy engine, and audit trail.
Choose the modules your organization needs, then evaluate them against the systems, tasks, and records in your requirements list.
AIC Enterprise Privilege Suite™ receives constant feeds, generates alerts, mitigates issues, and constantly checks each system against its baseline configuration where a feed path exists. That makes continuous compliance possible instead of a point-in-time check. Training is free. We work with the reseller, Managed Service Provider, or service provider the customer already uses.
Capability List
Privileged Access
| Capability | What It Does |
|---|---|
| Privileged Identity Management (PIM) | Discover systems, accounts, privileged group membership, password age, SSH keys, and cloud access keys. Find where each credential is used, change it, and push the new value to every service, task, application pool, COM+ and DCOM application, connection string, and configuration file that uses it. Covers Windows, macOS, Linux and Unix, Active Directory and LDAP, databases, cloud accounts, network and hardware devices, and applications. Extend to any other platform with SSH and Telnet scripts, browser automation, or the REST API (OpenAPI). Vault and check out credentials. See Privileged Identity Management. |
| Privileged Access Management (PAM) | Live SSH, RDP, and VNC sessions in the browser through a broker, approvals, and Command Restriction that blocks dangerous commands as they are typed. |
| Jump | Managed access path for privileged sessions. AIC Enterprise Privilege Suite™ isolates Jump and records sessions. |
| Privileged User Management (PUM) | Privilege Elevation and Delegation Management: endpoint elevation, delegation, Least Privilege, application and command control, Just-in-Time elevation, and privileged activity auditing. Elevate through the Agent on the system or by remote control from the AIC Server, with one-time activation codes, challenge and response, signed grants, or agentless WinRM and SSH. Windows is the most complete today. macOS and Unix/Linux are expanding. See Privileged User Management. |
| Secure Application Launch | Start an application with credentials the user never sees. |
| Known default credential detection | Scan networks, match systems and devices to licensed public default-password dictionaries, and flag dangerous defaults still in use. See Known default credentials. |
Identity Security
| Capability | What It Does |
|---|---|
| Identity Governance and Administration (IGA) | Account lifecycle and periodic access review for suite accounts. Governance across other applications is planned. |
| Data classification | US government, NATO, and national markings with clearances, mandatory access control, and audited formal release. See Data classification. |
| Conditional Access | Allow, step up, or deny sign-in by country, network address, Multi-Factor Authentication, and session policy. See Conditional Access and threat defense. |
| Threat intelligence and attack report | Deny sign-in from addresses on threat feeds, and report blocked and failed attempts mapped to MITRE ATT&CK. |
Compliance and Operations
| Capability | What It Does |
|---|---|
| Session Recording | Recorded SSH, RDP, and VNC sessions with replay. |
| Document sharing vault | Store and share sensitive files with classification marking. |
| Audit | Privileged-action and session records, Windows Event Log, and syslog in RFC 5424, CEF, or LEEF. Route each event type to its own destinations: Splunk, Microsoft Sentinel, Azure Monitor, Datadog, Amazon CloudWatch, Google Cloud Logging, any web service, another AIC Server, email, and ServiceNow or Jira tickets. Text message notices through seven providers. See Logging, SIEM, and event forwarding. |
| Assessment Binder | Living evidence package shared by the assessor, the Managed Service Provider, and the Customer. |
| Current State Compliance | Ledger of control findings with rescan. |
| Configuration Compliance | Check workstations and servers against STIG-oriented baselines, repair known settings with Fix-It, flag what needs IT, and optionally block a system until it complies. See Configuration Compliance. |
| VM power scheduling | Power off idle workstations and session capacity on a schedule or after idle time, and start them on demand, to cut cloud cost and shrink the attack surface. See VM power scheduling. |
| Incident Response | Incident records, detectors, and email or text alerts when a messaging path is configured. |
| Training and attestation | Assign documents to named people and collect a signed attestation. |
| Governed mail | Governed mail for sensitive information inside the suite. |
| Cryptography and key custody | AWS-LC, which holds a FIPS 140-3 certificate, on server cryptographic paths. Keys in software, in a PKCS#11 HSM, or in a customer-owned AWS KMS, Azure Key Vault Managed HSM, or Google Cloud KMS key. Separate key sets per system group, with rotation and re-encryption. See Key Management. |
| Directory sign-in | Active Directory and LDAP sign-in, and Microsoft Entra ID, Okta, Ping Identity, and other OpenID Connect and Security Assertion Markup Language (SAML) 2.0 providers, with another step beyond a password. |
| High availability | Automatic database failover on customer-supplied hosts. |
| Air-gapped operation | AIC Enterprise Privilege Suite™ runs on connected and fully air-gapped systems on Windows, Linux, and macOS, in the cloud or on premises. The Agent rotates passwords on schedule from a shared seed with local propagation and no server connection, and handles elevation on the system itself. See Air-gapped systems. |
| Managed Service Provider operation | A Managed Service Provider can administer inside the customer boundary. |
| Localization | The operator console ships with 18 language packs. See Localization. |
| Evidence feeds | Records can feed compliance automation platforms through export and syslog. |
| Certificate Lifecycle Management | Discovery, renewal, and governance of certificates across certificate authorities. This capability is planned. |
| Cloud Infrastructure Entitlement Management | Analysis of cloud account permissions. This capability is planned. |
| Vulnerability analysis | Analysis of discovered systems for known vulnerabilities. Planned as an add-on module. |
| Universal host logon banner | One banner pushed to every system. This capability is planned. |
The industry terms for these capabilities are on Industry Functions.
Screenshots
More on Product Screenshots.
Industry Functions
Analog Informatics Corporation (AIC) builds the AIC Enterprise Privilege Suite™. AIC Enterprise Privilege Suite™ performs Privileged Account and Session Management (PASM), Privilege Elevation and Delegation Management (PEDM), Secrets Management, Remote Privileged Access Management (RPAM), Just-in-Time (JIT) privilege management, Zero Standing Privileges (ZSP) for elevation, Identity Governance and Administration (IGA) for suite accounts, Identity Threat Detection and Response (ITDR), Identity Security Posture Management (ISPM), and machine identity for service accounts. Cloud Infrastructure Entitlement Management (CIEM) is planned. Each function is performed by a module of the suite.
Which Industry Functions Do the AIC Modules Perform?
Each function is performed by the AIC Enterprise Privilege Suite™ module named in the answer.
Does AIC perform Privileged Account and Session Management?
Yes. AIC Enterprise Privilege Suite™ performs Privileged Account and Session Management (PASM) through Privileged Identity Management, Privileged Access Management, Audit, Secure Application Launch, and Jump.
Does AIC perform Privilege Elevation and Delegation Management?
Yes. AIC Enterprise Privilege Suite™ performs Privilege Elevation and Delegation Management (PEDM) through Privileged User Management. It covers endpoint privilege elevation, delegation, least-privilege enforcement, application and command control, Just-in-Time elevation, and privileged activity auditing. Windows coverage is the most complete today. macOS and Unix/Linux coverage is expanding.
Does AIC perform Secrets Management?
Yes. AIC Enterprise Privilege Suite™ performs Secrets Management through Privileged Identity Management and Secure Application Launch.
Does AIC perform Cloud Infrastructure Entitlement Management?
Planned. Cloud Infrastructure Entitlement Management (CIEM), the analysis of cloud permissions across cloud accounts, is on the Analog Informatics Corporation (AIC) roadmap. Today the suite controls privileged access to the systems it manages.
Does AIC perform Remote Privileged Access Management?
Yes. AIC Enterprise Privilege Suite™ performs Remote Privileged Access Management (RPAM) through Privileged Access Management and Jump, with Session Recording on Jump.
Does AIC perform Just-in-Time privilege management?
Yes. AIC Enterprise Privilege Suite™ performs Just-in-Time (JIT) privilege management through Privileged User Management.
Does AIC perform Zero Standing Privileges?
Yes, for elevation. AIC Enterprise Privilege Suite™ removes standing administrator rights on enrolled systems and grants time-bound elevation through Privileged User Management. Creating short-lived accounts on demand is planned.
Does AIC perform Identity Governance and Administration?
Yes, for suite accounts. AIC Enterprise Privilege Suite™ performs Identity Governance and Administration (IGA) for accounts the suite manages: account lifecycle and periodic access review. Governance across other business applications is planned.
Does AIC perform Identity Threat Detection and Response?
Yes. AIC Enterprise Privilege Suite™ performs Identity Threat Detection and Response (ITDR) through Audit and Incident Response. The suite receives constant feeds, generates alerts, and mitigates issues.
Does AIC perform Identity Security Posture Management?
Yes. AIC Enterprise Privilege Suite™ performs Identity Security Posture Management (ISPM) through Current State Compliance and Configuration Compliance. The suite constantly monitors system posture.
Does AIC perform machine identity management?
Yes, for service and machine accounts. AIC Enterprise Privilege Suite™ vaults and rotates service and machine account credentials through Privileged Identity Management. Certificate Lifecycle Management is planned.
These are the industry terms for privileged access and identity. Privileged Account and Session Management (PASM), Privilege Elevation and Delegation Management (PEDM), Secrets Management, Cloud Infrastructure Entitlement Management (CIEM), and Remote Privileged Access Management (RPAM) are the privileged-access tool categories. Just-in-Time (JIT) privilege management and Zero Standing Privileges (ZSP) are functions in that scope. Identity Governance and Administration (IGA), Identity Threat Detection and Response (ITDR), and Identity Security Posture Management (ISPM) are adjacent identity terms.
| Capability (AIC Module) | What It Does | Industry Function Performed | Built Into |
|---|---|---|---|
| Assessment Binder | Living evidence package an assessor can read | Shared audit record for the assessor, the Managed Service Provider (MSP), and the Customer | AIC Enterprise Privilege Suite™ |
| Current State Compliance | Ledger of control-oriented findings, with rescan | Identity Security Posture Management (ISPM) | AIC Enterprise Privilege Suite™ |
| Privileged Identity Management (PIM) | Credential lifecycle and vaulted identities | Privileged Account and Session Management (PASM); Secrets Management; machine identity | AIC Enterprise Privilege Suite™ |
| Privileged Access Management (PAM) | Session connect and open, Jump, Command Restriction, and Session Recording | Privileged Account and Session Management (PASM); Remote Privileged Access Management (RPAM) | AIC Enterprise Privilege Suite™ |
| Privileged User Management (PUM) | Privilege Elevation and Delegation Management (PEDM): endpoint privilege elevation, delegation, least-privilege enforcement, application and command control, Just-in-Time (JIT) elevation, and privileged activity auditing on Windows, macOS, and Unix/Linux | Privilege Elevation and Delegation Management (PEDM); Just-in-Time (JIT) privilege management; Zero Standing Privileges (ZSP) | AIC Enterprise Privilege Suite™ |
| Identity Governance and Administration (IGA) | Account lifecycle and periodic access review | Identity Governance and Administration (IGA) for suite accounts. Cloud Infrastructure Entitlement Management (CIEM) is planned | AIC Enterprise Privilege Suite™ |
| Audit | Privileged-action and session records on product paths, and Windows Event Log or syslog when configured | Privileged Account and Session Management (PASM) session audit; Identity Threat Detection and Response (ITDR) | AIC Enterprise Privilege Suite™ |
| Document sharing vault | Store and share sensitive files with classification marking | Protected information sharing. Not a privileged-access tool category | AIC Enterprise Privilege Suite™ |
| Training and attestation | Assign documents and collect a signed attestation | Workforce attestation. Not a privileged-access tool category | AIC Enterprise Privilege Suite™ |
| Secure Application Launch | Start an application with credentials the user does not see | Secrets Management; Privileged Account and Session Management (PASM) | AIC Enterprise Privilege Suite™ |
| Jump | Managed access path for sessions, with Session Recording | Remote Privileged Access Management (RPAM); Privileged Account and Session Management (PASM) | AIC Enterprise Privilege Suite™ |
| Incident Response | Incident records and notification | Identity Threat Detection and Response (ITDR) | AIC Enterprise Privilege Suite™ |
| Federal Information Processing Standards (FIPS) cryptography | Cryptography on product paths | Cryptographic protection of product paths. Not a privileged-access tool category | AIC Enterprise Privilege Suite™ |
| Configuration Compliance | Check system configuration against an approved baseline, with an optional block, when workstations connect | Identity Security Posture Management (ISPM) | AIC Enterprise Privilege Suite™ |
| Governed mail | Governed mail for sensitive information | Protected email communication | AIC Enterprise Privilege Suite™ |
Screenshots
More on Product Screenshots.
Connected Privilege Workflows
Discover & Analyze
Understand identity exposure and configuration findings
Protect & Respond
Control privilege and act on findings
Verify & Prove
Confirm remediation and retain evidence
Platform Questions
What does fewer vendors mean in practice?
Bring identity and privilege security, security assurance, and Audit Evidence into one consistent platform. This reduces separate product handoffs and integration work across these functions while retaining connections to your existing security and IT systems.
Which capabilities are still planned?
Governance across other business applications, Certificate Lifecycle Management, and Cloud Infrastructure Entitlement Management are planned. Identity Governance for platform-managed accounts is available today.
Evaluate the Workflow, Not Just the Feature Name
- Discover a test account and the services or tasks that use it.
- Rotate the credential, open an approved recorded session, and review the associated activity.
- Match the observed result to your requirements using the RFP checklist and evaluation guide.