Integrated Identity Security and Privileged Access
Analog Informatics Corporation (AIC) builds privileged access, identity, audit, and compliance evidence into one set of kits. The modules are built into the Level 1, Level 2, and Level 3 kits. They are not sold as separate products. The Level 2 kit includes the Level 1 kit. The Level 3 kit includes the Level 2 kit. The kits run in the cloud or on premises, in a secure enclave, and on air-gapped systems.
The kits receive constant feeds, generate alerts, mitigate issues, and constantly monitor configuration compliance where a feed path exists. That makes continuous compliance possible instead of a point-in-time check. Training is free. We work with the reseller, Managed Service Provider, or service provider the customer already uses.
Capability List
Privileged Access
| Capability | What It Does |
|---|---|
| Privileged Identity Management (PIM) | Vault, check out, and rotate privileged and service account credentials, including local administrator passwords. |
| Privileged Access Management (PAM) | Live SSH, RDP, and VNC sessions in the browser through a broker, approvals, and command restriction that blocks dangerous commands as they are typed. |
| Jump | Managed access path for privileged sessions. The Level 3 kit isolates Jump and records sessions. |
| Privileged User Management (PUM) | Privilege elevation and delegation management: endpoint elevation, delegation, least privilege, application and command control, just-in-time elevation, and privileged activity auditing. Windows is the most complete today. Apple Mac and Unix/Linux are expanding. |
| Secure Application Launch | Start an application with credentials the user never sees. |
| Known default credential detection | Scan networks, match systems and devices to licensed public default-password dictionaries, and flag dangerous defaults still in use. See Known Default Credentials. |
Identity Security
| Capability | What It Does |
|---|---|
| Identity Governance and Administration (IGA) | Account lifecycle and periodic access review for kit accounts. Governance across other applications is planned. |
| Data classification | CMMC, US government, NATO, and national markings with clearances, mandatory access control, and audited formal release. See Data Classification. |
| Conditional access | Allow, step up, or deny sign-in by country, network address, multifactor authentication, and session policy. See Conditional Access and Threat Defense. |
| Threat intelligence and attack report | Deny sign-in from addresses on threat feeds, and report blocked and failed attempts mapped to MITRE ATT&CK. |
Compliance and Operations
| Capability | What It Does |
|---|---|
| Session recording | Recorded SSH, RDP, and VNC sessions with replay on the Level 3 kit. |
| Document sharing vault | Store and share sensitive files with classification marking. |
| Audit | Privileged-action and session records, Windows Event Log, and syslog for a security information and event management system. |
| Assessment Binder | Living evidence package shared by the assessor, the Managed Service Provider, and the customer. |
| Current State Compliance | Ledger of control findings with rescan. |
| Configuration compliance | Check workstations and servers against STIG-oriented baselines, repair known settings with Fix-It, flag what needs IT, and optionally block a system until it complies. See Configuration Compliance. |
| VM power scheduling | Power off idle workstations and session capacity on a schedule or after idle time, and start them on demand, to cut cloud cost and shrink the attack surface. See VM Power Scheduling. |
| Incident Response | Incident records, detectors, and email or text alerts when a messaging path is configured. |
| Training and attestation | Assign documents to named people and collect a signed attestation. |
| Governed mail | Mail for Federal Contract Information or Controlled Unclassified Information inside the kit. |
| Cryptography and key custody | AWS-LC cryptography with a FIPS 140-3 certificate on server cryptographic paths. Keys in software, in a PKCS#11 HSM, or in a customer-owned AWS KMS, Azure Key Vault Managed HSM, or Google Cloud KMS key. Separate key sets per system group, with rotation and re-encryption. See Key Management. |
| Directory sign-in | Active Directory and LDAP sign-in, and Microsoft Entra ID, Okta, Ping Identity, and other OpenID Connect and Security Assertion Markup Language (SAML) 2.0 providers, with another step beyond a password. |
| High availability | Automatic database failover on customer-supplied hosts. |
| Air-gapped operation | The kits run on systems that are not generally connected. |
| Managed Service Provider operation | A Managed Service Provider can administer inside the customer boundary. |
| Localization | The operator console ships with 18 language packs. See Localization. |
| Evidence feeds | Records can feed Competitors and other compliance packages through export and syslog. |
| Certificate lifecycle management | Discovery, renewal, and governance of certificates across certificate authorities. |
| Cloud infrastructure entitlement management | Analysis of cloud account permissions. |
| Vulnerability analysis | Analysis of discovered systems for known vulnerabilities. Planned as an add-on module. |
| Universal host logon banner | One banner pushed to every system. |
The industry terms for these capabilities are on Industry Functions.
Screenshots
More on Product Screenshots.
Industry Functions
Analog Informatics Corporation (AIC) Level 2 and Level 3 kits perform privileged account and session management (PASM), privilege elevation and delegation management (PEDM), secrets management, remote privileged access management (RPAM), just-in-time (JIT) privilege management, zero standing privileges (ZSP) for elevation, identity governance and administration (IGA) for kit accounts, identity threat detection and response (ITDR), and machine identity for service accounts. Cloud infrastructure entitlement management (CIEM) is planned. Identity security posture management (ISPM) is built into the Level 1, Level 2, and Level 3 kits. The modules are not separate products. The Level 2 kit includes the Level 1 kit. The Level 3 kit includes the Level 2 kit.
Which Industry Functions Do the AIC Modules Perform?
Each function is built into the AIC kit named in the answer.
Does AIC perform privileged account and session management?
Yes. Analog Informatics Corporation (AIC) performs privileged account and session management (PASM) in the AIC Level 2 and Level 3 kits through Privileged Identity Management, Privileged Access Management, Audit, Secure Application Launch, and Jump.
Does AIC perform privilege elevation and delegation management?
Yes. Analog Informatics Corporation (AIC) performs privilege elevation and delegation management (PEDM) in the AIC Level 2 and Level 3 kits through Privileged User Management. It covers endpoint privilege elevation, delegation, least-privilege enforcement, application and command control, just-in-time elevation, and privileged activity auditing. Windows coverage is the most complete today. Apple Mac and Unix/Linux coverage is expanding.
Does AIC perform secrets management?
Yes. Analog Informatics Corporation (AIC) performs secrets management in the AIC Level 2 and Level 3 kits through Privileged Identity Management and Secure Application Launch.
Does AIC perform cloud infrastructure entitlement management?
Planned. Cloud infrastructure entitlement management (CIEM), the analysis of cloud permissions across cloud accounts, is on the Analog Informatics Corporation (AIC) roadmap. Today the kits control privileged access to the systems they manage.
Does AIC perform remote privileged access management?
Yes. Analog Informatics Corporation (AIC) performs remote privileged access management (RPAM) in the AIC Level 2 and Level 3 kits through Privileged Access Management and Jump. The Level 3 kit adds session recording on Jump.
Does AIC perform just-in-time privilege management?
Yes. Analog Informatics Corporation (AIC) performs just-in-time (JIT) privilege management in the AIC Level 2 and Level 3 kits through Privileged User Management.
Does AIC perform zero standing privileges?
Yes, for elevation. Analog Informatics Corporation (AIC) removes standing administrator rights on enrolled systems and grants time-bound elevation through Privileged User Management in the AIC Level 2 and Level 3 kits. Creating short-lived accounts on demand is planned.
Does AIC perform identity governance and administration?
Yes, for kit accounts. Analog Informatics Corporation (AIC) performs identity governance and administration (IGA) for accounts the kit manages in the AIC Level 2 and Level 3 kits: account lifecycle and periodic access review. Governance across other business applications is planned.
Does AIC perform identity threat detection and response?
Yes. Analog Informatics Corporation (AIC) performs identity threat detection and response (ITDR) in the AIC Level 2 and Level 3 kits through Audit and Incident Response. The kit receives constant feeds, generates alerts, and mitigates issues.
Does AIC perform identity security posture management?
Yes. Analog Informatics Corporation (AIC) performs identity security posture management (ISPM) in the AIC Level 1, Level 2, and Level 3 kits through Current State Compliance and configuration compliance. The kit constantly monitors configuration compliance.
Does AIC perform machine identity management?
Yes, for service and machine accounts. Analog Informatics Corporation (AIC) vaults and rotates service and machine account credentials through Privileged Identity Management in the AIC Level 2 and Level 3 kits. Certificate lifecycle management is planned.
These are the industry terms for privileged access and identity. Privileged account and session management (PASM), privilege elevation and delegation management (PEDM), secrets management, cloud infrastructure entitlement management (CIEM), and remote privileged access management (RPAM) are the privileged-access tool categories. Just-in-time (JIT) privilege management and zero standing privileges (ZSP) are functions in that scope. Identity governance and administration (IGA), identity threat detection and response (ITDR), and identity security posture management (ISPM) are adjacent identity terms.
| Capability (AIC Module) | What It Does | Industry Function Performed | Built Into |
|---|---|---|---|
| Assessment Binder | Living evidence package an assessor can read | Shared audit record for the C3PAO, the MSP, and the customer | AIC Level 1, Level 2, and Level 3 kits |
| Current State Compliance | Ledger of control-oriented findings, with rescan | Identity security posture management (ISPM) | AIC Level 1, Level 2, and Level 3 kits |
| Privileged Identity Management (PIM) | Credential lifecycle and vaulted identities | Privileged account and session management (PASM); secrets management; machine identity | AIC Level 2 and Level 3 kits |
| Privileged Access Management (PAM) | Session connect and open, Jump, command restriction, and session recording on Level 3 | Privileged account and session management (PASM); remote privileged access management (RPAM) | AIC Level 2 and Level 3 kits |
| Privileged User Management (PUM) | Privilege Elevation and Delegation Management (PEDM): endpoint privilege elevation, delegation, least-privilege enforcement, application and command control, just-in-time (JIT) elevation, and privileged activity auditing on Windows, Apple Mac, and Unix/Linux | Privilege elevation and delegation management (PEDM); just-in-time (JIT) privilege management; zero standing privileges (ZSP) | AIC Level 2 and Level 3 kits |
| Identity Governance and Administration (IGA) | Account lifecycle and periodic access review | Identity governance and administration (IGA) for kit accounts. Cloud infrastructure entitlement management (CIEM) is planned | AIC Level 2 and Level 3 kits |
| Audit | Privileged-action and session records on product paths, and Windows Event Log or syslog when configured | Privileged account and session management (PASM) session audit; identity threat detection and response (ITDR) | AIC Level 2 and Level 3 kits |
| Document sharing vault | Store and share FCI and Controlled Unclassified Information (CUI) | Protected information sharing. Not a privileged-access tool category | AIC Level 1, Level 2, and Level 3 kits |
| Training and attestation | Assign documents and collect a signed attestation | Workforce attestation. Not a privileged-access tool category | AIC Level 2 and Level 3 kits |
| Secure Application Launch | Start an application with credentials the user does not see | Secrets management; privileged account and session management (PASM) | AIC Level 2 and Level 3 kits |
| Jump | Managed access path for sessions. The Level 3 kit adds session recording | Remote privileged access management (RPAM); privileged account and session management (PASM) | AIC Level 2 and Level 3 kits |
| Incident Response | Incident records and notification | Identity threat detection and response (ITDR) | AIC Level 2 and Level 3 kits |
| Federal Information Processing Standards (FIPS) cryptography | Cryptography on product paths | Cryptographic protection of kit paths. Not a privileged-access tool category | AIC Level 2 and Level 3 kits |
| Configuration compliance | Check system configuration against an approved baseline, with an optional block, when workstations connect | Identity security posture management (ISPM) | AIC Level 1, Level 2, and Level 3 kits |
| Governed mail | Mail for FCI or CUI | Mail for FCI and CUI. Not a privileged-access tool category | Optional on the AIC Level 1 kit. Built into the AIC Level 2 and Level 3 kits |
Screenshots
More on Product Screenshots.
An assessment organization, certification body, or regulator decides whether a requirement is satisfied.
Connected Privilege Workflows
Discover & Analyze
Understand identity exposure and configuration findings
Protect & Respond
Control privilege and act on findings
Verify & Prove
Confirm remediation and retain evidence
Platform Questions
What does fewer vendors mean in practice?
Bring identity and privilege security, security assurance, and audit evidence into one consistent package. This reduces separate product handoffs and integration work across these functions while retaining connections to your existing security and IT systems.
Which capabilities are still planned?
Governance across other business applications, certificate lifecycle management, and cloud infrastructure entitlement management are planned. Identity governance for platform-managed accounts is available today.