Access control and account management
Access control rules are placed under security policies, and allow or deny decisions are made by matching resource types against roles. Rules are evaluated on a priority basis and use role-based and attribute-based conditions together. Accounts are managed through a lifecycle from issuance to change, dormancy, and disposal, and linked to HR information. Authentication supports 3 multi-factor methods and backup codes, and sessions provide concurrent session limits, inactivity timeouts, and forced termination. Minimum password length and complexity, session duration, allowed login failure counts, and lockout duration are set at the organization level.
Audit trails and data protection
Audit logs record the action, target, severity, source IP, and timestamp together, and prevent forgery and alteration through an append-only structure. Data access logs record lookups, creations, modifications, and deletions at the table and record level. Both logs are stored in monthly partitions and migrated automatically according to retention periods by type. Encryption keys are managed by algorithm (AES-256, RSA-2048, RSA-4096, ECDSA-P256) and by purpose (data encryption, token signing, communication encryption, key exchange), with status and expiry dates tracked; the actual key values are held in a key management system and only the metadata is tracked. When a key is rotated, a reference to the previous key remains so the history can be followed.
Threat detection and incident response
Security alerts are managed by occurrence, acknowledgement, and remediation status. Vulnerability assessments are registered as either scheduled or urgent, and the number of findings, their distribution by severity, and the remediation status are tracked. Security incidents are recorded stage by stage from registration through investigation, response, and closure, with containment and recovery actions and lessons learned retained. 4 operations-center status screens (security incident status, access management, vulnerability status, security audit) are provided and used for continuous monitoring.
Network and OT security
The IP block list supports blocking of both individual addresses and address ranges, and manages manual blocks, automatic blocks, and expiry times separately. Request rate limiting is configured across 6 scopes (global, authentication, AI, code generation, upload, real-time communication), and authentication-related requests are limited strictly to defend against brute force attacks. The OT asset inventory manages type, manufacturer, model, firmware, IP, level, and criticality, and tracks the vulnerability count and the most recent inspection date alongside them.
Integrated log analysis and threat intelligence (SIEM)
Logs from multiple sources such as firewalls, servers, and operational systems are registered and gathered in one place, and correlation rules group individual events into a single threat. For example, when events that look harmless on their own, such as "repeated authentication failures late at night followed by a success and then a bulk lookup," match a rule, a correlation alert is generated and, depending on severity, automatically converted into an incident record. By registering external threat intelligence feeds you can manage known malicious IP addresses, domains, and hashes as indicators, and by saving hunting queries you can repeatedly search past logs for traces when a new threat is disclosed.
Endpoint protection and leakage prevention (EDR, DLP)
The installation status and last communication time of the agent installed on each endpoint are managed, and a normal baseline is registered per endpoint so that behavior outside it is detected. Response actions such as quarantine and process blocking are retained as records against each detection. Leakage prevention is managed through policies by channel. Policies are applied to paths through which materials can leave, such as email attachments, web uploads, external storage devices, and printing, and when a violation occurs it is handled through warning, blocking, and reporting stages, connecting through to HR disciplinary procedures where necessary. If drawings and recipes are registered in the sensitive data list, the handling of those materials is tracked separately.
Privileged accounts and single sign-on (PAM, SSO)
Sessions accessed with administrator privileges are recorded separately from ordinary access. Because a record is left of who used a privileged account, when, and for what purpose, you obtain the administrator access control evidence that prime contractor assessments frequently request. Service accounts used for system-to-system integration rather than by people are also managed as a separate list, allowing you to find integration accounts that have been left in place without an expiry. Through single sign-on (SSO) configuration, the system can be connected to your existing internal account infrastructure.
Vulnerability remediation and security training
Vulnerability assessment results are managed per finding, with detailed descriptions, severity, and remediation status. When remediation requires a patch, it is registered in the patch management register and proceeds as a workflow through verification, approval, deployment, and rollback stages. Because patching production equipment entails a stoppage, this verification stage is especially important. Security training registers courses and manages completion records by employee. Evidence of training delivery, required in certification audits and prime contractor assessments, accumulates automatically.
Compliance checks and evidence management
Check items are registered by standard, and conforming, nonconforming, and not-yet-checked statuses are managed together with the evidence. Items that can be verified in the system have evidence linked automatically, and evidence outside the system is supplemented with attachments. Nonconforming items are assigned corrective actions, responsible personnel, and deadlines, and completion is tracked. If a schedule for periodic checks is registered, an alert is raised when it comes due.