Zetect

One platform for every
identity decision

Access, governance and privilege on one identity fabric — one policy engine, one audit trail, one console.

  • Cloud, on-premise or air-gapped
  • Agentless
  • ISO 27001 · SOC 2 · PCI-DSS evidence
One console covering access, governance and privilege: headline counters, a login trend, privileged session status and a correlated event feed. IDENTITIES ENTITLEMENTS PRIVILEGED ASSETS OPEN RISKS SIGN-INS — LAST 30 DAYS PRIVILEGED SESSIONS ONE CORRELATED EVENT TRAIL sign-in access granted session recorded privilege revoked

Connects agentlessly to the systems you already run

  • Active Directory
  • SAML & OIDC
  • Microsoft Azure
  • Windows (RDP)
  • Databases
  • SCIM & REST

Three tools. Three truths.

Attackers live in the seams between point products — and so do audit findings.

Three copies of the truth

Each tool keeps its own list of who exists, kept in step by connectors that run on a schedule.

Privilege that never expires

Admin credentials issued for one migration, still live four years later.

Audit built by hand

Exports pasted into spreadsheets, describing a state that already changed.

Access outlives the person

Disabled in one tool on Friday, still active in another for months.

One identity fabric underneath all three

Sources feed the fabric. The fabric drives the modules. Nothing is synchronised in between.

The Zetect identity fabric Identity sources, applications and privileged assets feed one identity fabric made of a single identity source, policy engine and audit trail, which drives Access Management, Identity Governance and Privileged Access. HR & directory sources Applications & cloud Servers, databases & vaults ONE IDENTITY FABRIC One identity source One policy engine One audit trail Every human, service and privileged account resolved once. The same rules for login, request and privileged session. Every event on one correlated timeline. Access Management Identity Governance Privileged Access Single sign-on · SAML & OIDC Adaptive & biometric MFA Passwordless · app launchpad Joiner, mover, leaver automation Access certification campaigns Segregation of duties Credential vaulting Just-in-time elevation Brokered RDP & SSH recording

One adaptive front door

Access Management gives every application one adaptive front door. Users sign in once and land on a launchpad of everything they are entitled to. The challenge steps up or down with the risk.

  • Single sign-on via SAML 2.0 and OIDC
  • Risk-based adaptive MFA
  • Biometric MFA — fingerprint or face
  • Passwordless and FIDO2 passkeys
Explore access management
A sign-in attempt is evaluated for risk, stepped up to a biometric factor when needed, and lands the user on a launchpad of the applications they are entitled to. Sign-in attempt Risk evaluated Step up if needed Known device Network zone Behaviour signals LAUNCHPAD — WHAT THIS USER IS ENTITLED TO

Access that stays justified

Identity Governance runs certification campaigns on schedule, and reviewers certify real entitlements in the console — not a spreadsheet emailed around the business.

  • Joiner, mover, leaver automation
  • Access requests and approvals
  • Certification campaigns
  • Segregation-of-duties enforcement
Explore governance
A certification campaign in progress: reviewers keep or revoke each entitlement, a segregation-of-duties conflict is flagged before approval, and the decisions are recorded. QUARTERLY ACCESS REVIEW 24 / 35 Keep Revoke Pending Segregation-of-duties conflict flagged before the grant, not after the audit

Nothing left standing

Privileged Access keeps credentials vaulted and never shows them to a person. Elevation lasts for the window agreed, then disappears — and the session is recorded.

  • Credential vaulting with rotation
  • Just-in-time elevation, auto-revoked
  • Brokered RDP and SSH — agentless
  • Tamper-evident session recording
Explore privileged access
A privileged request is checked against policy, elevated for an agreed window, brokered and recorded, then revoked automatically when the window closes. Requested Policy & SoD Elevated Revoked by the engineer checked first for the window automatically ELEVATION WINDOW granted 14:00 expires 16:00 Session brokered and recorded — RDP / SSH, no agent on the target

Evidence as a by-product

Authentications, approvals, entitlement changes and keystrokes land on one timeline — so an audit is a report, not a project.

  • One correlated timeline across all three
  • Tamper-evident session recordings
  • ISO 27001, SOC 2, PCI-DSS, HIPAA, SOX, GDPR, NIST 800-53
Why that matters
One timeline carrying an authentication, an approved access request, a recorded privileged session and an automatic revocation — in order, from the three disciplines. 09:14 09:26 11:02 13:02 Sign-in — adaptive MFA satisfied Access request approved Privileged session started and recorded Elevation revoked automatically known device · trusted network zone policy checked · single approver RDP brokered · no agent on target window closed · nothing left standing access governance privilege privilege One trail — three disciplines, correlated in order, nothing stitched together afterwards

What changes on an ordinary week

Monday

A joiner starts

Provisioned from the HR record — role-based entitlements, nothing extra.

Tuesday

A contractor needs prod

Two hours of elevation, recorded, then revoked automatically.

Friday

Someone resigns

Account, entitlements and standing privilege go at the same moment.

Quarter-end

The auditor asks

The evidence already exists. Run the report.

One platform. Minutes, not days. Zero standing privilege.

  • One Platform instead of three tools and the connectors between them
  • Minutes From access request to a governed, recorded grant
  • Zero Standing privileged credentials once a session ends

Runs where your identities live

The same platform in all three shapes, with agentless connectors reaching any network.

Fully managed

Cloud · SaaS

  • Elastic and always current
  • No infrastructure to run
  • Regional data residency

Best for speed and scale

Your datacenter

On-premise

  • Full data sovereignty
  • Container-based
  • Air-gap capable

Best for strict mandates

Best of both

Hybrid

  • Control plane your choice
  • Agentless connectors
  • Cloud and on-prem together

Best for phased moves

Connectors for every system you run

Agentless into the identity sources, applications and privileged assets you already have.

  • Active Directory / LDAP
  • SAML 2.0 & OIDC apps
  • SCIM & REST APIs
  • AWS
  • Microsoft Azure AD
  • Windows Servers (RDP)
  • Linux Servers (SSH)
  • Databases & SaaS platforms
  • HR & directory sources
See the connector documentation