Compliance & Assurance
Evidence generated by the control, not assembled around it.
Privileged access sits inside almost every framework you are measured against. Vaultris produces the artefacts those frameworks ask for as a by-product of doing the work correctly.
The audit problem, stated honestly
Most organisations can describe their privileged access controls. Far fewer can demonstrate them. The gap usually appears at the same point: an auditor asks for the list of everyone who held administrative access to a system during a given quarter, what they did with it, and who approved it — and the answer has to be reconstructed from directory exports, ticket queues, and the memory of two long-serving engineers.
A brokered gateway removes that reconstruction step. Entitlements, approvals, sessions, and recordings are already one dataset, because every privileged action passed through one place.
A useful test: pick a random production server and a random week from six months ago. If you cannot produce, within an hour, the list of privileged sessions on that host, who opened them, and what commands were run — the control is documented but not evidenced.
Framework Mapping
Where a bastion gateway does the heavy lifting.
Indicative mapping of platform capabilities to common control families. Scoping and applicability are confirmed during assessment.
| Framework | Relevant control area | How the gateway satisfies it |
|---|---|---|
| CJIS Security Policy | Advanced authentication, access control, auditing and accountability | MFA enforced on all administrative access to CJI systems; named-individual accounts; complete, retained session audit |
| NIST SP 800-53 | AC (Access Control), AU (Audit & Accountability), IA (Identification & Authentication) | Least privilege and separation of duties enforced at the broker; audit generation, protection, and retention built in |
| NIST SP 800-171 | Controlled unclassified information — access and audit families | Scoped, expiring access to CUI-bearing systems with attributable session records |
| SOC 2 | Common Criteria — logical access, change management, monitoring | Continuous evidence of provisioning, review, and revocation; session recordings as change evidence |
| ISO/IEC 27001 | A.5 & A.8 — privileged access rights, secure authentication, logging | Central management of privileged rights with documented review cycles and protected logs |
| PCI-DSS | Requirements 7, 8 and 10 — restrict access, authenticate, log and monitor | Unique IDs, MFA into the CDE, and full tracking of all access to system components |
| HIPAA Security Rule | Technical safeguards — access control, audit controls, person authentication | Recorded, attributable administrative access to systems holding electronic protected health information |
| Sector regulation | Utility, transport, and telecommunications remote access requirements | Demonstrable control and audit of vendor and remote access at the IT/OT boundary |
Vaultris supplies the technical control and its evidence. It does not, by itself, make an organisation compliant — certification depends on scope, process, and controls well beyond privileged access. We are explicit about that boundary during assessment.
Evidence Artefacts
What you can hand an auditor.
Entitlement Register
Who holds privileged access, to which assets, under what role, granted by whom, and when it expires — as of any date you select.
Access Review Packs
Periodic certification packages routed to system owners, with attestations and revocations recorded as part of the trail.
Session Recordings
Full replay of any privileged session, exportable with a cryptographic integrity manifest for evidentiary use.
Access Analytics
Trend reporting on privileged session volume, dormant entitlements, out-of-hours activity, and approval turnaround.
Baseline Attestation
Point-in-time proof that gateway hardening matched the approved baseline, with a dated record of any drift and its remediation.
Incident Timelines
Reconstructed sequences of privileged activity across assets for a defined window — the first thing an investigation asks for.
Auditor Access
Give the auditor a login, not a binder.
Instead of assembling exports on request, auditors get their own read-only seat in the console. They see exactly two workspaces — their own access and the record — and nothing that could change state.
- Read-only by construction — no admin controls exist in the auditor's interface, so there is nothing to misuse.
- Self-service evidence — session activity, access review, evidence integrity, file transfer and command reports over any date range, exported to CSV or print.
- Watched like everyone else — every report an auditor runs is itself written into the ledger.
Data Governance
Recording responsibly.
Session recording is a powerful control and a significant responsibility. Recordings can capture sensitive data, and in some jurisdictions monitoring employee activity carries specific legal obligations. Vaultris deployments are configured with that in mind from the start.
- Retention policy per system class, so recordings are kept as long as required and no longer.
- Access to recordings is itself privileged — and itself recorded. Watching the watchers is not optional.
- Dual authorisation for playback of the most sensitive session archives.
- Data residency controls keeping evidence within a defined jurisdiction.
- Masking and redaction of defined sensitive fields in captured database result sets.
- Documented notice and consent posture aligned to local employment and privacy law.
$ vaultris evidence export \ --asset prod-db-04 \ --from 2026-01-01 --to 2026-03-31 \ --format audit-pack Collecting entitlements ................ 14 records Collecting approvals ................... 9 records Collecting sessions .................... 231 sessions Collecting recordings .................. 231 objects Collecting baseline attestations ....... 92 daily Verifying storage seals ................ intact audit-pack-prod-db-04-2026Q1.tar.gz manifest signed · sha256 verified export logged as privileged action by j.okafor
Frequently asked by auditors
Can you prove a specific administrator did not access a given system?
Yes, within the scope of the gateway. Because the target accepts connections only from the gateway's private address, the absence of a session record for that person and asset is meaningful evidence rather than an absence of logging. That property is exactly what makes the chokepoint architecture valuable to auditors.
How do you stop a privileged user from deleting their own session recording?
Recordings are written to write-once, retention-locked storage and forwarded to your SIEM as they are created. Administering the gateway and administering the evidence store are separated duties, and any access to recordings is itself a recorded privileged action.
What is the retention period?
Configurable per system class and set during design against your regulatory and legal-hold obligations. Public safety and defense deployments commonly run considerably longer retention on evidence-bearing systems than on general infrastructure.
Can auditors be given read-only access rather than exports?
Yes. A scoped auditor role provides read-only visibility of entitlements, session metadata, and — where authorised — recording playback, without any ability to grant access or alter records. Auditor activity is logged like any other.
Does the gateway itself get audited?
It should be, and we design for it. The gateway runs against a documented hardened baseline with continuous drift detection, and its own administrative access is brokered and recorded under the same rules as everything else.
Next Step
Bring us your last audit findings.
We will tell you plainly which of them a governed access gateway closes — and which it does not.