Compliance & Assurance

Evidence generated by the control, not assembled around it.

Privileged access sits inside almost every framework you are measured against. Vaultris produces the artefacts those frameworks ask for as a by-product of doing the work correctly.

The audit problem, stated honestly

Most organisations can describe their privileged access controls. Far fewer can demonstrate them. The gap usually appears at the same point: an auditor asks for the list of everyone who held administrative access to a system during a given quarter, what they did with it, and who approved it — and the answer has to be reconstructed from directory exports, ticket queues, and the memory of two long-serving engineers.

A brokered gateway removes that reconstruction step. Entitlements, approvals, sessions, and recordings are already one dataset, because every privileged action passed through one place.

A useful test: pick a random production server and a random week from six months ago. If you cannot produce, within an hour, the list of privileged sessions on that host, who opened them, and what commands were run — the control is documented but not evidenced.

Framework Mapping

Where a bastion gateway does the heavy lifting.

Indicative mapping of platform capabilities to common control families. Scoping and applicability are confirmed during assessment.

FrameworkRelevant control areaHow the gateway satisfies it
CJIS Security Policy Advanced authentication, access control, auditing and accountability MFA enforced on all administrative access to CJI systems; named-individual accounts; complete, retained session audit
NIST SP 800-53 AC (Access Control), AU (Audit & Accountability), IA (Identification & Authentication) Least privilege and separation of duties enforced at the broker; audit generation, protection, and retention built in
NIST SP 800-171 Controlled unclassified information — access and audit families Scoped, expiring access to CUI-bearing systems with attributable session records
SOC 2 Common Criteria — logical access, change management, monitoring Continuous evidence of provisioning, review, and revocation; session recordings as change evidence
ISO/IEC 27001 A.5 & A.8 — privileged access rights, secure authentication, logging Central management of privileged rights with documented review cycles and protected logs
PCI-DSS Requirements 7, 8 and 10 — restrict access, authenticate, log and monitor Unique IDs, MFA into the CDE, and full tracking of all access to system components
HIPAA Security Rule Technical safeguards — access control, audit controls, person authentication Recorded, attributable administrative access to systems holding electronic protected health information
Sector regulation Utility, transport, and telecommunications remote access requirements Demonstrable control and audit of vendor and remote access at the IT/OT boundary

Vaultris supplies the technical control and its evidence. It does not, by itself, make an organisation compliant — certification depends on scope, process, and controls well beyond privileged access. We are explicit about that boundary during assessment.

Evidence Artefacts

What you can hand an auditor.

Entitlement Register

Who holds privileged access, to which assets, under what role, granted by whom, and when it expires — as of any date you select.

Access Review Packs

Periodic certification packages routed to system owners, with attestations and revocations recorded as part of the trail.

Session Recordings

Full replay of any privileged session, exportable with a cryptographic integrity manifest for evidentiary use.

Access Analytics

Trend reporting on privileged session volume, dormant entitlements, out-of-hours activity, and approval turnaround.

Baseline Attestation

Point-in-time proof that gateway hardening matched the approved baseline, with a dated record of any drift and its remediation.

Incident Timelines

Reconstructed sequences of privileged activity across assets for a defined window — the first thing an investigation asks for.

The Vaultris audit ledger, filterable by actor, action, outcome and date
The append-only, hash-chained ledger — in plain sentences, not raw fields. Each entry's hash covers the one before it, so altering any past record breaks the chain visibly.
Vaultris reports: session activity, access review, evidence integrity, file transfers and commands
Five report types over any date range, exportable to CSV or print — and running a report is itself written into the ledger.

Auditor Access

Give the auditor a login, not a binder.

Instead of assembling exports on request, auditors get their own read-only seat in the console. They see exactly two workspaces — their own access and the record — and nothing that could change state.

  • Read-only by construction — no admin controls exist in the auditor's interface, so there is nothing to misuse.
  • Self-service evidence — session activity, access review, evidence integrity, file transfer and command reports over any date range, exported to CSV or print.
  • Watched like everyone else — every report an auditor runs is itself written into the ledger.
The Vaultris console signed in as a read-only auditor, showing only the Audit workspace with sessions and reports
The console as an auditor sees it — two workspaces, read-only, reports on tap

Data Governance

Recording responsibly.

Session recording is a powerful control and a significant responsibility. Recordings can capture sensitive data, and in some jurisdictions monitoring employee activity carries specific legal obligations. Vaultris deployments are configured with that in mind from the start.

  • Retention policy per system class, so recordings are kept as long as required and no longer.
  • Access to recordings is itself privileged — and itself recorded. Watching the watchers is not optional.
  • Dual authorisation for playback of the most sensitive session archives.
  • Data residency controls keeping evidence within a defined jurisdiction.
  • Masking and redaction of defined sensitive fields in captured database result sets.
  • Documented notice and consent posture aligned to local employment and privacy law.
vaultris · evidence export
$ vaultris evidence export \
    --asset prod-db-04 \
    --from 2026-01-01 --to 2026-03-31 \
    --format audit-pack

Collecting entitlements ................ 14 records
Collecting approvals ................... 9 records
Collecting sessions .................... 231 sessions
Collecting recordings .................. 231 objects
Collecting baseline attestations ....... 92 daily
Verifying storage seals ................ intact

audit-pack-prod-db-04-2026Q1.tar.gz
manifest signed · sha256 verified
export logged as privileged action by j.okafor

Frequently asked by auditors

Can you prove a specific administrator did not access a given system?

Yes, within the scope of the gateway. Because the target accepts connections only from the gateway's private address, the absence of a session record for that person and asset is meaningful evidence rather than an absence of logging. That property is exactly what makes the chokepoint architecture valuable to auditors.

How do you stop a privileged user from deleting their own session recording?

Recordings are written to write-once, retention-locked storage and forwarded to your SIEM as they are created. Administering the gateway and administering the evidence store are separated duties, and any access to recordings is itself a recorded privileged action.

What is the retention period?

Configurable per system class and set during design against your regulatory and legal-hold obligations. Public safety and defense deployments commonly run considerably longer retention on evidence-bearing systems than on general infrastructure.

Can auditors be given read-only access rather than exports?

Yes. A scoped auditor role provides read-only visibility of entitlements, session metadata, and — where authorised — recording playback, without any ability to grant access or alter records. Auditor activity is logged like any other.

Does the gateway itself get audited?

It should be, and we design for it. The gateway runs against a documented hardened baseline with continuous drift detection, and its own administrative access is brokered and recorded under the same rules as everything else.

Next Step

Bring us your last audit findings.

We will tell you plainly which of them a governed access gateway closes — and which it does not.