WebAuthn / Passkeys
FIDO2 hardware key and biometric login surfaces for environments that configure passkeys.
3-Tier RBAC
Viewer, Operator, Admin. Every action gated by risk tier, every access logged.
Audit Trail
Login, command, approval, and healing activity in a searchable operational log.
SSO (SAML + OIDC)
SAML 2.0, OIDC, LDAP, social login. Integrate with any identity provider.
AD / LDAP Sync
Azure AD, Entra ID, on-prem LDAP. Role mapping, migration wizards, M&A acquisition merge.
Encrypted Vault
Fernet-encrypted secret storage surface for credentials and operational secrets.
OWASP-Oriented Controls
Security controls include HSTS/CSP headers, DOMPurify rendering boundaries, PBKDF2 password hashing, rate limiting, and lockout behavior.
NIS2 Checklist
NIS2-oriented compliance checklist and reporting surfaces for teams that need evidence during evaluation.
Public Status Page
Component groups, 90-day uptime bars. No auth required. Share with customers.
8 Notification Channels
Pushover, Gotify, Slack, Discord, Telegram, Email, Webhook, ntfy. Composite alert rules with escalation policies.
Cross-Domain Migration
AD-to-AD consolidation with reconciliation, pre-flight checks, health scoring, drift detection, machine migration, LAPS backup, and rollback decision engine.
Compliance Evidence
NIS2 and SOC2-oriented evidence views, migration records, and post-migration cleanup checklist tracking for evaluation.