COMPLIANCE

Auditors don't want promises. They want logs.

Access control that generates its own evidence: 202 event types, 11 reports, session replay, and architecture aligned to NIST SP 800-207.

A compliance officer reads a report at her desk while the access layer maps itself to GDPR, HIPAA, PCI DSS, ISO 27001 and SOC 2.

Every audit question is one of five.

the evidence layer

Who can reach what? How do you know they are who they claim to be? What could they do once they are in? How would you know if something went wrong? And: prove it.

202logged event types
11report types
7SIEM export formats
  • A perimeter answers with drawingsPerimeter architectures answer those five with network diagrams and assurances, which is why the evidence work starts after the question is asked.
  • Zero Trust answers with recordsHere the control is the evidence. Entitlements are the portal's provisioning data, authentication strength is the auth-profile configuration, session controls are policy objects, and everything that happens is one of 202 logged event types.

Framework mapping, in summary.

  • DPDP Act (India)Access minimisation and purpose-scoped access are policy objects here rather than intentions, and the split-plane design keeps application data on your own paths.
  • RBI / SEBI / IRDAISector guidance on access control, multi-factor authentication, vendor-access oversight and audit trails. Third-party session recording answers the outsourcing-oversight clauses directly.
  • PCI DSSMulti-factor authentication, least privilege and access logging for the systems adjacent to cardholder data.
  • HIPAA / GDPRAccess minimisation, plus an accounting of who reached what and when.
  • ISO 27001 / SOXAccess-control and logging clauses evidenced from the console rather than reconstructed for the auditor.
  • NIST SP 800-207The architecture itself: InstaSafe implements the Zero Trust model the standard describes, with CSA SDP alignment alongside it.

Full clause-by-clause mappings live in the Trust Center.

Use cases

Answer the audit from the record.

Audit evidence

The control is the evidence

Every access-related audit question is a variant of five: who can reach what, how do you know they are who they claim, what could they do once in, how would you know if something went wrong, and prove it. Perimeter architectures answer with diagrams and assurances. Entitlements, authentication strength and session controls are configuration objects here, and what happens to them is already logged — so audit preparation becomes an export rather than archaeology.

m.sundaram · statutory audit · nothing assembled on demand

InstaSafe · evidence

202 event types · already written

  • access reviewson file
  • session recordingson file
  • policy historyon file
  • device postureon file
  • sign-inson file
  • third-party sessionson file
OUTCOMES

The controlis the evidence.

What changes in the audit when the access layer keeps its own records.

Prep becomes export

Audit preparation turns into an export rather than an archaeology project across five systems.

Vendor clauses answered

Outsourcing-oversight clauses get session replay as the answer, which is a shorter conversation than a policy summary.

Residency posture holds

Geofencing constrains where access may originate, and the split plane keeps application data on your own paths.

FAQ

compliance, answered.

Tap a question. If yours is not here, a specialist can answer it.

Talk to a specialist

//Ready when you are//

Bring your audit questions. Leave with the exports.

We'll answer the five from the console: entitlements, factors, session controls, events and reports.

Regulated, air-gapped, or on-premise? See deployment options