Zero integration to API
Start on day one with an offline CSV/JSON upload – no API required. Scale seamlessly to our 24/7 API monitoring.
End the loss of control over cross-system access rights. Our SaaS platform untangles identities from Okta and Entra ID, explains SoD conflicts with AI and generates audit-ready evidence packs for ISO 27001, NIS-2 and B3S.
Security & Compliance
Live preview
The dashboard with IAM objects, SoD classes, open decisions and evidence coverage – open the interactive preview.
Open previewNo login required
The status quo
The SaaS solution
Compliance-with-Content
The four pillars of the platform
Start on day one with an offline CSV/JSON upload – no API required. Scale seamlessly to our 24/7 API monitoring.
Our parsing engine untangles nested groups and the AI translates cryptic permissions into plain language for your auditors.
One-click approvals and revocations directly in Slack or MS Teams. Changes are versioned audit-proof via GitOps.
Strong European focus: NIS-2, DORA, GDPR segregation of duties, ISO 27001.
Compliance engine
Every phase is privacy by design: personal data only leaves your infrastructure as irreversible hashes – while auditors still receive understandable evidence.
Zero data retention
PII masking runs in the background. Raw data is not retained after processing.
Deterministic
Python calculates rules precisely, the LLM writes readable output – without hallucinations.
Plain-text view
You review the clean, unmasked data in a clear dashboard.
Smart dropdowns
When data is ambiguous, the engine asks a targeted question – you clarify via dropdown.
Delta to IdP
Only changes are pushed to your IdP (e.g. Okta) – with immutable audit logs.
eSign approval
Reports are generated and approved by stakeholders via eSign.
Live data flow · Sample identity
John Doe passes through all six engine phases
Upload & Sanitization
01John Doe
Zero data retention
AI & Python engine
02JML: Mover
Deterministically checked
Dashboard & review
03John Doe · Finance
Reviewed unmasked
Human-in-the-Loop
04Department? → Finance
Smart dropdown
API-Push
05Okta Delta +12 / −3
Deltas only
Audit-Ready Reports
06Report_0926.pdf
NIS-2 · DORA · ISO 27001
Human-in-the-loop
Ambiguous columns or missing owners are never guessed. IAM Compass asks a concrete question – you decide via dropdown.
| Identity | Question | Answer |
|---|---|---|
| John DoeSource: FIN-OPS-2 | Clarify column 'Department' | Finance |
| Sofia MillerSource: — | Who is the deputy? | Select… Jonas Ferreira Mara Brandt No deputy |
| Jonas FerreiraSource: SAP | Map role 'SAP_FIN_0815' | Invoice approval |
Actionable error handling
If an Okta push fails, you get clear tasks in plain language – with cause, affected users and a one-click fix.
Group 'Finance-Approvers' missing in Okta
Group created · 4 users
Mara Brandt is deactivated in Okta
Skip leaver revoke or reactivate
Rate limit while pushing 12 changes
Auto-retry in 2 min
40+ hrs
Saves IT 40+ hours of manual work before every audit.
10–50×
A single failed audit costs 10 to 50 times as much as our platform.
ISO 27001
Foundation for ISO 27001: no transparent permission table, no certificate.
Pricing
All plans include evidence archive, GDPR-compliant EU hosting and data processing agreement.