Platform & Company Statement
Complete reference for what Rivitan offers today — platform modules, services, integrations, deployment model, target customers, and honest maturity notes for marketing and positioning. Last updated: August 2026.
1. Company identity
| Field | Value |
|---|---|
| Company name | Rivitan |
| Website | https://rivitan.com |
| Contact | info@rivitan.com · support@rivitan.com |
| Category | Identity Governance & Administration (IGA) + hybrid Microsoft identity operations |
| Positioning | Enterprise IAM for hybrid Microsoft estates — govern Active Directory, Microsoft Entra ID, applications, files, cloud IAM, and infrastructure from one customer-controlled platform, with optional senior advisory and custom tooling. |
Suggested one-line pitch: Hybrid identity governance for AD and Entra ID — access reviews that actually revoke access, day-2 identity operations, and governance your auditors can evidence.
- Govern every identity. Prove every access.
- Hybrid IAM for AD & Entra — reviews, requests, and operations in one console.
- Identity governance that closes the loop — from request to revoke.
2. What Rivitan sells (three business lines)
Rivitan is not only a software vendor. The website and commercial model present three offerings.
A. Rivitan Platform (software) — Customer-deployed IAM/IGA application. Runs in the customer's environment (on-prem VM, customer VPC, or dedicated pilot host). Not a multi-tenant public SaaS where customer directory data sits next to other tenants' data.
B. Identity Advisory (consulting) — Senior-led engagements: Entra/hybrid migration, AD health and architecture, directory cleanup, IAM governance design, privileged access, fractional identity leadership.
C. Custom IAM Tools (professional services) — Custom portals, approval flows, HR/ITSM/Secret Server integrations, PowerShell/Graph automation, and workflows that extend Rivitan Platform or ship standalone — source-controlled and customer-owned.
3. Deployment & commercial model
| Aspect | Detail |
|---|---|
| Deployment | Customer-managed Windows host or VM; typical HTTPS port 8443; PostgreSQL database |
| Auth | Microsoft Entra ID SSO + break-glass local admin |
| Licensing | Signed licence with module entitlements; trial → grace → read-only enforcement |
| API | Full REST API + hashed API keys with RBAC |
| Pilot | Fixed-scope 8–12 week paid pilot: 1 AD domain + 1 Entra tenant, one end-to-end access review with remediation, 2–3 day-2 demos, training + readout |
| Target buyer | Mid-market orgs with hybrid AD + Entra; audit pressure (SOX, SOC 2, ITGC); IAM teams tired of spreadsheets and tools that never revoke access |
4. Rivitan.com (marketing website)
The public site at rivitan.com markets:
- Rivitan Platform — ten portals interactive previews (IAM Console, Group Portal, App Access, Identity Analysis, AWS IAM, File Governance, Reporting, Licenses, Infrastructure, App Owner).
- Zero Trust narrative — identity-in-motion storytelling (Entra, Conditional Access, MFA, least privilege). Positioning and advisory design language, not a full ZTNA product.
- Rivitan AI — marketed as portal-aware, role-scoped, audited AI assistant. Important: legacy AI assistant code was retired from the platform codebase; treat as roadmap unless a separate AI build is verified live.
- Advisory services — migration, AD health, cleanup, governance, PowerShell automation.
- Custom IAM tools — bespoke portals and integrations.
- Knowledge base — articles on Entra, AD, governance, automation.
- Free self-assessment — 8-question identity maturity quiz.
- CTAs — demo, custom tooling discussion, advisory consultation.
5. Rivitan Platform — product architecture
Core concept: A FastAPI monolith (~100+ registered application pages) with role-based access control, modular licensing (11 sellable modules + always-on core admin), connector framework with honest verified vs declared capability reporting, audit logging, multi-portal UX, and white-label branding.
Enterprise Integrations Hub (/connections → “Integrations”) — single control plane for all connections:
- Dashboard — health/status of connected systems
- Directories — multi-domain Active Directory
- Cloud Identity — multi-tenant Microsoft Entra ID
- Data & Vaults — databases, Secret Server, Jamf
- Connector Catalog — 30+ connector types (SaaS, vaults, HR, etc.)
- Secret Backends — Delinea, Azure Key Vault, AWS Secrets Manager, HashiCorp KV2, GCP Secret Manager, local encrypted store, 1Password Connect
- Notifications — Teams, Slack, email configuration
- Deployment Defaults — org-wide naming, attribute maps, OU paths, license groups
- Per-domain overrides — each AD domain can override deployment defaults with inherited vs overridden UI
- Inline drawers — configure AD, Entra, DB, Secret Server, Jamf without leaving the page
6. Platform modules (licensable product areas)
Module 1: Identity & User Management — User search, create, filter across multi-domain AD and Entra; account creation from templates; account mirroring (employeeID correlation); Credential Reset (AD password, Entra password, Entra TAP, multi-vault handoff, single-use reveal links, configurable complexity profiles); admin unlock and password reset (operator-facing; not end-user self-service SSPR yet).
Module 2: Group & Access Management — Group membership (AD + Entra); membership requests with multi-step approvals, SLA, escalation, delegation; group creation requests; group owners portal; group security policies; automated rules; group tags; Group Access Portal; time-bound/temporary membership support (models and scheduler exist; activation path being hardened).
Module 3: Directory Management (AD) — Organizational Units; computer/device management; domain controller management.
Module 4: File & NTFS Governance — NTFS permission lookup and editing; advanced NTFS tools; path explorer; folder security policies; NTFS audit trail; dedicated portal shell.
Module 5: Infrastructure Operations — DNS zones and records; DHCP scopes and leases; domain controller health; cross-system address lookup; IP address management; infrastructure change history; monitoring; dedicated infrastructure portal.
Module 6: Azure / Entra Services — App registrations and enterprise apps lifecycle; secret and certificate management; App Owner self-service portal; Microsoft 365 license management; dedicated licenses portal.
Module 7: AWS IAM — AWS connections (AssumeRole + External ID, Identity Center); account inventory and org multi-account view; access key hygiene; permission-set grants and reviews; SoD and evidence export; dedicated AWS IAM portal.
Module 8: Access Reviews & Compliance — Entitlement review campaigns (v1 and v2 with auditor workflows); owner keep/revoke; auditor verification; dry-run preview then live apply removals; privileged-group guards; SoD toxic-combination policies; Zero Trust identity governance overlay (/zero-trust) with Entra Graph signals, grant policies, JIT inventory, posture score; evidence pack export.
Module 9: Identity Lifecycle (JML) — Joiner/Mover/Leaver automation; identity sources; lifecycle policies and cases; 18+ step types including secure PowerShell lifecycle hooks; account templates; access roles and entitlements catalog.
Module 10: Application Access — Business application catalog with owners/operators; access levels (AD, Entra, connectors, licenses, manual); self-service requests with fulfillment; auto-grant policies for joiner paths.
Module 11: Identity Analysis — On-demand hygiene scans (~40 finding categories); health score with PDF assessment report; Kerberoast, delegation, AD CS, Entra MFA/CA findings; remediation with dry-run; role discovery; dedicated analysis portal.
Module 12: Reporting & Analytics — Security, user, and operational reports; audit log search and export; user activity and session reports; group membership analytics; metrics dashboards; custom report builder.
Always-on platform administration — Role & permission management; Integrations hub; Security configuration (enforced session timeouts, lockout, concurrent sessions, UI IP allow-list, force-logout); Deployment configuration; Branding; Module enable/disable; Account reconciliation; Approval workflow designer; Task scheduler (30+ handlers); API keys; Service status; Help & documentation; Product licence management.
7. Integrations & connectors (honest maturity)
| Connector | Capabilities |
|---|---|
| Active Directory | Multi-domain, LDAPS, incremental sync (uSNChanged), provision/deprovision |
| Microsoft Entra ID | Multi-tenant Graph, delta sync, group/app operations |
| Okta | Paginated read, provision, deprovision, incremental watermark sync |
| Delinea Secret Server | Vault integration for credential operations |
| Database | Managed DB connection registry |
Connector catalog (available / varying maturity): 30+ declared types including ServiceNow, Workday, BambooHR, SuccessFactors, Google Workspace, GitHub, GitLab, Salesforce, Slack, Teams, Zoom, Duo, Intune, CrowdStrike, Datadog, Auth0, Snowflake, Jira, Confluence, PagerDuty, Box, Dropbox, AWS, Cloudflare, Zendesk, SendGrid, Twilio, 1Password Connect, Jamf, and more.
Secret manager backends for credential reset: Delinea Secret Server, Azure Key Vault, AWS Secrets Manager, HashiCorp Vault KV2, GCP Secret Manager, 1Password Connect, local Fernet-encrypted store.
8. Security & trust posture
- Deployed in customer environment; customer controls host, network, backups, TLS
- Entra SSO + RBAC + page registry access control
- Integration secrets encrypted at rest (ENCRYPTION_KEY)
- API keys stored hashed, expirable, RBAC-scoped
- Audit logging; optional SIEM shipping (Splunk, syslog, webhook)
- Governance removals: dry-run → privileged role → audit event
- Not a password vault for end users; service-account secrets go to customer vaults
- MFA/device trust delegated to Microsoft Entra Conditional Access + Intune
9. Self-service portals
| Portal | Audience | Purpose |
|---|---|---|
| Group Access Portal | Employees | Request group access, view my groups/activity |
| Application Access Portal | Employees | Browse app catalog, request application entitlements |
| App Owner Portal | App owners | Manage owned app registrations, secrets, assignments |
| Group Owners Portal | Group owners | Manage owned groups, approve requests |
| Entitlement Reviews (owner view) | Access owners | Keep/revoke decisions during campaigns |
| Self-Service Portal | End users | Links to external Microsoft SSPR (native Rivitan end-user password reset not yet shipped) |
| My Approvals / My Requests | Approvers / requesters | Unified work queue |
10. Target customers (ICP)
Best fit: 500–10,000 employees (mid-market sweet spot); hybrid Active Directory + Microsoft Entra ID; regulated or audit-sensitive sectors (financial services, healthcare, retail, manufacturing, higher ed, public sector, technology); pain around spreadsheet access reviews and day-2 work in ADUC/PowerShell/tickets; optional scope for NTFS, DNS/DHCP/DC ops, Secret Server service accounts.
Less ideal today: Cloud-only Okta-first estates without AD; full HRIS-driven JML on day one without integration work; buyers expecting multi-tenant SaaS with zero install; buyers needing full SailPoint-scale SaaS connector catalog on day one.
11. Competitive differentiation
| vs. legacy IGA | vs. Microsoft-native only | vs. AD tooling / scripts |
|---|---|---|
| Faster time-to-value on hybrid Microsoft | Broader day-2 operations (NTFS, infra, AWS, app regs) | Governed workflows + audit trail |
| Customer-controlled deployment | Closed-loop access reviews with live remediation | Multi-domain, multi-tenant in one console |
| Honest connector maturity reporting | Application access catalog + JML foundation | Requests, approvals, SoD, ZT signal policies |
| Modular licensing | Identity hygiene scanning + PDF assessment | Enterprise integrations hub |
- Hybrid AD + Entra governance and operations in one product
- Access reviews that preview and apply revocations
- Enterprise integrations hub with per-domain configuration inheritance
- Identity Analysis with security findings + executive PDF report
- AWS IAM portal with same operating model as AD/Entra
- Zero Trust identity governance overlay (signals → grant policy), not network ZTNA
12. What is NOT shipped yet (do not over-market)
| Gap | Status |
|---|---|
| End-user self-service password reset/unlock inside Rivitan | Not built; portal links to Microsoft SSPR |
| Rivitan AI assistant | Marketed on website; platform AI code retired — treat as roadmap |
| Full SaaS connector catalog at production depth | Only AD, Entra, Okta, Secret Server are production |
| HR-driven JML (Workday/SuccessFactors auto-provision) | Engine exists; HR connectors mostly catalog |
| Multi-tenant MSP SaaS (row-level tenancy) | Single deployment per customer today |
| Rivitan-native MFA / step-up auth | Uses Entra SSO + local bcrypt break-glass |
| External change detection (DC event log / directory audit correlation) | Not built |
| Attack-path analysis (shadow admin, ACL abuse graphs) | Partial via Identity Analysis, not full product |
| Time-bound membership auto-activation/expiry | Models and scheduler exist; activation path needs hardening |
| 24×7 enterprise support SLA | Not standard on pilot |
| Public multi-tenant SaaS | Product is customer-deployed software |
13. Suggested messaging pillars
- Close the loop — Access reviews that end in revoked access, not signed spreadsheets.
- Hybrid Microsoft first — Built for AD + Entra estates, not cloud-only SaaS shops.
- One console, many portals — Operators, owners, app requesters, auditors each get the right view.
- Govern + operate — Not just governance; also day-2 identity, file, license, infra, and AWS work.
- Your environment, your data — Customer-controlled deployment for regulated industries.
- Prove it fast — 8–12 week pilot with one real review cycle and audit evidence.
- Identity Zero Trust — Signal-driven grant policies on top of Entra CA/MFA/Intune.
- Platform + people — Software plus advisory and custom tooling when the standard product is not enough.
14. Suggested go-to-market motions
| Motion | Offer | Proof point |
|---|---|---|
| Platform demo | 30-min walkthrough | Entitlement review dry-run → apply on lab group |
| Paid pilot | 8–12 weeks, fixed scope | One completed review + 2–3 day-2 capabilities |
| Identity assessment | Free quiz on website + optional paid scan | Identity Analysis PDF report |
| Advisory | Migration / AD health / governance design | Deliverable-based consulting |
| Custom build | Bespoke portal or integration | Extends or stands beside platform |
Channels to consider: LinkedIn (founder-led), Microsoft partner ecosystem, IAM/audit communities, SOC 2 / ITGC buyers, regional MSPs serving regulated mid-market.
15. Technology summary
- Stack: Python 3.13, FastAPI, Uvicorn, SQLAlchemy, PostgreSQL, Jinja2 templates, vanilla JS/CSS
- Directories: ldap3 (LDAPS), multi-domain, per-domain config inheritance
- Cloud: msal + Microsoft Graph (multi-tenant Azure integrations)
- Vaults: REST/SDK integrations to major secret managers
- Background work: PostgreSQL-backed scheduler + optional python -m worker process
- Testing: pytest unit tests + GitHub Actions CI (growing coverage)
- Install: Unattended installer + Windows service option
- API: REST throughout; API keys for integrations
16. Instruction block for marketing AI
Ready to position Rivitan?
Use this page as the source of truth for marketing AI, agency briefs, and investor conversations — then book a demo when you are ready to show the product.