Skip to content
Internal reference

Platform & Company Statement

Complete reference for what Rivitan offers today — platform modules, services, integrations, deployment model, target customers, and honest maturity notes for marketing and positioning. Last updated: August 2026.

1. Company identity

FieldValue
Company nameRivitan
Websitehttps://rivitan.com
Contactinfo@rivitan.com · support@rivitan.com
CategoryIdentity Governance & Administration (IGA) + hybrid Microsoft identity operations
PositioningEnterprise IAM for hybrid Microsoft estates — govern Active Directory, Microsoft Entra ID, applications, files, cloud IAM, and infrastructure from one customer-controlled platform, with optional senior advisory and custom tooling.

Suggested one-line pitch: Hybrid identity governance for AD and Entra ID — access reviews that actually revoke access, day-2 identity operations, and governance your auditors can evidence.

  • Govern every identity. Prove every access.
  • Hybrid IAM for AD & Entra — reviews, requests, and operations in one console.
  • Identity governance that closes the loop — from request to revoke.

2. What Rivitan sells (three business lines)

Rivitan is not only a software vendor. The website and commercial model present three offerings.

A. Rivitan Platform (software) — Customer-deployed IAM/IGA application. Runs in the customer's environment (on-prem VM, customer VPC, or dedicated pilot host). Not a multi-tenant public SaaS where customer directory data sits next to other tenants' data.

B. Identity Advisory (consulting) — Senior-led engagements: Entra/hybrid migration, AD health and architecture, directory cleanup, IAM governance design, privileged access, fractional identity leadership.

C. Custom IAM Tools (professional services) — Custom portals, approval flows, HR/ITSM/Secret Server integrations, PowerShell/Graph automation, and workflows that extend Rivitan Platform or ship standalone — source-controlled and customer-owned.

3. Deployment & commercial model

AspectDetail
DeploymentCustomer-managed Windows host or VM; typical HTTPS port 8443; PostgreSQL database
AuthMicrosoft Entra ID SSO + break-glass local admin
LicensingSigned licence with module entitlements; trial → grace → read-only enforcement
APIFull REST API + hashed API keys with RBAC
PilotFixed-scope 8–12 week paid pilot: 1 AD domain + 1 Entra tenant, one end-to-end access review with remediation, 2–3 day-2 demos, training + readout
Target buyerMid-market orgs with hybrid AD + Entra; audit pressure (SOX, SOC 2, ITGC); IAM teams tired of spreadsheets and tools that never revoke access
Primary wedge: Time-to-value on hybrid Microsoft — not “cheaper than SailPoint.”

4. Rivitan.com (marketing website)

The public site at rivitan.com markets:

  • Rivitan Platform — ten portals interactive previews (IAM Console, Group Portal, App Access, Identity Analysis, AWS IAM, File Governance, Reporting, Licenses, Infrastructure, App Owner).
  • Zero Trust narrative — identity-in-motion storytelling (Entra, Conditional Access, MFA, least privilege). Positioning and advisory design language, not a full ZTNA product.
  • Rivitan AI — marketed as portal-aware, role-scoped, audited AI assistant. Important: legacy AI assistant code was retired from the platform codebase; treat as roadmap unless a separate AI build is verified live.
  • Advisory services — migration, AD health, cleanup, governance, PowerShell automation.
  • Custom IAM tools — bespoke portals and integrations.
  • Knowledge base — articles on Entra, AD, governance, automation.
  • Free self-assessment — 8-question identity maturity quiz.
  • CTAs — demo, custom tooling discussion, advisory consultation.

5. Rivitan Platform — product architecture

Core concept: A FastAPI monolith (~100+ registered application pages) with role-based access control, modular licensing (11 sellable modules + always-on core admin), connector framework with honest verified vs declared capability reporting, audit logging, multi-portal UX, and white-label branding.

Enterprise Integrations Hub (/connections → “Integrations”) — single control plane for all connections:

  • Dashboard — health/status of connected systems
  • Directories — multi-domain Active Directory
  • Cloud Identity — multi-tenant Microsoft Entra ID
  • Data & Vaults — databases, Secret Server, Jamf
  • Connector Catalog — 30+ connector types (SaaS, vaults, HR, etc.)
  • Secret Backends — Delinea, Azure Key Vault, AWS Secrets Manager, HashiCorp KV2, GCP Secret Manager, local encrypted store, 1Password Connect
  • Notifications — Teams, Slack, email configuration
  • Deployment Defaults — org-wide naming, attribute maps, OU paths, license groups
  • Per-domain overrides — each AD domain can override deployment defaults with inherited vs overridden UI
  • Inline drawers — configure AD, Entra, DB, Secret Server, Jamf without leaving the page

6. Platform modules (licensable product areas)

Module 1: Identity & User Management — User search, create, filter across multi-domain AD and Entra; account creation from templates; account mirroring (employeeID correlation); Credential Reset (AD password, Entra password, Entra TAP, multi-vault handoff, single-use reveal links, configurable complexity profiles); admin unlock and password reset (operator-facing; not end-user self-service SSPR yet).

Module 2: Group & Access Management — Group membership (AD + Entra); membership requests with multi-step approvals, SLA, escalation, delegation; group creation requests; group owners portal; group security policies; automated rules; group tags; Group Access Portal; time-bound/temporary membership support (models and scheduler exist; activation path being hardened).

Module 3: Directory Management (AD) — Organizational Units; computer/device management; domain controller management.

Module 4: File & NTFS Governance — NTFS permission lookup and editing; advanced NTFS tools; path explorer; folder security policies; NTFS audit trail; dedicated portal shell.

Module 5: Infrastructure Operations — DNS zones and records; DHCP scopes and leases; domain controller health; cross-system address lookup; IP address management; infrastructure change history; monitoring; dedicated infrastructure portal.

Module 6: Azure / Entra Services — App registrations and enterprise apps lifecycle; secret and certificate management; App Owner self-service portal; Microsoft 365 license management; dedicated licenses portal.

Module 7: AWS IAM — AWS connections (AssumeRole + External ID, Identity Center); account inventory and org multi-account view; access key hygiene; permission-set grants and reviews; SoD and evidence export; dedicated AWS IAM portal.

Module 8: Access Reviews & Compliance — Entitlement review campaigns (v1 and v2 with auditor workflows); owner keep/revoke; auditor verification; dry-run preview then live apply removals; privileged-group guards; SoD toxic-combination policies; Zero Trust identity governance overlay (/zero-trust) with Entra Graph signals, grant policies, JIT inventory, posture score; evidence pack export.

Module 9: Identity Lifecycle (JML) — Joiner/Mover/Leaver automation; identity sources; lifecycle policies and cases; 18+ step types including secure PowerShell lifecycle hooks; account templates; access roles and entitlements catalog.

Module 10: Application Access — Business application catalog with owners/operators; access levels (AD, Entra, connectors, licenses, manual); self-service requests with fulfillment; auto-grant policies for joiner paths.

Module 11: Identity Analysis — On-demand hygiene scans (~40 finding categories); health score with PDF assessment report; Kerberoast, delegation, AD CS, Entra MFA/CA findings; remediation with dry-run; role discovery; dedicated analysis portal.

Module 12: Reporting & Analytics — Security, user, and operational reports; audit log search and export; user activity and session reports; group membership analytics; metrics dashboards; custom report builder.

Always-on platform administration — Role & permission management; Integrations hub; Security configuration (enforced session timeouts, lockout, concurrent sessions, UI IP allow-list, force-logout); Deployment configuration; Branding; Module enable/disable; Account reconciliation; Approval workflow designer; Task scheduler (30+ handlers); API keys; Service status; Help & documentation; Product licence management.

7. Integrations & connectors (honest maturity)

ConnectorCapabilities
Active DirectoryMulti-domain, LDAPS, incremental sync (uSNChanged), provision/deprovision
Microsoft Entra IDMulti-tenant Graph, delta sync, group/app operations
OktaPaginated read, provision, deprovision, incremental watermark sync
Delinea Secret ServerVault integration for credential operations
DatabaseManaged DB connection registry

Connector catalog (available / varying maturity): 30+ declared types including ServiceNow, Workday, BambooHR, SuccessFactors, Google Workspace, GitHub, GitLab, Salesforce, Slack, Teams, Zoom, Duo, Intune, CrowdStrike, Datadog, Auth0, Snowflake, Jira, Confluence, PagerDuty, Box, Dropbox, AWS, Cloudflare, Zendesk, SendGrid, Twilio, 1Password Connect, Jamf, and more.

Marketing rule: The UI distinguishes verified (actually implemented) vs declared (on roadmap). Only AD, Entra, Okta, and Secret Server should be sold as production reconciliation targets today.

Secret manager backends for credential reset: Delinea Secret Server, Azure Key Vault, AWS Secrets Manager, HashiCorp Vault KV2, GCP Secret Manager, 1Password Connect, local Fernet-encrypted store.

8. Security & trust posture

  • Deployed in customer environment; customer controls host, network, backups, TLS
  • Entra SSO + RBAC + page registry access control
  • Integration secrets encrypted at rest (ENCRYPTION_KEY)
  • API keys stored hashed, expirable, RBAC-scoped
  • Audit logging; optional SIEM shipping (Splunk, syslog, webhook)
  • Governance removals: dry-run → privileged role → audit event
  • Not a password vault for end users; service-account secrets go to customer vaults
  • MFA/device trust delegated to Microsoft Entra Conditional Access + Intune

9. Self-service portals

PortalAudiencePurpose
Group Access PortalEmployeesRequest group access, view my groups/activity
Application Access PortalEmployeesBrowse app catalog, request application entitlements
App Owner PortalApp ownersManage owned app registrations, secrets, assignments
Group Owners PortalGroup ownersManage owned groups, approve requests
Entitlement Reviews (owner view)Access ownersKeep/revoke decisions during campaigns
Self-Service PortalEnd usersLinks to external Microsoft SSPR (native Rivitan end-user password reset not yet shipped)
My Approvals / My RequestsApprovers / requestersUnified work queue

10. Target customers (ICP)

Best fit: 500–10,000 employees (mid-market sweet spot); hybrid Active Directory + Microsoft Entra ID; regulated or audit-sensitive sectors (financial services, healthcare, retail, manufacturing, higher ed, public sector, technology); pain around spreadsheet access reviews and day-2 work in ADUC/PowerShell/tickets; optional scope for NTFS, DNS/DHCP/DC ops, Secret Server service accounts.

Less ideal today: Cloud-only Okta-first estates without AD; full HRIS-driven JML on day one without integration work; buyers expecting multi-tenant SaaS with zero install; buyers needing full SailPoint-scale SaaS connector catalog on day one.

11. Competitive differentiation

vs. legacy IGAvs. Microsoft-native onlyvs. AD tooling / scripts
Faster time-to-value on hybrid MicrosoftBroader day-2 operations (NTFS, infra, AWS, app regs)Governed workflows + audit trail
Customer-controlled deploymentClosed-loop access reviews with live remediationMulti-domain, multi-tenant in one console
Honest connector maturity reportingApplication access catalog + JML foundationRequests, approvals, SoD, ZT signal policies
Modular licensingIdentity hygiene scanning + PDF assessmentEnterprise integrations hub
  • Hybrid AD + Entra governance and operations in one product
  • Access reviews that preview and apply revocations
  • Enterprise integrations hub with per-domain configuration inheritance
  • Identity Analysis with security findings + executive PDF report
  • AWS IAM portal with same operating model as AD/Entra
  • Zero Trust identity governance overlay (signals → grant policy), not network ZTNA

12. What is NOT shipped yet (do not over-market)

GapStatus
End-user self-service password reset/unlock inside RivitanNot built; portal links to Microsoft SSPR
Rivitan AI assistantMarketed on website; platform AI code retired — treat as roadmap
Full SaaS connector catalog at production depthOnly AD, Entra, Okta, Secret Server are production
HR-driven JML (Workday/SuccessFactors auto-provision)Engine exists; HR connectors mostly catalog
Multi-tenant MSP SaaS (row-level tenancy)Single deployment per customer today
Rivitan-native MFA / step-up authUses Entra SSO + local bcrypt break-glass
External change detection (DC event log / directory audit correlation)Not built
Attack-path analysis (shadow admin, ACL abuse graphs)Partial via Identity Analysis, not full product
Time-bound membership auto-activation/expiryModels and scheduler exist; activation path needs hardening
24×7 enterprise support SLANot standard on pilot
Public multi-tenant SaaSProduct is customer-deployed software

13. Suggested messaging pillars

  • Close the loop — Access reviews that end in revoked access, not signed spreadsheets.
  • Hybrid Microsoft first — Built for AD + Entra estates, not cloud-only SaaS shops.
  • One console, many portals — Operators, owners, app requesters, auditors each get the right view.
  • Govern + operate — Not just governance; also day-2 identity, file, license, infra, and AWS work.
  • Your environment, your data — Customer-controlled deployment for regulated industries.
  • Prove it fast — 8–12 week pilot with one real review cycle and audit evidence.
  • Identity Zero Trust — Signal-driven grant policies on top of Entra CA/MFA/Intune.
  • Platform + people — Software plus advisory and custom tooling when the standard product is not enough.

14. Suggested go-to-market motions

MotionOfferProof point
Platform demo30-min walkthroughEntitlement review dry-run → apply on lab group
Paid pilot8–12 weeks, fixed scopeOne completed review + 2–3 day-2 capabilities
Identity assessmentFree quiz on website + optional paid scanIdentity Analysis PDF report
AdvisoryMigration / AD health / governance designDeliverable-based consulting
Custom buildBespoke portal or integrationExtends or stands beside platform

Channels to consider: LinkedIn (founder-led), Microsoft partner ecosystem, IAM/audit communities, SOC 2 / ITGC buyers, regional MSPs serving regulated mid-market.

15. Technology summary

  • Stack: Python 3.13, FastAPI, Uvicorn, SQLAlchemy, PostgreSQL, Jinja2 templates, vanilla JS/CSS
  • Directories: ldap3 (LDAPS), multi-domain, per-domain config inheritance
  • Cloud: msal + Microsoft Graph (multi-tenant Azure integrations)
  • Vaults: REST/SDK integrations to major secret managers
  • Background work: PostgreSQL-backed scheduler + optional python -m worker process
  • Testing: pytest unit tests + GitHub Actions CI (growing coverage)
  • Install: Unattended installer + Windows service option
  • API: REST throughout; API keys for integrations

16. Instruction block for marketing AI

You are helping Rivitan, an early-stage IAM/IGA startup, build positioning and marketing strategy. Rivitan sells (1) customer-deployed IAM platform software, (2) identity advisory consulting, and (3) custom IAM tooling. The primary wedge is hybrid Microsoft (AD + Entra) mid-market buyers who need access reviews that actually revoke access, governed self-service requests, and day-2 identity operations in one console — deployed in their own environment. Do not position Rivitan as a full SailPoint replacement or a network Zero Trust / ZTNA vendor. Do not claim Rivitan AI, end-user SSPR, or full HR-driven JML as shipped unless explicitly updated. Lead with time-to-value, audit evidence, and hybrid Microsoft depth. The website at rivitan.com is the public marketing layer; the platform is a large modular FastAPI application with 11 licensable modules and an enterprise Integrations hub. Preferred commercial entry is a paid 8–12 week pilot proving one access review cycle end-to-end.

Ready to position Rivitan?

Use this page as the source of truth for marketing AI, agency briefs, and investor conversations — then book a demo when you are ready to show the product.

Book a Call