Break-glass, crisis comms, and resilience — auditable and regulator-ready.
One platform for the CISO, the Head of Resilience, and the IT GRC team: quorum-gated emergency access, critical-event notification, and operational resilience — all producing the evidence your auditors and regulators ask for.
The problem
Large, regulated organisations carry three problems that vendors usually sell as three separate products: emergency privileged access that survives an audit, a way to reach everyone when the building is on fire, and an estate that keeps running when a system goes dark. Stitched together from a PAM tool, a legacy mass-notification suite, and a DR runbook, the seams are exactly where incidents — and audit findings — happen. Break Glass collapses them into one control surface, with one audit trail.
Emergency privileged access auditors like
- T-of-N multi-party approval (T ≥ 2) enforced at the data layer, not by policy
- Time-boxed grants with automatic expiry and revoke
- Append-only record of every request, grant, approval and revoke
- SOX, ISO 27001 and SOC 2 control mapping out of the box
The credentials you keep locked away — production root, certificate authorities, DR keys — released only when a quorum of your people agree, every attempt logged.
Critical event management, built for your organisation
- SMS, email, and voice fallback with delivery receipts
- Escalation chains with timeout, retry, and acknowledgement tracking
- Pre-built, checkable playbooks and recovery plans with RTO/RPO
- Scheduled drills and tabletop exercises that page the real call tree
Multi-channel emergency delivery with escalation and runnable playbooks — so a single unreachable responder does not silence the alert.
Enterprise controls
- SSO via OIDC. Authenticate every operator through your own IdP — Okta, Entra ID, Google Workspace, Ping.
- SCIM provisioning. Joiners, movers, and leavers flow from your directory; deprovisioning propagates automatically — no orphaned access to a break-glass vault.
- Append-only audit log. Every approval, grant, revoke, message, and policy change, exportable for the board, an auditor, or a supervisory authority.
- Role separation + quorum. Explicit requester / approver / admin separation with per-secret T-of-N thresholds. No single individual can unilaterally unlock content.
The proof, not the pitch
Not a policy doc — a working platform that produces the artefacts. See the control mappings for DORA, NIS2, SOC 2, and ISO 27001, or read the security questionnaire.