Security for Enterprise CISO

Management-plane evidence for privileged automation-SSO/MFA, dual-plane logging, and Sentinel forwarding without replacing your SIEM.

Govern privileged automation with signing, separation of duties, and exportable audit-beside your RMM, verifiable in a trial tenant.

Enterprise security teams need management-plane audit separate from RMM operational noise. Trustholm records publish, approve, policy change, and execution events in a dedicated security audit plane-exportable via API or forwarded to Microsoft Sentinel through Event Hub/DCR sinks.

Identity: OIDC/SAML SSO, MFA, RBAC, and JWT tenant binding (403 on mismatch). Module feature gates reduce attack surface when packaged modules are disabled.

SIEM handoff: ASIM-mapped JSON to Event Hub is shipped. Splunk/Datadog native templates remain backlog-plan interim JSON/CSV pipelines and document in your SSP.

Vendor diligence: SOC 2 Type II observation in progress-not certified. Use Shipped/Gap tables and trial reproduction for your third-party risk register.

This page describes product capabilities for your control matrix. Trustholm does not hold SOC 2, ISO 27001, IRAP, Essential Eight, CMMC, Cyber Essentials, NIS2, or framework certification badges.

Key capabilities

  • Dual-plane logging: security audit vs HTTP request logs
  • Event Hub/DCR audit sink with DCR template download
  • SSO/MFA/RBAC with Security Center posture summary
  • Rate limiting and heavy endpoint concurrency caps
  • Honest gaps: WORM immutability, vendor SOC 2 Type II
TopicEvidenceStatusNotes
Security Center postureMFA, SSO mode, audit logging, script signing flagsShipped-
Script signingPowerShell code signing policy enforcementShipped-
Microsoft Sentinel / Event Hub audit sinkazure_eventhub / azure_dcr sink; DCR template download; per-customer routingShippedSplunk/Datadog native sinks and in-product detection rules remain backlog
Audit export sinks (webhook)HMAC webhook sink via GET/POST /api/tenant/audit-sinksShipped-

Related

Frequently asked questions

Does Trustholm replace our SIEM?

No. We are authoritative for management-plane privileged actions. Forward audit events to Sentinel via shipped sinks; detection rules remain in your SIEM.

How does this map to SOC 2 CC6/CC7?

CC6: IAM evidence, admin action audit. CC7: audit export, rate limits-pair with your infrastructure monitoring. We do not supply a vendor SOC 2 report.