FAQs
Questions tend to repeat. Luckily, so do the answers.
Search and filter by capability, industry, use case, or just type what's keeping you up at night.
CyberElements gives you the choice of using our platform as a fully managed SaaS service, manage it yourself or mix both models by module. For example, you can run ZTNA as a service while managing IGA internally. A lightweight Edge Gateway can optionally be deployed inside your environment to connect internal systems to the platform without exposing your network.
The Edge Gateway acts as a filter that sits inside your environment and securely connects local applications to CyberElements. It enables access to internal systems without opening inbound ports and without exposing infrastructure to the internet, so your network stays out of view from outside.
Access is enforced at the access level. Every request is verified, resource and time-bound and identity is continuously validated against behaviour, device posture and context rather than network location.
Yes. CyberElements applies the same Zero Trust access controls across AI, IT and OT environments, including industrial and on-premise infrastructure. The line keeps moving, the segmentation stays clean, and the auditor reads one trail.
Regular user sessions are assessed through device posture, context, behaviour and activity. Lens, our AI session analysis engine, reads each privileged session as it happens, with the ability to isolate, record or revoke the session instantly if conditions change or risks are detected.
All access activity is logged automatically. CyberElements creates a continuous, unified audit trail showing who accessed what, when and why, with NIS2, DORA, EHDS, GDPR and ISO 27001 evidence produced as the platform works.
Yes. CyberElements integrates with your existing infrastructure, identity providers, HR systems and applications, so you can layer enforcement on top of your current stack rather than replacing it.
Yes. Each capability (ZTNA, PAM, IGA, authentication and AI agent control) can be activated independently while still operating under the same Zero Trust access model and audit trail. Start with the part of the platform that solves your noisiest problem and expand as needed.
Five capabilities run under one Zero Trust access model, Zero Trust Network Access, Privileged Access Management, Identity & Governance Administration, Authentication & SSO and Securing AI (covering agentic AI and MCP control). Every capability shares the same console, the same rulebook and the same audit trail.
No. CyberElements is activated capability by capability. Start with the part of the platform that solves your noisiest problem today, often ZTNA or PAM, and add the rest when the audit, the team or the regulator asks for it.
Each capability sits on the same Zero Trust access identity model, so the policy that governs an employee’s remote access also governs their privileged session, their lifecycle changes and their AI agent’s API call. One Zero Trust access model, one set of conditions, one log across the lot.
In most cases, yes. CyberElements replaces VPN concentrators, standalone PAM appliances and the patchwork of MFA, SSO and identity governance products that have grown up over time. Where you keep a tool, the platform integrates with it rather than fighting it.
The platform is live from the browser in minutes. Connecting your first applications and defining policies takes around fifteen minutes per capability, and your team is governing real workloads by the end of the working day.
Yes. Grant time-bound, application-level access to vendors, contractors and managed service providers from any device, on any network. Revocation is one click, and every action is tied to one named identity for the audit.
Every access action is recorded, time-stamped and tied to a single identity. CyberElements produces NIS2, DORA, EHDS and ISO 27001 evidence continuously as your team works, so the audit week starts calm and the auditor finds the trail already on the table.
Zero Trust Network Access (ZTNA) grants access to specific applications based on identity, context and policy, instead of opening a tunnel to the network. With CyberElements, ZTNA runs through a site-hosted gateway, with no inbound ports, no exposed endpoints and no implicit trust attached to a device, location or login.
Zero Trust is the principle: never trust, always verify. ZTNA is one of the products that puts the principle into practice for remote access. CyberElements applies Zero Trust across ZTNA, PAM, IGA, authentication and AI agent control, with one Zero Trust access model running underneath.
Yes. CyberElements ZTNA removes the always-on tunnel, the open inbound port and the lateral movement risk that come with traditional VPN access. Each connection lives at the application, the network stays out of view, and behaviour is read in real time as the session continues.
Yes, it is possible. Access can run in the browser, so users can connect without VPN clients, agents or local installation. The platform recognises the user, the device and the context, and decides each session on the spot.
The platform is live from the browser in minutes. Connecting your first applications and defining policies takes around fifteen minutes, and your team is governing real workloads by the end of lunch time.
Every access action is logged, time-stamped and tied to a single identity. Lens uses AI to read privileged sessions live for behavioural anomalies, and the platform produces audit-ready evidence continuously, instead of asking your team to reconstruct it after the fact.
Yes. CyberElements grants time-bound, application-level access to employees, contractors and managed service providers from any device, on any network. Revocation is one click, and every action is tied to a single named identity for the audit.
Privileged Access Management (PAM) controls how privileged users, administrators, engineers, third parties, access most critical systems that keep your organisation running. CyberElements PAM brokers every session, vaults every credential and ties every action to one named identity.
Traditional PAM tools depend on jump servers, on-premise appliances and a long deployment project. CyberElements PAM activates from the browser, runs as SaaS, records web applications without a jump server and ties straight into the rest of the platform.
Yes. Every privileged session is recorded with full video, command history and metadata, tied to one named identity and searchable. Lens watches each session and can pause or alert on sensitive actions.
Yes. CyberElements PAM applies the same controlled access model to operational technology, with partitioned access between IT and OT and one audit trail across both.
Yes. CyberElements enforces AD tiering natively, with Kerberos-based access to the Privileged Access Workstation and no inbound RDP traffic. The three tiers stay separated on the same console.
Yes. Vendors, contractors and managed service providers connect through CyberElements with time-bound, application-level access. Multi-tenant by design, with one console for the MSP and one audit trail per client.
IGA controls the lifecycle of digital identities: who has access to what, why they have it, and when it should be active and expire. CyberElements IGA automates joiner, mover and leaver workflows, enforces segregation of duties, and runs recertification campaigns on your schedule.
Every access grant, role change and recertification decision is recorded and tied to one identity. CyberElements produces NIS2, GDPR, DORA and ISO 27001 evidence continuously as your team works. The auditor asks a question. The platform already has the answer.
No. CyberElements IGA synchronises with your existing source of truth. The platform ingests identities from HR and third-party databases, then provisions accounts and rights to target systems, starting with AD. Your current infrastructure stays intact.
Yes. Bulk onboarding workflows let you provision hundreds of workers in a single operation. When the season ends, access is revoked automatically. The contractor’s account expires with their contract.
IGA tells you who should have access. Zero Trust checks whether that access is safe right now. CyberElements combines both, so a legitimate credential from a compromised device is not legitimate access.
Yes. CyberElements applies the same identity governance model to operational technology. OT engineers reach the ICS through the same policies as the IT team, with one audit trail across both.
If your role model is ready, CyberElements is live from the browser in minutes. Connecting your HR system and configuring entitlement rules takes around a day. With prepared data, your team can start governing real identities within the working week.
Yes. Each capability can be activated independently while still operating under the same access model and audit trail. Start with IGA and add ZTNA, PAM or Securing the AI when the auditor asks.
Model Context Protocol (MCP) is the standard that allows AI agents to leverage and interact with enterprise resources: databases, file systems, APIs and business applications. Without a governance layer, these connections are direct, unmonitored and governed only by the agents. CyberElements inserts a mediation architecture at every MCP connection point, so every interaction is authorised, logged and traceable before it reaches your systems.
A privileged human user exercises judgement, works at human speed and can be challenged in the moment. An AI agent executes instructions at machine speed, across more systems than any person could handle manually. The governance approach has to match the risk profile. CyberElements applies the same Zero Trust controls to AI agents that it applies to privileged human administrators: contained sessions, continuous device assessment and policy-based pause or block when the device is unsafe for the authorised agentic activity.
Shadow AI refers to AI agents and automations deployed by employees without IT or security team oversight, typically using copilots, workflow platforms and no-code tools. CyberElements governs access at the connector level, so only registered and authorised agents can reach approved systems, data and applications. Your IT team gains visibility over agents it did not know existed.
No agent re-deployment is required. CyberElements inserts the mediation layer between your existing agents and your existing resources. The agents continue operating as designed. The difference is that every interaction now passes through a governed layer before it reaches your systems.
The platform is live from the browser in minutes. Connecting your environment, registering connectors and defining access policies takes around fifteen to twenty minutes. Your agents operate under governance from the first governed session.
Single Sign-On (SSO) authenticates a user once and grants access to every authorised application without requiring them to log in again. CyberElements extends this across web applications, desktop applications and Windows workstation login through a centralised vault and enterprise SSO layer.
A password vault enables CyberElements SSO. The user authenticates once to the vault, which then authenticates them to each application in one of two ways. It can inject the credentials associated with the user’s account, or issue a token to a federated web application. The vault handles each subsequent login in the background.
Yes. For federated web applications, CyberElements issues an authentication token. For applications that do not support federation, including fat Windows clients and many legacy on-premises systems, it injects the appropriate credentials from the vault. Users get one sign-in across cloud, web, desktop and legacy applications, using the authentication method each application supports.
AI-powered Pulse authenticates through the user’s behavioural biometric pattern, specifically their typing rhythm. No smartphone, no hardware token and no extra device is required. The keyboard already in front of the user becomes the authentication factor. This makes AI-powered Pulse suitable for sterile environments, production floors and any setting where conventional MFA is impractical.
Yes. Self-service covers password resets, workstation access recovery, authentication card unlocking and factor re-registration. Each self-resolved request is one the helpdesk doesn’t handle.
Every authentication event, application access and administrator action is recorded continuously and tied to a named identity. The platform produces audit-ready reporting covering who accessed what, from which workstation, through which application and when. NIS2, EHDS and ISO 27001 evidence are available before the audit begins.
The platform is live from the browser without infrastructure changes. Connecting your first applications and configuring policies takes a working day. Users can authenticate through the platform by the end of the same session.
A VPN connects the contractor to your network, not to the task. Once connected, they often reach far more than the job requires. There is no automatic expiry, no action-level logging and no way to verify what they did after the fact. CyberElements grants access to a specific resource, for a defined duration, with a full session record.
No. Contractors can connect through the browser with no local installation. CyberElements breaks the protocol connection between their device and the protected system, allowing only screen output and keyboard or mouse inputs to pass through. Deeper device-posture checks are available when the CyberElements client is installed.
The connection closes automatically at the end of the defined access window. There are no standing permissions to revoke, no AD entries to clean up and no credentials to rotate. The access expires with the job.
Pulse provides biometric MFA through typing behaviour, so no token, smartphone or extra hardware is required. The contractor only needs an internet connection to access the cloud-based service.
Lens monitors privileged sessions in real time. Suspicious behaviour triggers an automated response while the session is still open, rather than a post-incident review three weeks later.
Yes. CyberElements provides the traceability, least-privilege enforcement and audit trail that both frameworks require for third-party access. Evidence is produced continuously, not reconstructed at audit time.
The platform is live from the browser in minutes. Contractors can be onboarded and operating under defined access conditions within a few hours.
A non-human identity is the digital identity a software programme uses to authenticate and interact with another software programme. It may belong to an AI agent, copilot, automation workflow or MCP connector. Like human identities, NHIs can carry access rights and the software programme which uses them can take actions on systems and data. Unlike human identities, they move at machine speed and are rarely governed by existing IAM tools. CyberElements tracks which agent requests which other agent, to do what, and on behalf of which human user the non-human identity is acting.
No. CyberElements governs AI agents. It does not prohibit them. Approved agents are whitelisted and operate within a defined scope. Unapproved agents are made inaccessible, so they cannot connect to production systems. The outcome is governed AI capability, not a blanket restriction.
Every non-human identity is registered with a named authorising user. When the agent queries a database, accesses a file share or triggers a workflow, the action is attributed to that identity in the audit log. The chain of responsibility from the original instruction to the downstream action is maintained throughout.
Shadow AI refers to copilots, automation tools and AI connectors deployed by employees or third parties without IT or security awareness. CyberElements addresses it at the identity layer. Agents that are not registered and whitelisted cannot be accessed or operated on governed systems.
CyberElements probes are calibrated separately for human and agentic activity. Legitimate AI agent hyperactivity, such as high-volume and high-speed action, does not trip the system by default. Genuine deviations from the agent’s authorised behaviour pattern, such as unexpected data access, exfiltration patterns or anomalous action chaining, can trigger a targeted alert or automated block.
Yes. CyberElements assigns each AI agent an authorised operating zone covering the systems, datasets and MCP connectors it may reach. Any connection outside that scope is blocked at platform level, regardless of which non-human identity is used to access the agent.
Every action taken by a registered AI agent is logged, timestamped and attributed to the authorising human identity. The log covers which agent was called, details of the request and which data was accessed, which systems were touched, which workflows were triggered and in what sequence. The full record is available for regulatory reporting and internal governance without reconstruction after the fact.
CyberElements is live from the browser without infrastructure changes. Defining whitelists and configuring access scopes follows the same process as onboarding human users. Security teams can have governed AI agents operating under defined conditions within a working day.
No. The Edge Gateway joins your network from the inside via an outbound-only encrypted connection. No inbound ports are opened and no changes to your existing OT architecture are required. Engineering stations, HMI and ICS systems stay invisible from the internet before, during and after each session.
Yes. With the CyberElements client, device posture checks can assess antivirus status, OS version and patch level before access. For browser-based clientless access, a protocol break isolates the contractor’s device from the target system, while device posture checks remain more limited.
Pulse provides MFA through the user’s typing behaviour, so warehouses, clean rooms and production sites can authenticate users through the keyboard already in place. An internet connection is required because the typing data is processed in the CyberElements cloud.
Multi-tenant, multi-gateway architecture manages IT regulated, IT non-regulated, OT regulated and OT non-regulated segments from the same console. Each segment operates under its own access policies. One platform covers the full NIS2 tiering requirement.
Yes. The platform supports concurrent access by multiple named users to the same resource, each in their own isolated session with their own audit trail.
Every privileged session is recorded in full and tied to a named identity. Lens monitors sessions in real time and can pause a session automatically when suspicious behaviour is detected, so the recording serves as a preventive tool as well as a compliance artefact.
ZTNA controls how external parties and remote workers reach OT systems, keeping the infrastructure invisible and granting task-specific, time-bound access. PAM controls and monitors what privileged users — internal or external — do once they are inside, with real-time session analysis via Lens. CyberElements combines both under the same Zero Trust access model.
The platform is live in a few minutes from the browser without infrastructure changes. First connections and access policies can be configured in a working day. Production environments with complex segmentation typically complete full deployment within a few weeks, depending on the number of assets and providers involved.
CyberElements supports both clientless and clientfull access. Unmanaged devices, including BYOD and contractor devices, can connect through the browser. Managed devices use the CyberElements client, whether they are inside or outside the corporate network.
CyberElements gives personal and unmanaged devices clientless, browser-based access. A protocol break separates the device from the target application, so users reach the resource while the underlying system stays isolated. Managed devices can use the client for fuller device-posture checks.
Pulse delivers MFA through typing behaviour, using the keyboard already in front of the user. This supports correctional facilities, warehouses, production floors and other environments where smartphones, hardware tokens or push prompts create problems.
Yes. Remote Browser Isolation and Virtual Desktop Infrastructure make legacy and homegrown applications reachable through isolated environments. Users connect from the browser while the application remains protected from direct device exposure.
Security teams can tune access policies with up to 20 configuration options, including update requirements, permitted IP ranges, allowed access windows and other conditions linked to the user, device, context and resource.
ZTNA is the underlying architecture. Secure remote access is the use case it delivers for organisations replacing VPN-based access across employees, contractors, field workers, IT systems and OT environments.
Yes. CyberElements combines ZTNA and PAM under the same access model and administration console. Users who need both remote access and privileged session governance can be managed through one platform, with one audit trail.
The platform is live from the browser without infrastructure changes. First users can connect under defined access policies within a working day. Large deployments covering multiple user profiles, environments and access types are typically complete within a few weeks.
CyberElements supports the access control, privileged account governance and audit evidence requirements found across NIS2, DORA, ISO 27001/27002, HIPAA, EU-GDPR, NIST 800-53 Rev.5, ISA/IEC 62443, TISAX and SOC 2. MFA, PAM, session recording, just-in-time access and continuous audit logging are part of the platform’s standard operating model.
Yes. Every access event, privileged session, authentication action and administrative change is logged continuously and tied to a named identity. When the auditor asks for evidence, the record is already there, rather than rebuilt from scattered logs after the fact.
CyberElements lets teams manage as many Active Directory segments as the environment requires from one multi-tenant console. Administrators can govern regulated tiers, non-regulated tiers, IT segments and OT segments from one interface, with one Zero Trust access model and one audit trail.
Cyber-insurers often look for documented access controls, including PAM, MFA and audit trails. CyberElements produces evidence of those controls continuously, giving teams clearer documentation for cyber-insurance discussions.
The brief notes that NIS2 recommends avoiding VPNs for remote workforce access. CyberElements ZTNA supports that direction by replacing broad VPN access with named-user traceability, device posture assessment and governed session controls.
CyberElements can sit above existing identity systems as a governance layer. That helps healthcare teams meet national framework requirements, such as EHDS, without replacing every underlying directory first. Pulse can also support MFA in clinical environments where a second device is impractical.
Yes. CyberElements helps MSPs control and trace access to each client environment, producing evidence that supports ISO 27001 requirements. Virtual Desktops also let operators work across multiple customers from the same machine, without switching devices or mixing client environments.
CyberElements supports segmented IT and OT access from one console, across multiple sites, providers and user profiles. Its multi-tenant, multi-gateway architecture helps teams govern identity controls and produce a unified audit trail for industrial frameworks such as ISA/IEC 62443 and NIST 800-82.
Yes. External access is time-bound, fully visible, and every session can be tracked and reviewed.
No. CyberElements sits on top of your existing setup, so operations continue without interruption.
Access is secured around those systems without changing or replacing them, making the platform suitable for older infrastructure.
The platform lets you prove who accessed what, when and why, helping you meet audit and traceability requirements.
Access is controlled centrally, so users can securely connect across sites without creating separate entry points.
Yes. Access is managed consistently across both, giving you visibility without merging or replacing systems.
CyberElements supports SaaS and client-hosted deployment, so critical infrastructure teams can set it up quickly around their security, operational and sovereignty requirements.
Yes. CyberElements gives your team one multi-tenant console to manage multiple client environments. Each client keeps its own access records, policies and audit trails, while your team gets one place to work.
CyberElements enforces one connection method across every client, regardless of what they were using before. The transition is handled at onboarding. Every session from that point runs through the same platform.
The platform generates ISO 27001, NIS2 and DORA evidence automatically as the team works. Compliance is a byproduct of normal operation, not a separate process that needs resourcing.
Yes. CyberElements governs what AI agents can access across every client environment in the portfolio from one interface, with a full audit trail per client.
CyberElements is SaaS-based and can be activated quickly without rebuilding the client’s infrastructure. A new client environment can be added to the platform and governed through the same repeatable service model.
Yes. The multi-tenant architecture is built for portfolio growth. Adding a client adds an environment to the console, not a new tooling stack to procure, configure and maintain.
Yes. CyberElements can govern access across IT and OT environments, including distributed sites, maintenance sessions and legacy systems. That matters when one client has cloud apps and another has operational infrastructure that still does important work in a corner.
Yes. CyberElements can recognise that separate digital identities belong to the same healthcare professional while keeping the underlying accounts distinct. Each hospital can assign its own role, rights and access rules, all managed through one central view.
CyberElements secures access around legacy systems without changing or replacing them. Pulse extends SSO and MFA to environments that predate modern authentication standards.
Yes. External access is time-bound, application-level and fully recorded. Every session is tied to a named identity and available for review.
CyberElements controls who can access patient records, medical images and clinical systems, under which conditions and for how long. Its IGA capability turns patient-expressed restrictions and opt-outs into live access rules. Every consultation is tied to a named identity and logged, so healthcare organisations can show patients who accessed their record and when.
CyberElements supports EHDS compliance by design. Authentication and SSO give each healthcare employee a unique identity while fast re-authentication keeps shared workstations practical. PAM brokers and monitors vendor or biomedical access to EHR systems and connected devices. ZTNA, browser isolation and VDI can prevent downloads, copying and printing from protected environments, while the MCP proxy limits what AI agents can read or export. Every access, session and action is logged for audit. These controls support the EHDS requirements for identifiable access, secure processing and controlled data use.
Access rights update automatically when a role or employment status changes. During a crisis, a single context switch can deprovision and reprovision rights instantly across connected systems, giving each person the access required for the situation while recording every change in the audit trail.
No. CyberElements sits on top of existing infrastructure. Clinical and administrative workflows continue without interruption during and after deployment.
CyberElements can be deployed in the cloud or within the organisation’s own environment. Teams can begin with one hospital, site or use case, then extend the same controls across the group while respecting each site’s infrastructure and deployment requirements.
Yes. Multi-tenant PAM lets a single administrator manage separate organisational entities and network segments from one interface, while keeping their systems, access policies and audit trails properly isolated.
VDI and RBI give users secure, isolated access to those systems without changing or exposing the underlying infrastructure. The systems stay where they are. The risk does not.
Yes. Access is granted for the duration of the work and closed automatically when it ends. Every session is recorded and tied to a named identity from the first connection.
CyberElements controls what AI tools can access on government infrastructure and restricts AI connections to a governed channel. Citizen and classified data cannot reach public AI training pipelines.
No. CyberElements sits on top of existing infrastructure. Public services continue without interruption during and after deployment.
Yes. CyberElements sits on top of existing infrastructure. OT systems and production operations continue without interruption during and after deployment.
Access is secured around those systems without changing or replacing them. The equipment stays where it is. Unmonitored remote access to it does not remain an option.
Yes. CyberElements enforces a single, centralised connection point for every external session, regardless of the vendor's preferred method. Every action is recorded and tied to a named identity.
The platform produces a full audit trail as the team works — who accessed what system, when, and what they did. Compliance reviews work from existing records rather than manual reconstruction.
PAM reduces the attack surface that penetration tests expose and insurers price. Several CyberElements clients have seen measurable reductions in insurance premiums after deployment.
CyberElements controls what AI agents can access on your infrastructure and restricts connections to a governed channel. Proprietary production and operational data cannot reach public AI training pipelines.
The platform generates a full audit trail across every access event as the team works. You can demonstrate who accessed what, when and why – on demand, without reconstruction.
Yes. Every third party connects through time-bound, application-level sessions tied to a named identity. Access is revoked automatically when the engagement ends, without a manual step.
CyberElements gives users secure access to legacy systems such as AS400 while leaving the underlying technology in place. Users authenticate through CyberElements, which then brokers the connection and injects the credentials required by the system.
Yes. CyberElements enforces which actions an AI agent can take for each user. It records what the agent was asked to do, which systems it accessed and the named user behind the original request.
No. CyberElements sits on top of existing infrastructure. Banking, insurance and payment operations continue without interruption during and after deployment.
PAM reduces the attack surface that penetration tests expose and insurers price. Several CyberElements clients in financial services have seen measurable reductions in premiums after deployment.
CyberElements can be deployed as a SaaS solution or on-premises. Teams can start with a production-ready instance in minutes, then connect their environment without a lengthy implementation programme.
CyberElements is headquartered at 21 rue de Dornach, 68120 Pfastatt, France, with the team distributed across Europe. Visitors are only attended to by appointment.
Kindly pick “Sales” in the form above and your message will reach the relevant sales team. We recommend that you include the number of users and the systems you need to cover so that our reply will be more relevant.
Please connect to your customer area to request support from the service desk.
We are a European team answering in European hours. You can expect an answer generally the very same day or within a maximum of 2 working days.
The platform unifies human and non-human identities into a single model. Access, privileges and policies are defined and enforced consistently across all users and systems.
