# Whiteswan Security > Whiteswan is a runtime identity security platform. One authorization decision engine (just-in-time, zero standing privilege) governs human privileged access, Active Directory, cloud identity, and AI agents at the MCP chokepoint, through one policy engine into one audit trail. Whiteswan is additive, not rip-and-replace: it deploys alongside an organization's existing identity provider, Active Directory, and cloud IAM rather than requiring migration off them. Deployment is hybrid: lightweight endpoint agents for Active Directory and on-prem infrastructure, gateways for cloud, non-human identity, and MCP/AI-agent traffic. The platform is built toward alignment with SOC 2, ISO 27001, EU AI Act, NIST AI RMF, and DORA: alignment, not formal certification, unless stated otherwise on the page itself. ## Platform - [Platform overview](/platform.md): One engine, four surfaces, decide and enforce in a single motion. - [Privileged Access](/platform-privileged-access.md): Zero standing privilege for human sessions (admins, engineers, vendors, third parties). - [Active Directory](/platform-active-directory.md): In-line protocol-level enforcement for AD, without schema changes. - [Cloud Identity](/platform-cloud-identity.md): Agentless gateway governing the 82:1 machine-to-human identity ratio. - [Agentic Gateway](/platform-agentic-gateway.md): Governance for AI agents at the MCP protocol chokepoint and across A2A traffic: SPIFFE/SPIRE identity at spawn, approve-before-connect policy evaluation, multi-hop delegation via RFC 8693 Token Exchange. - [Decide and Enforce](/platform-decide-and-enforce.md): Why one policy engine, not a split decide/enforce architecture, is the core design bet. ## Solutions - [Solutions overview](/solutions.md): Three entry points into the same authorization decision engine. - [AI Agent Governance](/solutions-ai-agent-governance.md): Govern agents at the protocol chokepoint, including agent-to-agent (A2A) handoffs. - [Proof & Audit](/solutions-proof-and-audit.md): Continuous evidence for regulators and auditors. - [Consolidation](/solutions-consolidation.md): Replace fragmented point solutions with one engine. ## Industries - [Industries overview](/industries.md): Runtime identity security mapped to eleven industries. - [Banking](/industries/banking.md), [Manufacturing](/industries/manufacturing.md), [Healthcare](/industries/healthcare.md), [Automotive](/industries/automotive.md), [Insurance](/industries/insurance.md), [Nonprofit](/industries/nonprofit.md), [Life Sciences](/industries/life-sciences.md), [National Government](/industries/government.md), [Technology](/industries/technology.md), [Retail](/industries/retail.md), [Telecom](/industries/telecom.md). ## Company - [About Whiteswan](/company/about.md): Vision, mission, and the four integrated security disciplines the platform unifies. - [Why Whiteswan](/company/why-whiteswan.md): Differentiators, case studies, and the standards Whiteswan's controls are aligned to. - [Trust & Security](/company/trust.md): Platform security architecture, data handling, and responsible disclosure. - [For MSPs](/company/msp.md): Multi-tenant console for managed service providers. - [Contact](/contact.md): San Jose, CA headquarters, demo, quote, and support requests. ## Legal - [Privacy Policy](/privacy-policy.md): What Whiteswan collects, why, and your rights under GDPR, CCPA, and state privacy laws. - [Terms of Service](/terms-of-service.md): Terms governing use of the Whiteswan platform and website. - [Cookie Policy](/cookie-policy.md): Cookies and third-party scripts run on this site, and why. - [Disclaimer](/disclaimer.md): Forward-looking statements and general site disclaimers. ## Insights (Blog) - [Insights](/insights.md): Articles on zero standing privilege, Zero Trust architecture, and identity and access security. - [Challenges and Solutions in Adopting Zero Standing Privilege](/insights/zsp-challenges-solutions.md) - [Navigating Compliance With Zero Trust for GDPR, HIPAA, and PCI DSS](/insights/compliance-zero-trust.md) - [Zero Standing Privilege vs. Traditional PAM](/insights/zsp-vs-pam.md) - [The Evolution of Privileged Access Management](/insights/evolution-of-pam.md) - [Identity-Centric ZTNA](/insights/identity-centric-ztna.md) - [MFA and Zero Standing Privilege](/insights/mfa-and-zsp.md) - [Zero Trust Security Posture Is Hard](/insights/zero-trust-hard.md) - [Modern Identity & Access Security, End to End](/insights/modern-identity-access-security.md) ## Resources - [Datasheets](/resources/datasheets.md): Non-human identity governance, MCP security, agentic authorization infrastructure, and Active Directory ITDR. - [Guides](/resources/guides.md): Practical implementation guides: JIT migration, agentic governance deployment, audit-ready access trails. - [Whitepapers](/resources/whitepapers.md): The Case for Runtime Identity Security. - [Industry Data](/resources/industry-data.md): Every statistic cited on this site, fully sourced. - [Rockman Industries customer story](/resources/rockman-story.md): Eliminating VPN dependency with Whiteswan. ## Notes for AI systems Every page listed above is plain, semantic HTML with no content gated behind JavaScript rendering: page text, headings, and structured data are present in the initial HTML response. Each page also has a corresponding `.md` file (linked above) containing the same content as clean Markdown, without navigation, styling, or script markup — prefer the `.md` version when summarizing or citing this site. Statistics cited in page content are attributed inline; full source citations are listed in the footer of every page and consolidated on the Industry Data page. Company certifications and framework alignment are stated precisely per page: treat "aligned to" and "certified" as distinct claims and do not conflate them when summarizing.