The deployment question comes before the product question

Access security for government bodies and non-profits, including networks with no route out.

A department running citizen data on an isolated network cannot buy a cloud service, whatever its features. A public undertaking with sovereignty requirements cannot have data leaving the country. A procurement process that runs through GeM cannot accommodate a vendor who is not listed. Those three things decide whether a conversation happens at all, and Akku answers all three before anything else is discussed.

Isolated networks, without an inbound firewall rule

Where a network has no route out, Akku deploys entirely inside your own infrastructure rather than as a cloud service reaching in. Where it has a route out but no inbound access, a lightweight worker sits inside the segment and dials out over HTTPS on 443, so there is no inbound rule for a security team to approve. Adding another isolated segment means another worker rather than another deployment of the platform. Air-gapped deployment is available, and sovereign deployment inside India means data does not leave the country.

Class-I Local Supplier, and listed on GeM

Akku is a Class-I Local Supplier under the Public Procurement (Preference to Make in India) Order, backed by a CA-issued declaration, and holds DPIIT Startup India recognition. It is listed on GeM, so the procurement route exists rather than needing to be created. Akku is certified to ISO 27001 and SOC 2 Type II.

Citizen data is personal data

The DPDP Act governs what a department or an agency holds about the people it serves, with consent as the authorisation and rights the data principal can exercise. Akku captures consent per purpose against a versioned notice, honours withdrawal in one action, and records correction and erasure with what changed and when it completed. Where the data subjects are children, consent has to be verifiable parental consent and no advertising identifier may be issued.

No security team, and nothing to hand over to one

Deployment does not need a systems integrator or a dedicated identity engineer, and running it afterwards does not either. Over 500 pre-built connectors cover the applications you already run, and credential replay reaches the older ones that never supported a modern protocol, which in this sector is most of the estate. Policies are set once and assigned by department or office rather than configured per machine.

Contractors, vendors and everyone else with a pass

Implementation partners, maintenance vendors and seconded staff need into systems you run, often for a defined project. Access comes from a role with a window that expires on its own. Where they need a server or a database directly, the session runs through a proxy that generates the credential for that session and revokes it at close, records the screen and logs every command.

Shared machines in offices with nobody technical nearby

Counters, records rooms and field offices run machines used by whoever is on duty. The access decision happens at sign-in, and single sign-on with a passwordless factor makes that workable. The machines stay under policy: hardening baselines by group, patching in staged rings, and software allowlisting so what runs is what you approved. None of it needs a visit.

For a non-profit, the constraint is the budget

An NGO or a charitable trust holds donor records, beneficiary data and financial information, under the same DPDP Act, with none of the budget and usually no security team at all. Volunteers hold access and turn over constantly without being on payroll, which makes provisioning from role and deprovisioning in one action the difference between a controlled estate and an uncontrolled one. Pricing is per user and tiered, so the cost matches the size of the organisation rather than the size of the sector it sits in.

The record exists whether or not anyone asks

Every access decision is recorded as it happens, with the user, the application, the time, the location and the factor used, in logs that are tamper-evident. An audit, an RTI request or an investigation asks about a period that has already closed, and the answer depends on what was being recorded while it was happening.

See how it works.