Access control across banking, lending, insurance and market operations, with the record that proves it was working at the time.
Core banking and loan origination. Policy administration and claims. Order management, depository and settlement systems. The general ledger and the reconciliation tools underneath all of them. Whichever of those you run, the same three questions arrive from a supervisor after the fact: who could reach it, who approved that, and what did they do there.

An inspection names a period from a year or more ago. Akku's controls write their records as the access happens: every privileged session recorded, every credential generated and revoked with both timestamped, every access request with its justification and the approver's name, every certification with who signed it off. All of it in a ledger where each entry is hash-chained to the one before, and exports carry the hash columns, so a file handed to an inspector can be re-checked independently.

Branch, back-office and processing work runs to known hours from known locations, which makes contextual controls decisive rather than a compromise. Access permitted only inside working hours and only from your own IP ranges means a credential that works at a desk does not work from a hotel at midnight. Single sign-on across the applications one person opens in a day removes the shared passwords that grow around a busy counter or a claims desk.

Maker-checker in payments, underwriting separated from claims settlement, dealing separated from settlement: the separation exists in the application because the business could not run without it. What usually fails is the layer above, in who holds which entitlements across which systems. Akku's segregation of duties engine holds the combinations you have declared conflicting and blocks them where a role change or an administrative assignment would create one, including conflicts reached through nested roles.

Moving people between branches, desks and roles is itself a fraud control, which makes re-provisioning the normal case rather than the exception. Akku re-provisions on the move rather than adding to what someone already holds, and a mover whose new role would conflict with their existing access is stopped at that point.

Core platforms, the databases behind them, payment and settlement infrastructure. Access to those is held by a few named administrators, and a shared credential among them leaves no record of who did what. Every session runs through a proxy that generates the credential for that session and revokes it at close, records the screen, and logs every command and query.

Banks, NBFCs, cooperative banks, payment operators and fintechs answer to the RBI Master Direction on IT Governance. Market infrastructure institutions, rating agencies, AMCs, custodians and brokers answer to SEBI's CSCRF. Insurers, reinsurance branches and intermediaries answer to IRDAI. The DPDP Act applies to all of them, and customer financial data is exactly what it was written for. Akku is mapped at clause level to each: 26 of the 30 RBI cybersecurity clauses, 63 of 244 SEBI CSCRF guidelines, 133 of the 347 IRDAI checklist items.
