Today that answer comes from the vendor. Their logs, their attestation, their questionnaire, their word. Every link in the evidence chain starts with the party being assessed.
Enterprise is the same architecture as the five doors, with one thing added that only matters at organizational scale: a record of who reached what, held by you.
Design partners · early access · not GAYour production systems are defended in layers. Your vendor selection has risk assessment, NDAs, a security annex.
Between those two points sits the environment your vendors use to demo, preview and UAT the software they're building for you — running on infrastructure each vendor picks for themselves. A public preview URL. A self-hosted staging subdomain. A temporary tunnel.
You don't see it. You don't control it. There is no access log. And the build sitting there contains your business logic, your interfaces, your data structures.
Every public subdomain writes its TLS certificate permanently into Certificate Transparency logs — which attackers scan in real time, looking for exactly this: the environment nobody hardened.
Most organizations run all vendor access through one mechanism — usually VDI or VPN — because that's what exists. It's the right tool for one lane and expensive overkill for the other two.
| Lane | What's actually happening | Right tool |
|---|---|---|
| 1 · Demo & preview | You view a build running on the vendor's infrastructure. The vendor touches nothing of yours | Ankayma private names. Reversed direction — your attack surface is close to zero |
| 2 · Vendor reaches internal resources | The vendor needs a controlled path, not a network — test systems, masked test data | Ankayma mesh. Per-resource, per-identity, default-deny. Every connection carries a named certificate |
| 3 · Production, real data, privileged sessions | Data cannot leave the data centre. Control is needed at session level | VDI. We don't replace this |
We're explicit about lane 3 because the alternative — claiming to replace everything — is how vendors lose credibility with the people who actually run these systems.
Lane 1 and lane 2 are where the cost sits: per-seat licensing, provisioning and deprovisioning cycles, onboarding measured in weeks. Narrowing VDI to lane 3 is where the economics change.
A vendor's work no longer arrives only through people. Builds are pushed by CI runners. Tests run as scripts. A growing share of tasks is executed by AI agents inside the vendor's environment.
Most access tooling was designed when "who accessed this" meant a person.
Every actor gets the same kind of identity — human, device, CI run, agent. Scoped. Time-bound. Recorded. There is no shared service account nobody is accountable for.
Designed in full — built out piece by piece with design partners.
Reach for us when you're a regulated fintech in Southeast Asia or the Gulf that will not route your data — or your access graph — through a vendor's cloud or another jurisdiction; and you need isolation you can prove to a regulator, not just a policy checkbox.
Reach for someone else when incumbent cloud tooling already satisfies your obligations; when you're a top-tier bank or national telco (we're early, on purpose); or when you operate primarily in the US, EU, China, or Russia — other vendors serve those markets well, and honestly, better, today.
This is a structural position, not a political one: the point is simply that a vendor can't reach what never crosses its path. We keep it at that level.
We have not yet mapped Ankayma's controls to POJK 38/2016, NCA ECC-1:2018, UAE CB guidelines, SOC2, or ISO 27001. That mapping — per regulator, per jurisdiction — is exactly the work we do with design partners. Please don't cite Ankayma as satisfying any framework without your own legal review. We'd rather tell you that here than in a procurement questionnaire.