Named-user platform audit log
Percepxion records management actions against the named user, and the event log is fully queryable through the REST API for retention in your own system.

Solutions
When an auditor asks who reached a device and when, the answer should be a query, not a week of log archaeology. Percepxion's named-user audit log and the SLC 9000's locked-down appliance give compliance teams that answer.
Capabilities
Percepxion records management actions against the named user, and the event log is fully queryable through the REST API for retention in your own system.
Percepxion supports SAML 2.0 SSO, RADIUS and TACACS+ with group mapping, RBAC and MFA. Device login supports RADIUS, TACACS+, LDAP and local accounts.
Every SLC 9000 verifies its firmware image signature at boot through the NXP LayerScape secure element before the system is allowed to start.
SLC 9000 firmware exposes no shell. Default credentials are unique per unit and changed at initial setup, with no vendor-wide default.
Search the Percepxion platform audit log. It records management actions against the named user, so a question like “who opened a console on the core firewall last Tuesday” has a direct answer. The event log is fully queryable through the Percepxion REST API, which lets you pull it on a schedule into the system that holds your retained evidence.
Pull that evidence from the platform, not device syslog. Device-side port audit logs attribute Percepxion-brokered sessions to a shared service account, so the named-user record lives in Percepxion. Session activity is audit-logged; individual keystrokes are not recorded.
For the device data itself, the SLC 9000 logs port output in real time to local storage, NFS, syslog or a USB drive.
Identity comes from the systems you already run. Percepxion supports SAML 2.0 SSO against Okta, Azure AD or any SAML 2.0 provider, plus RADIUS and TACACS+ with group mapping, RBAC and MFA. Access is organized by project, portal and organization, with three default roles and per-operation permissions, so a contractor scoped to one site sees one site.
On the appliance, device login supports RADIUS, TACACS+, LDAP and local accounts, with Duo MFA through a RADIUS proxy. Local accounts give your admins a way in when the central auth service is the thing that’s down.
A small attack surface and a verified boot chain. Every SLC 9000 checks its firmware image signature at boot through the NXP LayerScape secure element. The firmware exposes no shell, and any containers run sandboxed at 256 MB of memory and one CPU core. Default credentials are unique per unit and changed at setup, so there’s no shared vendor password to leak.
The unit registers to Percepxion over an outbound-only MQTT connection. You don’t open an inbound firewall rule to reach your management plane.
Know the boundaries before the questionnaire arrives. The SLC 9000 is not FIPS certified. Every SKU includes a discrete TPM 2.0 chip. The TPM 2.0 chip is present on every SKU; GA firmware does not yet use it for encryption or attestation. Scope your control mapping to secure boot, centralized identity, RBAC and the named-user platform audit log.
Questions
Yes. The Percepxion platform audit log records management actions against the named user, and the event log is queryable through the REST API.
The SLC 9000 is not FIPS certified.
Session activity is audit-logged; individual keystrokes are not recorded.
Percepxion supports SAML 2.0 SSO with Okta, Azure AD or any SAML 2.0 provider, plus RADIUS and TACACS+. SLC 9000 device login supports RADIUS, TACACS+, LDAP and local accounts, with Duo MFA through a RADIUS proxy.
The Product Selector opens with this page's filters applied. Add models to My List, then export it or email it for a quote.
Find SLC 9000 models for your sites