Learn about Silo features

Administrator Capabilities

GRAPHICAL ADMIN CONSOLE
Yes, accessed within Silo.
DELEGATION OF ADMIN ROLE
Yes, roles at selectable node within hierarchy.
ORGANIZATIONAL STRUCTURE
Customer data stored in hierarchical data structure with root and sub-org(s).
POLICY ASSIGNMENTS
Definable at the root or sub-org, can be inherited or excepted.
USER MANAGEMENT MODEL
Via admin console, bulk csv file, or directory synchronization.
LIVE SESSION KILL SWITCH
Immediate on User Suspend or User Delete action.
ACTIVE DIRECTORY SYNC
OU structure, synchronized Adds, Deletes, Moves, Suspends.
POLICY UPDATE PROPAGATION
In real time for account actions, next session on other policies.
MULTI-FACTOR AUTHENTICATION
Always, never, dependent on trust level of device.
USER ACCESS CONTROLS
Configurable for corporate devices vs. other devices.
WEB CONTENT FILTERING
URL Category filtering, whitelist and blacklist support. Set at Root or Sub-org.
ACCESS TO WEB ACCOUNTS
Configurable by admin. Central provisioning at user or org level.
CREDENTIAL MANAGEMENT
Configurable by admin. Managed by admin or user.
SHARED ACCOUNT SUPPORT
Managed by admin, not revealed to user. Each user logged discretely.
DATA LOSS PREVENTION CONTROLS
Configurable by admin. Enable or block file transfer, copy/paste, print.
TIME BASED ACCESS CONTROLS
Configurable by admin.
BROWSER PLUG IN CONFIGURATION
Configurable by admin. Enable or restrict Flash, Media Formats, Java.
LOG FORMATS
Extract API returns JSON.
AUDIT LOGS
User, Session, URL data, HTTP POST data, admin activity.
LOG ENCRYPTION
Customer supplied public key, encrypted at root or sub-org(s).
LOG DATA ACCESS
Download via authenticated API at root or sub-org(s).
LOG ROTATION
Deleted on 90 day basis.

User Capabilities

ISOLATION
All code executed in secure, cloud-based container. No web data reaches client, client ID not exposed.
CONNECTION
A8 proprietary non-web protocol over TLS port 443 connection.
CONTENT SUPPORTED
All web content formats transcoded into benign display data. Filtering of ad content and web scripts depending on configuration.
WEB CONTENT filtering
Configurable by category, white/black lists; configurable at root or group.
ACCESS MODES
Native client app. Direct launch or from within local browser.
BROWSER EXECUTION LOCATION
As configured by admin. Restricted to set geography or dynamic.
SINGLE SIGN ON
As configured by end user or admin.
BROWSING HISTORY AND COOKIES
Configurable. Default is to delete non-first party cookies.
DATA TRANSFER
As configured by admin.
DATA STORAGE
As configured by admin. Temporary and/or persistent encrypted storage in the cloud.
ATTRIBUTION
All attribution to co-location providers, not to end user.

Researcher Capabilities

WEB CONTENT RENDERING
Unadulterated page DOM. No filtering or modifying.
MULTIPLE, DISPARATE INSTANCES
Multiple browser locations and configurations within single user workflow.
SOURCE CODE ANALYSIS
Yes.
HTTP PACKET CAPTURE
Yes.
USER AGENT STRING
Configurable within session.
BROWSER FINGERPRINT
Configurable within session.
LANGUAGE TRANSLATION
Yes, within live session. Source-target translation based on selected region or entire page.
COOKIE INSPECTION AND TRACKING
Yes.
DATA STORAGE
As configured by admin. Temporary and/or persistent encrypted storage in the cloud.
JAVA SUPPORT
Yes. Java v6 and v7 containment.
VIRTUALIZED X-TERM
Yes.
SSH KEY MANAGEMENT
Configurable by admin.
ATTRIBUTION
Non-attributed as default, session can be mis-attributed based on geographical egress node selected.
GEOGRAPHICAL RESTRICTIONS
Browser execution and data egress configured across ~20 geo locations.

Requirements & Integration

PLATFORMS
Win, Mac, Linux, iOS iPad.
CLIENT MEMORY CONSUMPTION
~100 MB RAM.
CLIENT STORAGE REQUIREMENTS
~15MB native client app.
SILO CLIENT DISTRIBUTION
Via web, internal hosted share, or packaged for MSI or other distribution.
CLIENT UPDATE MODEL
Auto-update can be enabled or disabled by admin.
ACTIVE DIRECTORY INTEGRATION
Users and Groups via on-premise Directory Sync Agent.
PAC FILE SUPPORT
Yes.
PROXY AUTH SUPPORT
Yes.
FEDERATED AUTH SUPPORT
Yes, via integration with Windows domain authentication.