SEKRAW.ENT v2.6
INFRA · CYBER · AI
HYDERABAD · IN
247 NODES LIVE
SEK RAW
BUSINESS
SERVICES
Zero-Trust Verified · Enterprise Systems Online
Cybersecurity · AI Solutions · Cloud · ERP · Managed IT · Enterprise Consulting
BIOS: SEKRAW ENTERPRISE PLATFORM v2.6 ✓ OK
NGFW HA-PAIR: SYNC · RULES: 12,847 ✓ OK
ZERO TRUST ENGINE · MICROSEGMENTATION: ON ✓ OK
SIEM / SOAR / XDR · THREAT INTEL: LIVE ✓ OK
AWS / AZURE / GCP · VPC PEERING: UP ✓ OK
DC1 PRIMARY + DC2 DR · REPLICATION: ACTIVE ✓ OK
SOC OPS: MONITORING 247 NODES · 0 ALERTS ⚠ ACTIVE
INIT 0%
CSVCOPCSVCOP
Authorised distributor · by DataBricks Technologies

Prove your lab workstations stayed compliant — every day, not just for the audit

CSVCOP applies 97 individually documented Windows controls to a laboratory workstation, restores any control that drifts within 30 seconds, and keeps a written, tamper-evident record of every attempt — with no internet connection required, ever. SEK RAW Business Services is the authorised distributor for India and the United States, handling quotations, purchase orders, invoicing and renewals.

21 CFR Part 11 laboratoriesGxP environmentsInstrument & shared operator PCsAir-gapped networksWindows 7 – 11
LAB-PC-07 · Compliance status
Watchdog service
Running
Controls enforced
96 / 97
Drift events today
2
Licence
Active
Last compliance check12s ago
Attempts logged today14
Why regulated labs need this

A policy setting is a promise. Nothing was keeping it.

Without CSVCOP

Group Policy describes how a workstation should be configured. It does not stop an operator from changing it back, and nothing re-checks that the setting held between one audit and the next — so "compliant" is only ever true on the day someone last looked.

With CSVCOP

A background service re-verifies all 97 controls every 30 seconds, restores anything that drifted, and writes down what changed, when, and under which account — so the workstation is provably compliant on every day, not just the day of the audit.

It stays enforced

A background service re-checks all 97 controls every 30 seconds against an encrypted master and restores anything that drifted, without waiting for the next audit to notice.

Restored and logged within 30 seconds

It resists tampering

Copy, cut, paste, delete, rename and drag are refused at the keyboard, the toolbar and the clipboard itself — so a redesigned menu or a different Windows language can't open a gap.

A deleted file is restored in milliseconds

It documents everything

Every configuration change, drift event and blocked attempt is written to a protected application log, a security log and the Windows Event Log, plus printable PDF reports for the validation file.

Three independent records of every event
Complete feature set

Everything CSVCOP does, from configuration to evidence

A desktop application to decide the configuration, a Windows service that keeps it true, and a small agent in every signed-in session for the things policy alone cannot reach.

Self-healing enforcement

A Windows service running as SYSTEM, starting before sign-in.

  • Re-checks every control on a 30-second cycle
  • Tells your own changes from tampering by version stamp
  • Restores its own master from a protected backup if deleted

Session guard

Blocks the effect, not the menu — works the same on any layout.

  • Keys, toolbar buttons, drag-and-drop and the clipboard itself
  • Rename closed by every route; deletes restored automatically
  • Cannot be ended, suspended or tampered with by a standard user

Audit trail & reports

Three independent, protected records of everything that happens.

  • Application log — sign-ins, changes, user administration
  • Security log — drift events and blocked attempts, by the service
  • Printable PDF configuration and activity reports

USB & removable storage

Controls 60–64 and 86, plus a per-device whitelist.

  • Deny all, or deny writing only
  • Portable devices controlled separately from disks
  • Whitelist an exact device by its hardware identity

Access control

CSVCOP's own accounts, held to their own standard.

  • Salted PBKDF2 password hashes, never stored in clear
  • Rate-limited sign-in and a 20-minute idle timeout
  • Re-authentication required on every Save & Apply

Offline licensing

Activation and renewal without the workstation ever going online.

  • A one-way machine key identifies the PC, reveals nothing about it
  • RSA-2048 signed licence, verified entirely on the workstation
  • Protection is never removed when a licence expires
What lands in the audit file

Restated in plain language, from a real log

The operator sees a setting that reverted itself within half a minute. The auditor sees exactly what happened — timestamped, with the account and the value found and restored.

security.log · LAB-PC-07
14:48:08DRIFTControl 59 · Remove Task Manager — found off, expected on. Restored automatically.
14:48:11BLOCKEDFile copy attempted in File Explorer — refused, clipboard cleared.
14:51:22BLOCKEDRename attempted on batch-0412.csv — rename box closed before it opened.
15:03:47BLOCKEDDelete of a result file — restored from the Recycle Bin in 40 ms.
15:04:00VERIFIEDCompliance check — all 97 controls confirmed. Heartbeat written.
From a fresh Windows PC to an audited workstation

Four steps, then it holds itself

01

Choose

Switch on the controls you need in Configure Controls. Each one states what it does, whom it affects and its side effects before you apply it.

02

Confirm

Save & Apply asks for the administrator's password again, so an unattended screen can never be used to change the lockdown.

03

Apply

The encrypted master is written and each control is applied at the right level — per-user policy, machine policy or security policy.

04

Enforce

From the next 30-second cycle the watchdog holds the state, and the session agents pick up their flags within seconds.

Built around 21 CFR Part 11

Mapped to § 11.10, requirement by requirement

CSVCOP supplies the workstation-level controls and the records that back them up. Your validation protocol and SOPs remain yours — this is what becomes far easier to evidence.

RequirementHow CSVCOP helps
§ 11.10(d)Limiting access — Windows policy for the workstation, plus CSVCOP's own rate-limited administrator accounts.
§ 11.10(e)Audit trails — time-stamped application and security logs, written independently of the operator.
§ 11.10(f)Operational checks — a configuration that re-verifies itself every 30 seconds cannot silently drift between audits.
§ 11.10(g)Authority checks — only an authenticated CSVCOP administrator can change the lockdown, with re-authentication on every save.
§ 11.10(h)Device checks — removable-storage control with a per-device whitelist by hardware identity.
§ 11.10(c)Protection of records — masters encrypted and machine-bound; log folders writable only by SYSTEM and administrators.

A few checkpoints your auditor is likely to ask about

CheckpointAnswered by
Modification and deletion of dataSession guard — keys, toolbar, drag, clipboard, rename, delete-restore
Access to removable storageUSB deny/read-only/whitelist controls
Access to the command promptCommand prompt, PowerShell and named-program blocks
Change of system date and timeTime-change rights withheld from standard users
Access to drivesDrive visibility and access controls
Restrict shutdownShutdown menu and the underlying right, both controlled

Send us your own auditor's checklist and we'll return it with the control numbers filled in.

Laboratory technician in a lab coat working at a computer workstation
Built for the shared operator PC

One installer, no server, no domain

Windows 7 SP1 through 11, with no server or network dependency — CSVCOP runs and activates entirely on the machine, exactly the constraint most instrument PCs and air-gapped lab networks operate under.

Who this is built for

Made for regulated workstations

21 CFR Part 11 laboratories

Pharma, biotech and diagnostics labs that need to show a workstation stayed in its validated configuration.

Instrument & shared operator PCs

One login, many operators, over years — exactly where policy alone tends to quietly drift.

Air-gapped & GxP networks

No internet needed to run, activate or renew — built for machines that are never meant to be online.

Windows 7 – 1132- and 64-bit
One MSI installerAdmin rights to install & configure
Fully offlineNo server, domain or network needed
.NET 4.5+Built into Windows 8 and later
Questions we hear most

FAQ

Product & deployment

Windows 7 SP1 through Windows 11, 32- and 64-bit, with .NET Framework 4.5 or later — already built into Windows 8 and above.

Compliance & evidence
Licensing & purchase
Pricing, through the authorised distributor

Tell SEK RAW how many workstations you need to protect

CSVCOP is licensed per workstation, for the period you choose. SEK RAW Business Services handles the quote, the paperwork and every renewal after it — for labs in India and the United States alike.

SEK RAWBUSINESSSERVICESCSVCOP
Authorised distributor
IN flagIndiaUS flagUnited States