Control, broker, rotate and audit every privileged credential and session across your estate.
A self-hosted, zero-dependency Privileged Access Management platform — an encrypted vault, a recorded session broker for SSH / RDP / VNC / databases, automatic credential rotation across 100+ target platforms, just-in-time access, dual-control approvals, and a tamper-evident audit trail. One installable service. No external runtime.
PAM closes the highest-risk gap in any environment: the standing, shared, over-privileged credentials that attackers prize. It takes those secrets out of spreadsheets, scripts and people's heads, puts them in an encrypted vault, and only ever releases them through controlled, recorded, time-boxed, approved access — rotating them automatically so a leaked password is worthless tomorrow.
Secure the secret
Every password, key and token is stored encrypted at rest and never exposed in the clear unless policy allows.
Broker the session
Admins connect to targets through PAM — it injects the credential, records the session, and they never see the password.
Rotate & prove it
Credentials rotate on schedule or after use; every action is written to a tamper-evident, exportable audit trail.
Capabilities
The full platform
Twelve capability areas, each shipping in the box.
Credential Vault
Encrypted secret store with versioning & rollback, per-secret metadata, and policy-driven access.
AES-256-GCM at rest, master-key custody (file / env / KMS)
Secret versioning + one-click rollback of a bad rotation
Honest deployment note. Out of the box the listener is plain HTTP for local evaluation. For production, enable the built-in TLS (PAM_TLS_CERT / PAM_TLS_KEY) or front it with an HTTPS proxy, and keep the master key outside the data directory (KMS-injected). These are the two must-dos before exposing PAM beyond localhost.
Coverage
Supported target platforms
The out-of-the-box platform catalog — what PAM natively recognises for session brokering and/or rotation. Capability is honest, per platform:
MANAGED live connector runs now (session + rotation)SESSION brokered/recorded session; rotation out-of-bandFRAMEWORK catalogued; activates when its driver/SDK/endpoint is configured
Operating Systems
Windows Server 2016/19/22Windows 10/11RHELCentOSUbuntuDebianRockyAlmaLinuxSUSEIBM AIXSolarisHP-UX
Web app (HTML forms)Scripts / flat config (.ini/.xml)Any SSH-reachable device
Don't see your platform? Anything reachable over SSH is managed today, and the catalog has a typed extension point — new targets activate by configuring their driver / SDK / endpoint. Tell us what you run on the requirements form and we'll confirm fit.
Get started
Tell us what you run
Open the requirements form, select the systems, databases, applications and clouds you need to bring under privileged-access control, and add anything custom. We'll scope the fit and licensing.