NOVA PAM Professional
Privileged Access Management · Capability Datasheet

Control, broker, rotate and audit every privileged credential and session across your estate.

A self-hosted, zero-dependency Privileged Access Management platform — an encrypted vault, a recorded session broker for SSH / RDP / VNC / databases, automatic credential rotation across 100+ target platforms, just-in-time access, dual-control approvals, and a tamper-evident audit trail. One installable service. No external runtime.

100+
Target platforms
SSH·RDP·VNC·DB
Brokered & recorded sessions
30+
Managed auto-rotators
0
Runtime dependencies
Encrypted vault (AES-256-GCM)Tamper-evident audit chain MFA / TOTPSSO (OIDC) · LDAP/ADDual-control Just-in-time accessSession recordingSIEM egress Air-gapped signed updatesSelf-hosted
Overview

What NOVA PAM does

PAM closes the highest-risk gap in any environment: the standing, shared, over-privileged credentials that attackers prize. It takes those secrets out of spreadsheets, scripts and people's heads, puts them in an encrypted vault, and only ever releases them through controlled, recorded, time-boxed, approved access — rotating them automatically so a leaked password is worthless tomorrow.

Secure the secret

Every password, key and token is stored encrypted at rest and never exposed in the clear unless policy allows.

Broker the session

Admins connect to targets through PAM — it injects the credential, records the session, and they never see the password.

Rotate & prove it

Credentials rotate on schedule or after use; every action is written to a tamper-evident, exportable audit trail.

Capabilities

The full platform

Twelve capability areas, each shipping in the box.

Credential Vault

Encrypted secret store with versioning & rollback, per-secret metadata, and policy-driven access.

  • AES-256-GCM at rest, master-key custody (file / env / KMS)
  • Secret versioning + one-click rollback of a bad rotation
  • Password policy engine (complexity, history, max-age)
  • Managed SSH keypairs

Privileged Session Manager

Browser-based brokered sessions — the operator never holds the credential.

  • PuTTY-grade web SSH terminal (PTY over WebSocket)
  • mstsc-grade RDP & VNC via the Guacamole gateway
  • Full session recording + replay (and MP4 export)
  • Live session monitoring + force-terminate
  • Per-session risk scoring

Credential Rotation (CPM)

Scheduled & on-checkin rotation with verification and reconcile-on-failure.

  • 30+ live managed rotators (see platform matrix)
  • Read-only credential verification probes
  • Cadence auto-verify + auto-reconcile
  • Per-platform rotation-policy forms

Just-in-Time & Dynamic Secrets

Zero standing privilege — ephemeral credentials that auto-expire.

  • JIT elevation with time-boxed grants
  • Dynamic DB/queue users (Postgres, MySQL, Mongo, Redis, RabbitMQ, Elasticsearch) leased & auto-revoked
  • Break-glass emergency access (audited)

Dual-Control & Approvals

Separation of duties on the most sensitive actions.

  • Approve-to-reveal / approve-to-connect
  • Access Groups (which devices) × Roles (which actions)
  • Per-safe membership & scoping
  • Hard SoD constraints

Application Access Manager

Secret retrieval for non-human identities (AAM / CCP).

  • Apps fetch secrets via scoped tokens — no hard-coded passwords
  • Per-application allow-lists (which safes / which secrets)
  • Session-only secrets (PSM-brokered, no plaintext)

Cloud Privileged Access

One-click console + JIT CLI credentials for the big three.

  • AWS console federation + JIT keys (STS)
  • Azure JIT AAD tokens · GCP JIT SA tokens
  • Google Workspace admin (domain-wide delegation)
  • Long-lived keys never leave the vault

Governance & Compliance

Prove who accessed what, when, and why.

  • Tamper-evident, hash-chained audit log
  • Access certification / recertification campaigns
  • Policy engine + "who accessed what & how long" reports
  • Exportable reports (XLSX / JSON)

Authentication & Identity

Strong auth on the front door, federated to your IdP.

  • MFA / TOTP with QR enrolment + backup codes
  • SSO via OpenID Connect
  • LDAP / Active Directory login + group→role mapping
  • Cluster-wide session revocation

Discovery & Onboarding

Find privileged accounts and bring them under management.

  • Network discovery scans (dual-control gated)
  • Guided add-device wizard + live supported catalog
  • Bulk server onboarding (CSV → vault import)

Monitoring & SIEM

Feed every privileged event to your SOC.

  • Real-time event stream (SSE) + notifications
  • SIEM / Syslog (RFC5424) audit egress — Splunk, QRadar, Sumo Logic
  • Outbound webhooks with circuit-breaker

Updates & Licensing

Ship and govern the product itself, securely.

  • Air-gapped, Ed25519-signed offline updates + rollback
  • Cloud licensing control plane (signed entitlements, grace-then-lock)
  • Content-pack OTA (zero-restart, signed)
Architecture & Security

Built secure, deployed simply

A single Node service over an embedded SQLite store — no external database, message broker, or runtime to stand up.

PropertyDetail
FootprintOne self-hosted service. Zero external runtime dependencies; embedded SQLite (WAL) datastore.
EncryptionAES-256-GCM for secrets at rest; master key via file, PAM_MASTER_KEY (KMS) or external path; master-key rotation / re-encryption.
TransportBuilt-in TLS listener (TLS 1.2+) or run behind a terminating proxy; HSTS when secure.
AuditAppend-only, hash-chained audit log (tamper-evident); fail-closed — an unwritable audit aborts the action.
IntegrityEd25519 vendor-signed updates and cloud licenses (the install verifies; it cannot forge).
Access modelRoles (viewer / operator / admin / owner) × Access-Group membership; dual-control on sensitive paths.
ResilienceTransactional integrity, graceful shutdown, bounded resource use, brute-force lockout on login.
Honest deployment note. Out of the box the listener is plain HTTP for local evaluation. For production, enable the built-in TLS (PAM_TLS_CERT / PAM_TLS_KEY) or front it with an HTTPS proxy, and keep the master key outside the data directory (KMS-injected). These are the two must-dos before exposing PAM beyond localhost.
Coverage

Supported target platforms

The out-of-the-box platform catalog — what PAM natively recognises for session brokering and/or rotation. Capability is honest, per platform:

MANAGED live connector runs now (session + rotation) SESSION brokered/recorded session; rotation out-of-band FRAMEWORK catalogued; activates when its driver/SDK/endpoint is configured

Operating Systems

Windows Server 2016/19/22Windows 10/11RHELCentOSUbuntuDebianRockyAlmaLinuxSUSEIBM AIXSolarisHP-UX

Hypervisors & Lights-Out

VMware vSphere/ESXiHyper-VNutanix AHVHP iLODell iDRACIBM HMC/IMMCisco UCS

Databases

OracleSQL ServerPostgreSQLMySQLMariaDBMongoDBMongoDB AtlasRedisIBM Db2InformixSybase ASETeradataSnowflakeODBC

Network & Appliances

Cisco IOS/NX-OSPalo AltoFortinet FortiGateCheck PointJuniper JunOSF5 BIG-IP

Cloud & DevOps

AWS IAMAzure IAMGCP IAMGoogle WorkspaceEntra IDKubernetesOpenShiftDockerHashiCorp VaultTerraformAnsibleJenkinsGitLab CIAzure DevOpsGitHub ActionsDatadogHarborCloudflareGrafana

Directory & Identity

Active DirectoryOpenLDAPOracle Internet DirectoryNovell eDirectorySunOne Directory

Auth Providers (MFA)

RADIUSSAML 2.0OpenID ConnectRSA SecurIDDuoOktaYubiKeyThales HSM

Enterprise Applications

SAP NetWeaverSAP S/4HANASalesforceMicrosoft 365Google WorkspaceServiceNowTwilioJira

SIEM, Monitoring & Storage

SplunkIBM QRadarSumo LogicSevcoSyslog (RFC5424)NetApp NASDell EMC Storage

Mainframe & Legacy

IBM z/OSIBM AS/400OpenVMSHPE NonStop

Custom & Web

Web app (HTML forms)Scripts / flat config (.ini/.xml)Any SSH-reachable device
Don't see your platform? Anything reachable over SSH is managed today, and the catalog has a typed extension point — new targets activate by configuring their driver / SDK / endpoint. Tell us what you run on the requirements form and we'll confirm fit.
Get started

Tell us what you run

Open the requirements form, select the systems, databases, applications and clouds you need to bring under privileged-access control, and add anything custom. We'll scope the fit and licensing.

Open the requirements form → Tip: press Ctrl / ⌘ + P to save this datasheet as PDF