1. What is NOVA PAM?
NOVA PAM Professional is a Privileged Access Management platform. It is the secure front door to all of your most sensitive accounts — the administrator and root passwords, SSH keys, database logins, and cloud credentials that, in the wrong hands, could compromise your whole organisation.
Instead of staff knowing and sharing these passwords, NOVA PAM holds them in an encrypted vault and gives people access without exposure: they connect to a server or database through NOVA PAM, the platform injects the credential for them, and the entire session is recorded. Passwords are rotated automatically, every action is written to a tamper-evident log, and high-risk activity is flagged in real time.
Store
A hardened, encrypted vault for every privileged account, key, and secret — with versioning and rollback.
Connect
Launch recorded SSH, RDP, VNC, and database sessions — users never see the password.
Govern
Approvals, just-in-time elevation, rotation, audit, and access reviews — all built in.
Who is it for? IT and security teams who need to control and prove who can access critical systems — and contractors or vendors who need safe, time-limited access without ever holding the real password.
2. Key ideas & roles ↑ top
A few words you'll see everywhere
- Account / Secret — a stored privileged login (username + password or key) for a target system.
- Vault — the encrypted store that holds all accounts and secrets.
- Session — a live connection (SSH, RDP, VNC, or database) to a target, opened through NOVA PAM and recorded.
- Rotation — automatically changing a password or key so it never stays the same for long.
- Access Group — a collection of accounts that you grant to specific people or roles.
- Approval / Dual control — a second person must sign off before a sensitive action proceeds.
- Just-in-time (JIT) — access that is granted only for a set window and then removed automatically, leaving no standing privilege.
The four roles
Everyone has exactly one role. Each role includes everything the one below it can do.
| Role | What they can do |
|---|---|
| Viewer | Read-only — see dashboards, reports, and audit; cannot change anything. |
| Operator | Use accounts and start sessions they're entitled to; request approvals. |
| Admin | Manage accounts, users, policies, rotation, settings, SSO, and directory sign-in. |
| Owner | Full control, including the most sensitive actions — installing the license, TLS, backups, and break-glass. The first account you create is the Owner. |
3. System requirements ↑ top
NOVA PAM runs on one server (physical, virtual, or a container) and is used from a normal web browser. It is light — these are comfortable sizes:
| Deployment size | CPU | Memory | Disk |
|---|---|---|---|
| Small (up to ~50 accounts, a few users) | 2 vCPU | 2 GB RAM | 20 GB SSD |
| Medium (hundreds of accounts, a team) | 4 vCPU | 4–8 GB RAM | 50 GB SSD |
| Large (thousands of accounts, heavy session + recording use) | 8 vCPU | 16 GB RAM | 100 GB+ SSD |
Where NOVA PAM runs
NOVA PAM Professional is a Windows application. Install it on Windows Server 2019/2022 (recommended for production) or on Windows 10/11 (64-bit) for a smaller or evaluation setup. It runs as a background Windows service that starts automatically with the machine.
Browser (for users)
Any current Google Chrome, Microsoft Edge, or Mozilla Firefox. No plug-ins or client software to install — RDP and VNC open right in the browser tab.
Network
- One inbound port for the console (default
7700, or443behind HTTPS). - Outbound reach from the server to the systems you want to manage (e.g. SSH 22, RDP 3389, database ports).
- If you use SSO or directory sign-in, outbound reach to your identity provider or domain controller (HTTPS, or LDAPS 636).
4. Installation ↑ top
NOVA PAM installs on Windows as a background service — Windows Server is recommended for production. There are three quick steps: install the app, allow it through your antivirus, then run the first-time setup. (Remote Desktop and VNC need one small extra service — see 4.3.)
4.1 Install on Windows
The Windows edition installs as a background service, so it starts automatically every time the machine boots.
- Copy the NOVA PAM application folder to the machine (for example to
C:\Program Files\NOVA PAM). - Open PowerShell as Administrator, move into that folder, and run the installer command. It registers the service, starts it, and prints the address to open.
- The service now runs in the background and will restart by itself after any reboot.
- Open your browser to
http://localhost:7700and continue at First-run setup.
You can stop, start, or check the service at any time from the same Administrator PowerShell.
4.2 Allow NOVA PAM through your antivirus
NOVA PAM is a brand-new program that opens administrator sessions and injects passwords, so antivirus software and Windows SmartScreen may flag or block it the first time it runs — this is normal for any privileged-access tool. Before the first start, tell your antivirus to trust NOVA PAM by adding its install folder to the exclusions / exceptions / allow list.
C:\Program Files\NOVA PAM — as an exclusion. A folder exclusion automatically covers the program NOVA-PAM.exe and the background service inside it. (If you installed NOVA PAM somewhere else, use that folder instead.)Microsoft Defender (built-in Windows Security)
This is the antivirus built into Windows. To add a folder exclusion:
- Open the Start menu, type Windows Security, and open the Windows Security app.
- Select Virus & threat protection.
- Under Virus & threat protection settings, select Manage settings.
- Scroll to Exclusions and select Add or remove exclusions (approve the admin prompt if it appears).
- Select Add an exclusion → Folder, browse to
C:\Program Files\NOVA PAM, and click Select Folder.
Other antivirus products
Every antivirus has an “exclusions”, “exceptions”, or “allow list”. Open yours and add the folder C:\Program Files\NOVA PAM. The exact path for the most common products:
| Antivirus | Where to add the folder exclusion |
|---|---|
| Norton | Newer app: Security → Scans (Open) → Exclusions tab → Add Exclusion → browse to the folder. Older app: Settings (gear) → Antivirus → Scans and Risks → next to Items to Exclude from Scans click Configure [+] → Add Folders; then repeat for Items to Exclude from Auto-Protect, SONAR and Download Intelligence Detection. |
| McAfee | Virus and Spyware Protection (or PC Security) → Scan Your PC → Run a custom scan (or Scheduled Scan) → Excluded Files and Folders → Add Folder → select the folder. |
| Bitdefender | Protection → Antivirus (Open) → Settings tab → Manage exceptions → + Add exception → Browse → choose the folder → Save. (GravityZone endpoint: Policies → Antimalware → Settings → Exclusions → Custom Exclusions → Add, Type = Folder.) |
| Kaspersky | Settings (gear) → Security settings → Exclusions and actions on object detection (older: Threats and Exclusions) → Manage exclusions → Add → Browse → the folder → keep all components ticked → Add. |
| ESET | Press F5 (Advanced setup) → Detection engine (v18: Scans) → Exclusions → Performance exclusions → Edit → Add → enter C:\Program Files\NOVA PAM\* → OK. |
| Avast / AVG | Menu → Settings → General → Exceptions → Add exception → Next → I understand risks → File/Folder tab → folder icon → select the folder → Add. |
| Sophos Home | Sign in at home.sophos.com → select the device → PROTECTION → General → Exceptions → type C:\Program Files\NOVA PAM → press Enter. (Sophos Central / Intercept X: Global Settings → Protection and Remediation → Allow and Block → Global Exclusions → Add Exclusion → “File or folder (Windows)”.) |
| Trend Micro | Settings → Exception Lists → Programs/folders → Add → Browse → select the folder → Open → OK → Apply → OK. |
| Malwarebytes | Detection History → Allow List → Add → Allow a file or folder → Select a folder → browse to the folder → Done. |
C:\Program Files\NOVA PAM in the policy — you may not be able to change it on the machine itself. If NOVA PAM was already quarantined, restore it from your antivirus's “quarantine” or “detection history” and choose to allow/trust it.4.3 Enable RDP / VNC (optional)
SSH, databases, and the whole console work out of the box. To also use Remote Desktop (RDP) and VNC in the browser, NOVA PAM needs one small companion service called the session gateway. The simplest way to run it is as a single Docker container on the same Windows machine:
- Install Docker Desktop on the NOVA PAM machine (from the official Docker website). Keep “Use WSL 2” ticked and wait until it says “Engine running”.
- Start the session gateway:
docker compose -f packaging\guacd\docker-compose.yml up -d - That's it — RDP and VNC immediately become available in the Sessions screen. No other configuration is needed.
4.4 First-run setup
The very first time you open NOVA PAM it walks you through a short setup wizard:
- Create the administrator. Choose a username and a strong password — this becomes the Owner account.
- Add your license. Paste or upload the license file your provider gave you. (You can also do this later from the License screen.)
- Sign in. Use the credentials you just chose.
- Turn on two-factor authentication for your account (recommended) under Account.
- Add your first accounts in the Vault, and you're ready to go.
https://….5. The console — every tab ↑ top
The left sidebar groups the screens into six sections. Below is every tab, what it's for, and how to use it. (A few tabs only appear for Admins and Owners.)
https://…6. Common tasks, step by step ↑ top
The most frequent jobs, start to finish.
Add your first account to the vault
- Go to Access → Vault and click Add secret.
- Pick the platform (for example Linux SSH, Windows, or PostgreSQL) — this tells NOVA PAM how to connect and rotate it.
- Enter the target address, the username, and the password or key.
- (Optional) set a rotation policy so the password changes on a schedule, and add it to an Access Group so the right people can use it.
- Save. The credential is now encrypted in the vault and ready to use.
Start a recorded session
- Open Sessions → Sessions (or click Connect on an account in the Vault).
- Choose the account and the connection type — SSH, RDP, VNC, or database.
- The session opens in your browser. NOVA PAM injects the password for you — you never see or type it.
- Work as normal. Everything is recorded.
- When you finish, the session appears in the list where it can be replayed like a video.
Require a second person to approve (dual control)
- An Admin sets the action (a reveal or a session) to need approval — and, if you like, an N-of-M quorum under Settings → Approvals and Policy.
- When a user requests that action, they're told it's pending.
- Approvers see the request in Access → Approvals and Approve or Deny it.
- Once enough approvers agree, the action is unlocked for the requester. Everything is audited.
Rotate a password automatically
- Open the account in the Vault and set a rotation policy (e.g. every 30 days), or open Lifecycle → Rotation.
- Make sure Scheduled rotation is on under Settings → Automation.
- NOVA PAM changes the password on schedule and then verifies the new one works.
- Need it changed right now? Click Rotate now on the account.
Give a contractor temporary access
- Go to Sessions → Remote Access and click to create a link.
- Choose the one machine, set how long the link is valid, and set a one-time code.
- Send the link and the code to the contractor (separately is safest).
- They open the link, enter the code, and get a recorded session — with no account on your system and no knowledge of any password.
- When the window ends, the access disappears on its own. You can also revoke it at any time.
Run an access review (recertification)
- Open Governance → Recertification and start a campaign.
- Assign the reviewers (usually each team's manager).
- Reviewers confirm or revoke each person's access to each account.
- The decisions are recorded as evidence for your auditors.
7. Sessions & remote access ↑ top
A “session” is a live, recorded connection to a target system, opened through NOVA PAM so the user never handles the real password.
The kinds of session
| Type | What you get |
|---|---|
| SSH | A full interactive terminal to Linux/Unix servers and network devices, in the browser — typed commands are recorded. |
| RDP | A Windows desktop in the browser — clipboard, fit-to-window, and full-screen, all recorded. (Needs the session gateway, see 4.3.) |
| VNC | Graphical access to machines that use VNC, in the browser. (Needs the session gateway.) |
| Database console | Run queries against a database in the browser with the password injected for you and every statement recorded. |
| Database gateway | Lets your own native database client connect through NOVA PAM using short-lived credentials, while NOVA PAM brokers and audits it. |
Recording & replay
Sessions are recorded and can be replayed later like a video (and screen sessions can be exported). This gives you a precise, reviewable record of exactly what was done on a system. How long recordings are kept is set under Settings → Recording & retention.
Approvals & just-in-time
You can require that a session is approved by a second person before it starts (dual control, including N-of-M quorum), and you can grant access only just in time for a limited window that expires automatically.
Remote access for guests
The Remote Access screen lets an administrator issue a single, time-boxed, code-protected link to one machine. A contractor opens the link, enters the one-time code, and gets a recorded session for the allowed window — with no account on your system and no knowledge of any password. When the window ends, the access is gone.
Always-on safeguards
- Live monitoring — watch any active session and step in if needed.
- Force-terminate — kill a risky session immediately.
- Risk scoring — every session is scored and high-risk ones are flagged.
- Credential injection — users connect without ever seeing the password.
8. Settings — every panel ↑ top
The Settings screen (in the Governance group) is where an Admin or Owner manages the whole system. It has a row of panels down the left. Every change takes effect immediately and is written to the audit log. The panels are below; single sign-on and directory sign-in are big enough to get their own sections (9 and 10).
8.1 System
A read-only health view of the server. It shows the product and version, the host and operating system, uptime, CPU load and cores, memory used vs total, the database size, the process memory, and the audit chain status — the number of entries followed by verified, or BROKEN if any tampering is detected. A Refresh button re-reads the live figures.
8.2 Security
Two things in one place:
Password policy
The rules for login passwords (self-service changes, admin resets, and new users). Vaulted target passwords are governed by Rotation instead.
| Setting | What it does |
|---|---|
| Minimum length | Shortest allowed password (8–256). |
| Reuse history | Reject any of the last N passwords (0 = off). |
| Require uppercase / lowercase / digit / symbol | Force each character class to appear. |
| Disallow username in password | Block passwords that contain the username. |
Multi-factor authentication posture
A read-only summary: how many accounts have MFA, how many privileged (admin/owner) accounts have it, and a warning that names any privileged account still missing it — with a shortcut to Users to fix it.
8.3 Recording & retention
How long recorded sessions are kept. Three windows, each in days — 0 means keep forever:
| Setting | What it deletes when older than the window |
|---|---|
| SSH transcript days | The typed-command transcripts of terminal sessions. |
| Desktop recording days | The RDP/VNC replay files. |
| Session record days | The whole ended/error session entry and anything left with it. |
With a window set, a housekeeping pass removes anything older — this is the only thing that overwrites old recordings. Below the form you'll see the live footprint (transcript rows, replay files and disk used, prunable entries) and a button to run the clean-up now.
8.4 Approvals
The defaults for dual control:
| Setting | What it does |
|---|---|
| Minimum approver role | Who is allowed to decide a request (operator, admin, or owner). |
| Allow self-approval | When off, a requester can never approve their own request (separation of duties). |
The per-request “N-of-M” quorum (e.g. any 2 of 3) is chosen when a request is created; this panel is the baseline.
8.5 Break-glass
Guardrails for emergency access:
| Setting | What it does |
|---|---|
| Require approval to activate | When on, an emergency grant must clear dual-control first. |
| Max grant duration (minutes) | A hard cap on how long any break-glass grant can live (5–1440). |
8.6 Automation
Two global switches for background work:
| Setting | What it does |
|---|---|
| Scheduled rotation | Auto-rotate credentials on each account's policy cadence. |
| Scheduled verification | Periodically re-check that vaulted credentials still authenticate. |
Turn these off to pause all background rotation and verification across the system.
8.7 Integrations (SIEM / Syslog egress)
Forward the tamper-evident audit chain (including each row's hash) to your SIEM. Off by default.
| Setting | What it does |
|---|---|
| Type | Syslog (RFC-5424) or Splunk HEC. |
| Host / Port | Where to send the events. |
| Protocol | UDP or TCP for Syslog (Splunk HEC always uses HTTPS). |
| HEC token | The Splunk token, stored encrypted. |
A Send test event button confirms the pipe is working. The Connectors screen offers the fuller integration view.
8.8 Email notifications (SMTP)
Send email alerts when selected events occur (approvals, break-glass, rotations, sessions, and more). A burst of events is coalesced into a single digest. Off by default.
| Setting | What it does |
|---|---|
| SMTP host / Port | Your mail relay. |
| Transport | STARTTLS (587), TLS/SSL (465), or none. The encrypted options verify certificates by default. |
| Username / Password | Optional — leave blank for an unauthenticated relay. The password is stored encrypted. |
| From address | The sender shown on alerts. |
| Recipients | Comma-separated, up to 50 addresses. |
| Notify on these events | Tick which events trigger an email. |
| Skip TLS verification | Only for an internal relay with a self-signed certificate — otherwise leave off. |
Use Send test email to confirm delivery. (Real-time machine-to-machine notifications go on the Webhooks screen instead.)
There is also a small Shortcuts panel with quick links to the screens you visit most.
9. Single sign-on (SSO) ↑ top
SSO lets your people sign in to NOVA PAM with the identity provider you already use — Microsoft Entra ID / Azure AD, Okta, Google, Keycloak, Auth0, Ping, or on-prem AD via AD FS — anything that speaks OpenID Connect (OIDC). Once it's on, a “Sign in with …” button appears on the login page.
Configure it under Settings → Single sign-on (Admin or Owner).
Set it up
- Turn Enabled on. Set a Display name (the text on the button) and a Provider id (a short URL slug like
azure). - Copy the Redirect URI shown on screen and register it exactly at your identity provider. It looks like:
https://<your-pam-address>/api/auth/sso/<provider-id>/callback - Paste the Issuer URL. NOVA PAM auto-discovers everything else from
<issuer>/.well-known/openid-configuration. Then paste the Client ID and Client secret from the provider. - If the PAM sits behind a proxy or TLS, set the Public base URL (this is what builds the redirect URI). Optionally restrict Allowed email domains, set a Default role for new users, and choose whether to Auto-provision accounts on first sign-in.
- (Optional) Fill in the Group → role mapping — one
IdP-group=roleper line; the highest-ranked match wins. - Click Test discovery to confirm NOVA PAM can reach the provider, then Save.
The fields, in plain English
| Field | What it's for |
|---|---|
| Issuer URL | Your provider's OIDC address; NOVA PAM reads its discovery document from here. |
| Client ID / Client secret | The app credentials you create at the provider. The secret is stored encrypted and never shown again. |
| Redirect URI | The exact return address to register at the provider (shown on screen with a Copy button). |
| Allowed email domains | Only these email domains may sign in (blank = any). |
| Default role | The role a new federated user gets when no group matches. |
| Auto-provision | Create a PAM account on first sign-in (off = only pre-existing accounts may use SSO). |
| Group → role mapping | Map provider groups to NOVA PAM roles; highest match wins (never Owner). |
| Advanced: claim names | The username / email / groups claim names, if your provider uses non-standard ones. |
Provider quick-reference
| Provider | Issuer URL | Notes |
|---|---|---|
| Microsoft Entra ID / Azure AD cloud Active Directory | https://login.microsoftonline.com/<tenant-id>/v2.0 | Register a Web app, add the redirect URI, create a client secret. For role mapping, add the optional groups claim and use group object-IDs or names. |
| On-prem AD via AD FS | https://<adfs-host>/adfs | Add an OpenID Connect application group; add an issuance rule that emits group membership into the groups claim. |
| Okta | https://<your-org>.okta.com | Create an OIDC Web app; add a “groups” claim to the ID token if you map roles. |
| Google Workspace | https://accounts.google.com | Create an OAuth Web client; restrict with Allowed email domains. Google doesn't emit groups, so use the Default role. |
| Keycloak / Auth0 / Ping | the realm/tenant issuer | Create a confidential OIDC client with the Authorization Code flow; ensure a groups/roles claim is in the ID token for role mapping. |
10. Active Directory & LDAP sign-in ↑ top
This lets people sign in to NOVA PAM with their existing on-prem Active Directory / LDAP username and password, through a direct, encrypted LDAPS connection to a domain controller — no separate identity provider needed. A “Sign in against …” selector appears on the login page.
Configure it under Settings → Directory (LDAP/AD) (Admin or Owner).
Set it up
- Turn Enabled on, set a Display name (what users pick on the login page) and a Connection id.
- Enter the LDAP URL — it must be
ldaps://…:636. (A password must never cross a plaintext connection.) - Choose a Bind mode:
- Search (recommended) — give a read-only Service bind DN and password, a Base DN to search under, and the Login attributes the typed username is matched against (e.g.
sAMAccountName, userPrincipalName). NOVA PAM looks the user up, then binds as them to check the password. - Template — skip the service account and build the user's DN directly with a User DN template using
{username}, e.g.{username}@corp.example.com.
- Search (recommended) — give a read-only Service bind DN and password, a Base DN to search under, and the Login attributes the typed username is matched against (e.g.
- Set a Default role and whether to Auto-provision accounts on first sign-in.
- (Optional) Group → role mapping — one
group=roleper line, by group CN or full DN; highest match wins. - Save. The directory now appears in the login-page selector.
The fields, in plain English
| Field | What it's for |
|---|---|
| LDAP URL | The domain controller, e.g. ldaps://dc1.corp.example.com:636. LDAPS is required. |
| Bind mode | Search = a service account finds the user then binds as them; Template = build the user DN directly. |
| Service bind DN / password | (Search mode) a read-only account that can search the directory. Password stored encrypted. |
| Base DN | (Search mode) where to look for users, e.g. DC=corp,DC=example,DC=com. |
| Login attributes | (Search mode) which attributes the typed username may match, e.g. sAMAccountName, userPrincipalName. |
| User DN template | (Template mode) e.g. {username}@corp.example.com. |
| Default role / Auto-provision | The role for new directory users, and whether to create accounts on first sign-in. |
| Group → role mapping | Map directory groups (CN or DN) to roles; highest match wins (never Owner). |
| Advanced | The mail, display-name, stable-id (objectGUID on AD), and groups (memberOf) attributes, plus TLS verification (on by default). |
11. License & subscription ↑ top
The License screen (in the Governance group) shows what your subscription includes and lets an Owner install or renew it. It is read-only for everyone else.
What it shows
| Item | Meaning |
|---|---|
| Edition / tier | Which edition of NOVA PAM you're licensed for. |
| User seats | How many people can have accounts. |
| Device limit | How many target accounts/secrets you can manage. |
| Expiry & grace | When the subscription renews, and any grace period after that date. |
| License ID | The identifier for this subscription, useful when contacting support. |
Install or renew the license
- Your provider gives you a license file (a small
.novalicense.jsonfile). - On the License screen, an Owner clicks Install / renew license and pastes or uploads that file.
- NOVA PAM checks the file's digital signature and applies the new entitlement immediately — no restart.
- Use Sync at any time to refresh your current entitlement (for example after a renewal).
12. Supported systems ↑ top
NOVA PAM manages a very wide range of systems. The lists below are the main categories.
12.1 Devices & servers
| Category | Examples | How NOVA PAM connects |
|---|---|---|
| Linux / Unix servers | RHEL, CentOS, Ubuntu, Debian, Rocky, AlmaLinux, SUSE, Solaris, HP-UX, AIX | SSH (recorded), password & key rotation |
| Windows servers & desktops | Windows Server 2016–2022, Windows 10/11 | RDP (recorded), WinRM password rotation |
| Hypervisors | VMware ESXi, Microsoft Hyper-V, Nutanix AHV | SSH rotation, vCenter/Prism integration |
| Network & security appliances | Cisco IOS, Palo Alto, FortiGate, Check Point, Juniper, F5 BIG-IP, Ruckus | SSH CLI rotation (enable/admin credentials) |
| Lights-out management | HP iLO, Dell iDRAC, IBM HMC, Sun ALOM, Cisco UCS | SSH CLI rotation |
| Storage | NetApp, Dell EMC | SSH CLI rotation |
| Mainframe & legacy | IBM z/OS, AS/400, OpenVMS, HPE NonStop | Terminal console framework, SSH brokering |
| Containers & orchestration | Kubernetes, OpenShift | Service-account token management |
12.2 Databases
| Database | Capabilities |
|---|---|
| PostgreSQL | ConsoleGatewayRotation |
| MySQL / MariaDB | ConsoleGatewayRotation |
| Oracle Database | ConsoleRotation |
| Microsoft SQL Server | ConsoleRotation |
| MongoDB | ConsoleRotation |
| Redis | ConsoleRotation |
| IBM Db2, Sybase ASE, Informix, Teradata | Rotation |
| Snowflake, MongoDB Atlas | Key / API rotation |
| Any ODBC 2.7+ database | Rotation |
12.3 Cloud
| Platform | What you can do |
|---|---|
| Amazon Web Services (AWS) | One-click browser console sign-in, just-in-time CLI credentials, IAM access-key rotation |
| Microsoft Azure | Just-in-time access tokens, Service-Principal secret rotation (Microsoft Graph) |
| Google Cloud (GCP) | Just-in-time access tokens, service-account key rotation |
| Google Workspace | Admin access via short-lived, scoped tokens |
12.4 Full platform catalogue
Beyond the above, NOVA PAM can vault and rotate credentials for a broad ecosystem of tools and services:
Cloud & DevOps
AWSAzureGCPGoogle WorkspaceKubernetesOpenShiftHashiCorp VaultJenkinsGitLabDatadogHarborCloudflareGrafanaDockerTerraformAnsibleAzure DevOpsGitHub Actions
Directory & identity
Active DirectoryOpenLDAPOracle Internet DirectoryeDirectorySunOne Directory
Multi-factor & SSO
RADIUSSAML 2.0OpenID ConnectRSA SecurIDDuoOktaYubiKeyThales HSM
Enterprise applications
SAP NetWeaverSAP S/4HANASalesforceMicrosoft 365ServiceNowTwilioJira
Monitoring & SIEM (audit forwarding)
SplunkIBM QRadarSumo LogicSyslog (RFC 5424)
Custom systems — web forms, scripts, and flat config files (.ini/.xml) — are also supported through credential injection.
13. Security & compliance ↑ top
Strong encryption
Every secret is encrypted at rest with AES-256-GCM. Session tokens are stored only as one-way hashes — a database copy reveals nothing usable.
Two-factor, SSO & AD
Built-in two-factor authentication, plus sign-in via your existing directory (LDAP/AD) or single sign-on (OIDC) — neither of which can ever grant Owner.
Least privilege
Role-based access plus per-account Access Groups mean people see only what they need — and just-in-time elevation removes standing privilege.
Dual control
Require a second approver (or several) before sensitive reveals and sessions — with break-glass for emergencies.
Tamper-evident audit
Every action is chained into a tamper-evident log, and can be forwarded to your SIEM in real time.
Full session recording
SSH, RDP, VNC, and database sessions are recorded and replayable — clear evidence of exactly what happened.
Together these support common compliance goals such as PCI-DSS, ISO 27001, SOC 2, HIPAA, and NIST — by enforcing least privilege, recording privileged activity, and proving it with an immutable audit trail.
14. Quick answers (FAQ) ↑ top
Do users ever see the real passwords?
No — by default they connect through NOVA PAM, which injects the credential. Revealing a password is a separate, controllable action that you can require approval for.
Can people sign in with our company accounts?
Yes. Use single sign-on (SSO) for cloud identity providers like Microsoft Entra/Azure AD, Okta, or Google, or directory sign-in for a direct connection to your on-prem Active Directory. Either way, the local Owner account always keeps its own password.
What if I lose my administrator password?
Another Owner or Admin can reset it from the Users screen. Always keep at least two administrator accounts.
Do I need to install anything on users' computers?
No. Everything runs in the web browser, including RDP and VNC.
My antivirus flagged NOVA PAM — is that a problem?
No. Because NOVA PAM opens admin sessions and injects passwords, antivirus and Windows SmartScreen may flag a brand-new install — that's expected for any privileged-access tool. Add the install folder as a trusted exclusion as shown in 4.2 Allow NOVA PAM through your antivirus.
How do I add or renew my license?
On the License screen, an Owner installs the license file your provider gave you; it applies immediately with no restart.
Does it keep working if the network has a hiccup?
Yes — NOVA PAM runs on your own Windows server and keeps operating. The Windows service restarts automatically after a reboot or a crash.
How do I give a contractor temporary access?
Use Sessions → Remote Access to issue a time-boxed, code-protected link to a single machine. It expires on its own and is fully recorded.
Where are my recordings and backups kept?
On your own server, in the data folder. Use Backup to make encrypted copies and store them safely off the machine; how long recordings live is set under Settings → Recording & retention.