Product · Privileged access (PAM)
Privileged access without a single password to share.
Your administrators and vendors access servers, databases, and Kubernetes when needed, with their identity, from their device, and from an authorized location. No VPN, no shared accounts, and every session recorded. Included in Ironchip Premium.
- Who
- External technician · maintenance
- Destination
- prod-db-01 · PostgreSQL
- Window
- 2 hours, today
- Reason
- "Billing index adjustment"
- Registered device
- From their safe zone
- No identity alerts
Approved · window open until 13:00
What changes for your team from day one.
Audits with evidence
Each session is recorded with who requested it, who approved it, where it was accessed from, and what was executed. What ENS, NIS2, or DORA require, without screenshots.
Vendors without shared accounts
The external technician accesses with their identity, on their device, and in their time window. When done, access disappears automatically.
No VPN or open ports
Ironchip Connect exits from your network toward Ironchip. Your servers are not published to the internet, not even to us.
A stolen credential opens nothing
Without the registered device, without the authorized location, and without approval, an intercepted username and password are useless.
Passwords no one knows
They are set on login and changed on logout. No one types them, no one copies them, and no one takes them when changing companies.
On top of what you already have
The same directory, the same console, and the same factors that Ironchip already uses to protect your applications.
The vault protects the secret. We keep it out of the way.
No one types or sees a privileged credential. Access is decided at the moment, with context, and what the system needs to connect is stored encrypted and rotated beyond reach.
| Traditional PAM | Ironchip PAM | |
|---|---|---|
| Privileged credentials | Stored in vault, shared by checkout | No one sees them: the broker supplies them at connection time and can rotate them after each session |
| Privileges | Permanent or by checkout | Just-in-Time: an approved window that closes on its own |
| Remote access | VPN + jump server | Browser or your own client (ssh, psql, kubectl) with a single-use ticket |
| If the login is stolen | Access to the vault and everything it contains | Without the device, safe zone, and access factors, it does not open |
| Network | Published inbound ports or VPN | Outbound only: Ironchip Connect opens the tunnel from inside |
| Deployment | Multi-month project | On top of the IdP, directory, and console you already have |
A single path to each machine, and Ironchip decides at each step.
The person requests access in the console and connects with a single-use ticket. The broker holds the connection while Ironchip checks device, location, risk, and approval; only then does it set the credential and start recording.
- 01The person requests access in the console, in My access, with a reason if the policy requires it.
- 02Connects with a single-use ticket, from the browser or with their own client.
- 03The broker holds the connection and asks Ironchip: access, factors, risk, and approval.
- 04If approved, the broker reads the credential from the store. The person never sees it.
- 05Opens the session and records it from start to finish.
- 06The agent reports and receives rules over HTTPS. With Ironchip Connect, your network opens no inbound port.
Just-in-time approval, at the moment you choose.
No one approves their own request or the same one twice, and the window closes automatically. The approval also counts as a factor for your SSO applications.
One approval opens a window.
- requests
- approve
- window open
- connects
- connects
- connects
- closes by itself
Within the window the person enters as many times as they want. Each connection still goes through the broker and through factor and risk checking.
Each connection is held until they decide.
- requests
- connects: held
- approve this connection
- enters
- another connection: waits
The approver sees this person, from this address, right now. It's the mode for machines where each entry counts.
Each session, with its full history.
Screen, commands, and decisions on a single timeline. You can watch it live, stop it instantly, and save it as evidence.
$ psql -h prod-db-01 billing billing=# REINDEX TABLE invoices; REINDEX billing=# \q $ sudo systemctl restart billing-api ⏸ Held by Ironchip: requires approval ✓ Approved by the systems administrator
- Connection allowedDevice, safe zone, and risk correct · approved by the systems administrator
- Process startedpsql, detected by the device agent
- sudo heldsystemctl restart billing-api, awaiting approval
- sudo approvedLogged who authorized it and which rule applied
- Session closedRecording saved · password changed
Ironchip Connect: we reach your machines without opening a single door.
A lightweight connector inside each site opens an encrypted outbound tunnel toward Ironchip. Through it, and only through it, arrives the broker.
- server
10.0.0.5 - database
10.0.0.8
- server
10.0.0.5 - desktop
10.0.0.9
The same vault, also for applications and clouds.
Applications and pipelines
Compatible with the Vault API: your code and CI read its secrets from Ironchip without changing a line, with database credentials that expire automatically.
Passwords for people
A manager for what must be known, like the router at a head office. It's shared by groups and every time someone reveals it, it's recorded.
AWS, Google Cloud, and Azure consoles
Protected with Ironchip's SSO and on-demand temporary credentials, instead of eternal keys distributed across laptops.
Frequently asked questions about privileged access
What does a PAM without shared passwords mean?
That people enter servers, databases and Kubernetes without knowing or typing the credential. Ironchip supplies it at connect time, can change it when the session ends, and no one takes it when they change companies.
How do I give access to an external vendor without a VPN?
The vendor requests access to a specific machine, an approver approves it, and they enter via the browser or their own client during a time window. The session is recorded and access closes when the window ends.
Do I need to open firewall ports?
No. Ironchip Connect is installed within each site and opens an encrypted outbound tunnel to Ironchip. Servers are not published on the internet.
Can a session be monitored or terminated in real time?
Yes. Terminal and desktop sessions are fully recorded, can be viewed as they happen, and terminated instantly. Each sudo or program executed is on the same timeline.
What systems does it cover?
SSH, RDP, VNC, PostgreSQL, MySQL and Kubernetes, from the browser or with standard clients. The Ironchip agent also controls which commands and programs are executed on Linux, macOS and Windows.
Start with your 20 most critical accounts.
A pilot on the servers and accounts that concern you most, with your existing IdP and directory.
What we need for the pilot
- The privileged accounts that concern you most
- A place to install Ironchip Connect
- Who approves each system
- A third-party vendor to test the complete flow