Product · Privileged access (PAM)

Privileged access without a single password to share.

Your administrators and vendors access servers, databases, and Kubernetes when needed, with their identity, from their device, and from an authorized location. No VPN, no shared accounts, and every session recorded. Included in Ironchip Premium.

Access requestExpires at 14:59
Who
External technician · maintenance
Destination
prod-db-01 · PostgreSQL
Window
2 hours, today
Reason
"Billing index adjustment"
  • Registered device
  • From their safe zone
  • No identity alerts
DenyApprove

Approved · window open until 13:00

What changes for your team from day one.

Audits with evidence

Each session is recorded with who requested it, who approved it, where it was accessed from, and what was executed. What ENS, NIS2, or DORA require, without screenshots.

Vendors without shared accounts

The external technician accesses with their identity, on their device, and in their time window. When done, access disappears automatically.

No VPN or open ports

Ironchip Connect exits from your network toward Ironchip. Your servers are not published to the internet, not even to us.

A stolen credential opens nothing

Without the registered device, without the authorized location, and without approval, an intercepted username and password are useless.

Passwords no one knows

They are set on login and changed on logout. No one types them, no one copies them, and no one takes them when changing companies.

On top of what you already have

The same directory, the same console, and the same factors that Ironchip already uses to protect your applications.

The vault protects the secret. We keep it out of the way.

No one types or sees a privileged credential. Access is decided at the moment, with context, and what the system needs to connect is stored encrypted and rotated beyond reach.

Traditional PAMIronchip PAM
Privileged credentialsStored in vault, shared by checkoutNo one sees them: the broker supplies them at connection time and can rotate them after each session
PrivilegesPermanent or by checkoutJust-in-Time: an approved window that closes on its own
Remote accessVPN + jump serverBrowser or your own client (ssh, psql, kubectl) with a single-use ticket
If the login is stolenAccess to the vault and everything it containsWithout the device, safe zone, and access factors, it does not open
NetworkPublished inbound ports or VPNOutbound only: Ironchip Connect opens the tunnel from inside
DeploymentMulti-month projectOn top of the IdP, directory, and console you already have

A single path to each machine, and Ironchip decides at each step.

The person requests access in the console and connects with a single-use ticket. The broker holds the connection while Ironchip checks device, location, risk, and approval; only then does it set the credential and start recording.

PersonBrowser, or their own client: ssh, psql, mysql, RDP, VNC, kubectl.Your network
Ironchip consoleAccess, factors, approvals, location, risk, and recordings. The same platform console.Ironchip
Ironchip PAM brokerThe only entry point: holds each connection, supplies the credential, and records the session.Ironchip
Secrets storeCredentials and secrets encrypted, each company in its own space. The broker reads and keeps no copy.Ironchip
Your machinesServers, desktops, databases, and Kubernetes. With Ironchip's agent, optional, which only opens outbound connections.Your network
  1. 01The person requests access in the console, in My access, with a reason if the policy requires it.
  2. 02Connects with a single-use ticket, from the browser or with their own client.
  3. 03The broker holds the connection and asks Ironchip: access, factors, risk, and approval.
  4. 04If approved, the broker reads the credential from the store. The person never sees it.
  5. 05Opens the session and records it from start to finish.
  6. 06The agent reports and receives rules over HTTPS. With Ironchip Connect, your network opens no inbound port.
SSHRDPVNCPostgreSQLMySQLKubernetesFrom the browser or with your usual client

Just-in-time approval, at the moment you choose.

No one approves their own request or the same one twice, and the window closes automatically. The approval also counts as a factor for your SSO applications.

On request: approved once

One approval opens a window.

  1. requests
  2. approve
  3. window open
  4. connects
  5. connects
  6. connects
  7. closes by itself

Within the window the person enters as many times as they want. Each connection still goes through the broker and through factor and risk checking.

On connect: each connection asks

Each connection is held until they decide.

  1. requests
  2. connects: held
  3. approve this connection
  4. enters
  5. another connection: waits

The approver sees this person, from this address, right now. It's the mode for machines where each entry counts.

Each session, with its full history.

Screen, commands, and decisions on a single timeline. You can watch it live, stop it instantly, and save it as evidence.

Liveprod-db-01PostgreSQL · external technician · 00:42:18End session
$ psql -h prod-db-01 billing
billing=# REINDEX TABLE invoices;
REINDEX
billing=# \q
$ sudo systemctl restart billing-api
⏸ Held by Ironchip: requires approval
✓ Approved by the systems administrator
  1. Connection allowedDevice, safe zone, and risk correct · approved by the systems administrator
  2. Process startedpsql, detected by the device agent
  3. sudo heldsystemctl restart billing-api, awaiting approval
  4. sudo approvedLogged who authorized it and which rule applied
  5. Session closedRecording saved · password changed
Linux and macOS: each sudo asksIt is allowed, denied with a reason, or held until someone approves it.
Windows: permitted programs onlyRules by program applied with AppLocker during the session, even if renamed.
Live monitoringWho is in, which machine, and from where, with the option to terminate the session instantly.

Ironchip Connect: we reach your machines without opening a single door.

A lightweight connector inside each site opens an encrypted outbound tunnel toward Ironchip. Through it, and only through it, arrives the broker.

Your site · Madrid
  • server 10.0.0.5
  • database 10.0.0.8
Ironchip Connect
Ironchip Ironchip PAM broker. Authorizes the networks of each site.
Another company
  • server 10.0.0.5
  • desktop 10.0.0.9
Ironchip Connect
No inboundYour network publishes no ports. The connector only opens outbound connections.
Your ranges, no conflictsEven if another company uses the same private addresses, each site follows its own path.
Direct when possibleIf the network allows it, the tunnel goes direct; if not, it passes through a relay without losing encryption.

The same vault, also for applications and clouds.

Applications and pipelines

Compatible with the Vault API: your code and CI read its secrets from Ironchip without changing a line, with database credentials that expire automatically.

Passwords for people

A manager for what must be known, like the router at a head office. It's shared by groups and every time someone reveals it, it's recorded.

AWS, Google Cloud, and Azure consoles

Protected with Ironchip's SSO and on-demand temporary credentials, instead of eternal keys distributed across laptops.

Frequently asked questions about privileged access

What does a PAM without shared passwords mean?

That people enter servers, databases and Kubernetes without knowing or typing the credential. Ironchip supplies it at connect time, can change it when the session ends, and no one takes it when they change companies.

How do I give access to an external vendor without a VPN?

The vendor requests access to a specific machine, an approver approves it, and they enter via the browser or their own client during a time window. The session is recorded and access closes when the window ends.

Do I need to open firewall ports?

No. Ironchip Connect is installed within each site and opens an encrypted outbound tunnel to Ironchip. Servers are not published on the internet.

Can a session be monitored or terminated in real time?

Yes. Terminal and desktop sessions are fully recorded, can be viewed as they happen, and terminated instantly. Each sudo or program executed is on the same timeline.

What systems does it cover?

SSH, RDP, VNC, PostgreSQL, MySQL and Kubernetes, from the browser or with standard clients. The Ironchip agent also controls which commands and programs are executed on Linux, macOS and Windows.

Start with your 20 most critical accounts.

A pilot on the servers and accounts that concern you most, with your existing IdP and directory.

What we need for the pilot

  • The privileged accounts that concern you most
  • A place to install Ironchip Connect
  • Who approves each system
  • A third-party vendor to test the complete flow