The Platform
A governed access plane, not another jump box.
Vaultris consolidates every privileged route into your protected network behind one authenticated, policy-driven, fully recorded gateway — deployable on-premises, in your cloud, or fully air-gapped.
Access Lifecycle
What happens between "I need access" and "the session is closed."
Identify
The operator authenticates to Vaultris as a named individual — never a shared or generic account — against your existing directory: Active Directory, LDAP, SAML, or OIDC.
Verify
A second factor is enforced at the gateway: TOTP, FIDO2 hardware key, PIV/CAC smart card, or push approval. No downstream asset is reachable until it clears.
Authorize
Policy resolves what this person may reach, on which asset, using which account, for how long — and whether a named approver must release it first.
Broker
The gateway opens the connection using a vaulted credential the operator never sees. The target accepts traffic from the gateway's private address only.
Record
The full session is captured — keystrokes, commands, file transfers, screen replay — indexed and written to tamper-resistant storage as it happens.
Expire
Idle timeout closes the session, the entitlement lapses on schedule, and the vaulted credential rotates. Nothing stays open because someone forgot to close it.
Credential Vault
Production passwords stop travelling.
The most durable fix for credential theft is making sure the credential is never in a place it can be stolen from. Vaultris holds target secrets in an encrypted vault and injects them at connection time.
- Encrypted at rest and in transit, with hardware security module integration where required.
- Automatic rotation on schedule, on release, or on demand after an incident.
- Zero credential disclosure — operators work productively without ever reading a production password.
- Service account governance so automation credentials are inventoried, scoped, and rotated like human ones.
- Emergency revocation that invalidates an operator's reach across every asset at once.
- Built-in risk detection — stale privileged secrets, missing secrets, dormant and widely granted credentials, ranked and named.
Session Assurance
If it happened on your network, you can watch it back.
Session recording turns privileged access from an act of trust into a matter of record. Every session is replayable, searchable, and attributable — which changes both investigation and behaviour.
- Video-style replay of graphical sessions, plus full keystroke and command transcripts for terminal sessions.
- Command indexing so you can search for a destructive command across months of sessions in seconds.
- Immutable storage with write-once retention and SIEM forwarding, so records survive the incident they document.
- Live session monitoring with the ability to join, take over, or terminate a session in progress.
- Command guardrails that block or require approval for defined high-risk operations before they execute.
Protocol Coverage
One gateway for every way your team connects.
Protocol-aware brokering means the audit trail records what was actually done — not merely that a tunnel was opened.
| Category | Protocols & Targets | Audit Depth |
|---|---|---|
| Linux & Unix | SSH, SFTP, SCP, Telnet | Full keystroke transcript, command index, file transfer log |
| Windows | RDP, WinRM, SMB file access | Screen replay, window title index, clipboard & transfer control |
| Remote Desktop | VNC, X11 forwarding | Screen replay with session metadata |
| Databases | MySQL, MariaDB, PostgreSQL, Oracle, SQL Server, MongoDB, Redis | Statement-level capture, result-set masking, query approval |
| Containers | Kubernetes exec, kubectl, container shells | Namespace-scoped policy, full exec transcript |
| Network & OT | Switch, router, firewall CLI; jump-mediated OT/SCADA consoles | Command transcript with configuration-change flagging |
| Web & Cloud | Cloud consoles and internal web admin panels via brokered browser | Session replay with navigation trail |
Network devices are configurations, not just shells. For Cisco IOS and MikroTik RouterOS the gateway captures the running configuration before and after every session — secrets masked — diffs it against an approved baseline, and can roll a stored configuration back. Rollback is never automatic: it demands re-authentication, the device name typed out, a written reason, and passes a pre-flight check that warns if the restore would drop the management address or the default route. How drift and rollback work →
Deployment Models
Deployed where your data and your rules require.
On-Premises
Runs entirely inside your datacenter on your hardware or hypervisor. No dependency on an external control plane.
Private Cloud
Deployed into your own VPC or tenancy with cloud-native high availability, autoscaling relays, and managed storage backends.
Sovereign / Regional
Pinned to a jurisdiction where residency rules, national security policy, or contract terms require data to remain in-country.
Air-Gapped
Fully disconnected operation for classified and isolated enclaves, with offline update bundles and local evidence retention.
Cross-site reach without inbound holes. Remote datacenters, precinct networks, station houses, vessels, and cloud VPCs run a lightweight relay that dials outbound to the control plane over an authenticated tunnel. Bringing a new segment under policy never requires a new inbound firewall exception or a site-to-site VPN.
Resilience
A chokepoint must never become a failure point.
Concentrating access into one gateway is only responsible if that gateway is engineered to survive. Vaultris deployments are designed around the assumption that something will eventually break.
- Active-active clustering across availability zones or physical sites with health-checked failover.
- Replicated vault and audit storage so evidence and secrets survive the loss of any single node.
- Rehearsed break-glass — dual-authorised, time-boxed, alarm-raising emergency access that is tested on a schedule, not improvised during an outage.
- Degraded-mode operation that keeps existing sessions alive and continues recording if the control plane is unreachable.
- Documented recovery runbooks validated during commissioning and re-validated at each major change.
$ vaultris cluster status CONTROL PLANE HEALTHY 3/3 nodes gw-core-a online leader uptime 214d gw-core-b online follower uptime 214d gw-core-c online follower uptime 96d SITE RELAYS HEALTHY 6/6 connected dc-east outbound tunnel rtt 4ms dc-west outbound tunnel rtt 41ms precinct-north outbound tunnel rtt 18ms station-12 outbound tunnel rtt 22ms eoc-primary outbound tunnel rtt 9ms cloud-vpc-1 outbound tunnel rtt 12ms AUDIT STORE SEALED replicated x3 BREAK-GLASS armed last drill 27d ago
Fits What You Run
Integrated with the stack already in place.
Identity
Active Directory, LDAP, SAML 2.0, OIDC, and SCIM provisioning — so joiners, movers, and leavers are reflected in access rights automatically.
Monitoring
Syslog, CEF, and JSON event streams into Splunk, Elastic, QRadar, Sentinel, or any SIEM, plus metrics endpoints for your existing observability stack.
Service Management
Change-ticket binding so a privileged session can require a valid open ticket, and the ticket carries the session recording as its evidence.
Secrets & PKI
Integration with existing HSMs, enterprise certificate authorities, and secret stores rather than forcing a parallel key hierarchy.
Automation
REST API and CLI for asset onboarding, entitlement grants, and evidence export — so access governance can live in your pipelines.
Notification
Approval requests and anomaly alerts routed to email, SMS, mobile push, or your existing on-call paging platform.
Next Step
See it against your own architecture.
We will walk your current access paths, show where the gateway sits, and be direct about what it does and does not solve.