Introduction
Quick Start
GuardVault is an open-core Privileged Access Management (PAM+) platform. One control plane unifies asset discovery, credential vaulting, session brokering, command-level authorization and immutable auditing across servers, databases, network devices, Kubernetes and cloud consoles.
Who GuardVault is for#
- Platform and SRE teams standardizing SSH, RDP and kubectl access across fleets.
- Security teams enforcing zero standing privilege, 4-eyes review and just-in-time credentials.
- Compliance owners producing evidence for SOC 2, ISO 27001, PCI-DSS and HIPAA audits.
What you get out of the box#
| Capability | Included | Notes |
|---|---|---|
| SSH / RDP / VNC / K8s / DB proxy | Yes | Frame-perfect recording |
| Credential vault + rotation | Yes | Static + dynamic secrets |
| Approval workflows | Yes | Single / dual / quorum |
| SIEM streaming | Yes | Splunk · Datadog · Elastic · Loki |
| Terraform + Pulumi | Yes | Fully declarative |
| Air-gapped install | Enterprise | Signed tarball + cosign |
GuardVault ships as a self-hosted control plane. Your team owns the crypto material, the audit log and the session recordings — GuardVault Inc. never sees them.