Skip to main content
Dark Pools product · Self-hosted privileged access management

Find every privileged account, control its use and record what happens

GovPAM finds the privileged accounts in your estate, takes custody of their credentials, grants access for a set period and records what administrators and suppliers do with it. It runs on infrastructure you control, from a single Linux server to segmented and fully air-gapped networks, with no dependency on a vendor cloud.

Visit govpam.com
WHO CONNECTSGOVPAMPRIVILEGED TARGETSAdministratorsSuppliersAuditors (read-only)01Sign-in and MFADirectory or SSO02Just-in-time grantApproved, time-bound03Credential vaultRotated, never shown04Access gatewayCredential injected05Session recordingReplay, export, SIEMLinux and UnixWindowsDatabasesNetwork devicesKubernetesWeb applicationsCredentials are injected at the gateway, so people never see them,and every session is kept with the approval that allowed it.
Overview

What GovPAM does

Privileged access accumulates faster than inventories record it: cloned local administrator accounts, service accounts with domain rights, supplier VPN profiles that outlive the contract and passwords passed around by email. GovPAM starts by sweeping servers, databases and network devices for local and privileged accounts, and flags the ones that are new, changed or unmanaged. Enrolled accounts move into an encrypted vault, their secrets are rotated to policy, and from then on people connect through GovPAM using the vaulted credential instead of knowing it.

Access is granted as an authorization scoped to a person, an asset, an account and a protocol, for a set period. Users request what they need through self-service, approvers sign off in one or more steps, and critical systems can require a fresh approval at the moment of connection. Access gateways broker SSH, SFTP, RDP, VNC, Telnet, database, Kubernetes and web application sessions, inject the credential, enforce command and data controls and record the session, so an auditor can replay what happened next to the approval that allowed it.

GovPAM is built for institutions that cannot hand privileged access to a vendor-operated service. It is agentless, installs on Linux in your own data center, private cloud or public-cloud tenancy, and runs fully air-gapped from an offline bundle. Credentials, recordings, audit records and keys stay in your environment. It pairs with KeyCare Pass, the password manager for everyday staff credentials, so privileged and non-privileged secrets are governed by products from the same family.

Capabilities

Built in, not bolted on

Privileged account discovery

Scheduled sweeps find the local and privileged accounts that were never enrolled, so the vault starts from what exists on the estate rather than from what was documented.

  • Sweeps of servers, databases and network devices on a schedule you set
  • New, changed and unmanaged accounts flagged for review
  • Assets organized in a tree by site, zone and platform
  • Bulk import of an existing asset inventory

Credential vault and rotation

Passwords, SSH keys and tokens are held encrypted at rest and used on a person’s behalf. Rotation runs on a schedule, on demand or when someone’s access ends.

  • Gateways inject the vaulted credential, so users connect without seeing it
  • Strong random secrets generated to policy at every rotation
  • Accounts pushed, verified and removed on hosts, databases and devices, with every run reported and failures surfaced
  • Account templates for consistency and scheduled, encrypted backups of vaulted accounts

Just-in-time access and approvals

Standing administrator rights give way to authorizations scoped to a user, asset, account and protocol, valid for a set period and then gone.

  • Grants with start and end dates that expire on their own
  • Self-service requests routed through multi-step approval
  • Approval at connection time for sensitive systems
  • Approvals stored with the sessions they authorized

Brokered remote access

One controlled route replaces exposed RDP, shared jump servers and opened database ports. More than a dozen protocols are brokered through access gateways, from a browser or an engineer’s own tools.

  • SSH, SFTP, RDP, VNC and Telnet sessions in the browser
  • MySQL, PostgreSQL, SQL Server, Oracle, MongoDB and Redis without shared database credentials
  • Kubernetes and web applications under the same authorizations and controls
  • An SSH gateway for engineers who prefer their own terminal
  • Gateways in each network zone reach segmented networks without exposing management ports

Session recording and audit evidence

Every brokered session is recorded and kept with its commands, file transfers and approvals, so evidence comes from the system that enforced the control.

  • Recordings searchable by person, system and time, with replay
  • Supervisors can watch a live session, join it or end it
  • Commands and file transfers logged per session
  • Sign-in, operation, password-change and session logs exported for assessors or forwarded to a SIEM over syslog
  • Recordings kept on the GovPAM server or in S3-compatible, Azure Blob or Ceph storage under your retention policy

Command and data controls

Policy is enforced inside the session as well as at sign-in, limiting what an administrator can run, see and move.

  • Risky commands blocked, flagged or held for approval
  • Sensitive database fields masked in live sessions
  • Copy, paste, upload and download allowed per authorization
  • Sign-in restricted by IP address and time of day

Identity, MFA and roles

GovPAM signs people in against the directory you already run and requires a second factor before any privileged session starts.

  • Microsoft Entra ID, Active Directory, LDAP, SAML 2.0, OpenID Connect, OAuth 2.0 and CAS
  • MFA by authenticator app (TOTP), FIDO2 passkey, RADIUS, email or SMS
  • Built-in and custom roles for administrators, operators and read-only auditors
  • Organizations that separate business units, customers or classifications

Privileged task automation

Routine administrative work runs as audited jobs across groups of servers instead of as interactive sessions on each one.

  • Commands or playbooks run across groups of servers
  • Jobs scheduled or run on demand
  • Runs scoped by the same permissions that govern sessions
  • Every run and its output kept for audit
How it works

GovPAM, step by step

  1. 01DiscoverScheduled sweeps of servers, databases and network devices list local and privileged accounts and flag those that are new, changed or unmanaged.
  2. 02Vault and rotateEnrolled accounts move into the encrypted vault. Their secrets are rotated to policy and verified on the target, so staff no longer know the current value.
  3. 03Sign in with MFAPeople authenticate against Entra ID, Active Directory, LDAP or single sign-on, then complete a second factor before any privileged session can start.
  4. 04Request accessAccess comes from an authorization or an approved request, scoped to an asset, account and protocol and limited to a set period.
  5. 05ConnectAn access gateway opens the session using the vaulted credential and applies command, clipboard and file-transfer controls while it runs.
  6. 06Record and proveThe session, its commands and file transfers are recorded and stored with the approval that allowed them, ready for replay, export or forwarding to your SIEM.
Security architecture

How your secrets are protected

  • Vaulted passwords, SSH keys and tokens are encrypted at rest and injected by the gateway at connection time, so the person connecting never handles the secret.
  • TLS protects the web console, web terminal and API, and MFA is enforced before any privileged session can start.
  • Agentless by design: sessions are brokered and recorded at the gateway, and nothing is installed on managed servers or on OT devices that cannot host software.
  • Management ports on target systems are reached from GovPAM gateways, not from user networks, so administrators work through one controlled route.
  • Suppliers and contractors sign in to GovPAM rather than to your network, with no directory accounts or VPN profiles to revoke when the engagement ends.
  • Role-based administration includes read-only auditor roles, and organizations separate business units, customers or classifications within one deployment.
  • There is no vendor cloud in the path: credentials, recordings, audit data and keys stay in your environment and your jurisdiction.
Deployment & editions

Run it the way your organization works

  • On-premises: installed on Linux servers in your data center, with the database and cache alongside GovPAM or on database servers you already operate
  • Private cloud or your own public-cloud tenancy. GovPAM is not offered as a vendor-hosted service
  • Hybrid and segmented estates: access gateways in each network zone let one deployment reach on-premises and cloud networks, so only GovPAM crosses the boundary
  • Fully air-gapped: installed from an offline bundle and run entirely inside an isolated network, for sovereign and classified environments
  • Single-server pattern for evaluations and smaller estates, starting from four vCPUs and 8 GB of memory. The same software scales to segmented estates without re-platforming
  • Quoted per estate on privileged users, managed systems, term, and the deployment and support required, with multi-year terms for public-sector budget cycles. Evaluations run on your own infrastructure under a time-limited license
Who it is for

Teams that rely on it

Government and public sector

Departments are audited on whether they can account for privileged access. GovPAM finds unenrolled administrator and service accounts, vaults them, turns access into an approval request and records the session, with sign-in through Entra ID, Active Directory or LDAP and data kept inside the department’s own environment.

Defense and national security

Closed networks need tools that run inside the enclave. GovPAM deploys air-gapped, keeps recordings and audit data inside it, requires approval at connection time for sensitive systems and separates programs or classifications into their own organizations.

Critical infrastructure and OT

Much OT equipment cannot run agents or take patches, and vendor engineers still need remote access. GovPAM brokers and records that access at a gateway placed in each segmented zone, time-bound and approved, without installing anything on the devices.

Financial services and healthcare

Banks get separation of duties enforced in the access path: multi-step approval for production, command controls and field masking in live sessions, and evidence for PCI DSS, DORA and SOC 2 testing. Clinical estates get pre-approved, recorded access through vaulted shared and emergency accounts, including for supplier engineers who are not in the directory.

Frameworks

Controls that support your obligations

GovPAM provides controls and evidence that help organizations meet these frameworks. Certification of your environment remains with your assessor.

  • ISO/IEC 27001:2022: privileged access rights (A.8.2), secure authentication (A.8.5), authentication information (A.5.17), and logging and monitoring (A.8.15, A.8.16)
  • NIST SP 800-53 Rev. 5: account management and least privilege (AC-2, AC-6), authenticator management (IA-5) and audit records (AU-2, AU-12)
  • PCI DSS v4.0: need-to-know access (7.2), MFA and system accounts (8.4, 8.6) and audit logs of administrative actions (10.2)
  • NIS2 and DORA: access control and MFA under NIS2 Article 21(2)(i) and (j), and limits on logical access with strong authentication under DORA Article 9(4)(c) and (d)
  • NCSC CAF, Cyber Essentials and Essential Eight: administrative rights limited to those who need them, with privileged access requested, approved, time-limited, recorded and protected by MFA
  • POPIA Section 19: technical safeguards for personal information, including recorded privileged access and masking of sensitive fields in database sessions
FAQ

GovPAM questions

Get started

Take the next step

See GovPAM in your environment, with a walkthrough tailored to your teams and systems.

All cybersecurity