How many people know the admin passwords of your servers, databases, applications and network devices today? Keycyte PAM makes the answer “nobody”. Passwords stay in an encrypted vault, PAM opens the connection, and the user reaches the target system without ever seeing the password.
Access is granted for a limited time, the session is recorded as video and keystrokes, and when it ends the privilege is revoked and the password is changed.
In most organisations the honest answer is “everywhere”:
Server admin accounts, database connections, service accounts, network devices. Most still carry the password they were set up with; changing it is the job everyone is afraid of.
How many people know the database root password? In how many places is the directory admin password written down? A shared password has no owner — and “who did it” has no answer.
When a system administrator leaves, every password they knew should change. In practice the list is incomplete, and months later a still-valid login turns up as an audit finding.
Access given to a consultant, a support engineer or an outside developer “until the job is done” usually outlives the job.
With Keycyte PAM, an administrator connecting to a critical server goes through six steps. In none of them does the password reach the user.
The user states which system they need, for what task and for how long.
The request is approved according to policy. The privilege is time-bound, never permanent.
The user passes multi-factor authentication both when signing in to PAM and when connecting to the target.
PAM takes the current password from the vault and injects it through its proxy. The user never sees it.
The session is recorded as screen video and keystrokes. An administrator can join it live or terminate it.
When time is up the privilege is revoked automatically and the password is rotated immediately.
There is no second session with the same password.
A password written on a note, caught in a screenshot or leaked is already invalid on the next attempt.
A system administrator has just left. The auditor asks who made a change last month.
Keycyte PAM does not stop at remote desktop and terminal sessions. It puts every system that needs privileged access — from servers to databases, from web consoles to desktop applications — behind the same gate.
RDP to Windows servers, SSH or Telnet to Linux and Unix servers and network devices, VNC to systems with a graphical console.
MSSQL, MySQL, PostgreSQL, MariaDB, MongoDB and other databases. Passwords of privileged database accounts also live in the vault and are rotated automatically by policy.
Not a short list of supported products: any application that opens in a browser. Device and virtualisation management panels, internal portals, admin consoles.
Any .exe desktop application and third-party software — management consoles, database clients, industry-specific tools. All launched through PAM, under the same approval and recording rules.
User, admin and service accounts on Linux servers. Passwords are kept in the vault and rotated at the end of a session or on a set schedule.
Whatever the system, the flow is the same: request, approval, MFA, password-less connection, recording, and a password that changes when the session ends. Keycyte PAM is the only interface users need to learn.
The whole life cycle of privileged access — from generating the password to auditing the session — on one platform.
Encrypted vault. Privileged credentials are stored encrypted with AES-256. The encryption key is kept apart from the vault and wrapped separately; even a copy of the database does not reveal the passwords.
Automated password rotation. A policy per account: hourly, daily or weekly rotation, length and character rules, rotation after every use or after every session.
Rotation by account type. Dedicated change methods for Linux servers, Windows accounts, directory service users and database accounts.
Verified changes. The new password is applied on the target, verified with a test connection, and only then written to the vault. If any step fails the change is rolled back and an alert is raised — the vault and the system never drift apart.
Strong password generation. Unguessable passwords that follow your policy. Nobody needs to memorise them, because nobody needs to know them.
Just-In-Time (JIT) access. Instead of standing admin rights, privilege granted when needed and for a set time. When time is up, access is revoked automatically.
Temporary privilege elevation. The most critical rights, such as Domain Admin, are granted for a single session and taken back when it ends.
Request and approval. Who asked for which system, for what reason, and who approved it — a decision record behind every access.
Least privilege. Each user is given access only to the systems their work requires, and only for as long as it requires.
Third-party access. Time-bound access for consultants and vendors; when the contract ends, their privilege and everything they knew become invalid without a single manual step.
Session recording. Every privileged session is recorded as screen video and keystrokes, ready to replay and review.
Live monitoring. Administrators watch sessions on the systems they are responsible for in real time.
Join and collaborate. An administrator can join a user’s session and work alongside them with shared keyboard and mouse control.
Terminate. When something looks wrong, the administrator can cut the session immediately.
Two-layer MFA. Multi-factor authentication at two doors: signing in to PAM and connecting to the target system. A stolen password alone opens neither.
Active Directory and LDAP. Users and groups come from your existing directory; you do not keep a second user list.
Agentless architecture. Nothing is installed on target servers or devices. PAM connects to them over their own standard protocols.
Audit trail. Who accessed which system, when, under which approval, and what they did — all on record.
Time-stamped password history. Every password change is kept as a time-stamped event and can be matched to the session that used it.
Compliance reporting. The access and credential evidence that ISO 27001 and data-protection audits ask for, without compiling it by hand.
ISO 27001:2022 never names password rotation or session recording; yet the controls below cannot be evidenced without them. Data-protection law’s duty of “appropriate security” covers privileged accounts too.
| Requirement | How Keycyte PAM meets it |
|---|---|
| ISO 27001 · A 5.17 Authentication information | Creation, change and revocation of passwords are logged with time stamps; the life cycle is run by policy, not by hand. |
| ISO 27001 · A 8.2 Privileged access rights | Time-bound (JIT) privilege, request and approval records, automatic revocation when the session ends. |
| ISO 27001 · A 8.5 Secure authentication | Two-layer MFA; users cannot disclose a password they have never seen. |
| ISO 27001 · A 8.24 Use of cryptography | AES-256 encryption in the vault, with the encryption key wrapped separately. |
| KVKK (Turkish data protection law) · Article 12 | Access logs, a trail of privilege changes and auditable authentication — a definite answer to “who used which password, and when”. |
No agents on target systems, users come from your directory. There is no new habit for users to learn: pick the system, connect.
Installation, configuration, maintenance and technical support come directly from the Keycyte team; we roll the product out together, shaped to your infrastructure.
Access, configuration, monitoring and guest internet from one place, one support team, one contract.
Keycyte MON shows the live state of the network, Keycyte NCM versions every change to its configuration; Keycyte PAM holds the record of the session that made the change. Keycyte Hotspot keeps the record of guest internet access.
No. The user picks the system to connect to; Keycyte PAM takes the current password from the vault and opens the connection itself through its proxy. The password never reaches the user’s screen, clipboard or browser. And because it is rotated after the session, it would be useless even if it were learned somehow.
No. Keycyte PAM is agentless; it connects to each target system over that system’s own standard protocol and interface. Nothing extra is installed on servers or devices.
Almost anything that needs privileged access. RDP, SSH, Telnet and VNC for servers; MSSQL, MySQL, PostgreSQL, MariaDB, MongoDB and others for databases; every web application that opens in a browser; Windows applications (.exe) and third-party software; Linux accounts. Whatever the system, request, approval, MFA and session recording work the same way.
Linux server accounts, Windows accounts, directory service users and database accounts. Each account type has its own change method; rotation frequency and password rules are set per account.
The new password is first applied on the target, then verified with a test connection, and only then written to the vault. If any step fails the change is rolled back, the previous password stays valid and an alert is raised. There is no in-between state where the vault and the system disagree.
Granting access when it is needed and for a set time, instead of standing admin rights. The user requests, the request is approved, and when the time is up access is revoked automatically. No admin account left open overnight, no forgotten privileges, no “we’ll close it later” access.
Yes. Administrators can watch sessions on the systems they are responsible for in real time, join a session and work alongside the user with shared keyboard and mouse control, or terminate it immediately if something looks wrong.
The screen video of the session and the user’s keystrokes. Each recording is tied to the person, the request and the approval behind it, so who made a change, and with what authority, can be shown with certainty later.
In two places: when signing in to Keycyte PAM, and again when connecting to a critical server, database or application. Someone who got into the interface is verified again before reaching a sensitive system.
Yes. Users and groups come from Active Directory or LDAP; authentication relies on your existing directory service, so you do not keep a second user list.
With time-bound access. The vendor sees only the systems assigned to them, only for the assigned period, and their sessions are recorded. When the time is up the privilege closes and the related passwords are rotated — there is no manual step to remember at the end of the contract.
Yes. The four products run independently. Together, the “what happened → what changed → who did it” chain closes on one platform, but that is not a requirement.
According to your organisation’s needs. Get in touch; let’s talk about what you need and show you the product in your own environment.
Pick a server, open a session, close it. See how the password is rotated and how the session is recorded — in your own environment.
Request a Demo Contact UsCopyright @2026 Keycyte All Rights Reserved.