PRIVILEGED ACCESS MANAGEMENT

Keycyte PAM Nobody knows the password. Every session is on record.

How many people know the admin passwords of your servers, databases, applications and network devices today? Keycyte PAM makes the answer “nobody”. Passwords stay in an encrypted vault, PAM opens the connection, and the user reaches the target system without ever seeing the password.

Access is granted for a limited time, the session is recorded as video and keystrokes, and when it ends the privilege is revoked and the password is changed.

Where do your privileged passwords live?

In most organisations the honest answer is “everywhere”:

Passwords unchanged for years

Server admin accounts, database connections, service accounts, network devices. Most still carry the password they were set up with; changing it is the job everyone is afraid of.

Shared accounts

How many people know the database root password? In how many places is the directory admin password written down? A shared password has no owner — and “who did it” has no answer.

People who leave

When a system administrator leaves, every password they knew should change. In practice the list is incomplete, and months later a still-valid login turns up as an audit finding.

Third-party access

Access given to a consultant, a support engineer or an outside developer “until the job is done” usually outlives the job.

The life of a session

With Keycyte PAM, an administrator connecting to a critical server goes through six steps. In none of them does the password reach the user.

  1. 01

    Request

    The user states which system they need, for what task and for how long.

  2. 02

    Approval

    The request is approved according to policy. The privilege is time-bound, never permanent.

  3. 03

    Verification

    The user passes multi-factor authentication both when signing in to PAM and when connecting to the target.

  4. 04

    Connection

    PAM takes the current password from the vault and injects it through its proxy. The user never sees it.

  5. 05

    Recording

    The session is recorded as screen video and keystrokes. An administrator can join it live or terminate it.

  6. 06

    Close

    When time is up the privilege is revoked automatically and the password is rotated immediately.

There is no second session with the same password.

A password written on a note, caught in a screenshot or leaked is already invalid on the next attempt.

Same morning, two different companies

A system administrator has just left. The auditor asks who made a change last month.

Without Keycyte PAM

  • Which passwords the leaver knew is reconstructed from a spreadsheet, from memory, from old emails.
  • Passwords are changed one by one, by hand; one is always forgotten.
  • The change was made with a shared admin account. Nobody knows who used it.
  • The evidence for the auditor is a user name in a server log.

With Keycyte PAM

  • The person’s access is closed in one place, and rotation is triggered at once for every affected account.
  • They never saw a password in the first place. There is nothing they know.
  • The session that made the change belongs to a person: who connected, under which request and approval.
  • The auditor gets the video and keystroke record of that session.

One gate, every critical system

Keycyte PAM does not stop at remote desktop and terminal sessions. It puts every system that needs privileged access — from servers to databases, from web consoles to desktop applications — behind the same gate.

Servers and network devices

RDP to Windows servers, SSH or Telnet to Linux and Unix servers and network devices, VNC to systems with a graphical console.

Databases

MSSQL, MySQL, PostgreSQL, MariaDB, MongoDB and other databases. Passwords of privileged database accounts also live in the vault and are rotated automatically by policy.

Every web application

Not a short list of supported products: any application that opens in a browser. Device and virtualisation management panels, internal portals, admin consoles.

Windows applications

Any .exe desktop application and third-party software — management consoles, database clients, industry-specific tools. All launched through PAM, under the same approval and recording rules.

Linux accounts

User, admin and service accounts on Linux servers. Passwords are kept in the vault and rotated at the end of a session or on a set schedule.

All under the same rules

Whatever the system, the flow is the same: request, approval, MFA, password-less connection, recording, and a password that changes when the session ends. Keycyte PAM is the only interface users need to learn.

Capabilities

The whole life cycle of privileged access — from generating the password to auditing the session — on one platform.

Password vault and rotation

Encrypted vault. Privileged credentials are stored encrypted with AES-256. The encryption key is kept apart from the vault and wrapped separately; even a copy of the database does not reveal the passwords.

Automated password rotation. A policy per account: hourly, daily or weekly rotation, length and character rules, rotation after every use or after every session.

Rotation by account type. Dedicated change methods for Linux servers, Windows accounts, directory service users and database accounts.

Verified changes. The new password is applied on the target, verified with a test connection, and only then written to the vault. If any step fails the change is rolled back and an alert is raised — the vault and the system never drift apart.

Strong password generation. Unguessable passwords that follow your policy. Nobody needs to memorise them, because nobody needs to know them.

Access and privilege

Just-In-Time (JIT) access. Instead of standing admin rights, privilege granted when needed and for a set time. When time is up, access is revoked automatically.

Temporary privilege elevation. The most critical rights, such as Domain Admin, are granted for a single session and taken back when it ends.

Request and approval. Who asked for which system, for what reason, and who approved it — a decision record behind every access.

Least privilege. Each user is given access only to the systems their work requires, and only for as long as it requires.

Third-party access. Time-bound access for consultants and vendors; when the contract ends, their privilege and everything they knew become invalid without a single manual step.

Session management

Session recording. Every privileged session is recorded as screen video and keystrokes, ready to replay and review.

Live monitoring. Administrators watch sessions on the systems they are responsible for in real time.

Join and collaborate. An administrator can join a user’s session and work alongside them with shared keyboard and mouse control.

Terminate. When something looks wrong, the administrator can cut the session immediately.

Identity and integration

Two-layer MFA. Multi-factor authentication at two doors: signing in to PAM and connecting to the target system. A stolen password alone opens neither.

Active Directory and LDAP. Users and groups come from your existing directory; you do not keep a second user list.

Agentless architecture. Nothing is installed on target servers or devices. PAM connects to them over their own standard protocols.

Audit and compliance

Audit trail. Who accessed which system, when, under which approval, and what they did — all on record.

Time-stamped password history. Every password change is kept as a time-stamped event and can be matched to the session that used it.

Compliance reporting. The access and credential evidence that ISO 27001 and data-protection audits ask for, without compiling it by hand.

0times a user sees a target system password
1session — the lifetime of a temporary privilege and its password
2layers of MFA — PAM sign-in and target system
5system classes — servers, databases, web apps, Windows apps, Linux accounts
0agents installed on target systems

The auditor’s question, already answered

ISO 27001:2022 never names password rotation or session recording; yet the controls below cannot be evidenced without them. Data-protection law’s duty of “appropriate security” covers privileged accounts too.

RequirementHow Keycyte PAM meets it
ISO 27001 · A 5.17 Authentication informationCreation, change and revocation of passwords are logged with time stamps; the life cycle is run by policy, not by hand.
ISO 27001 · A 8.2 Privileged access rightsTime-bound (JIT) privilege, request and approval records, automatic revocation when the session ends.
ISO 27001 · A 8.5 Secure authenticationTwo-layer MFA; users cannot disclose a password they have never seen.
ISO 27001 · A 8.24 Use of cryptographyAES-256 encryption in the vault, with the encryption key wrapped separately.
KVKK (Turkish data protection law) · Article 12Access logs, a trail of privilege changes and auditable authentication — a definite answer to “who used which password, and when”.

Why Keycyte PAM

Simple to deploy, simple to use

No agents on target systems, users come from your directory. There is no new habit for users to learn: pick the system, connect.

One point of contact, from install to maintenance

Installation, configuration, maintenance and technical support come directly from the Keycyte team; we roll the product out together, shaped to your infrastructure.

And four products from one vendor

Access, configuration, monitoring and guest internet from one place, one support team, one contract.

Keycyte MON shows the live state of the network, Keycyte NCM versions every change to its configuration; Keycyte PAM holds the record of the session that made the change. Keycyte Hotspot keeps the record of guest internet access.

Frequently asked questions

Does the user see the target system’s password?

No. The user picks the system to connect to; Keycyte PAM takes the current password from the vault and opens the connection itself through its proxy. The password never reaches the user’s screen, clipboard or browser. And because it is rotated after the session, it would be useless even if it were learned somehow.

Do I need to install agents on servers or devices?

No. Keycyte PAM is agentless; it connects to each target system over that system’s own standard protocol and interface. Nothing extra is installed on servers or devices.

Which systems can Keycyte PAM give access to?

Almost anything that needs privileged access. RDP, SSH, Telnet and VNC for servers; MSSQL, MySQL, PostgreSQL, MariaDB, MongoDB and others for databases; every web application that opens in a browser; Windows applications (.exe) and third-party software; Linux accounts. Whatever the system, request, approval, MFA and session recording work the same way.

Which accounts can it rotate automatically?

Linux server accounts, Windows accounts, directory service users and database accounts. Each account type has its own change method; rotation frequency and password rules are set per account.

What happens if a password change fails halfway?

The new password is first applied on the target, then verified with a test connection, and only then written to the vault. If any step fails the change is rolled back, the previous password stays valid and an alert is raised. There is no in-between state where the vault and the system disagree.

What exactly is Just-In-Time (JIT) access?

Granting access when it is needed and for a set time, instead of standing admin rights. The user requests, the request is approved, and when the time is up access is revoked automatically. No admin account left open overnight, no forgotten privileges, no “we’ll close it later” access.

Can I watch sessions live?

Yes. Administrators can watch sessions on the systems they are responsible for in real time, join a session and work alongside the user with shared keyboard and mouse control, or terminate it immediately if something looks wrong.

What do session recordings contain?

The screen video of the session and the user’s keystrokes. Each recording is tied to the person, the request and the approval behind it, so who made a change, and with what authority, can be shown with certainty later.

Where does multi-factor authentication apply?

In two places: when signing in to Keycyte PAM, and again when connecting to a critical server, database or application. Someone who got into the interface is verified again before reaching a sensitive system.

Does it work with Active Directory?

Yes. Users and groups come from Active Directory or LDAP; authentication relies on your existing directory service, so you do not keep a second user list.

How do I give access to third parties?

With time-bound access. The vendor sees only the systems assigned to them, only for the assigned period, and their sessions are recorded. When the time is up the privilege closes and the related passwords are rotated — there is no manual step to remember at the end of the contract.

Can I buy PAM without Keycyte NCM, MON or Hotspot?

Yes. The four products run independently. Together, the “what happened → what changed → who did it” chain closes on one platform, but that is not a requirement.

How is it priced?

According to your organisation’s needs. Get in touch; let’s talk about what you need and show you the product in your own environment.

The day nobody knows your admin passwords

Pick a server, open a session, close it. See how the password is rotated and how the session is recorded — in your own environment.

Request a Demo Contact Us