Early access On-premise Agentless by default Air-gap capable
No vendor-hosted control plane. No relay fleet. No telemetry. Everything runs on infrastructure you control.
Governs an estate with nothing installed on a single target host. Short-lived certificates where you control the trust store (SSH today), credential injection where you don't, chosen per account. And a data path chosen per session by policy: the gateway path runs today, and the peer-to-peer paths for sessions that need no inspection are not built yet.
The credential never reaches the client. In either tier, injection happens at the termination point: the gateway today, and a connector on the target host once its session half is built. No target credential is ever present on a laptop, in a client application, or in the Agent.
Capability levels
Each level is a strict superset of the one below, same Agent, same gateway binary, same schema. A deployment that enters at Level 0 and grows to Level 4 never changes vendor, never re-enrolls a device, and never migrates data.
Level 0
Agent, device identity and resource ACLs. No inspection; connection metadata as the audit trail. Today the device key lives in a software key store and the tunnel is a TCP relay to the gateway: hardware-backed identity and the managed tunnel are not built yet.
Level 1
SSO through your identity provider, device trust tiers from OS-native posture, time-window policy, just-in-time access requests, full connection audit, internal tenant segmentation. MFA enforced at session start is not built yet.
Level 2
The L7 proxy engaged, session recording, Tier A certificates for SSH, the privileged-account model and remote session kill. Live session monitoring is not built yet.
Level 3
Crosses the vault line
Tier B credential injection, dual approval, clipboard and file-transfer DLP, SSH command filtering, and a clientless portal for SSH. Not built yet: vault leases, rotation, change-ticket binding, account discovery, clientless RDP and WORM recordings.
Level 4
Governed PostgreSQL sessions with query audit and result-set DLP, and Agent-native posture. Not built yet: other database engines, approvals on mobile with biometric confirm, and the tablet IDE.
Why now
The objection to PAM was never the controls. It was the rollout: eighteen months, a large upfront cost, and a well-documented failure rate. Capability levels are designed to replace it. Deploy governed connectivity now, and turn on recording, credential injection and approvals when the audit question actually arrives. By design, moving up is a setting, not a migration, not a re-deployment, not a second purchase.
Built for organizations of 50 to 2,000 seats that need NIS2, DORA or ISO 27001 evidence for privileged access, and cannot absorb a CyberArk or WALLIX programme to get it.
Downgrading is part of the design, and evidence survives it: recordings and audit history captured at a higher level stay queryable. Enforcing the level, and disabling and flagging the policies a lower level can no longer honour, is not built yet.
Where it sits
Mesh and access-proxy vendors govern sessions and decline to hold secrets, publicly, and by conviction. PAM suites hold secrets and cannot go peer-to-peer. Real estates need both, which today means two purchases.
L3 reachability
Certificates and ephemeral identity. Governs modern Linux, Kubernetes and certificate-capable databases, and cannot rotate a password on a device that only speaks passwords.
Stop here: certificates and ephemeral identity only
Credential governance
Vault, rotate, inject. Governs Windows local administrators, network appliances, Oracle sa and legacy systems, and proxies every session, whether or not it needs inspecting.
Start here, and cannot come back across
Dual-tier
Tier A
The platform CA issues a certificate valid for minutes, scoped to one account on one host. There is no password to steal, leak or rotate.
Wherever you control the trust store. Today that is SSH on modern Linux; Kubernetes, certificate-capable databases and internal web are planned.
Tier B
The credential is released to the termination point for the one connection being opened and injected there, so the operator never sees the secret. Today the control plane releases it from its own environment; leases from your vault, KMS or HSM, and rotation after each use, are designed but not built yet.
For everything that cannot be issued a certificate: Windows local administrators, network appliances, Oracle sa, legacy and third-party systems. Today that covers accounts reached over SSH, VNC and PostgreSQL.
Per account
Credential tier is a property of the account, not of the product. One host commonly carries both: root on a certificate, oracle injected by the gateway, one policy engine and one audit trail over the pair.
Tier is a property of the account, not of the deployment. A single resource commonly carries both, and every session, in either tier, is attributed to a named human and the account they used.
Flexible
A global L7 proxy taxes every byte in the system to govern the minority of sessions that need governing. Here the policy engine returns the set of modes a policy permits, and the operator picks within it.
DIRECT
Not built yet
Peer-to-peer, client straight to target, with no inspection point. Not built yet: policy can already offer this mode, but nothing terminates it.
DIRECT_RECORDED
Not built yet
Peer-to-peer to a connector on the target host, which would terminate the protocol over loopback, inject the credential and record. Not built yet: connectors register today, but their session half is not written.
PROXIED
Default
Runs today
Through the regional gateway, which terminates, records, injects and enforces DLP. Runs today for SSH, SFTP, VNC and PostgreSQL, on an estate you have not touched.
CLIENTLESS
SSH runs today
Browser to gateway. SSH in the browser runs today; RDP in the browser is not built yet. For contractors, break-glass, and devices you do not manage.
Every session is audited with the mode chosen, the policy that permitted it and its recording level. Auditing the full set of modes offered beside the choice is not built yet.
Agentless is the default, not an option. PROXIED governs a completely untouched estate, recorded, injected, audited, with nothing installed on any target host. Connectors are for where performance justifies them, and their session half is not built yet; their absence costs speed, never capability.
Platform components
All of it runs inside your network, single-tenant, with internal segmentation.
Sovereign
We operate nothing. There is no vendor-side plane to assess, no telemetry path to review, and no customer data in our custody, which matters enormously to a sovereignty-bound buyer and not at all to anyone else. It is what we ship, stated plainly.
Native
Every privileged-access rollout fails the same way: engineers route around the portal, because the portal is miserable. Here the connection manager is designed to be the enforcement point, with session mode, credential injection and recording state shown as indicators, never as configuration. Not built yet: Console and Database Manager do not link to the gateway today.
Both are edgely_core applications designed to speak to the Access Agent directly, so governed access becomes part of the client rather than something bolted onto it: sign in, and the estate you are entitled to appears next to the connections you already keep. Until that link is built, any tool reaches governed resources through the Agent's SOCKS5 proxy.
In Database Manager the same path will carry governed database sessions, with query audit and result-set DLP; in Console it will carry SSH, VNC and SFTP, then RDP once the gateway carries it. One Agent, one policy engine, one audit trail behind both.
Single sign-on against your identity provider, with the device's own key and its signed posture. Hardware-backed device keys and MFA at session start are not built yet. No VPN client to configure, no tunnel to pick.
Once the client links to the Agent, it will pull the resources the policy engine says you are entitled to, with their protocols, environments and privileged accounts, and list them beside your own connections. Nothing to type in, nothing to keep in sync by hand.
The client calls the local Agent, policy resolves the session mode and the account, the gateway injects the credential, and recording starts if the policy requires it. You never see a password.
Approvals belong on the phone, where four-eyes workflows survive. Push notification with biometric confirm, live session shadowing, remote session kill and the break-glass second factor are planned there, not built yet; today an approver decides in the Enterprise Dashboard. Approval routed through email is where four-eyes dies in practice.
Governance
NIS2, DORA and ISO 27001 questions answered with one query instead of a reconciliation across three systems.
Evidence
Every session, in every mode, lands in the audit trail as (human, account, resource, mode). Not a reconciliation exercise across three systems.
"Who used root on host X on 12 March, and what did they type?"
Shared accounts are attributed to the named human who requested them, and the session recording is bound to the same record.
"Show me the change request that authorized this session."
Binding a session to an approved ticket in ServiceNow, Jira Service Management or GLPI is planned, not built. Today a policy can require a single or dual approval before a session starts, and every request and decision is audited.
"Which sessions ran unrecorded last quarter, and under which policy?"
Mode is a field on every session record, so unrecorded sessions are a query rather than an absence of evidence.
"What could this operator have chosen, and what did they choose?"
Every session is audited with the mode chosen, and the policy and recording level behind it. Adding the full set of modes that was offered is not built yet.
The short table
Most of a PAM comparison table is contestable and moves every quarter. These are the rows that don't: where a competitor is absent below, it is absent by design rather than by backlog.
| Capability | Mesh & access proxies | PAM suites | Enterprise Access |
|---|---|---|---|
| Peer-to-peer data path (planned) | Yes | No | Planned |
| Session recording | Yes | Yes | Yes |
| Short-lived certificates issued for the target PAM suites accept X.509 to authenticate the user to the bastion; they do not act as a CA issuing certificates for the target. | Yes | No | Yes |
| Credential vault and rotation (planned) Absent by stated conviction, not by roadmap, "no more vaults, rotation workflows, or fragile proxies." | No | Yes | Planned |
| Credential injection, the operator never sees it | No | Yes | Yes |
| Shared-account attribution | No | Yes | Yes |
| Both credential models, chosen per account | No | No | Yes |
| Data path selected per session (gateway path today) The nearest analogue is cluster-wide recording configuration, which is neither per session nor operator-facing, and does not change the network path. | No | No | Yes |
| Governs targets with nothing installed on them | No | Yes | Yes |
| No vendor-operated infrastructure in the path | No | Partial | Yes |
"Mesh & access proxies" means Tailscale including its PAM extension, Teleport Enterprise, Twingate, Cloudflare and Zscaler. "PAM suites" means WALLIX, CyberArk and BeyondTrust. Verified against vendor documentation and re-checked every six months.
What this is not
You would find these in the first technical meeting anyway. Finding them here is worth more to both of us than the deals it costs.
Questions
A VPN or ZTNA product decides whether you can reach a host. It does not hold the credential you use once you are there, does not record what you did, and cannot attribute a shared account to a named person. This platform does all three. A peer-to-peer path for the sessions that need no inspection is part of its design, and not built yet.
No. The default mode routes through a regional gateway and governs an estate with nothing installed on any target host: recorded, credential injected, audited. Connectors are for where you want extra speed; their session half is not built yet, and their absence costs performance rather than capability.
Both govern sessions well and both stop at credential custody. Tailscale has said so publicly, and Teleport has no vault in any edition. Where your estate needs a password rather than a certificate, our gateway injects it and the operator never sees it. Today that covers accounts reached over SSH, VNC and PostgreSQL, with the credential released by the control plane; leases from an external vault, Windows local administrators over RDP, Oracle sa and password rotation are not built yet.
They vault and rotate credentials; our Tier B injection runs today, while vault leases and rotation are designed and not built yet. What they do not do is issue short-lived certificates for the target or model device trust, and every byte hairpins through a bastion; our design adds a peer-to-peer path to avoid that, but that path is not built yet. They also hold CSPN and BSI certification, which we do not yet.
Yes. There is no hosted control plane, no coordination server, no relay fleet and no telemetry. The whole platform runs inside your network, and an air-gapped deployment is supported. The licence is installed offline; verifying its signature is not built yet.
Every session lands in the audit trail as a named human, the account they used, the resource and the data path, with the recording bound to the same record. A session can require an approval before it starts; binding it to a change ticket is planned. Certification of the product itself is planned, not held.
Enterprise Access is in early access. We are onboarding design partners with 50 to 2,000 seats, particularly ones with an untouched estate, a NIS2 or DORA deadline, and no appetite for an eighteen-month programme.
Product names, logos and brands mentioned on this page are the property of their respective owners. They are used for identification and comparison only, and their use does not imply any affiliation with or endorsement by them.
Tailscale is a trademark of Tailscale Inc. Teleport is a trademark of Gravitational, Inc. Twingate is a trademark of Twingate Inc. Cloudflare is a trademark of Cloudflare, Inc. Zscaler is a trademark of Zscaler, Inc. WALLIX is a trademark of WALLIX GROUP. CyberArk is a trademark of CyberArk Software Ltd. BeyondTrust is a trademark of BeyondTrust Corporation. ServiceNow is a trademark of ServiceNow, Inc. Jira is a trademark of Atlassian Pty Ltd. GLPI is a trademark of TECLIB SAS. Kubernetes is a trademark of The Linux Foundation. Oracle is a trademark of Oracle Corporation and/or its affiliates. Windows is a trademark of Microsoft Corporation. PostgreSQL is a trademark of the PostgreSQL Community Association of Canada. Amazon S3 is a trademark of Amazon.com, Inc. Linux is a trademark of Linus Torvalds.