Privileged SSH becomes a controlled, audited and interruptible channel with the Inshipia Secure Shell Gateway.

No standing credentials, no agent to install on your servers — a blocked command stops before it reaches the target machine.

SSG_hero

Inshipia Secure Shell Gateway

Privileged Access Management for your Linux estate — without agents.

  • Administrators log in to the gateway, not to the target machine. The certificate that grants access is created at the moment of the request, lives for five minutes and never leaves the gateway's memory. There is nothing to steal from a workstation and nothing to forget to revoke — removing someone from the directory takes effect immediately.

  • Every command is evaluated against policy before it reaches the server: allow, require approval, or deny. A blocked command never starts — you don't find out afterwards from a recording. The built-in denials — interactive root shell, destructive system deletion — cannot be overridden; everything above that layer is freely configurable.

  • Two complementary records are produced, both on the gateway: a structured command log (searchable, alertable, ready for your SIEM) and a time-accurate recording of the full interactive session. The log is written where the attacker isn't — a root user who breaks into a target machine cannot reach the record of what they did.

  • A command awaiting approval waits on the gateway: nothing runs on the target machine until the decision is made. The decision, the approver and the timestamp stay in the audit log and linked to the ticket. Every access above the configured threshold opens a JIRA ticket — even when no approval was required.

  • The dashboard shows who is logged in where, and since when. Any session can be terminated from the outside with a single action — response time drops to minutes, and none of it requires anything installed on the target machine.

How are we different from other solutions?

Where prevention meets accountability

No agents on your servers

No running component is installed on target machines — the footprint is a single configuration line and a host certificate. No kernel version dependency, no agent compatibility matrix, no performance risk, and nothing to update across thousands of machines. Upgrades happen in one place: on the gateway.

Prevention, not just recording

Classic PAM tools record: you can review afterwards what happened. Here the policy decides before execution, so a blocked command never starts. The recording is still there — but alongside it there is real, live prevention.

The log isn't in the attacker's hands

In the traditional model the log is written on the target machine, where root can delete it — after an incident the evidence is exactly what's missing. Here the audit trail is written append-only on the gateway and read directly by your SIEM. If the write fails, the operation fails.

Fits the systems you already run

Directory (LDAP / Active Directory) for entitlements, JIRA for tickets, CMDB labels for machine classification, Prometheus and Grafana for monitoring, your SIEM for the audit trail. No parallel user database to maintain.

What's in the Inshipia Secure Shell Gateway?

Four layers of defense, built on each other.

Supports your obligations under PCI-DSS 4.0, ISO 27001:2022, NIS2, SOX and GDPR for access control and logging.

Identity and entitlement

Directory authentication with mandatory MFA (TOTP or emailed code). Group membership as the gate, with per-machine entitlement requirements.

Command control and approval

Per-command policy by lockdown level, with built-in denials that cannot be overridden. Four-eyes approval and automatic JIRA tickets above the configured threshold.

Monitoring and intervention

Structured command logs, full session recordings, a live session list and one-click termination. Prometheus metrics and system checks for your operations team.

Machine identities (NHI)

Backup scripts, CI/CD jobs and scheduled tasks without long-lived keys: certificates valid for one hour, renewed automatically and revocable instantly.

Call us for more information!

Get in touch with us

+36-30-110-7004