A PAM bastion your own IT team installs and runs
SSH, RDP, password vault, LDAP/AD: the building blocks of a real privileged access bastion, without the price tag or the complexity built for a fifty-person security department.
What a bastion needs, minus the machinery around it
No separate paid module, no quarter-long rollout: the six building blocks below run from day one.
SSH and RDP gateway
One checkpoint to reach a Linux server or a Windows machine. The target account's real password never makes it to the user's own machine.
Recording and replay
Every SSH and RDP session gets filmed, no checkbox to enable it. The day you need to know what happened, the answer is already recorded.
Live session monitoring
Something feels off about an ongoing session? An administrator watches it live, read-only, and cuts it in one click if needed.
Password vault
AES-256-GCM encryption, master key kept outside the encrypted system. Not even a Bastigo administrator ever sees the plain text password.
LDAP/AD and MFA
Local accounts or Active Directory, AD groups mapped automatically to a Bastigo role, MFA enforceable per role instead of left to everyone's good will.
Policies and audit
Who can reach what, written down instead of living in someone's memory. The full log exports to your SIEM over syslog.
Built for two or three admins, not a fifty-person department
WALLIX and other established PAM solutions were built for dedicated security teams, with the budget and integration time that comes with them. Bastigo aims for the same outcome a different way: administration a small IT team owns from day one.
| Criteria | Bastigo | Legacy PAM solutions |
|---|---|---|
| Installation | ✓ Guided web wizard, on your own infrastructure | Assisted deployment, often lengthy |
| Data hosting | ✓ 100% on-premise, no data held by the vendor | Varies by offer |
| SSH and RDP | ✓ Included from day one | Often gated behind licensing tiers |
| Vendor network dependency | ✓ None, license verified locally | Common (activation, telemetry) |
| Admin learning curve | ✓ Built for a small IT team | Often designed for a dedicated security role |
What IT teams ask us most
What is a PAM bastion?
A PAM (Privileged Access Management) bastion is the single point through which administrators connect to sensitive servers and workstations. It removes the need to distribute privileged account passwords, records every session for audit purposes, and lets an administrator cut a live connection during an incident.
Does Bastigo run on our own servers or in the vendor's cloud?
Bastigo runs on your own infrastructure (a VM or appliance), not in a cloud operated by the vendor. No data, passwords, session recordings, or user directory ever leaves your network. Day to day operation does not depend on any mandatory network connection to the vendor.
How is Bastigo different from WALLIX or Apache Guacamole?
Bastigo targets the same need as WALLIX, a PAM bastion with SSH/RDP gateway, recording and a password vault, but with a deliberately simpler installation and administration experience for an SME without a dedicated security team. Unlike solutions built on top of Apache Guacamole, Bastigo's WebSocket tunnel, session broker and recording format are proprietary: only the low level RDP protocol engine (FreeRDP) is reused, the same way any SSH bastion relies on an SSH library.
Does Bastigo support both SSH and RDP?
Yes, from the first release. An SME with both Linux servers and Windows machines only needs one bastion for both protocols, each with full session recording and replay.
Does Bastigo integrate with an existing Active Directory?
Yes. Bastigo authenticates users via direct bind against an LDAP or Active Directory server and can automatically map directory groups to Bastigo roles, alongside local accounts and two-factor authentication (TOTP).
Ready to see Bastigo running on your own environment?
A demo takes thirty minutes, on your own servers or a test environment.