A PAM bastion your own IT team installs and runs

SSH, RDP, password vault, LDAP/AD: the building blocks of a real privileged access bastion, without the price tag or the complexity built for a fifty-person security department.

100% on-premise SSH and RDP included LDAP/AD and MFA No mandatory cloud dependency

What a bastion needs, minus the machinery around it

No separate paid module, no quarter-long rollout: the six building blocks below run from day one.

SSH and RDP gateway

One checkpoint to reach a Linux server or a Windows machine. The target account's real password never makes it to the user's own machine.

Recording and replay

Every SSH and RDP session gets filmed, no checkbox to enable it. The day you need to know what happened, the answer is already recorded.

Live session monitoring

Something feels off about an ongoing session? An administrator watches it live, read-only, and cuts it in one click if needed.

Password vault

AES-256-GCM encryption, master key kept outside the encrypted system. Not even a Bastigo administrator ever sees the plain text password.

LDAP/AD and MFA

Local accounts or Active Directory, AD groups mapped automatically to a Bastigo role, MFA enforceable per role instead of left to everyone's good will.

Policies and audit

Who can reach what, written down instead of living in someone's memory. The full log exports to your SIEM over syslog.

See every feature in detail

Built for two or three admins, not a fifty-person department

WALLIX and other established PAM solutions were built for dedicated security teams, with the budget and integration time that comes with them. Bastigo aims for the same outcome a different way: administration a small IT team owns from day one.

Criteria Bastigo Legacy PAM solutions
Installation Guided web wizard, on your own infrastructure Assisted deployment, often lengthy
Data hosting 100% on-premise, no data held by the vendor Varies by offer
SSH and RDP Included from day one Often gated behind licensing tiers
Vendor network dependency None, license verified locally Common (activation, telemetry)
Admin learning curve Built for a small IT team Often designed for a dedicated security role

What IT teams ask us most

What is a PAM bastion?

A PAM (Privileged Access Management) bastion is the single point through which administrators connect to sensitive servers and workstations. It removes the need to distribute privileged account passwords, records every session for audit purposes, and lets an administrator cut a live connection during an incident.

Does Bastigo run on our own servers or in the vendor's cloud?

Bastigo runs on your own infrastructure (a VM or appliance), not in a cloud operated by the vendor. No data, passwords, session recordings, or user directory ever leaves your network. Day to day operation does not depend on any mandatory network connection to the vendor.

How is Bastigo different from WALLIX or Apache Guacamole?

Bastigo targets the same need as WALLIX, a PAM bastion with SSH/RDP gateway, recording and a password vault, but with a deliberately simpler installation and administration experience for an SME without a dedicated security team. Unlike solutions built on top of Apache Guacamole, Bastigo's WebSocket tunnel, session broker and recording format are proprietary: only the low level RDP protocol engine (FreeRDP) is reused, the same way any SSH bastion relies on an SSH library.

Does Bastigo support both SSH and RDP?

Yes, from the first release. An SME with both Linux servers and Windows machines only needs one bastion for both protocols, each with full session recording and replay.

Does Bastigo integrate with an existing Active Directory?

Yes. Bastigo authenticates users via direct bind against an LDAP or Active Directory server and can automatically map directory groups to Bastigo roles, alongside local accounts and two-factor authentication (TOTP).

Ready to see Bastigo running on your own environment?

A demo takes thirty minutes, on your own servers or a test environment.