Your data never leaves your network
Bastigo is a software vendor, not a hosting provider. The bastion runs on your own infrastructure: no one else has access to your passwords, your session recordings, or your user directory.
100% on-premise
Bastigo installs on a VM or appliance on your own infrastructure. The vendor hosts nothing and never touches customer data, and day-to-day operation does not depend on any mandatory network connection to its infrastructure.
- ✓ Passwords, recordings and your user directory stay on your own network
- ✓ No third-party processor in the chain handling your sensitive data
- ✓ You remain solely responsible for hosting, and therefore for its compliance
Vault and passwords
Target account credentials are protected with an AES-256-GCM envelope, master key kept outside the encrypted system. Local Bastigo account passwords, meanwhile, are hashed with Argon2id, the function recommended today for this use case, not bcrypt.
- ✓ AES-256-GCM for target account credentials, external master key
- ✓ Argon2id for local passwords, not bcrypt
- ✓ External HSM/KMS planned for a future release
Exhaustive audit and SIEM export
Every login, admin action, session and security event is logged and exportable, ready for an internal or external audit request. Events relay continuously to your existing syslog collector.
- ✓ Filter by user, target, event type or time range
- ✓ Syslog export to your SIEM, no additional tool
Offline verification
The license file is signed (Ed25519) and verified locally by your bastion, with no permanent network connection to the vendor. No telemetry is sent by default: any reporting stays optional and anonymized.
- ✓ Ed25519 signature, verifiable offline
- ✓ Telemetry off by default, opt-in and anonymized if enabled
What the on-premise positioning means for you
Bastigo is a software vendor: the product is deployed and operated on your own infrastructure, not hosted by the vendor. You remain solely responsible for hosting and for the compliance of your own infrastructure, which gives you full control over data location and processing, including for sectors subject to specific hosting obligations.
This architecture avoids, by design, the questions raised by a third-party processor handling your sensitive data: privileged account passwords, session recordings and your user directory all stay right where they are, on your own network.
A specific security question before you decide?
Our technical team answers directly, no sales detour.