Access that ends on its own.
Short-lived, policy-checked access for people and workloads. Nothing is left standing.
| Account | Safe | Last rotation | Policy | Verify |
|---|---|---|---|---|
| dba@payments-db | Databases | 2h ago | Daily | OK |
| root@linux-web-01 | Linux | 5h ago | Daily | OK |
| Administrator@win2019 | Windows | 1d ago | Weekly | OK |
| sa@hr-sql | Databases | 3d ago | Weekly | Pending |
| svc_backup@linux-db-02 | Linux | 6h ago | Daily | OK |
payments-dbread-onlyRuns with what you already have
- Kubernetes
- AWS
- Azure
- Google Cloud
- Okta
- Linux
- Windows
- PostgreSQL
- MySQL
- SQL Server
- Oracle
- HashiCorp Vault
Legacy PAM vaults what it cannot remove. Zerostand removes it: every grant is a lease, and a lease expires.
One platform. Every identity. Every target.
Zero standing privilege
Every credential is a lease with an expiry. There is nothing to revoke later.
Workload identity
Machines prove what they are with the identity they already run with. No shared secret is handed out.
Vaulted accounts, rotated and verified
For the logins you cannot remove yet: safes, scheduled rotation, verification and reconcile, on every major OS and database.
| Account | Safe | Last rotation | Policy | Verify |
|---|---|---|---|---|
| dba@payments-db | Databases | 2h ago | Daily | OK |
| root@linux-web-01 | Linux | 5h ago | Daily | OK |
| Administrator@win2019 | Windows | 1d ago | Weekly | OK |
| sa@hr-sql | Databases | 3d ago | Weekly | Pending |
| svc_backup@linux-db-02 | Linux | 6h ago | Daily | OK |
Approvals that expire
Request in context, approve out of band, land on the credential the instant it is granted.
Sessions, recorded
SSH, RDP, database and browser sessions brokered through Zerostand and replayable afterwards.
What it covers.
- Identities
- PeopleWorkloadsService accountsCI jobs
- Targets
- LinuxWindowsPostgreSQLMySQLSQL ServerOracleKubernetesWeb applications
- Controls
- Policy as codeApprovalsRotationRecordingDiscoveryRecertificationBreak-glass
- 0standing credentials. Every grant is a lease.
- 6operating systems and databases rotated natively.
- 1console for people, workloads and the accounts they use.
- 3steps from a request to a credential that expires.
Prove. Decide. Lease.
The same three steps for an engineer and for a service.
-
1
Prove
People sign in with your IdP and MFA. Workloads attest with their platform identity.
kubernetes:prod/payments-api -
2
Decide
Policy as code decides what, for how long, and who must approve.
permit if role == "dba" and ttl <= 1h -
3
Lease
A credential with an expiry. Recorded while it lives, gone when it ends.
expires 14:35:00
Production-grade from the first install.
TLS everywhere
Every hop encrypted, including between Zerostand's own components.
Highly available
Multi-node control plane on PostgreSQL. A node can fail; access continues.
Keys you hold
Envelope encryption with the master key in your KMS. Break-glass needs more than one person.
Everything audited
Every grant, rotation, approval and session: actor, reason, time.
Questions buyers ask first.
Does Zerostand replace our password vault?
It removes standing credentials wherever a short-lived one can be issued instead, and vaults, rotates and verifies the accounts that must remain. You can start with one safe.
Do we need to install agents on every target?
No. Targets are reached over the protocols they already speak: SSH, WinRM, and the native database wire protocols.
Where does it run?
As containers on infrastructure you control, on-premises or in your cloud. Secrets never leave your environment.
What happens if the control plane is down?
The control plane runs as multiple nodes on PostgreSQL. A sealed break-glass export, openable only by several named people together, covers the worst case.
How are machines and AI agents handled?
As identities, with the same policy, approvals and audit as people. A workload attests with its Kubernetes or cloud identity and receives a credential that expires.
See it on your own targets.
Thirty minutes. One server and one database you choose. Watch access get granted, used, recorded and expire.