ZEROSTAND

Access that ends on its own.

Short-lived, policy-checked access for people and workloads. Nothing is left standing.

Runs with what you already have

  • Kubernetes
  • AWS
  • Azure
  • Google Cloud
  • Okta
  • Linux
  • Windows
  • PostgreSQL
  • MySQL
  • SQL Server
  • Oracle
  • HashiCorp Vault
Standing passwords. Shared secrets. Access nobody revokes.

Legacy PAM vaults what it cannot remove. Zerostand removes it: every grant is a lease, and a lease expires.

What it covers.

Identities
PeopleWorkloadsService accountsCI jobs
Targets
LinuxWindowsPostgreSQLMySQLSQL ServerOracleKubernetesWeb applications
Controls
Policy as codeApprovalsRotationRecordingDiscoveryRecertificationBreak-glass

Prove. Decide. Lease.

The same three steps for an engineer and for a service.

  1. 1

    Prove

    People sign in with your IdP and MFA. Workloads attest with their platform identity.

    kubernetes:prod/payments-api
  2. 2

    Decide

    Policy as code decides what, for how long, and who must approve.

    permit if role == "dba" and ttl <= 1h
  3. 3

    Lease

    A credential with an expiry. Recorded while it lives, gone when it ends.

    expires 14:35:00

Production-grade from the first install.

  • TLS everywhere

    Every hop encrypted, including between Zerostand's own components.

  • Highly available

    Multi-node control plane on PostgreSQL. A node can fail; access continues.

  • Keys you hold

    Envelope encryption with the master key in your KMS. Break-glass needs more than one person.

  • Everything audited

    Every grant, rotation, approval and session: actor, reason, time.

Questions buyers ask first.

Does Zerostand replace our password vault?

It removes standing credentials wherever a short-lived one can be issued instead, and vaults, rotates and verifies the accounts that must remain. You can start with one safe.

Do we need to install agents on every target?

No. Targets are reached over the protocols they already speak: SSH, WinRM, and the native database wire protocols.

Where does it run?

As containers on infrastructure you control, on-premises or in your cloud. Secrets never leave your environment.

What happens if the control plane is down?

The control plane runs as multiple nodes on PostgreSQL. A sealed break-glass export, openable only by several named people together, covers the worst case.

How are machines and AI agents handled?

As identities, with the same policy, approvals and audit as people. A workload attests with its Kubernetes or cloud identity and receives a credential that expires.

See it on your own targets.

Thirty minutes. One server and one database you choose. Watch access get granted, used, recorded and expire.

Request a demo