Agentless connection
Bring existing RDP, SSH, VNC, terminal, and Kubernetes targets under management through a gateway or defined access path.
- RDP
- SSH
- VNC
- K8S
Governed desktop and terminal access
Cerberus brings RDP, SSH, VNC, terminal, and Kubernetes resources into a centralized access plane. Agent or gateway models keep resource ports away from direct user access. Approved sessions open in the browser while assignment, credential custody, revocation, and auditable records stay in one flow.
RDP access to erp-windows-02 is open with a timed permission; start and closure events are tracked.
Where does the need begin?
Access operations require the credential, network path, user assignment, work duration, and resulting evidence to be governed together with the connection.
RDP, SSH, and local-account material circulates across teams while credential use becomes detached from the access decision.
PAM-governed credential custody and dynamic credentialsEach location and resource adds another client, profile, NAT rule, or inbound connection path.
A private access path through an Agent or gatewayEmployees, vendors, and temporary support access live in separate accounts while a single maintenance task can expand into broad network reach.
Assignment combining identity, role, resource, and durationRDP, SSH, VNC, terminal, and Kubernetes work spans separate screens while decision, start, and closure events remain in separate records.
Multi-protocol access with an auditable event trailRDP, SSH, and local-account material circulates across teams while credential use becomes detached from the access decision.
PAM-governed credential custody and dynamic credentialsEach location and resource adds another client, profile, NAT rule, or inbound connection path.
A private access path through an Agent or gatewayEmployees, vendors, and temporary support access live in separate accounts while a single maintenance task can expand into broad network reach.
Assignment combining identity, role, resource, and durationRDP, SSH, VNC, terminal, and Kubernetes work spans separate screens while decision, start, and closure events remain in separate records.
Multi-protocol access with an auditable event trailCerberus brings credential handling, the private access path, resource assignment, work duration, session control, and closure records into one governed access flow.
Explore the other access problems we addressThe CerberusD operation path
A connection protocol establishes the access path. PAM determines who may use it, for which resource and duration, how access closes, and what evidence remains. Cerberus brings connection, authorization, session, and record into one access operation.
Users connect to assigned resources. Access decisions, session starts, state changes, revocation, and closure events remain in auditable records.
Connection models
Existing resources can connect through a gateway with the agentless model. The Windows Agent enriches readiness and health signals. Both models work together in the same workspace.
Swipe to compare both connection models
Bring existing RDP, SSH, VNC, terminal, and Kubernetes targets under management through a gateway or defined access path.
Use the Agent on Windows machines when resource preparation, service health, and private connectivity signals are required.
In both models, the resource enters the panel, is tied to a person and time window, opens for work, and leaves a visible closure record.
The Agent is an optional connection model that adds resource preparation and richer machine signals when needed. Read the Agent documentation.
First month TRY 1 campaign
Choose an Agent or gateway connection model, use the verified fast setup, and govern remote machines, terminal sessions, and Kubernetes resources through one PAM-controlled flow. Start with the first-month TRY 1 campaign.