govpam

classic Classic list List threaded Threaded
♦
♦
1 message Options
Reply | Threaded
Open this post in threaded view
♦
♦
|

govpam

govpam
Who is Gov PAM?
27 September 2026 • Cybersecurity Consortium
Privileged access management for institutions that have to prove it: what Gov PAM is, who it is built for, and where it stands in the market.

Ask any regulated institution a question that sounds simple: who used the domain administrator account last quarter, and what did they do with it? Most can offer a policy, a spreadsheet or an assurance. Few can hand over evidence that survives an auditor testing it.

Gov PAM exists to close that gap, and its name says how: Gov PAM stands for Governance PAM. It is a privileged access management platform that holds the credentials an institution runs on and hands them out for minutes, not for the length of somebody’s employment. It records what was done with them, then seals that record so a privileged insider cannot quietly edit it afterwards.

It is built for government, defence, critical infrastructure, financial services and healthcare: institutions that must keep control of their own keys and answer to an oversight body. Its own summary fits in one line: privileged access management for institutions that have to prove it.
The problem it was built against
Most estates hand out privilege once and never take it back. A role granted when somebody joins a team outlives the project that needed it, the reorganisation after it, and often the person’s last day.

That standing privilege is what attackers inherit. An account that is privileged on Monday is privileged on Sunday at three in the morning, in the hands of whoever phished it. Gov PAM’s reading is blunt: most escalations through a government estate run through an account that legitimately held administrative rights it was not using at the time.


So the platform works the other way round. A person holds few or no standing privileged roles. They request one with a reason, people who are not them approve it, and it activates for a bounded window.
Then it expires on its own, with nobody needing to remember to revoke it. An attacker who takes that account inherits only the ability to ask for privilege — and asking is visible, auditable and refusable.
What the platform does
The clearest way to understand Gov PAM is to follow one privileged action from start to finish:
1. An operator requests the domain administrator credential and states a reason.
2. Two approvers sign off. Neither is the requester, and they are not each other.
3. The role activates for 45 minutes, then expires by itself.
4. The credential is issued on an exclusive lease and injected at the gateway, so the operator never sees the password.
5. The session is recorded while two staff watch it live. Either of them can end it.
6. The credential is rotated on return, before the lease closes.
7. Every step is hash-chained and sealed under a signed checkpoint.


That produces seven records, joined on identifiers they already share. An investigator reads one narrative instead of stitching together a flat event log by hand.


Five modules make this work, and none of them is licensed separately:
• Enterprise credential vault. Shared and static credentials held under AES-256-GCM envelope encryption, checked out on exclusive leases, and rotated on a schedule or on return.

• Just-in-time access and approvals. Deny-by-default policy, N-of-M approvals, separation of duties, time-bounded grants and audited break-glass.

• Privileged session control. Recording, live monitoring by several observers at once, command filtering and immediate termination across SSH, RDP, database, Kubernetes and web targets.
•Tamper-evident audit chain. Append-only records that expose any alteration, deletion, reordering or back-dating.

• Operations console. No CDN, no external fonts and no remote scripts, with every screen driven by the same JSON API customers get.


Optional modules sit on top: Cybersecurity Consortium compliance evidence, privileged threat analytics with per-person baselines, and SIEM forwarding to Microsoft Sentinel, syslog over TLS or NDJSON files. Privileged account discovery, application credentials for scripts and services, SSH key management, and Entra ID and LDAP integration are included rather than priced.
Deploy it anywhere
Gov PAM runs wherever an institution needs it: on-premises, in a private cloud, in its own public-cloud tenancy, or across a hybrid of these. The same platform also runs fully air-gapped, on networks where many products cannot operate at all.

That range comes from what the platform does not depend on. There is no activation server, no callback and no telemetry requirement, and licences are signed files checked offline against a trusted public key. The choice of deployment stays with the customer instead of being dictated by the product.

Keys and data stay under the customer’s control wherever it runs. With no vendor cloud in the path, data residency can be checked with a packet capture rather than taken on trust. A FIPS 140-3 validated cryptographic module is available as a build option.

Evidence, not assurances
Gov PAM’s threat model starts inside the building. It designs against a privileged insider — even a Gov PAM administrator or the database administrator — who edits, deletes, reorders or back-dates a record to hide what they did. Access control cannot stop that person, because they already hold the access.

So every audit record carries the hash of the one before it, and signed checkpoints seal the head of the chain with a key held apart from the datastore. Alter one record and every link after it fails verification. Rewrite the whole chain and the signature on the head still gives it away.

The audit interface has no update or delete operation at all. Gov PAM is precise about what that buys: tamper evidence, not tamper prevention. Where records must be impossible to destroy, a WORM export copies sealed bundles into write-once storage such as S3 Object Lock in compliance mode.

The evidence maps to the control catalogues auditors already work from:
• NIST SP 800-53: AC, AU, IA and SC families
• ISO/IEC 27001: A.5 and A.8
• SOC 2: CC6 and CC7
• PCI DSS v4.0: Requirements 7, 8 and 10
• HIPAA Security Rule: §164.308 and §164.312
• CIS Controls v8: Controls 5, 6 and 8

Every report states the period it covers, the records it read and the result of chain verification — at the top, never in a footnote. The company is also clear that no product can be compliant on a customer’s behalf. Only an organisation can be.

A licence without hostages
PAM vendors often sell back the controls an institution cannot operate without. Gov PAM’s licensing is designed to rule that out, and the company says its licensing code enforces the rules rather than leaving them to a contract.

The vault, the access model, session control, the audit chain and the console are never gated — not by a missing licence, and not by an expired one. A deployment whose licence lapses mid-procurement keeps protecting credentials. It reports the lapse loudly, with a 30-day grace period by default.

The Core and Assurance tiers are priced per named user per year, from 25 seats: count the administrators, and that is the number. The Sovereign tier, for estates behind an air gap, is priced per deployment. All three are quoted on application, in whatever format a public tender requires.

Just as telling is what is never metered:
• managed servers and target systems
• sessions and concurrency
• use of the API
• audit retention
• non-human identities such as scripts, services and scheduled jobs
• reading your own evidence

One supplier, four lines

Gov PAM is also the name of a wider portfolio: two platforms the company licenses, and two services it delivers.

• Gov PAM (licensed platform): the privileged access management platform described above.
•  KeyGuard Password (licensed platform): a self-hosted, end-to-end encrypted password manager for every member of staff, with a web vault, browser extension, desktop app and command-line client. The server only ever holds ciphertext.    
•  IAM Solutions (delivered service): identity programmes on Entra ID and Active Directory, covering federation, single sign-on, MFA and conditional access, joiner-mover-leaver automation, access reviews and service-account ownership.    
• Cybersecurity (delivered service): posture assessment against a named framework, penetration testing including OT and SCADA estates, Microsoft Defender and Sentinel enablement, and managed security services.


The logic is that privileged access is the sharpest part of the problem, not the whole of it. Gov PAM secures the privileged few and KeyGuard secures everybody else. Identity work decides who the privileged tier actually is, and assessment shows where the exposure lies.

Each line is contracted separately, and none depends on another to work. Both platforms deploy wherever the customer chooses, from on-premises to cloud to fully air-gapped. Service engagements end with the customer’s own staff running what was built.

Where Gov PAM stands

How does Gov PAM compare with the established names in privileged access? The chart below comes from the company’s own published comparison. It places seven vendors on two axes: how much of the privileged-access job a product does, and how freely an institution can choose where it runs.

Across: deployment choice and sovereignty. This asks how freely an institution can decide where a product runs — on-premises, in its own cloud, hybrid or fully air-gapped — while keeping its own keys and jurisdiction. Products that steer buyers towards a vendor-hosted service sit further left.

Up: privileged-access depth. This asks whether a product can take custody of a shared credential, hand it out under control, watch what is done with it and produce evidence afterwards. Tools that broker access well but hold no vault sit lower. They are answering a narrower question, not failing at it.

Gov PAM sits top right, in the quadrant the chart calls sovereign PAM, and furthest along the deployment axis. It is deliberately not at the top. CyberArk and BeyondTrust sit higher on depth, with a decade or more of connector catalogues, endpoint privilege management and operational maturity behind them.
Teleport sits far along the deployment axis but lower on depth. On Gov PAM’s reading, it answers short-lived infrastructure access for engineers directly, while custody of shared static credentials is a deeper question. Delinea, One Identity and Keeper sit toward the vendor-hosted side, which reflects where each steers new buyers rather than whether it offers a self-hosted edition.

In Gov PAM’s own words, it is younger and narrower than the established suites, and the chart says so.

What Gov PAM will not claim
For a security vendor, Gov PAM’s public material is unusually willing to send buyers elsewhere. Choose another product, it says, if you need:
•  a mature, decade-deep connector catalogue for hundreds of niche target systems on day one
•  endpoint privilege management across tens of thousands of workstations, which is a different product category


It is just as direct about its roadmap. Hardware key custody through PKCS#11 has not shipped, and key custody is software-only today. The company sells it only as a clearly labelled, contractually dated entitlement, and the platform itself reports it as “entitled but not shipped”.

There are also no customer logos anywhere on its website. Naming a customer needs that customer’s written permission. More importantly, publishing which privileged access platform an institution runs tells an attacker exactly what to study before calling the service desk. References are offered under NDA, once an evaluation reaches the point where they help.

Who is behind it
Gov PAM is developed by Gov PAM Ltd, a company registered in England and Wales. Wherever it is deployed, it runs against the customer’s own directory and under their key custody. So it is sold and implemented through local partners who hold public-sector framework positions and support customers in their own time zone:
• EU and UK: Cybersecurity Solutions, Acquire and Bowkins Security
• Australia: Cyber Solutions Australia
• Africa (South Africa and the SADC region): Virtueda Systems and Dark Pools
 
An evaluation follows five steps:
1. A 30-minute scoping call, which includes whether Gov PAM is the wrong answer.
2. Deployment in the environment the customer chooses, with nothing calling back to Gov PAM.
3. Discovery against the real estate, run with delegated permissions.
4. An evidence review with the customer’s own assessor, who asks for a control’s evidence and watches it being generated.
5. Adversarial testing: rewrite the audit chain, pull the network, install an expired licence.


That last step sums up the company’s stance. It would rather buyers tested its claims than believed them. You can read more at govpam.com, or see the full comparison at govpam.com/compare.