Privileged access you can evidence in an audit – without foreign jurisdiction.
Privileged RDP, SSH and VNC access through the browser — every session recorded and instantly stoppable. Run by you.Privileged RDP, SSH and VNC access through the browser — every session recorded, supervised live and stopped instantly if needed. Run by you — on-premises or in your own cloud, agentless, audit-ready for DORA and NIS2.
We set up the PAB in your environment — try it for 90 days, no obligation. No data leaves your house.
Built in Germany · Run by you: on-premises or in your own cloud
For CISO & ISO
Demonstrable, auditable, in your hands
- Auditable sessions: every privileged session is recorded, can be supervised live and terminated instantly – the controls can be retrieved as evidence at any time.
- Data sovereignty: recordings and logs stay in your environment and within the EU.
- DORA and NIS2: the required control layer for privileged access – rights matrix, session recording, tamper-evident audit trail directly from the system.
- Simpler third-party assessment: EU operation, on-premises and full transparency over data flows make the register and exit assessment required by DORA lean and demonstrable – instead of a black box under foreign jurisdiction.
For CTO & IT leadership
No extra hardware, on your existing infrastructure
- Agentless: no software on client or target, access solely through the browser via RDP, SSH and VNC.
- On-premises on your existing hypervisor: no dedicated appliance and no extra hardware required.
- Priced by the real number of admins: you pay for the people who actually administer, not for an enterprise floor.
- Managed option: on request, Blackfort takes over operation, patch management and monitoring – in the break-glass model you keep the sealed emergency access.
Session recording
Every privileged session is recorded in full and replayable directly in the portal – the basis for forensics and complete audit evidence. Who accessed what and when is retraceable frame by frame after the fact.
Tamper-evident audit trail
Security-relevant actions are logged per actor and tamper-evident. That provides the audit-ready evidence DORA, NIS2 and ISO 27001 require for privileged access – retrievable directly from the system, without manual after-the-fact documentation.
Market standard, sovereign by design
The controls a PAM has to provide
These capabilities are market standard. What sets the PAB apart is the combination of operation in your own environment (on-premises or your cloud), a fit to your actual number of admins instead of a fixed base fee and agentless access – full data control with a simple third-party assessment.
Live supervision & kill switch
A supervisor follows any running session in real time, read-only, and terminates it instantly if needed. Supervision is enforced technically, not merely expected via a policy.
Role-based access
Permissions are granted role-based on least-privilege – fine-grained per connection and group. Every action is attributed to a person and logged.
MFA
Multi-factor authentication at the hardened portal. The session is held server-side; the browser only holds an HttpOnly cookie protected against CSRF.
Browser-based access
RDP, SSH and VNC run entirely in the browser. Nothing is installed on client or target – legacy systems and vendor support stay untouched.
On-premises, agentless
Operated on your existing hypervisor. No dedicated appliance, no agent on the target systems, no data flow to third parties.
PAB in comparison
Privileged Access Bridge versus classic enterprise PAM
The feature gap is small – the differences lie in the operating model, jurisdiction and price. “Enterprise PAM” here stands generically for established platforms of that class.
| Criterion | Privileged Access Bridge | Classic enterprise PAM |
|---|---|---|
| Operation & jurisdiction | EU operation. Operated in your own environment — on-premises or your cloud. No data flow to third parties; fully EU-sovereign on request. | Often US jurisdiction. Vendors often under US jurisdiction (e.g. Balabit via One Identity / Quest / Clearlake). Cloud components and support access may sit outside the EU. |
| Operating model | On-premises, agentless. On your existing hypervisor. Also available as a managed service by Blackfort. | Appliance- or agent-bound. Often tied to appliances or agents on target systems; SaaS lock-in with some vendors. |
| Cost / licensing model | Priced per admin. By the real number of administrators, with no fixed base fee. | High entry floor. Frequently a high entry floor, scaled by target systems or enterprise bundles. |
| Session recording, live supervision, kill switch | Included. Recording, real-time supervision and instant termination directly in the portal. | Market standard. Usually included – depending on module and licence tier. |
| Third-party risk under DORA/NIS2 | Shorter assessment. Operated in your own environment — on-premises or your cloud: full data control, no data flow to third parties, data flows visible; fully EU-sovereign on request – this shortens your risk assessment and the register assessment. | More involved assessment. Frequently US jurisdiction with cloud/support access outside the EU – a more involved assessment of outsourcing, data flow and exit. |
Show further criteria (3)
Statements on vendor structure refer to publicly documented ownership and operating relationships and serve general market orientation. Sources: One Identity–Balabit (2018) oneidentity.com/balabit-acquisition · Quest → Clearlake Capital (2021/22) blocksandfiles.com. Always verify the specific scope against the respective current vendor information.
PAB vs. enterprise PAM — comparison & DORA/NIS2 checklist (PDF)
A compact comparison of both operating models and a checklist of the evidence DORA and NIS2 expect for privileged access – available as a direct download.

Christian Gebhardt
Founder & Managing Director, Blackfort Technology
Former Deputy CISO at Gothaer Solutions (DORA/VAIT), and for several years an audit lead in Internal Audit at Postbank and Deutsche Bank. Lead author of the German ACS/BSI guideline on penetration testing of LLMs and a standing member of the BSI’s AI working group (Alliance for Cyber Security). Focus: information security, compliance (DORA/NIS2) and their technical implementation.
Demo
See the PAB in action
Two ways: the online demo runs instantly in the browser, no installation. Or talk to us – in a short personal demo we show session recording, live supervision with kill switch and the audit-ready trail applied to your use case.
- 3 months free — no obligation
- Set up by us, in your environment
- Online demo: instant, no installation
3 months free
Start your PAB pilot
We set up the PAB in your environment — try it free for 90 days, no obligation. Two details are enough.
The PAB provides evidence for privileged access; overall compliance depends on your implementation. Not legal advice.