Privileged Access Bridge
availableOpens access to SSH, RDP and VNC in the browser, with no agent on the target. Every session is recorded, supervised live and can be stopped instantly; every join is in the audit log.

Operated by Blackfort
Eight products for security operations: privileged access, event collection, vulnerabilities and hardening, log retention, certificates, and getting findings to the team that fixes them. Each one can be ordered on its own; each one is set up and run by us. Nothing stays on your side — no server, no database, no rule sets.
Every product does one clearly defined job and can be ordered on its own. Which ones are worth having depends on what your environment turns up.
available = orderable, set up and operated by us · pilot phase = orderable, in active development · in preparation = not yet orderable
Opens access to SSH, RDP and VNC in the browser, with no agent on the target. Every session is recorded, supervised live and can be stopped instantly; every join is in the audit log.
Collects the events from your systems in one place, checks them against a maintained rule set and reports what stands out — whatever the day or hour.
See also
Matches your software inventory against public CVE data and checks each system against its CIS policy — with a compliance score per system.
Retains logs tamper-evidently under separate administration — apart from the people whose activity they document.
See also
Moves Microsoft Defender findings into your ticketing system on a risk basis. Whatever crosses the threshold becomes a ticket for the responsible team.
See also
Keeps every certificate in one inventory, rates them and flags expiry dates in time — including the PKI dependencies whose expiry stops entire services.
Rates vulnerabilities by the business relevance of the affected system and turns that into the order of remediation.
See also
No server on your side, no database, no rule-set maintenance. Where we operate a product for you, it runs on a separate instance — no shared environment, no mixing of data. Whether a product runs with us or in your environment is agreed in the initial call.
One place to ask, one contact for every product. And a single Art. 28 GDPR data processing agreement that names the components we use and the sub-processors involved.
You get a written description of everything we install on your systems, and you can remove it at any time. Our administrative access runs through an outbound encrypted tunnel; no management port is reachable from outside.
In Germany, NIS2 is transposed through the BSIG, which is why we cite Section 30 BSIG rather than the directive itself. Treat the mapping as a starting point: whether a requirement is met depends on your implementation, and no tool satisfies it on its own.
| Standard | Reference | Requirement | Product |
|---|---|---|---|
| BSIG (Germany) | Section 30(2) No. 1 | Policies on risk analysis and on information technology security | Vulnerability Management, Event Intelligence |
| BSIG (Germany) | Section 30(2) No. 5 | Security measures in acquisition, development and maintenance of information technology systems, components and processes, including vulnerability handling and disclosure | Vulnerability Management, Security Bridge |
| BSIG (Germany) | Section 30(2) No. 6 | Policies and procedures to assess the effectiveness of risk management measures for information technology security | Vulnerability Management — supplies the metrics for the assessment |
| BSIG (Germany) | Section 30(2) No. 9 | Establishment of policies for human resources security, access control and the management of ICT systems, products and processes | Privileged Access Bridge (access control aspect) |
| ISO/IEC 27001 | Annex A.8.8 | Management of technical vulnerabilities | Vulnerability Management |
| ISO/IEC 27001 | Annex A.8.15 / A.8.16 | Logging and monitoring of activities | Event Intelligence |
| ISO/IEC 27001 | Annex A.8.2 / A.8.18 | Privileged access rights and use of privileged utility programs | Privileged Access Bridge |
| BSI IT-Grundschutz | OPS.1.1.3 | Patch and change management — detection and evidence of open vulnerabilities | Vulnerability Management (detection and evidence side) |
| BSI IT-Grundschutz | DER.1 | Detection of security-relevant events | Event Intelligence |

Founder & Managing Director, Blackfort Technology
Previously Deputy CISO at Gothaer Solutions (DORA/VAIT context), audit lead in internal audit at Postbank and Deutsche Bank. Lead author of the BSI/ACS guide on penetration testing of LLMs and standing member of the AI working group of the Allianz für Cyber-Sicherheit (BSI).
What follows describes how we operate the two products Event Intelligence and Vulnerability Management. For the other products we agree the operating model — with you or with us — in the initial call.
No shared environment, no mixing of data. At the end of a pilot we wipe the instance entirely.
Event Intelligence runs at a German hosting provider. For Vulnerability Management the location depends on the engine: the ones we operate run in Germany or in your environment, the vendor cloud services in the vendor's data centres — the vendor then becomes a sub-processor. We tell you in the initial call what each choice means.
Before we start we conclude a data processing agreement describing the technical and organisational measures; the hosting provider and any further services in use are named as sub-processors.
Exactly one port on the instance is reachable from outside, and only from your company's addresses. Our administrative access runs through an outbound encrypted tunnel.
A lightweight agent that reports events and inventory. The rights it holds are documented in the connection description, and you can uninstall it yourself at any time.
So that you can size the effort in advance:
No. Every product stands on its own and can be ordered individually. Many customers use exactly one. Event Intelligence and Vulnerability Management can also be ordered separately, even though they can technically run on the same instance.
We set it up and operate it: you provide no server, run no database and maintain no rule sets. Before you order, we tell you exactly what falls to you — rolling out an agent, one firewall rule and the onboarding sessions.
It collects events centrally, evaluates them against a rule set and reports what stands out. What it is not: a permanently staffed SOC and a long-term archive. For durable, tamper-evident history there is the Log Vault.
Rule violations trigger automatically, whatever the day or hour. During setup we agree how the alert reaches you and how often we review it. What you do not get is a permanently staffed analyst shift.
In Germany. What we operate for you runs on an instance dedicated to your company with a German hosting provider, which we name as a sub-processor in the Art. 28 GDPR data processing agreement. For Vulnerability Management you can instead choose the vendor cloud service; that vendor is then added as a further sub-processor.
We agree that up front — from a single server segment to your full endpoint estate.
One contact for setup and operation and a single data processing agreement, even if further products are added later. The value of the individual product does not depend on you booking more.
The price depends on scope: which products, how many systems, how much guidance. You receive a fixed-price offer after the initial call.
Kontakt aufnehmen
In the first call we work out which product makes the biggest difference for you — and which one you can skip.