A PAM platform for Linux and Windows servers

Privileged access management (PAM) on your own infrastructure

Control SSH and RDP access to your servers in one place. Bastion provides time-limited access approvals, session recording and automated password rotation. Centralised server patching is built into the same platform. The server runs in your network and agents connect outbound only, with no open inbound ports.

Bastion dashboard: host status, resource load and recent audit events
Dashboard: host status, resource load and recent audit events.
For IT teams and MSPs: comfortable management of 20 to a few hundred servers.
Easy deployment: one binary, MariaDB, and agents for Linux and Windows.
Built in Lithuania: reliable local support.

Connection model

No new open firewall ports

A Bastion agent runs on every managed server and itself initiates the connection to the central server in your infrastructure. Because only an outbound connection is used, you don't need to open any new inbound ports. Administrators manage access, session recordings and approvals conveniently in the browser.

Access workflow

From request to recorded session

  1. 1

    Request

    An engineer picks a server and requests access for a set window.

  2. 2

    Approval

    An administrator approves or denies the request. The decision is logged to the audit trail immediately.

  3. 3

    Session

    The SSH or RDP session opens right in the browser. Everything is recorded and, when needed, watched in real time.

  4. 4

    Expiry and audit

    When the time is up, access cuts off automatically. The recording and audit logs are kept for later review.

Bastion access request queue: pending and resolved requests with statuses

Capabilities

Access control, session recording and password rotation

SSH & RDP in the browser

Terminal and remote desktop with no VPN and no extra software on the engineer's machine.

Temporary access (JIT)

Access is granted only when it is needed and switches off by itself.

Session recording

Every SSH and RDP session is recorded for security incident investigations.

Live view

Administrators can watch an active session in real time.

Password rotation

Account passwords are rotated automatically and only ever stored encrypted.

Tamper-proof audit log

Events are chained together, so logs cannot be quietly altered.

SIEM export

Audit events feed straight into the SIEM system you use.

Granular permission control

Roles define precisely who sees which servers and who may connect to them.

Product screens

What Bastion looks like at work

Real screens from a working environment. Some data is redacted.

Host list

Managed Linux and Windows servers, login accounts and agent status in one view. The terminal or RDP desktop opens from here.

Bastion host list with operating systems, ports and login accounts

Audit log

Every connection and action with source IP, session ID and timestamp. A recorded session plays back straight from the log row.

Bastion audit log with session rows and a replay button

Per-host patching

Available updates with security labels, package holds, and a history of recent installs with the option to roll a version back.

Bastion per-host patch view: pending packages and install history

Server maintenance

Patch management in the same platform

Missing Linux package and Windows Update patches appear in a single overview. The system shows pending packages, security severity and the date of the last check. Rollout starts centrally, so a separate patching tool is simply unnecessary.

Bastion patch inventory by host with pending and security update counts

Why Bastion

What Bastion replaces

A PAM solution for teams that don't need a heavy, multi-module enterprise platform. Session recordings, temporary access and a linked audit trail deliver traceability and help meet the requirements of the NIS2 directive.

Feature Manual VPN / jump-host process Separate access and patching tools Bastion
Granting access VPN accounts and keys are administered by hand. Permissions are coordinated across several systems separately. Request and approval in one interface. Access is time-limited.
Session visibility Recordings usually don't exist; you rely on server logs alone. Session capture may require a separate tool. SSH/RDP sessions are recorded. Replay and live viewing available.
Audit trail Data is scattered across several devices and hops. Each tool writes its own logs; the full picture is hard to stitch together. One linked log with direct SIEM export.
Patching Installed by hand or with assorted scripts. A separate patch-management system is needed. Linux and Windows updates managed in the same interface.
Deployment footprint Requires network and firewall configuration. Several different systems, each needing its own upkeep. One binary and unobtrusive agents that connect to the server on their own.

This comparison is a generalisation: the exact flow depends on your current infrastructure.

Let's see what this would look like in your environment.

Discuss a trial deployment

Getting started

Three steps to a controlled session

  1. 1

    Install the Bastion server

    One binary and a MariaDB database on your virtual machine is enough.

  2. 2

    Install the agent

    The agent connects to the central server on its own, so no inbound firewall ports need opening.

  3. 3

    Get started

    Sign in through the browser, approve the first access request and review its recording in the audit log.

Technical specification

Server
One binary and a MariaDB database.
Agents
Linux and Windows OS; the agent always initiates the connection.
Access
SSH and RDP right in the browser (no VPN).
Sessions
Recorded; later replay or real-time viewing.
Audit
Tamper-proof entries, ready for SIEM integration.
Passwords
Encrypted, rotated on a set schedule.
Patching
Linux packages and Windows Update, centrally.
Permissions
Role-based access control (RBAC).

Is Bastion for you?

A good fit if:

  • You manage 20 to a few hundred Linux and Windows servers.
  • Admin access currently runs over VPN, jump-host servers or shared accounts.
  • Clients, auditors or NIS2 demand strict session traceability and audit.
  • You want access control and server patch management in one tool.

Maybe not if:

  • Your main need is access to databases, network routers or cloud consoles (Bastion focuses on operating systems).
  • Complex integration with your existing IAM (identity management) systems is mandatory (contact us about non-standard integrations).
  • You require specific high-availability architectures that need to be planned individually.

Technical questions

Frequently asked questions

Do I need to open ports on managed servers?

No. The agent initiates an outbound connection to the Bastion server, so no inbound ports need to be opened for Bastion.

Where does Bastion run and where does the data stay?

You deploy the Bastion server in your own infrastructure, on a virtual machine with a MariaDB database. Session recordings and the audit log stay in your network.

Do operators need a VPN or extra software?

No. The SSH terminal and RDP desktop open in the browser.

How does temporary access work?

An engineer submits a request and an administrator approves or denies it. When the window ends, access switches off automatically, and both the request and the decision remain in the audit log.

Can I see what an administrator did on a server?

Yes. SSH and RDP sessions are recorded; replay them later or watch a session live.

Can audit events be forwarded to a SIEM?

Yes, audit log events export to the SIEM you use.

Which operating systems are supported?

Agents install on Linux and Windows servers; patching covers Linux packages and Windows Update. For specific versions, write to us.

How much does it cost?

Price and scope are discussed during the trial deployment, based on your server count and environment.

Trial deployment

Let's assess your environment

We'll show how Bastion works and discuss your server estate, access processes and the scope of a trial project.

We are looking for IT teams and MSPs managing 20 or more servers.

info@bastion.lt