Docs Downloads Support
EN·TR·FR
Fidwyn

Privilege is not a right. It is a moment.

Fidwyn is a modern PAM platform that governs privileged access for human, machine and third-party identities from a single place. It grants every privilege at the moment of need, takes it back when the work is done, and proves everything in between. Self-hosted, with on-prem AI and zero egress.

Product features change.
Principles don't.

Every capability in Fidwyn serves one of three zeros. This is the assumption the whole platform is built on.

0

Zero Standing Privilege

There is no permanent admin account. A grant is born the moment it is needed, measured in minutes, and destroys itself when the work is done. No key is left to steal.

0

Zero Hidden Path

Attackers read the access graph, not the org chart. Augur AI maps every indirect path an identity takes toward privilege and closes it before you even notice.

0

Zero Blind Spot

Human, machine, AI agent; data center, cloud, OT — all in one risk engine. When no identity is unseen, no door is left undefended.

One platform for every identity that holds privilege.

Machine identities now outnumber humans 82 to 1, and AI agents are the fastest-growing class of all. Fidwyn governs them the same way it governs people: with context, a time limit and a record.

Human

Employees, administrators and privileged operators.

Machine & Service

Service accounts, automation and API identities.

AI Agent

The new, machine-speed workforce that writes and acts.

Third-party

Vendors, consultants and external support.

When access is granted, the work isn't over;
that's when security begins.

Fidwyn turns pre-access verification, in-session control and post-access audit into a single security flow.

Right identity > Right privilege > Right time > Continuous control
Define
Discover the identity and the target system
Authorize
Apply policy, MFA and approval
Connect
Open a secure session without showing a password
Monitor
Record the session and every command
Analyze
Produce anomaly and risk scores

Not a catalog. One organism.

Every module is wired to the same risk engine that Augur AI feeds, and all of them are managed from one console. Pick the family your problem lives in.

Trust Core
SecretVault
Encrypted central vault for passwords, SSH keys and secrets
Password Guardian
Policy-based password rotation, verification and reconciliation
KeyFlow
SSH key and SSL/TLS certificate lifecycle
MyVault
Personal password and TOTP vault for end users
Access & Session
Privilege Access Portal
One web gateway for the vault, approval flow and reports
PrivilegeNow
Just-in-time, time-boxed, approved and auditable privilege
Secure Session Guard
Watches, records and cuts RDP/SSH/Web/DB sessions
Secure Remote Gateway
VPN-free, password-free, auditable remote access gateway
Expanding Surfaces
Endpoint Privilege Manager
Removes local admin, elevates per application
Secret DevVault
Dynamic secrets for CI/CD, K8s, RPA and machine identities
Cloud Entitlement Guard
Cleans excess entitlements and standing roles in cloud and SaaS
TrustBridge
Joins Unix/Linux/macOS to central directory services
Intelligence & Governance
Augur AI
Behavioral analytics, anomaly detection and live risk scoring
Secure Identity Insights
Dormant-account and attack-path analysis in AD/Entra/Okta
ComplianceHub
SoD, access certification and compliance-report automation
RemoteCare
Secure remote support and file transfer for the helpdesk

Same night. Same attack. Two different endings.

An employee's password is stolen by phishing. What happens next depends on your architecture.

Traditional
03:47Password stolen
03:52In through the VPN
04:15Lateral movement
05:30Reached the OT network
+21 daysBreach finally noticed
Fidwyn
03:47Password stolen
03:52No standing privilege
03:53Low context → request denied
03:54Evidence package to the SOC
DamageThe session never opened
The difference isn't the technology, it's the assumption: we never assume any access is innocent.

Privilege that lives only as long as the work.

Book a working session. Boot a fresh appliance in under a minute, request a just-in-time grant, and watch it expire on its own.