Modules

Six modules. One control plane.

Every GuardVault module ships in the same binary, shares the same policy engine and the same audit log — deploy what you need today, turn on the rest with a feature flag tomorrow.

Privileged Session Manager

Broker, record and replay every privileged session.

PSM terminates SSH, RDP, VNC, Telnet and Kubernetes protocols at a hardened proxy. Every keystroke, mouse movement and window title is captured, hash-chained and indexed for OCR search — no agents on target hosts, no changes to client tools.

60 fps
RDP capture
< 40ms
Proxy overhead
OCR 40+
Languages
guardvault · bash
$ guardvaultctl session ls --live
ID       USER          ASSET             STARTED     REC   POLICY
s-8821   ops.alice     prod-db-01        14:02:11    on    tier-2
s-8822   sre.bob       edge-fw-lax       14:04:03    on    net-r/o

$ guardvaultctl session kill s-8821 --reason 'off-hours DDL'
session terminated · evidence bundle: /forensics/s-8821.tar.zst
Frame-perfect replay

Scrub SSH keystroke timelines and RDP video frame-by-frame with adjustable playback speed and jump-to-command.

OCR & command search

Search across recorded sessions by keystroke, command name, window title or arbitrary text on screen.

Command-level policy

Block, warn or step-up on regex or AST-matched commands in real time, mid-session, without disconnecting the user.

Live monitoring

Watch active sessions live, take over, or terminate with a single click. Auditors get a shadow-view feed.

Capabilities

Everything included in PSM

SSH, RDP, VNC, Telnet, MySQL, PostgreSQL, MSSQL, Oracle, MongoDB, Kubernetes exec/attach
Signed forensic bundles ready for legal handoff
Session TTL, idle-timeout and geo-fence enforcement
Real-time SIEM streaming (Splunk, Datadog, Elastic)
Web-based RDP and SSH clients — no plugins
Session sharing for pair-ops and break-glass co-signing
The full toolkit

Jump to any module

One binary. Every module.

Turn any module on with a feature flag — no separate installs, no separate licenses to reconcile.