Every GuardVault module ships in the same binary, shares the same policy engine and the same audit log — deploy what you need today, turn on the rest with a feature flag tomorrow.
PSM terminates SSH, RDP, VNC, Telnet and Kubernetes protocols at a hardened proxy. Every keystroke, mouse movement and window title is captured, hash-chained and indexed for OCR search — no agents on target hosts, no changes to client tools.
$ guardvaultctl session ls --live
ID USER ASSET STARTED REC POLICY
s-8821 ops.alice prod-db-01 14:02:11 on tier-2
s-8822 sre.bob edge-fw-lax 14:04:03 on net-r/o
$ guardvaultctl session kill s-8821 --reason 'off-hours DDL'
session terminated · evidence bundle: /forensics/s-8821.tar.zstScrub SSH keystroke timelines and RDP video frame-by-frame with adjustable playback speed and jump-to-command.
Search across recorded sessions by keystroke, command name, window title or arbitrary text on screen.
Block, warn or step-up on regex or AST-matched commands in real time, mid-session, without disconnecting the user.
Watch active sessions live, take over, or terminate with a single click. Auditors get a shadow-view feed.