Privileged Access and Credential Management

Credential Vaulting

Protect privileged credentials. Rotate them with their dependencies in view.

Discover accounts, control their secrets, and carry each credential change through to the services and applications that use it.

Available now
Controlled Credential LifecycleAccounts connect to an encrypted credential vault. Credential changes are propagated to dependent services and applications, with an audit record.ENCRYPTED VAULTRotate · RecordAccountsSecretsServicesApplications
Controlled Credential Lifecycle

Credential Control Across Your Environment

Privileged Identity Management (PIM) brings credential discovery, custody, rotation, and propagation into one managed lifecycle.

Explore Privileged Identity Management →
Find Accounts and Their Dependencies
Discover privileged and service accounts, password age, and last sign-in. Identify the services, tasks, and application pools that depend on a credential.
Reduce Shared-Credential Exposure
See the hosts and services a shared credential reaches. Rotate and propagate it, or split it into one managed service account per host, with a preview first.
Keep an Operational Record
Verify sign-in after the change and retain each step in the audit trail.

Screenshots

Privileged credentials are vaulted and rotated. Operators never see the secret.

A Credential Change, End to End

Preview the change plan before applying it. The workflow accounts for the systems that rely on the credential.

  1. Discover and Map

    Identify the account and where its credential is used.

  2. Preview the Plan

    Review the target change and dependency updates before execution.

  3. Rotate and Propagate

    Stop dependent services, change the credential, update dependencies, and restart in order.

  4. Verify and Record

    Test the new credential and retain the results of every step.

Choose Where Encryption Keys Live

Stored secrets are encrypted. Key custody can follow your deployment and security requirements.

Explore Key Management →
  • Software keys in the platform secret store.
  • A hardware security module (HSM) through PKCS#11.
  • A customer-owned key in AWS KMS, Azure Key Vault Managed HSM, or Google Cloud KMS.
  • Separate key sets for different system groups, with rotation and re-encryption.

Frequently Asked Questions

How Is Credential Vaulting Different from Session Management?

Credential vaulting is part of Privileged Identity Management: discovering, protecting, rotating, and propagating credentials. Privileged Access Management controls the sessions opened with those credentials, including Connect, Jump, and recording.

Can Passwords Rotate on Air-Gapped Systems?

Yes. The AIC Agent can derive and apply scheduled passwords locally from a protected shared seed without reaching AIC Server. It propagates the change to local services and applications and records the action. An authorized administrator can derive the current password when needed.

Can We Manage a Device Without a Built-In Connector?

Yes. Use browser automation for a device with a web management page, a Secure Shell (SSH) or Telnet script for a command-line interface, or the REST API for an application that can call it. Ready-made browser automations are included, and organizations can create their own.

See Credential Vaulting in Action

A live demonstration of credential custody, rotation, and dependency updates.