Platform Overview

Unified Security. Five Pillars.

CoreLink brings PAM, IAM, IGA, Compliance, and SecOps into a single platform -- so every identity is governed, every credential is protected, and every access event is audited end to end.

PAM

Privileged Access Management

Replace shared passwords and standing privileges with ephemeral, audited, policy-driven access. From envelope-encrypted secrets to live SSH and RDP sessions, CoreLink PAM enforces least privilege at every layer.

Secrets Management

AES-256-GCM envelope encryption with a random DEK per secret. Multi-KMS support for AWS KMS, Azure Key Vault, GCP Cloud KMS, and HashiCorp Vault. Versioning, soft-delete, and bulk import via CSV or Transit Agent.

Dynamic Credentials

On-demand database credentials for PostgreSQL, MySQL, and MongoDB with configurable TTL leases. Credentials are created on request and automatically rotated or revoked -- no standing DB accounts.

Certificate Authority

Per-tenant SSH CA with ephemeral Ed25519 certificate issuance scoped per session. OCSP stapling, configurable extensions (port forwarding, agent forwarding), and HSM-backed CA key storage via PKCS#11.

Privileged Sessions

SSH and RDP session brokering with JIT access approval. Full TTYRec gzip-compressed recordings, 8 built-in command policy presets (block shells, block file transfer, etc.), and real-time command interception.

TLS Certificate Discovery

Scan external domains and internal hosts to detect TLS certificates. Track expiry dates, SANs, issuer chains, and cipher suites. Alert before certificates expire to prevent outage-inducing lapses.

Custom Rotation Scripts

Bring-your-own shell scripts for rotating any target credential: rotate, verify, and rollback stages. Sandboxed execution with timeout controls and structured output parsing.

LDAP Rotation Provider

Native LDAP rotation provider with Active Directory unicodePwd support. Rotate domain account passwords directly over LDAPS without requiring a domain controller agent, with automatic rollback on verification failure.

Rotation Policy Templates

Reusable rotation policy templates with configurable schedule, retry count, and backoff intervals. Apply a single template across dozens of secrets and update rotation behavior fleet-wide with one change.

Infrastructure Credential Rotation

Rotate credentials for platform-managed connections -- database connections, API integrations, and cloud service accounts -- without service downtime. Dual-credential overlap ensures zero-disruption handover during rotation.

PostgreSQL Rootless Rotation

Rotate PostgreSQL credentials without requiring superuser access. Uses the GRANT-based rotation pattern -- the managed role grants itself a new password -- so rotation works in locked-down environments where superuser is not available.

RDP Credential Injection

Inject brokered credentials directly into RDP sessions via .rdp file download with pre-populated username and CredSSP negotiation. Users launch native Remote Desktop without ever seeing the underlying password.

Transparent Sessions Agent

Config-driven TCP proxy agent that intercepts application connections and injects just-in-time credentials transparently. Applications connect to localhost; the agent handles authentication, session recording, and policy enforcement without code changes.

IAM

Identity & Access Management

Connect every identity source your organization relies on. CoreLink IAM federates users from Active Directory, HR systems, and external IdPs into one authoritative identity graph that drives all access decisions.

Active Directory

Bidirectional LDAPS sync for users, groups, and OUs. Automated account lifecycle management with real-time change detection and configurable sync intervals.

Connectors

Native integrations with Okta and Workday plus generic SCIM 2.0. Automated user provisioning and deprovisioning aligned to HR events.

Identity Provider

OIDC, SAML 2.0, and LDAP federation with per-tenant IdP configuration. Custom claim mapping, group sync, and JIT user provisioning on first SSO login.

NHI Registry

Catalog every non-human identity -- service accounts, API keys, machine credentials, and CI/CD tokens. Track ownership, expiration, last-used timestamps, and risk scores in a single inventory.

Provider Sync

Push secrets to external providers -- AWS Secrets Manager, Azure Key Vault, GCP Secret Manager -- and keep them synchronized. Changes in CoreLink propagate automatically within the sync interval.

Identity Graph

Correlate identities across AD, Okta, Workday, and local accounts into a unified graph. Detect orphaned accounts, duplicate identities, and missing ownership links automatically.

Endpoint Privilege Management

Evaluate endpoint posture -- OS patch level, disk encryption, EDR presence -- before granting privileged access. Integrate with CrowdStrike and SentinelOne for real-time posture signals.

SPIFFE JWT-SVID Issuance

Issue SPIFFE-compliant JWT-SVIDs for workload identity. Workloads authenticate with a short-lived, signed JWT that encodes their SPIFFE URI, enabling zero-trust service-to-service authentication without long-lived secrets.

Identity Graph with Escalation Paths

BFS traversal of the full identity graph to compute privilege escalation paths between any two principals. Visualize how an attacker could move from a low-privilege service account to domain admin, and block the path before exploitation.

Privilege Discovery and Classification

Automated discovery of privileged entitlements across connected systems with per-entitlement risk scoring on a 0-100 scale. Classify accounts as standard, privileged, or highly-privileged and surface remediation actions ordered by risk impact.

Constrained Certificate Authorities

Issue X.509 certificates with RFC 5280 Name Constraints extensions that restrict the DNS names, IP ranges, and email addresses a subordinate CA may sign for. Prevent certificate misuse by scoping each CA to exactly the namespace it needs to cover.

IGA

Identity Governance & Administration

Govern who has access to what -- and for how long. CoreLink IGA operationalizes least privilege through self-service workflows, workspace isolation, periodic recertification, and JIT approval chains.

Self-Service Portal

Guided access request wizards that route to the correct approver without admin intervention. Users can request secrets, sessions, AD groups, and workspace membership in a single flow.

Workspaces

Hierarchical workspace isolation with environment-scoped access. Organize secrets, sessions, and policies by team, project, or lifecycle stage while enforcing strict cross-workspace boundaries.

Access Reviews

Periodic access recertification campaigns with configurable reviewer assignments. Approve or revoke entitlements in bulk, track SLA completion rates, and export evidence for auditors.

Approvals

JIT multi-level approval chains for privileged access. Configurable escalation paths, time-bound grants with automatic expiration, and full decision audit trail per request.

SoD Policies

Define segregation of duties rules that prevent conflicting role combinations. SimulateGrant checks every access request against active policies before the grant is made, blocking violations at the source.

Micro Certifications

Continuous, lightweight recertification events triggered by access pattern changes. When a user's role shifts or new entitlements are granted, targeted certifications fire immediately rather than waiting for quarterly review cycles.

Deprovisioning Workflows

Automated offboarding triggered by HR system events. When Workday or Okta signals termination, CoreLink revokes secrets access, terminates active sessions, disables AD accounts, and logs a complete deprovisioning audit trail.

Policy Engine

Declarative, policy-as-code governance rules that evaluate in real time. Define access constraints, time-of-day restrictions, geo-fencing, and conditional approval requirements as versioned policies.

Role Mining

Analyze actual access patterns to discover implicit roles and suggest role definitions. Identify over-privileged users, recommend least-privilege role assignments, and simulate the impact of proposed role changes.

Compliance

Compliance & Audit

Demonstrate control to auditors and regulators with confidence. CoreLink captures every action in a tamper-evident SHA-256 hash-chained trail, maps controls to major frameworks, and alerts on violations before they become findings.

Audit Logs

SHA-256 hash-chained audit trail across 216+ event types. Every create, read, update, delete, and session action is captured with full user attribution, IP, and timestamp -- and chain integrity is verifiable on demand.

Compliance Reports

Automated SOC 2, HIPAA, and PCI-DSS v4.0 reporting with scheduled scans. Exportable evidence packages with control narratives and raw log attachments for auditor handoff.

Framework Support

Pre-built control mappings for SOC 2 Type II, HIPAA, PCI-DSS v4.0, and ISO 27001. Gap analysis dashboards highlight unmet controls with prioritized remediation guidance.

Violation Alerting

Real-time alerts for policy violations and anomalous access patterns. Configurable severity thresholds, notification channels (email, webhook, Slack), and escalation rules.

ISPM Scoring

Identity Security Posture Management score tracks dormant accounts, orphaned identities, SoD violations, and over-privileged access. Configurable risk weights let you tune scoring to your organizational risk tolerance.

SoD Remediation Log

Track every SoD violation detection, the remediation action taken (revoke, reassign, exception grant), who approved the resolution, and the before/after state. Exportable as evidence for SOC 2 and ISO 27001 audits.

Break-Glass Emergency Access

N-of-M quorum unsealing for emergency credential access. Require M out of N designated custodians to approve and authenticate before a break-glass secret is unsealed. Every access is logged with full custodian attribution and mandatory post-incident review.

Data Residency Controls

Per-tenant geographic enforcement of data residency requirements. Bind a tenant's secrets, audit logs, and session recordings to a specific cloud region or self-hosted deployment. Cryptographic proof of residency available for regulatory audits.

Adaptive Overload Protection

Progressive load shedding that degrades gracefully under sustained traffic spikes. Non-critical API requests are queued or shed first; secret reads and session operations are protected. Automatic recovery detection restores full capacity without manual intervention.

Usage Metering and Billing API

Tier-based usage limits with real-time metering across secrets count, API request volume, active sessions, and connected identities. The billing API exposes per-tenant consumption data so finance and platform teams can allocate costs without manual reporting.

SecOps

Security Operations

Close the gap between identity governance and threat detection. CoreLink SecOps feeds your SIEM, detects behavioral anomalies, scans code repos for leaked credentials, and evaluates device posture before granting access.

SIEM Integration

Native syslog RFC 5424 and CEF output modes. Pre-built connectors for Splunk, Microsoft Sentinel, and IBM QRadar. Configurable UDP, TCP, or webhook delivery with field normalization per target.

UEBA / Peer Analytics

Establish baseline access patterns per user and peer group. Flag off-hours logins, excessive secret reads, unusual geo-location, and privilege escalation patterns before they become incidents.

Git Secret Scanning

Scan source repositories for exposed credentials, API keys, certificates, and private keys. Integrates with GitHub, GitLab, and Bitbucket via Transit Agent with configurable entropy and pattern rules.

Device Posture

Evaluate OS patch level, disk encryption status, EDR agent presence, and certificate trust chain integrity before granting access. Gate secret reads and session approvals on real-time posture signals.

Secret Scanning

Regex and entropy-based pattern scanning across repositories and file systems. Detect API keys, connection strings, private keys, and certificates across 40+ service-specific formats with configurable severity thresholds.

Secret Sprawl Detection

Map where secrets are consumed across your infrastructure. Identify duplicated credentials, unused secrets, and over-shared access patterns. Prioritize remediation with sprawl risk scores per secret.

Developer

Developer & Platform

Give developers first-class access to secrets and identity infrastructure. CoreLink provides SDKs, a CLI, AI-native MCP integration, and CI/CD pipeline support -- so security is part of the workflow, not a barrier to it.

MCP Server

Model Context Protocol integration for AI coding assistants. Claude, Cursor, and other MCP-compatible tools can query secret metadata, list workspaces, and check rotation status -- all under the same RBAC controls.

CLI & SDKs

Full-featured CLI for macOS, Linux, and Windows. Official client libraries for Go, Python, Node.js, Java, and Ruby with typed models, automatic token refresh, and retry with exponential backoff.

CI/CD Integration

GitHub Actions, GitLab CI, and Jenkins plugins inject secrets at build time without storing credentials in pipeline configs. The scan agent runs as a pipeline step to block commits containing exposed secrets.

A2A Agent Protocol

Application-to-application authentication for workloads that need secrets without human intervention. Agent tokens with automatic rotation, mutual TLS verification, and workspace-scoped permissions.

Developer Console

API key management, webhook configuration, and integration testing from a dedicated developer workspace. View API request logs, test webhook delivery, and manage app registrations.

Support Ticketing

Built-in support ticket system for access requests, incident reports, and configuration help. Canned responses, SLA tracking, and escalation rules -- all inside the same platform, no third-party ticketing tool required.

Kubernetes Secrets Operator

Native Kubernetes operator that syncs CoreLink secrets into Kubernetes Secret objects. Define a SecretSync custom resource pointing to a CoreLink secret path and the operator manages creation, updates, and deletion -- no init containers or sidecar injectors required.

Ready to secure your organization?

Start with a free developer account. Upgrade as you grow.