All Use Cases
PAM

Zero-Trust Session Brokering for SSH, RDP, and Databases

Ephemeral certificates, keystroke-level command intercept, and full session recording -- without VPNs, bastion hosts, or standing credentials.

Watch the Session Broker Work

JIT certificate. Instant access. Full recording.

Three steps. No standing access.

From target registration to an active session, every step is gated, audited, and ephemeral.

Configure Target

Register an SSH, RDP, or database target in the portal. Associate a CA config, command policy, and approval workflow. No credentials stored.

Request JIT Access

The user or agent submits a JIT access request. An approver reviews it -- or auto-approval fires based on policy. No access exists until the request is granted.

Connect with Cert

CoreLink issues an ephemeral Ed25519 certificate from the tenant CA. The certificate carries a short TTL and is restricted by policy. Recording starts automatically.

From Request to Recorded Session

One brokered path. Every protocol. Full observability.

Supported protocols
SSH
RDP
Database
Kubernetes

Every PAM Capability, Built In

From certificate issuance to command intercept, CoreLink covers the full session brokering stack.

SSH

Ephemeral SSH Certificates

Each session gets a unique Ed25519 certificate signed by the tenant CA. No long-lived SSH keys. Certificates expire and cannot be reused.

Ed25519 short TTL tenant CA
RDP

RDP Credential Injection

CoreLink creates a temporary AD account with a random password for each RDP session. The account is removed when the session ends. No credentials exposed to the user.

temp AD account random password auto-cleanup
Database

Database Proxy

Dynamic database credentials are issued per session via the database proxy. Works with PostgreSQL, MySQL, and other supported engines. Credentials expire with the session.

PostgreSQL MySQL dynamic creds
Recording

Full Session Recording

Every SSH session is recorded as a gzip-compressed TTYRec file stored in the database. Replay any session keystroke by keystroke for forensic investigation.

TTYRec gzip-compressed replayable
Control

Command Intercept Policy

8 built-in command preset groups (sql-read-only, no-destructive, etc.) or custom block rules. The interceptor buffers keystrokes and checks the first token before forwarding Enter.

8 presets custom rules keystroke buffer
Agent

Transparent Sessions Agent

The sessions agent runs on target infrastructure to broker connections without exposing credentials. Sessions are brokered over WebSocket without requiring a VPN or bastion host.

WebSocket no VPN no bastion

Zero Standing Privileges, Full Observability

No user or service account has permanent access to any target. Every session is gated by a JIT approval, issued an ephemeral certificate, and terminated when the TTL expires. Access cannot outlive its approval.

Every session is recorded and every command is checked against policy before execution. The hash-chained audit log links each session record, approval, and certificate issuance to a single tamper-evident chain.

Approval
Certificate
Session

Ready to broker every privileged session?

Deploy CoreLink and eliminate standing access to your servers, databases, and Windows endpoints. Every session gated, recorded, and audited.