Ephemeral certificates, keystroke-level command intercept, and full session recording -- without VPNs, bastion hosts, or standing credentials.
See It In Action
JIT certificate. Instant access. Full recording.
From target registration to an active session, every step is gated, audited, and ephemeral.
Register an SSH, RDP, or database target in the portal. Associate a CA config, command policy, and approval workflow. No credentials stored.
The user or agent submits a JIT access request. An approver reviews it -- or auto-approval fires based on policy. No access exists until the request is granted.
CoreLink issues an ephemeral Ed25519 certificate from the tenant CA. The certificate carries a short TTL and is restricted by policy. Recording starts automatically.
One brokered path. Every protocol. Full observability.
JIT Access
Policy Gated
Manual approval or auto-approve by policy
Ephemeral Ed25519
Short-lived cert signed by tenant CA
TTYRec + Audit
Full keystroke recording, gzip-compressed
From certificate issuance to command intercept, CoreLink covers the full session brokering stack.
Each session gets a unique Ed25519 certificate signed by the tenant CA. No long-lived SSH keys. Certificates expire and cannot be reused.
CoreLink creates a temporary AD account with a random password for each RDP session. The account is removed when the session ends. No credentials exposed to the user.
Dynamic database credentials are issued per session via the database proxy. Works with PostgreSQL, MySQL, and other supported engines. Credentials expire with the session.
Every SSH session is recorded as a gzip-compressed TTYRec file stored in the database. Replay any session keystroke by keystroke for forensic investigation.
8 built-in command preset groups (sql-read-only, no-destructive, etc.) or custom block rules. The interceptor buffers keystrokes and checks the first token before forwarding Enter.
The sessions agent runs on target infrastructure to broker connections without exposing credentials. Sessions are brokered over WebSocket without requiring a VPN or bastion host.
No user or service account has permanent access to any target. Every session is gated by a JIT approval, issued an ephemeral certificate, and terminated when the TTL expires. Access cannot outlive its approval.
Every session is recorded and every command is checked against policy before execution. The hash-chained audit log links each session record, approval, and certificate issuance to a single tamper-evident chain.
Deploy CoreLink and eliminate standing access to your servers, databases, and Windows endpoints. Every session gated, recorded, and audited.