Nova Security Operations ← Back
Nova Security Operations Product Datasheet

Privileged Access Management

Lock down the keys to your kingdom. NovaSecOps PAM vaults every credential, brokers just-in-time privileged sessions, and records every action — so the right people get the right access, for the right time, with a tamper-evident trail of everything they did.

Product line: Nova PAM Deployment: SaaS · On-prem · Air-gapped Document: v1.0 · 2026
0passwords exposed to operators
100%privileged sessions recorded
JITjust-in-time, zero standing privilege
1-clickbrokered SSH / RDP / DB / cloud
Append-onlytamper-evident audit trail

Overview

Privileged accounts are the number-one target in modern breaches. Nova PAM removes standing privilege and shared secrets from your environment: credentials live in an encrypted vault, access is granted just-in-time against policy, and every session is brokered so your operators' workstations never see the raw password. Full session recording and an append-only audit log give you complete, court-ready accountability — and make audits painless.

Key capabilities

Encrypted credential vault

Passwords, keys and secrets stored encrypted with per-secret policy and automatic rotation.

Just-in-time access

Zero standing privilege — access is granted on request, time-boxed, and auto-revoked.

One-click brokered sessions

Launch SSH, RDP, database, Kubernetes or cloud sessions without ever seeing the credential.

Full session recording

Byte-level keystroke and video-style replay of every privileged session.

Approvals & workflows

Dual-control, request/approve and break-glass workflows for sensitive targets.

Append-only audit trail

Tamper-evident log of every checkout, grant, session and command for compliance.

Secrets & key management

API keys, service accounts and machine secrets with programmatic retrieval.

MFA & zero-trust

Phishing-resistant MFA and policy-based, least-privilege access by identity.

Supported targets

Broker privileged access to everything that runs your business — with recording on by default.

SSHLinux / macOS / network gear
RDPWindows Remote Desktop
PostgreSQLpsql / admin
MySQL / MariaDBmysql CLI
MSSQLsqlcmd / SSMS
MongoDBmongosh
Kubernetesscoped kubectl
AWS / Azure / GCPfederated console & CLI

How it works

👩‍💻
OperatorRequests access from the portal — never sees the secret
🛡️
Policy & approvalJIT grant checked against least-privilege policy
🔐
Vault & brokerInjects the vaulted credential into a brokered session
🖥️
TargetSSH / RDP / DB / cloud — fully recorded & audited

Technical specifications

DeploymentSaaS (multi-tenant), single-tenant cloud, on-premises, or fully air-gapped
Access methodsBrowser-based sessions and one-shot downloadable launchers (e.g. .rdp); optional HTML5 in-browser terminal/desktop
Vaulting & encryptionAES-256 at rest, TLS 1.3 in transit; per-secret policy; automatic & on-demand rotation
Session recordingKeystroke/byte-level for shells; metadata and screen capture for graphical sessions; searchable replay
AuthenticationSSO / SAML / OIDC, phishing-resistant MFA, RBAC, per-site scoping
Access modelJust-in-time, time-boxed grants; dual-control approvals; break-glass
Secrets APIREST API & CLI for programmatic secret retrieval by machines and pipelines
IntegrationsActive Directory / Entra ID / LDAP, SIEM/SOAR forwarding, ticketing & webhook notifications
Audit & loggingAppend-only, tamper-evident audit log; export for evidence; SIEM streaming
Standalone or unifiedRuns on its own, or feeds the all-in-one Nova XDR monitoring brain

Security & compliance

Use cases

Stop credential theft

Remove shared admin passwords and standing access that attackers pivot through.

Third-party & vendor access

Give contractors time-boxed, recorded access without ever sharing a password.

Pass audits faster

Produce a complete, replayable record of who did what, when, on every system.

Secure DevOps secrets

Vault pipeline keys and service accounts with programmatic, audited retrieval.

See Nova PAM in action

Book a walkthrough or start a free assessment of your privileged-access risk.

Nova Security Operations · novasecops.com · hello@novasecops.com · 7 W Monroe St, APT 424, Chicago, IL 60603, United States
© 2026 Nova Security Operations. PAM product datasheet v1.0. Specifications subject to change.