Skip to main content
VaultPAM
00 FAQ

frequently asked questions

Short answers on what VaultPAM does, how it deploys, and how it maps to NIS2, GDPR and SOC 2.

01 Product & deployment

Product and deployment.

1.1

What is Privileged Access Management (PAM)?

PAM is a security tool that sits between your team and your servers. Instead of logging in directly with a shared password, every privileged session goes through the PAM system, which authenticates the user, checks their permissions, provides the credentials without revealing the password, and records the session — so you always know who accessed what, when, and what they did.

1.2

Do I need a PAM tool?

You probably do if admins share passwords to servers or network equipment, contractors or third parties access your systems, an auditor has asked you to demonstrate privileged access controls, you have 10+ servers with no consistent access record, or you're subject to NIS2, ISO 27001, SOC 2 or similar frameworks. You probably don't need one yet if your entire infrastructure is two servers, every admin is a full-time employee, and you're under no compliance obligation.

1.3

How long does VaultPAM take to deploy? Do I need agents?

Deployment takes about 5 minutes and requires zero agents. Access is browser-based — no client software on user devices.

1.4

Which protocols does VaultPAM support?

Agentless RDP, SSH, VNC, and HTTP session brokering, all through the browser.

02 Compliance & security

Compliance and security.

2.1

How does VaultPAM help with NIS2 compliance?

VaultPAM maps directly to NIS2 Article 21: multi-factor authentication (Art. 21(2)(g)), privileged access management with just-in-time credential checkout and no standing privileges (Art. 21(2)(h)), cryptography policies (Art. 21(2)(i)), access control and automated off-boarding (Art. 21(2)(j)), plus audit trail and session recording for risk analysis and incident handling. Full NIS2 enforcement and administrative fines begin April 2027.

2.2

Where is my data hosted?

GCP europe-central2, Warsaw, Poland. Data never leaves the EU — no third-country transfers, in line with GDPR Article 44.

2.3

Which MFA methods does VaultPAM support?

TOTP, FIDO2/WebAuthn, and SAML 2.0 SSO with MFA enforcement at the session layer.

2.4

Are session recordings tamper-proof?

Every access event is sealed with a cryptographic hash that chains to the next record — altering any record breaks the chain, making tampering immediately detectable. Data is encrypted with AES-256-GCM at rest and TLS 1.3 in transit.

2.5

Is VaultPAM SOC 2 and ISO 27001 certified?

The SOC 2 Type II audit is in progress, with the final report expected in 2026. ISO 27001 is on the 2026 roadmap. VaultPAM is GDPR-native and aligned with DORA Article 9.

03 Pricing & trial

Pricing and trial.

3.1

Is there a free trial?

Contact us to discuss trial options. Click Request a Demo to get started.

3.2

What counts as a managed target?

Any server, workstation, or network device registered in VaultPAM. Active sessions and passive assets count equally.

3.3

Can I switch pricing tiers?

Yes — upgrade at any time, downgrade at next renewal.

04 Get started

Ready to see it yourself?

Or read more: What is PAM? · NIS2 compliance map · Security blog