Tanflow PAM · Capability
Universal Protocol Access
One gateway, every target. Servers, desktops, databases, Kubernetes and internal web apps - reached from the browser, with nothing installed on the endpoint.
Overview
Every protocol your teams actually use
A privileged access platform is only useful if it reaches everything. Tanflow PAM brokers remote desktops, terminals, Kubernetes, the full spread of database engines - through both CLI and native GUI clients - and internal web applications, all through one zero-agent gateway rendered in the browser.
SSH, RDP, VNC, Telnet and Kubernetes access, brokered through the gateway and recorded end to end.
Direct, secure command-line access to PostgreSQL, MySQL, Microsoft SQL Server, MongoDB, Redis, Oracle and MariaDB.
Launch native tools - DBeaver, pgAdmin, DataGrip, MySQL Workbench, Azure Data Studio, Oracle SQL Developer, MongoDB Compass, SAP GUI and more - through the managed gateway.
Secure browser-based access to internal web apps via a managed container, no direct network exposure.
Organise targets into logical groups so access, policy and reporting scale across large estates.
Nothing installed on targets or endpoints - onboarding a new server is a configuration entry, not a rollout.
Why it matters
Outcomes you can put in front of an auditor
- One consistent, recorded access path for the entire estate
- No VPN clients, jump-host sprawl or per-target agents to maintain
- DBAs keep their native tools while every action stays governed
- New targets onboarded in minutes, not deployment cycles
- Consistent policy and audit across IT, OT and database access
Part of Tanflow PAM
This capability is built into Tanflow PAM - the zero-agent privileged access platform that deploys in 2-4 weeks on your infrastructure.
Explore the full platform →FAQ
Common questions
Do users have to give up their preferred database tools?
No. Tanflow brokers native GUI clients such as DBeaver, pgAdmin and DataGrip through the gateway, so teams keep familiar tools while access stays vaulted, controlled and recorded.
What has to be installed on target servers?
Nothing. The gateway brokers connections using each target's native protocol, so there are no agents to deploy or maintain on the servers themselves.
See Universal Protocol Access in action
A focused demo against your environment and your compliance requirements.