Short-lived by default
Issue narrowly scoped OpenSSH certificates in minutes, not permanent keys that outlive the person or project.
10-minute certificate defaultReplace standing SSH keys with short-lived, identity-aware access—without putting a proxy in the path of every connection.
SHA256:4Xs…m8QOne access plane for the identity and operating systems you already run.
Tenvyr governs who may connect, to what, for how long, and with which privileges. Your engineers still use the system OpenSSH client they know.
Issue narrowly scoped OpenSSH certificates in minutes, not permanent keys that outlive the person or project.
10-minute certificate defaultRoute access through policy-driven requests, one- or two-person approvals, duration limits, and explicit privilege profiles.
No self-approvalEnroll FIDO2 credentials locally, require touch and PIN, and keep private-key material off the control plane.
YubiKey-readyConnect Entra ID, Okta, or Google with OIDC. Use SCIM to turn directory membership into governed SSH access.
OIDC + SCIMApply typed, signed desired state through outbound-only agents built for major Linux families, macOS, and Windows OpenSSH.
No inbound agent portTrace requests, approvals, certificates, policy decisions, host drift, and exports through tamper-evident tenant audit chains.
SIEM-ready eventsIdentity, policy, and evidence live in Tenvyr. SSH traffic stays between the engineer and the target host.
Keep your existing network path and host controls.
Tenvyr does not sit inside your interactive SSH traffic.
Choose strict, bounded, or persistent behavior by host group.
Every host receives a unique identity. Every desired-state change is typed, host-bound, signed, versioned, and replay-resistant. Every tenant boundary is enforced in PostgreSQL as well as application code.
Discuss our security architectureTenant isolationMandatory tenant-scoped rows, inclusive foreign keys, and forced row-level security.
Host identity pinningPer-host mTLS identity and pinned SSH host keys detect drift and cloned hosts.
Isolated signingCertificate authority keys remain encrypted and are exposed only to the signer for issuance.
Tamper evidenceCanonical audit events are chained per tenant and anchored outside the application database.
Platform support is capability-tested. Compatibility public keys remain available where an operating system's OpenSSH build cannot use FIDO-backed certificates.
Tenvyr is currently in private pilot, not general availability. We are qualifying installers and cross-platform behavior, completing restore and tenant-isolation evidence, and preparing an independent security review before GA.
V1 does not proxy or record sessions. Revocation stops new certificate issuance and reconciles hosts, but does not guarantee termination of an already-open SSH session.