Private pilot now open

SSH access,
governed.

Replace standing SSH keys with short-lived, identity-aware access—without putting a proxy in the path of every connection.

  • Direct OpenSSH
  • Private keys stay local
  • Outbound-only agents
TenvyrNorthstar Labs
ACCESS REQUEST

Production diagnostics

Approved
Resource
prod-web-01
Identity
ryan@northstar.example
Privilege
Login only
Grant
60 minutes
Policy decisionGroup, approval, and hardware key verified
CERTIFICATESHA256:4Xs…m8Q
VALID FOR09:42
$ tenvyr ssh prod-web-01
Connection goes directly from your OpenSSH client to the host

One access plane for the identity and operating systems you already run.

Microsoft Entra IDOktaGoogle WorkspaceBuilt-in MFA
01 / PLATFORM

Reduce standing access.
Keep the SSH you trust.

Tenvyr governs who may connect, to what, for how long, and with which privileges. Your engineers still use the system OpenSSH client they know.

01

Short-lived by default

Issue narrowly scoped OpenSSH certificates in minutes, not permanent keys that outlive the person or project.

10-minute certificate default
02

Just-in-time decisions

Route access through policy-driven requests, one- or two-person approvals, duration limits, and explicit privilege profiles.

No self-approval
03

Hardware-backed identity

Enroll FIDO2 credentials locally, require touch and PIN, and keep private-key material off the control plane.

YubiKey-ready
04

Directory lifecycle

Connect Entra ID, Okta, or Google with OIDC. Use SCIM to turn directory membership into governed SSH access.

OIDC + SCIM
05

Cross-platform control

Apply typed, signed desired state through outbound-only agents built for major Linux families, macOS, and Windows OpenSSH.

No inbound agent port
06

Evidence you can verify

Trace requests, approvals, certificates, policy decisions, host drift, and exports through tamper-evident tenant audit chains.

SIEM-ready events
02 / ARCHITECTURE

The control plane governs.
It never becomes your tunnel.

Identity, policy, and evidence live in Tenvyr. SSH traffic stays between the engineer and the target host.

EngineerDirect encrypted SSH sessionYour host
No mandatory bastion

Keep your existing network path and host controls.

No vendor session proxy

Tenvyr does not sit inside your interactive SSH traffic.

Offline-aware enforcement

Choose strict, bounded, or persistent behavior by host group.

03 / SECURITY

Secure defaults are product behavior, not a checklist.

Every host receives a unique identity. Every desired-state change is typed, host-bound, signed, versioned, and replay-resistant. Every tenant boundary is enforced in PostgreSQL as well as application code.

Discuss our security architecture
01

Tenant isolationMandatory tenant-scoped rows, inclusive foreign keys, and forced row-level security.

02

Host identity pinningPer-host mTLS identity and pinned SSH host keys detect drift and cloned hosts.

03

Isolated signingCertificate authority keys remain encrypted and are exposed only to the signer for issuance.

04

Tamper evidenceCanonical audit events are chained per tenant and anchored outside the application database.

04 / EVERYWHERE YOU SSH

One policy model.
Three operating-system families.

Linux

UbuntuDebianRHELRockyAlmaAmazon LinuxSUSEFedoraAlpine

macOS

Apple siliconIntelRemote LoginNative OpenSSH

Windows

Windows 11Server 2019Server 2022Server 2025Windows OpenSSH

Platform support is capability-tested. Compatibility public keys remain available where an operating system's OpenSSH build cannot use FIDO-backed certificates.

PRIVATE PILOT

Help shape a simpler standard for direct SSH access.

Tenvyr is currently in private pilot, not general availability. We are qualifying installers and cross-platform behavior, completing restore and tenant-isolation evidence, and preparing an independent security review before GA.

Designed with clear boundaries

V1 does not proxy or record sessions. Revocation stops new certificate issuance and reconciles hosts, but does not guarantee termination of an already-open SSH session.

Request a private pilot Best for teams managing 10–200 SSH hosts.