Open source security bastion built in Rust, designed to protect and control SSH and RDP access to critical infrastructure across enterprise, industrial, and defense environments.
Secure access, full traceability, and granular control — with no proprietary vendor lock-in.
Access your Linux and Windows servers directly from the browser. SSH terminal in the browser, RDP remote desktop in the browser.
TOTP, HOTP, and SSO integration (OIDC, SAML). Compatible with LDAP and Active Directory to integrate with your existing directory.
Granular policies by role, group, and server through the access policy engine. Just-In-Time access to limit temporal exposure.
MP4 video recording with BLAKE3 cryptographic integrity. Replay any session for audit or investigation.
Live dashboard: active sessions, metrics, security alerts, and recent activity.
Encrypted storage for SSH keys, passwords, and certificates. AES-GCM encryption with HKDF-SHA3 key derivation.
Seven isolated services, orchestrated by a single supervisor. OpenSSH-inspired privilege separation, Capsicum sandboxing.
A sovereign approach to access security, with no compromises.
Source code available under BSD-2-Clause license. No black box: every line is verifiable by your teams or an independent auditor.
Deployed on your infrastructure, under your control. No data flows through a third-party cloud.
Rust eliminates memory vulnerabilities. Privilege separation and Capsicum sandboxing limit the impact of a compromise.
Full traceability, session recording with cryptographic integrity, and granular access control.
|
Vauban
|
Proprietary | |
|---|---|---|
| Source code | Open (BSD-2) | Closed |
| Hosting | Self-hosted | Vendor cloud |
| License cost | Free | Per user / year |
| Language | Rust (memory-safe) | Java / C++ / Go |
| Code audit | Possible | Not possible |
| Vendor lock-in | None | Full |
Meet the team at Ambition Industry in Liege, or contact us for a demo of Vauban on your infrastructure.