Platform coverage

Every module, not just the popular ones

Ask most integrators about PSMP or Secrets Hub and the conversation gets vague. This is the estate our engineers are certified and deployed against.

The estate

Self-Hosted, Privilege Cloud and ISPSS

Four groups, every component named. If it is in the Idira catalogue, we have either deployed it or trained on it, and usually both.

PAM Self-Hostedon-premises & private cloud
  • Digital Vaultprimary
  • DR Vault / Cluster VaultHA / DR
  • CPMrotation
  • PVWAportal
  • PSMsessions
  • PSMPSSH proxy
  • HTML5 Gatewaybrowser RDP
  • PTAanalytics
  • Central Credential ProviderCCP
  • Credential Provideragent
  • Secrets Manager Self-HostedConjur
  • Vault Synchronizersync
  • Backup & ReplicatePAReplicate
  • Remote Accessvendors
Privilege CloudIdira-hosted
  • Tenant onboardingsetup
  • Connector serversPSM / CPM
  • Secure Tunnelconnectivity
  • Platform managementpolicy
  • Discovery & onboardingaccounts
  • Session managementPSM
  • Privilege Cloud Shared ServicesISPSS
  • Migration from Self-Hostedcutover
Access & Sessionszero standing privilege
  • Secure Infrastructure AccessSIA
  • Secure Web SessionsSWS
  • Secure Cloud AccessSCA
  • Secure Browserisolation
  • Endpoint Privilege ManagerEPM
  • Remote Access / Vendor PAMthird party
  • Cloud Entitlements ManagerCEM
Identity, Secrets & Threatshared services
  • Idira IdentitySSO / MFA
  • Workforce Password ManagementWPM
  • Identity Flowsautomation
  • Identity Compliancecertification
  • Identity Threat Detection & ResponseITDR
  • Secrets HubAWS / Azure / GCP
  • Secrets Manager SaaSDevOps
  • Secure AI Agentsagentic
Why it matters

Depth is the difference

A PAM programme that stops at the vault and the web portal leaves most privileged access ungoverned. The modules that make the platform complete are also the ones most teams have never deployed.

  • PSMP, HTML5 Gateway and CCP are where generalist teams stall
  • Secrets Hub and Secrets Manager close the gap between PAM and DevOps
  • SIA, SWS and SCA replace standing privilege with just-in-time access
  • ITDR and PTA turn the vault into a detection source, not just a store

Ready to reduce identity risk?

If privileged access is hard to explain or credentials are hard to control, your organisation is exposed. That risk can be reduced with the right design and hands-on delivery.

Talk to an architect
How we work

These principles guide every engagement

They define how we design, deliver and operate identity security for our customers.

Certified, not just familiar

Guardian-led, with CDE credentials across PAM, Privilege Cloud, EPM and Secrets Manager, kept current on every release.

Architect-led delivery

Design is reviewed and signed off before anything is built, so what goes live is what was agreed.

Written scope, fixed price

Deliverables, timeline and price in writing before work starts. No open-ended retainers.

Enablement built in

Your team is trained during delivery, so what we build does not depend on us to keep running.

Contact us

Need identity security you can trust?

Talk to a certified architect about protecting privileged access, identities and critical systems. The first call is technical, not a sales pitch.