Sectona PAM-Cloud Architecture

Sectona PAM-Cloud is built on a secure, multi-layered architecture that provides logical separation between customer-managed infrastructure and Sectona PAM-Cloud infrastructure. The architecture enables secure communication, centralized privileged access management, and scalable service delivery across cloud and hybrid environments.

The architecture incorporates isolated customer environments, centralized platform services, and secure outbound connectivity mechanisms to protect privileged access while minimizing exposure of customer infrastructure. This design reduces the need for direct inbound connectivity and helps maintain network segmentation between customer environments and the PAM-Cloud platform.

The following diagram illustrates the Sectona PAM-Cloud architecture, including its core components, communication flows, connectivity mechanisms, and associated protocols.

PAM Cloud Architecture_HA.drawio 1-20260819-073523.png

Sectona Cloud Infrastructure

Customer Instance

The Customer Instance hosts dedicated Sectona PAM-Cloud components for each customer within an isolated environment. These components provide the core capabilities required for privileged access management, including credential protection, privileged session management, and session auditing.

  • RNA Proxy Server: Acts as a secure communication gateway between the Customer Infrastructure and the Customer Instance hosted in the Sectona Cloud environment. It facilitates encrypted and controlled communication while minimizing direct exposure of customer infrastructure.

  • WebApp: Provides the administrative and user interface for managing privileged accounts, access policies, privileged sessions, and other PAM functions. Multiple WebApp instances deployed to provide high availability and service continuity.

  • Vault: Securely stores privileged credentials, secrets, and other sensitive PAM data using appropriate encryption and access controls.

  • Session Video Log: Stores recordings of privileged sessions to support real-time monitoring, post-session review, auditing, security investigations, and compliance requirements.

Shared Services

Shared Services provide centralized platform capabilities that are consumed by multiple customer instances. These services support common security, traffic management, customer configuration, licensing, and notification functions across the Sectona PAM-Cloud environment.

  • Access Security and Monitoring: Provides centralized security controls, monitoring, and oversight of privileged access activities across customer instances.

  • Application Load Balancer (ALB): Distributes incoming application traffic across available PAM WebApp instances to improve service availability, optimise resource utilization, and maintain consistent application performance.

  • Web Application Firewall (WAF): Protects PAM-Cloud applications against common web-based threats by inspecting and filtering incoming traffic based on defined security rules and policies.

  • Customer Infrastructure and License Information: Maintains customer-specific infrastructure, configuration, and licensing information required for provisioning, administration, and lifecycle management of PAM-Cloud services.

  • Email and Notification Service: Manages system-generated notifications, alerts, and other PAM-related email communications to support operational awareness and administrative workflows.

Cloud Security Layer

The Cloud Security Layer provides an external security boundary for Sectona PAM-Cloud by filtering and inspecting incoming traffic before it reaches the platform. It helps protect the service against internet-based threats and ensures that access to the PAM-Cloud environment is governed by defined security policies.

  • Cloud Web Application Firewall (WAF): Serves as the first layer of traffic inspection and filtering, protecting the PAM-Cloud platform against common internet-based and web application threats. It evaluates incoming requests against configured security rules and policies, blocking potentially malicious traffic before it reaches the application layer.

Customer Infrastructure

PAM Components

Customer Infrastructure refers to the on-premises or customer-managed environment that hosts enterprise systems, target assets, and PAM connectivity components. These components establish secure connectivity with the Sectona PAM-Cloud environment and enable controlled access to managed assets.

  • RNA Proxy Connector: Establishes secure, outbound communication between the Customer Infrastructure and the Customer Instance hosted in the Sectona Cloud environment. It facilitates communication with PAM services and enables controlled connectivity to managed assets without requiring direct inbound access to the customer network.

  • Satellite Vault: Provides a break-glass vault capability for PAM-Cloud, enabling access to critical privileged credentials during specific availability or connectivity scenarios.

  • Jump Host: Functions as an intermediary Windows-based host for privileged connections to target systems. It enables controlled, monitored, and auditable access to Windows-based customer assets.

  • Jump Shell: Functions as an intermediary Unix/Linux-based host for privileged connections to target systems. It enables controlled, monitored, and auditable access to Unix/Linux-based customer assets.

Connectivity and Communication

Sectona PAM-Cloud uses secure, outbound communication mechanisms to establish connectivity between the customer environment and the cloud-hosted PAM platform. The connectivity model minimizes network exposure while enabling controlled communication between PAM components and managed assets.

  • Secure Communication: Component-to-component communication is secured using HTTPS over TCP port 443, providing encrypted data transmission between participating services.

  • Outbound-Only Connectivity: Communication from the customer environment to the PAM-Cloud environment is established using outbound connections, eliminating the need for direct inbound connectivity and reducing the customer's network attack surface.

  • RNA Proxy Connectivity: The RNA Proxy Server and RNA Proxy Connector establish the secure communication channel between the Customer Instance hosted in the cloud and the Customer Infrastructure hosted on-premises or in a customer-managed cloud environment. This communication layer enables controlled interaction between PAM-Cloud services and managed assets while maintaining network segmentation.