AlpacaX

Vendor access management

Add vendors without widening exposure

Give every outside party a scoped session instead of a VPN account—access that expires, privileged commands judged before they run, and one audit record per session.

Built for the security and infrastructure teams that own the environment vendors, contractors, and MSPs need to work in.

Start free

Trusted by

  • NSR
  • ETRI

The scaling trap

The access nobody revoked

Every third party you let in leaves behind a way back in that someone has to remember to take away.

Standing access

Outside firms get a VPN account, a bastion login, or a shared credential—and then they keep it. Nobody holds a list of which third parties still have a way in.

Offboarding that slips

Onboarding a contractor is manual, and offboarding is manual too. It happens after the work is done, when nobody is watching—so access outlives the contract.

Nothing to hand an auditor

When an auditor asks what a third party actually did, the answer is scattered across VPN logs, jump hosts, and shell history, with no session to tie it back to.

You don't have a vendor problem—you have a standing-access problem.

The answer

One controlled way in for every third party

One way in

Vendors, contractors, and auditors reach your servers, databases, and Kubernetes clusters through the browser. No VPN account to provision, no SSH key to hand out—they are working minutes after you approve.

Execution control

Incumbents gate access. Alpacon gates execution—every privileged command is judged against the session's declared scope before it runs. Turn enforcement on and anything outside scope needs your approval first.

One record per session

Every session leaves its own audit record: who came in, the scope you granted, and every command they ran. Hand it to an auditor as is.

software for the vendor to install
server credentials to hand over
inbound ports to open on your hosts
audit record per session

How it works

How Alpacon works

A lightweight agent on your infrastructure, a browser on the vendor's. That's it.

Outside your perimeterYour infrastructure
Vendor browser
AI Agent
CI/CD
Alpacon Cloud
No firewall changes
Behind your firewall
ServerAgent
Direct access
Bastion hostAgent
kubectl
K8s cluster
Kubernetes
Bastion hostAgent
proxy
DB / Storage
Database
1
Agent install

Under 5 min, no firewall changes.

2
Scoped grant

You declare the scope and the expiry.

3
Browser session

The vendor opens a browser and starts work.

4
Automatic audit

Session recording + one timeline per session.

You keep full control—you scope each session before it opens, watch it live, and revoke it in one click. No vendor ever holds a credential.

Use cases

Every outside party that needs in

Before
  • Vendor engineers wait days on a VPN account
  • The account stays live long after the ticket closes
  • No record of what the vendor ran on your servers
After
  • Vendor works in a browser minutes after you approve
  • Access expires when the session ends
  • Every command in the session is on the record

The math

What changes for your security team

Same vendors, same work—without the standing access.

Without AlpaconWith Alpacon
Vendor onboardingDays of VPN and credential provisioningScoped browser session in minutes
OffboardingManual, and it slips past the end dateAccess expires with the session
Standing accessShared credentials with no inventoryJust-in-time access, nothing left behind
Privileged commandsTrusted by contract, reviewed after the factJudged against scope before they run
Proving it to an auditorLog gathering across five systemsOne audit record per session
Your vendors move at browser speed. You keep every session scoped, expiring, and on the record.

Security posture

Security & compliance

Zero standing access

No shared credentials, no vendor VPN accounts. Every session is authenticated and authorized when it opens, and expires when it ends.

Execution control, not just entry

Every privileged command is judged against the session's scope before it runs. Enforcement starts in monitor mode, so you watch the judgments before you switch them on.

SOC 2 ready

Session recording, access logs, and one filterable timeline per session, built in. Your third-party access evidence is ready before the auditor asks.

Granular access control

Scope declared up front, access that expires with the session, and instant revocation. You stay in control.

Vendor access management

Get started in 3 steps

Every vendor account still open is exposure you can't see—and the list only grows.

1Install the agent

You run a single install command on your own servers. Under 5 minutes, no firewall changes.

2Grant scoped access

Invite the vendor, declare what the session covers, and set when it expires.

3Stay in control

They work in a browser. Every command is judged against scope and lands in the session's audit record.

See it in action—book a 15-min demo

Add vendors without widening exposure | Alpacon