Add vendors without widening exposure
Give every outside party a scoped session instead of a VPN account—access that expires, privileged commands judged before they run, and one audit record per session.
Built for the security and infrastructure teams that own the environment vendors, contractors, and MSPs need to work in.
The access nobody revoked
Every third party you let in leaves behind a way back in that someone has to remember to take away.
Standing access
Outside firms get a VPN account, a bastion login, or a shared credential—and then they keep it. Nobody holds a list of which third parties still have a way in.
Offboarding that slips
Onboarding a contractor is manual, and offboarding is manual too. It happens after the work is done, when nobody is watching—so access outlives the contract.
Nothing to hand an auditor
When an auditor asks what a third party actually did, the answer is scattered across VPN logs, jump hosts, and shell history, with no session to tie it back to.
One controlled way in for every third party
One way in
Vendors, contractors, and auditors reach your servers, databases, and Kubernetes clusters through the browser. No VPN account to provision, no SSH key to hand out—they are working minutes after you approve.
Execution control
Incumbents gate access. Alpacon gates execution—every privileged command is judged against the session's declared scope before it runs. Turn enforcement on and anything outside scope needs your approval first.
One record per session
Every session leaves its own audit record: who came in, the scope you granted, and every command they ran. Hand it to an auditor as is.
How Alpacon works
A lightweight agent on your infrastructure, a browser on the vendor's. That's it.
Under 5 min, no firewall changes.
You declare the scope and the expiry.
The vendor opens a browser and starts work.
Session recording + compliance export.
Under 5 min, no firewall changes.
You declare the scope and the expiry.
The vendor opens a browser and starts work.
Session recording + compliance export.
Every outside party that needs in
- Vendor engineers wait days on a VPN account
- The account stays live long after the ticket closes
- No record of what the vendor ran on your servers
- Vendor works in a browser minutes after you approve
- Access expires when the session ends
- Every command in the session is on the record
- Vendor engineers wait days on a VPN account
- The account stays live long after the ticket closes
- No record of what the vendor ran on your servers
- Vendor works in a browser minutes after you approve
- Access expires when the session ends
- Every command in the session is on the record
What changes for your security team
Same vendors, same work—without the standing access.
| Without Alpacon | With Alpacon | |
|---|---|---|
| Vendor onboarding | Days of VPN and credential provisioning | Scoped browser session in minutes |
| Offboarding | Manual, and it slips past the end date | Access expires with the session |
| Standing access | Shared credentials with no inventory | Just-in-time access, nothing left behind |
| Privileged commands | Trusted by contract, reviewed after the fact | Judged against scope before they run |
| Proving it to an auditor | Log gathering across five systems | One audit record per session, exported as is |
Security & compliance
Zero standing access
No shared credentials, no vendor VPN accounts. Every session is authenticated and authorised when it opens, and expires when it ends.
Execution control, not just entry
Every privileged command is judged against the session's scope before it runs. Enforcement starts in monitor mode, so you watch the judgments before you switch them on.
SOC 2 ready
Session recording, access logs, and compliance exports built in. Your third-party access evidence is ready before the auditor asks.
Granular access control
Scope declared up front, access that expires with the session, and instant revocation. You stay in control.
Get started in 3 steps
You run a single install command on your own servers. Under 5 minutes, no firewall changes.
Invite the vendor, declare what the session covers, and set when it expires.
They work in a browser. Every command is judged against scope and lands in the session's audit record.