AlpacaX

Add vendors without widening exposure

Give every outside party a scoped session instead of a VPN account—access that expires, privileged commands judged before they run, and one audit record per session.

Built for the security and infrastructure teams that own the environment vendors, contractors, and MSPs need to work in.

Start free trial
Trusted by
ETRIKAISTNSRETRIKAISTNSR

The access nobody revoked

Every third party you let in leaves behind a way back in that someone has to remember to take away.

Standing access

Outside firms get a VPN account, a bastion login, or a shared credential—and then they keep it. Nobody holds a list of which third parties still have a way in.

Offboarding that slips

Onboarding a contractor is manual, and offboarding is manual too. It happens after the work is done, when nobody is watching—so access outlives the contract.

Nothing to hand an auditor

When an auditor asks what a third party actually did, the answer is scattered across VPN logs, jump hosts, and shell history, with no session to tie it back to.

You don't have a vendor problem—you have a standing-access problem.

One controlled way in for every third party

One way in

Vendors, contractors, and auditors reach your servers, databases, and Kubernetes clusters through the browser. No VPN account to provision, no SSH key to hand out—they are working minutes after you approve.

Execution control

Incumbents gate access. Alpacon gates execution—every privileged command is judged against the session's declared scope before it runs. Turn enforcement on and anything outside scope needs your approval first.

One record per session

Every session leaves its own audit record: who came in, the scope you granted, and every command they ran. Hand it to an auditor as is.

min from approval to session
% of commands checked against scope
audit record per session
standing credentials to hand out

How Alpacon works

A lightweight agent on your infrastructure, a browser on the vendor's. That's it.

Outside your perimeterYour infrastructure
Vendor browser
AI Agent
CI/CD
Alpacon Cloud
No firewall changes
Behind your firewall
ServerAgent
Direct access
Bastion hostAgent
kubectl
K8s cluster
Kubernetes
Bastion hostAgent
proxy
DB / Storage
Database
1
Agent install

Under 5 min, no firewall changes.

2
Scoped grant

You declare the scope and the expiry.

3
Browser session

The vendor opens a browser and starts work.

4
Automatic audit

Session recording + compliance export.

You keep full control—you scope each session before it opens, watch it live, and revoke it in one click. No vendor ever holds a credential.

Every outside party that needs in

Before
  • Vendor engineers wait days on a VPN account
  • The account stays live long after the ticket closes
  • No record of what the vendor ran on your servers
After
  • Vendor works in a browser minutes after you approve
  • Access expires when the session ends
  • Every command in the session is on the record

What changes for your security team

Same vendors, same work—without the standing access.

Without AlpaconWith Alpacon
Vendor onboardingDays of VPN and credential provisioningScoped browser session in minutes
OffboardingManual, and it slips past the end dateAccess expires with the session
Standing accessShared credentials with no inventoryJust-in-time access, nothing left behind
Privileged commandsTrusted by contract, reviewed after the factJudged against scope before they run
Proving it to an auditorLog gathering across five systemsOne audit record per session, exported as is
Your vendors move at browser speed. You keep every session scoped, expiring, and on the record.

Security & compliance

Zero standing access

No shared credentials, no vendor VPN accounts. Every session is authenticated and authorised when it opens, and expires when it ends.

Execution control, not just entry

Every privileged command is judged against the session's scope before it runs. Enforcement starts in monitor mode, so you watch the judgments before you switch them on.

SOC 2 ready

Session recording, access logs, and compliance exports built in. Your third-party access evidence is ready before the auditor asks.

Granular access control

Scope declared up front, access that expires with the session, and instant revocation. You stay in control.

Get started in 3 steps

Every vendor account still open is exposure you can't see—and the list only grows.
1Install the agent

You run a single install command on your own servers. Under 5 minutes, no firewall changes.

2Grant scoped access

Invite the vendor, declare what the session covers, and set when it expires.

3Stay in control

They work in a browser. Every command is judged against scope and lands in the session's audit record.

See it in action—book a 15-min demo

Add vendors without widening exposure | Alpacon