Every privileged connection goes through the proxy, or it doesn't happen

SSH, RDP, MySQL, PostgreSQL, MongoDB, Kubernetes and web targets, recorded end to end.

No session runs directly between a user and a target. AkkuReka sits in the path, and because it sits in the path it can record what happened, log every command, and cut the connection while it is still open. The target sees the proxy, not the person, and never knows the real user's identity.

What AkkuReka proxies

SSH to Linux, Unix and network devices, with full screen capture and a complete keystroke log per command. RDP to Windows servers and desktops, with screen video at a frame rate you set. MySQL, PostgreSQL and MongoDB, with screen capture plus every query stored as structured data rather than as pixels. Kubernetes, natively, with the command log. And HTTP and HTTPS for web applications. Coverage expands, so confirm the current list for a specific environment.

What a recording contains

Recordings stream to encrypted storage as the session runs, indexed for playback in the console with no media player and no download. Each carries the session ID, the actor, the target, start and end timestamps, duration and the reason it ended. Forensic search runs inside recordings by timestamp, by command string or by SQL query, so finding the moment someone dropped a table is a search rather than a viewing.

Watching, and stopping

Every active session is visible in the console as it happens. Any of them can be terminated instantly, severed at the proxy rather than requested politely of the target. The termination is written to the audit log with the actor, the timestamp and the reason, the session is flagged in history, and the recording remains available in full.

Nothing on the target

Targets need no agent. The worker reaches them over their existing ports, and they are never directly reachable from the internet.

More in PAM

See how it works.

Every privileged session runs through the proxy, with a credential the user never sees and a recording of what happened. The worker dials out, so nothing needs an inbound firewall rule.

No standing accessAppend-only audit logOutbound only, no inbound ports