Krontech · Privileged Access Management

Kron PAM

Privileged Access Management — the Single Connect™ platform for IT, cloud, and OT/ICS.

Kron PAM (Single Connect™) is a comprehensive Privileged Access Management platform from Krontech — built to secure, control, and audit all privileged access across IT, cloud, OT/ICS, and hybrid environments. It's an agentless, modular solution that deploys up to 80% faster than comparable PAM products, with no multi-tier dependencies.

Single Connect™ consolidates every PAM function — session management, password vaulting, MFA, database access, task automation, secure remote access, and behavioral analytics — into one unified platform managed from a single console.

How it works — access gateway architecture

Kron PAM acts as an intelligent access gateway between users and target systems. No user ever connects directly to a server, database, or network device — all connections are brokered, authenticated, recorded, and policy-enforced through the Single Connect™ engine. The gateway supports every major protocol — SSH, RDP, VNC, HTTPS, SQL, Modbus, DNP3, and more — making it suitable for IT, cloud, and industrial environments from a single deployment.

Kron PAM — Privileged Access Gateway ArchitectureWHO CONNECTSTARGET SYSTEMSIT AdminsInternal privileged usersDevOps / EngineersSSH · RDP · DatabasePartners / PartnersThird-party remote accessRemote WorkersSecure remote access (SRA)OT / ICS EngineersModbus · DNP3 · ICSServers & VMsLinux · Windows · UnixDatabasesOracle · MySQL · MSSQLNetwork DevicesRouters · Switches · FirewallsCloud & HybridAWS · Azure · GCPOT / ICS SystemsSCADA · Modbus · DNP3Authenticate · MFAControlled · RecordedKRON PAMSingle Connect™Privileged Session Manager (PSM)Password Vault & Credential CheckoutMulti-Factor Authentication (MFA)User Behavior Analytics (UBA)Policy-Based Access Control (PBAC)Agentless · Modular · Fast DeployClick any node — a user, the gateway, or a target system — for details
Users authenticate through the Kron PAM gateway to reach target systems; every session is brokered and recorded

Core modules — the Single Connect™ suite

All modules are included in the platform and managed through one console — no separate licenses or separate deployments per module.

Kron PAM — Single Connect™ Module SuitePrivileged SessionManager (PSM)Record & replay all sessionsReal-time monitoring & alertsPassword Vault& Credential MgmtZero-knowledge checkoutAuto rotation & vaultingMulti-FactorAuthentication (MFA)OTP · TOTP · Adaptive AIBehavior-based factorUser BehaviorAnalytics (UBA)Anomaly detection & scoringAI-based risk alertsDatabase AccessManager (DAM)Dynamic data maskingOracle · MySQL · MSSQL+Privileged TaskAutomation (PTA)Script & workflow automationNetwork config managementSecure RemoteAccess (SRA)Partner & third-party accessJIT · Time-bound sessionsPolicy-Based AccessControl (PBAC)Role · Schedule · GeoIP rulesCompliance & audit reportsAll modules in one platform — click any module for details
The eight integrated Single Connect modules: PSM, Password Vault, MFA, UBA, DAM, PTA, SRA, and PBAC

Privileged session lifecycle

Every privileged session follows a strict lifecycle — from access request to audit log — ensuring complete traceability and zero standing privileges. Credentials are never exposed to users, all activity is recorded, anomalies trigger automatic termination, and compliance reports are generated automatically for auditors.

Kron PAM — Privileged Session Lifecycle1RequestAccessUser connects toKron PAM portalRequests target access2Authenticate+ MFAIdentity verifiedOTP sent to mobileAI adaptive factor3CredentialCheckoutPassword Vaultissues credentialsUser never sees it4SessionMonitoredFull recordingReal-time UBAKill switch on anomaly5SessionTerminatedCredential auto-rotated on exitConnection closed6AuditLogFull video + replayCompliance reportready for auditorsEvery session controlled end-to-end — click any stage for details
The six-stage privileged session lifecycle from request to audit log

Industry use cases

Enterprise IT

Secure admin, DevOps, and remote-worker privileged access across hybrid infrastructure.

Telecom / ISP

Protect core network devices, OSS/BSS systems, and field-engineer remote sessions.

OT / ICS

Privileged access to SCADA, PLCs, and ICS components over Modbus and DNP3.

Third-Party Partners

Just-in-Time access for contractors and suppliers — time-limited, fully recorded, zero trust.

Multi-Tenant MSSP

Manage privileged access for multiple client environments from one MSSP console.

Cloud & Hybrid

Consistent PAM across AWS, Azure, GCP, and on-premise from a single platform.

Why Kron PAM?

80% faster deploy

Agentless architecture with no multi-tier dependencies — go live in days, not months.

All-in-one platform

PSM, Vault, MFA, DAM, PTA, UBA, SRA, PBAC — one platform, one console, one license.

OT/ICS native

Supports Modbus, DNP3, and industrial protocols alongside IT and cloud protocols.

Massive scale

Proven for tens of thousands of users and millions of managed devices.

Any environment

On-premise, cloud, hybrid, or air-gapped — a single deployment handles all.

Compliance-ready

Built-in reports for ISO 27001, PCI DSS, SOX, HIPAA, and GDPR out of the box.

Compliance & certifications

Kron PAM provides built-in compliance reporting and audit-trail capabilities that directly support the major regulatory frameworks. Session recordings, credential-checkout logs, access approvals, and policy-change events are all retained and searchable for audits.

ISO/IEC 27001

Information Security Management

PCI DSS

Payment Card Industry Data Security Standard

SOX

Sarbanes-Oxley financial data integrity controls

HIPAA

Healthcare data access and audit requirements

GDPR

Personal data access governance and accountability

NIST SP 800-53

Privileged account management controls

Technical specifications

Deployment
Agentless; Linux-based server; on-premise, cloud VM, or containerised
Protocols
SSH, RDP, VNC, HTTPS, SQL, Telnet, Modbus, DNP3, and proprietary OT protocols
Directory
Active Directory, LDAP, RADIUS, SAML 2.0, OIDC / OAuth2
MFA methods
OTP, TOTP, Push notification, FIDO2/WebAuthn, AI adaptive factor
Database
Oracle, MySQL, MariaDB, MSSQL, PostgreSQL, MongoDB
Cloud
AWS, Microsoft Azure, Google Cloud Platform; native API integration
Availability
Active/Passive HA; Active/Active cluster option; DR failover supported
Scale
Tens of thousands of users; millions of managed accounts/devices
API
RESTful API for SIEM, SOAR, ticketing, and automation tool integration

Ready to secure your privileged access?

Contact iconnet — an authorised Krontech partner — for a demo or proof-of-concept of Kron PAM (Single Connect™).