Privileged Access Auditing
Create defensible records of privileged operations on Linux infrastructure.
Verifiable privileged access
Identity-gated privileged access with tamper-evident session audit trails — independently verifiable without trusting the operator.
Private technical preview · Self-hostable · Built on IOTA
Identity
DID
Credential check
VC / VP
Terminal session
Linux
Session audit
recorded history
SHA-256 hash
digest
IOTA ledger
anchor
Verification
independent
Session content stays in your infrastructure. Only the digest of the actions audit document is anchored.
The problem
Privileged session recordings usually live in a database controlled by the operator. That gives you an audit trail — but ultimately asks you to trust the system storing it.
TangleGate creates a cryptographic proof of the audit artifact so its integrity can be independently checked later.
Conventional
Trust that the stored recording is the original.
TangleGate
Verify the artifact against a hash anchored outside centralized control.
How it works
Session content never leaves your infrastructure. Only the fingerprint of the performed acttions artifact is anchored publicly.
Prove your identity before privileged access is granted.
Decentralized identity · Verifiable Credentials
Work normally in a Linux terminal while the privileged session is recorded.
Terminal session · Sysadmin controls sessions termination
Create a cryptographic fingerprint of the canonical session audit and anchor it to the IOTA ledger.
IOTA
An auditor or external party can independently check whether the audit artifact matches the notarized hash.
Independent verification
Privileged terminal session
operator side
Canonical audit artifact
deterministic document
SHA-256
fingerprint
IOTA ledger
public anchor
Independent verifier
auditor / third party
✓ MATCH
The audit artifact is identical to the one notarized at session time.
✕ MODIFIED
The artifact no longer matches the notarized hash and cannot be relied on.
Use cases
Create defensible records of privileged operations on Linux infrastructure.
Gate and record privileged terminal access without adopting a heavyweight PAM platform.
Allow auditors or external parties to verify that submitted audit evidence has not been altered.
Control and record privileged access performed by contractors, vendors or other external operators.
Why TangleGate
Verifiable
Session integrity can be independently checked against a notarized cryptographic hash.
Identity-gated
Privileged access starts only after a cryptographically verifiable identity credential is presented.
Self-hostable
Run the system within your own infrastructure and keep session data and audit records under your control.
Technical transparency
TangleGate is being developed as a technical product with explicit attention to verification, threat modeling and security hardening.
Alternatives
One capability sets TangleGate apart across every category: session integrity that an outside party can verify without trusting whoever stores the log.
Status
Currently in technical preview
TangleGate is an early-stage security product under active development and hardening. We will soon start working with a small number of technical evaluators to validate the architecture, operational model and real-world use cases.
Become a design partnerContact
We're looking for infrastructure, security and compliance teams interested in evaluating TangleGate and helping shape the product.