THE 12PORT PLATFORM
One platform for every privileged identity: human, machine, and AI.
12Port brokers privileged access, vaults credentials, manages accounts, and records every session through a single agentless control plane. Deploy on-prem, in the cloud, or in isolated networks.
How it works
A single broker between every privileged identity and every system.
Operators, vendors, scripts, and AI agents authenticate to 12Port with their corporate identity. 12Port retrieves the target credential from the vault, opens an SSH, RDP, PowerShell, VNC, Telnet, or HTTP(s) session against the target system, and records everything that happens. The credential is injected through the broker. It never reaches the user, the endpoint, or the device.
Because the broker is agentless and protocol-native, you can put 12Port in front of any system that already speaks SSH, RDP, PowerShell, or HTTP(s), without installing software on the targets, the endpoints, or anything else. That is what makes 12Port deployable in days instead of months.
Four modules
Every capability ships in one license.
Turn on what you need today. Turn on the rest when you’re ready. No new SKU, no new contract.
Privileged Access Management
Agentless brokering, just-in-time elevation, approval workflows, and full session video + transcript on every privileged session.
Credential Vault
One vault for every privileged secret: service accounts, API keys, certificates, SSH and database credentials. JIT injection. Never disclosed to the user.
Account Management
Automated password reset, key rotation, and reconciliation across operating systems, databases, network devices, and cloud identities. Includes credential rotation, credential history, and full audit.
AI & Session Intelligence
MCP server for AI agents, real-time session monitoring, plain-language behavioral analytics, adaptive MFA, and UEBA on every privileged session.
Why it’s different
Built for the way privileged access actually works in 2026.
Agentless from day one
Nothing on the endpoint. Nothing on the target. No agent fleet to manage, patch, or audit. Targets just need the protocols they already speak.
Credential never disclosed
JIT injection through the broker. The user logs into 12Port, never the target system. The credential never reaches the user’s clipboard, browser, or terminal.
Multi-tenant by design
One control plane, isolated tenants. MSPs run multiple customers from one deployment. Enterprises run multiple business units, regions, or environments, without standing up multiple stacks.
On-prem, cloud, hybrid, isolated
The same architecture runs on customer hardware, in your VPC, in our hosted environment, or fully air-gapped. Deploy where your privileged systems already live.
Auto-discovery
Discover privileged accounts on Windows, Linux, Kubernetes clusters, network devices, and databases. Bring them under management without an inventory project first.
Built for AI agents
An MCP server fronts every privileged action. AI agents request access through the same broker as humans, with the same identity, the same audit trail, and the same controls.
Architecture
Three components. No agents. No proxies in the data path.
12Port runs as three loosely-coupled services that you can stand up in a day. Highly available, horizontally scalable, and tenant-isolated.
1.
Control Plane
Identity, policy, vault, audit, analytics. The brain. Highly available, tenant-isolated, runs on customer hardware or in our hosted environment.
2.
Session Broker
Lightweight protocol broker. Sits between the user and the target. Injects credentials, records the session, enforces policy in flight. Scales horizontally per region or VPC.
3.
Web Console
Browser-based access for end users, administrators, and approvers. No native client install. Works from any modern browser, on any OS, with full session recording.