THIRD-PARTY REMOTE ACCESS

Privileged access for vendors, contractors, and outsourced teams.

Brokered, recorded, Just-in-Time vendor sessions. No VPN. No vendor-side software. No standing accounts left behind when the engagement ends.

12Port gives outside parties the access they need to do the work, and nothing else. Every action is named, watched, and revocable in a click.

The problem

Vendor access is the breach surface most enterprises still treat as trusted.

The average enterprise grants privileged access to dozens of outside parties: technology vendors, MSPs, contractors, integrators, medical-device technicians, OT field engineers. They reach in over shared VPN accounts, persistent jump-host logins, or vendor-supplied remote-support tools the security team has never reviewed.

The result reads the same in almost every breach post-mortem: standing credentials, no per-session attribution, no recording of what the vendor actually did, and a slow revoke path when the engagement ends. 29% of all breaches in 2023 were attributable to a third-party attack vector, and 98% of organizations use a third party that has experienced a breach (SecurityScorecard, 2024). 91% of organizations describe third-party access as a top concern (CyberArk, 2024).

How it works

One web link. Bounded session. Full audit.

The vendor logs in to a 12Port portal with their own identity. 12Port checks the request against AccessWall policy, opens the protocol session against the target, and records everything. No client install, no inbound firewall hole, no credential ever leaves the vault.

Agentless on both sides

No software on the vendor’s laptop. No agent on the target. 12Port brokers RDP, SSH, PowerShell, VNC, Telnet, and HTTP(s) through any modern browser.

Just-in-Time access windows

Time-boxed sessions tied to a ticket or approval. Access expires automatically when the window closes. No standing accounts left behind when the engagement ends.

Credentials never leave the vault

Passwords and keys are injected by the broker into the session. The vendor never sees, copies, or stores a credential. Rotation happens behind the scenes.

Every keystroke recorded

Full video, transcript, file transfer, and clipboard capture. Searchable, exportable, and tied to a named vendor identity for evidence-grade audit.

Why it’s different

Vendor access without the appliance, the agent, or the multi-day onboarding.

No footprint

Truly agentless

Vendor laptops do not need a Jump Client. Targets do not need an installed agent. There is no jump host to maintain on either side of the session.

Browser-native

Sessions render as HTML5 in any current browser. No native client, no Java applet, no per-vendor desktop configuration to push or troubleshoot.

Native protocol proxies

12Port brokers RDP, SSH, PowerShell, VNC, Telnet, HTTP(S), and Kubernetes as native protocol sessions. No gateway translation overhead. Vendors work in the interface they already know.

Strong defaults

MFA at every access

Every privileged session starts with multi-factor verification, not just the initial login. Adaptive re-verification mid-session, through the identity provider your vendor already uses.

Just-in-Time, Zero Standing Privilege

Vendor accounts do not sit dormant in Active Directory between visits. Access is provisioned at request time and removed at session end. ZSP by default, not as an upgrade tier.

Server-side recording

Recording happens at the broker, not on the vendor endpoint. The vendor cannot disable it, the target cannot tamper with it, and the audit trail lives in your tenant.

Your data, your control

Self-hosted, customer-controlled

You host 12Port in your own environment. The control plane, the audit data, and the session recordings all live in your tenant. There is no third-party cloud in the session data path.

Reverse tunnel on outbound 443

Peer nodes reach into isolated networks via a reverse tunnel they initiate outbound on port 443. No inbound firewall changes in the asset network. No DMZ appliance to size.

Identity-first, not appliance-first

Vendors authenticate through your identity provider and your AccessWall policy. No more shared service accounts handed out by email. Federate with the vendor’s IdP so their offboarding deprovisions yours.

Covers human and non-human identities

The same broker that controls human vendor sessions handles vendor scripts, automation, and AI agents through the MCP Server. One policy surface, one audit trail.

Per-vendor isolation

One site per vendor. Their identity, your governance.

Each vendor on 12Port gets their own site: a logical container scoped to only the assets that vendor needs to reach. Vendor technicians never see, let alone touch, anything outside that scope. The blast radius of a compromised vendor account stops at the site boundary.

Site-scoped access

Each vendor gets a 12Port site, isolated to the assets they are authorized to reach. A compromised vendor session cannot pivot to assets that are not in that site. Each vendor company sees only their own people, their own audit trail, their own session history.

Identity you do not have to manage

Create 12Port accounts for the vendor’s people, or federate with the vendor’s own identity provider. The federated path is what most customers settle on: when the vendor offboards an employee, their IdP deprovisions, and 12Port follows. You never have to learn that a tech left their company three weeks ago through a status report.

How 12Port compares

12Port vs. CyberArk and BeyondTrust.

Two enterprise vendors dominate the third-party-access category: CyberArk Vendor Privileged Access Manager and BeyondTrust Privileged Remote Access. Each has tradeoffs worth knowing before you sign. Capabilities below were captured from each vendor’s own product documentation in May 2026.

Capability 12Port CyberArk Vendor PAM BeyondTrust PRA
Agent on the target system None None Jump Client (persistent endpoint agent) for full feature set; Jumpoints for agentless paths
Software on the vendor endpoint None. Browser only. Proprietary mobile client required for biometric MFA Browser-based; native clients available
Software inside customer network 12Port broker (self-hosted), with peer nodes that reach isolated networks via a reverse tunnel initiated outbound on port 443. No inbound firewall changes needed in customer asset networks. HTML5 Gateway + Remote Access Connector (Docker containers) B Series Appliance (physical, virtual, or cloud)
Deployment footprint Self-hosted. Customer controls the control plane and the data. Full data sovereignty. SaaS broker plus required customer-side Docker containers B-Series appliance (physical, virtual, cloud) or SaaS
Industry posture Industry-agnostic Broad enterprise; often paired with existing CyberArk PAM Broad IT, with a recent OT and critical-infrastructure push
AI agents and non-human identities Native MCP Server for AI Agents covers the same broker, policy, and audit Secure AI Agents Solution; Palo Alto Networks Idira platform GA May 2026 Pathfinder for AI Agents (March 2026); Pathfinder MCP Server (April 2026)
Session recording location Server-side at the broker; vendor cannot disable Browser-isolated session stream via CyberArk PAM Captured at the Jump Client or appliance depending on path
Pricing Per named user. Lowest cost in the category, with the most features included. Quote-only. Requires CyberArk PAM (Self-Hosted or Privilege Cloud) as the parent platform; professional services typically required. Quote-only. Typically bundled with Password Safe, Identity Security Insights, and Entitle in the Pathfinder stack.

Sources: CyberArk Vendor Privileged Access Manager product page and datasheet; BeyondTrust Privileged Remote Access product page and Jump Technology documentation. Vendor product capabilities change frequently; verify before purchase.

Use cases

Where third-party PAM actually shows up.

IT outsourcing and MSP support

Give every MSP technician a named identity. Sessions are JIT, tied to a ticket, recorded, and revocable at the broker the moment the engagement closes.

Medical device and EHR vendor access

Auditable access to imaging archives, EHR servers, and connected medical devices without a shared password or a vendor-specific VPN tunnel. Supports HIPAA vendor-access controls.

OT and field-service technicians

Plant-floor and substation vendors get brokered access to SCADA, HMIs, jump boxes, and engineering workstations over the same protocols the equipment already speaks. VNC and Telnet included.

Contractor and professional-services access

Time-boxed credentials for project work. Access disappears when the statement of work closes, with a complete recording of what each contractor touched and changed.

See your vendor sessions inside 12Port.

We will spin up a sandbox and walk through your real vendor-access patterns in 30 minutes.