Bastion · Managed services module

One door onto your servers

Your teams and your contractors open a session from their browser, with nothing to install and without ever seeing the password of the machine. You know who came in, where, and what they did. The bastion sits on infrastructure we already host or already run for you, so it is a module of your contract rather than a separate subscription.

What's included

Nothing to install

RDP, SSH and VNC run in the browser. The contractor opens a link, enters their code, and they are on the machine. No client to deploy on devices you do not own.

One account per person

Each person gets their own, with their machines and nothing else. This is the end of the shared administrator account whose password nobody can trace.

Second factor at the door

One-time code or hardware key, enforced for everyone. A stolen login is not enough to get in.

Passwords stay with you

The bastion presents the credentials to the machine, the user never sees them. The end of an assignment is handled by disabling one account, without changing passwords across the estate.

Recorded sessions

A session replays like a video. It helps after an incident, and it helps to show what was done during work you invoiced.

Access windows

A contractor can have the door open only during their assignment. After that it closes again, with nobody having to remember.

How it is billed

Priced on your estate, inside your contract

The bastion is added to your managed services. The amount depends on how many machines it must reach and on the setup work: an inventory of the access paths that exist today, the connection itself, the first accounts, then the plan to close the direct routes. We price it after looking at your estate, there is no grid.

Let's talk about it

Good to know

Where it is simple, and where it becomes a project

If we host your infrastructure, the bastion sits next to your machines and there is no network to build. If we run your firewall, the path already exists. If you have your own datacentre and your own network, the bastion is deployed on your premises and we run it remotely: that works, and it is often the right answer, but it is a project with its own study and quote.

Is our bastion shared with your other customers?

No, and that matters. One instance per customer, with its own path to your estate and no shared routing. An incident at another customer gives nothing at yours. It is the first question a security officer asks, and this has to be the answer.

Does it replace our VPN?

Not necessarily, and it solves a different problem. A VPN puts someone on the network. A bastion decides which machine they reach, and keeps the record of what they did there. Many customers keep the VPN for their staff and send contractors through the bastion.

What does our contractor have to install?

A browser. That is all. No RDP client, no VPN profile to configure, nothing for their own IT department to approve.

Are we allowed to record sessions?

Yes, as long as you tell people. Staff and contractors must be informed, and the retention period has to be set in advance. We give you the wording for your contracts and your internal notice, and we set the automatic purge with you.

What if the bastion goes down?

You keep your usual access, it does not cut anything that already exists. But we would rather say it plainly: as long as direct RDP and shared accounts stay open alongside, you have gained convenience and not a control. Closing the other doors is the real work, which is why we plan it with you instead of selling you a subscription.

Where is it hosted?

On an instance of your own, in France at OVHcloud, backed up every night to another site. It can also run on your premises if your policy requires it.

The bastion runs on Apache Guacamole, an Apache Software Foundation project published under the Apache License 2.0.