Realm: Modern Access Bastion & Sovereign PAM

Realm: Modern Access Bastion & Sovereign PAM

Browser-based access bastion, no client software, no VPN

Heimlane Realm is a modern bastion host (PAM): browser-based RDP, SSH and VNC access, full session recording, and credential injection from Vault: administrators never see the password. No jump server, no firewall changes.

See Heimlane Realm in Action

Watch on YouTube ↗

Why This Bastion Host Is Different

Traditional access solutions, notably PAMs (also called access bastions or administration bastions), require expensive infrastructure, complex configuration, and dedicated teams.
Realm is a sovereign bastion, designed for the real needs of SMBs and mid-market companies, built around zero trust and least privilege principles.

Every enterprise-PAM capability, without the complexity or the cost:

  • Session recording
  • Full traceability and audit
  • Secure credential storage
  • Role-based access control
  • 100% browser access, no client to install
  • Credentials handled by Heimlane Vault
  • Operational from day one
  • No heavy infrastructure or dedicated team

Who it's for

Perfect for MSPs/MSSPs managing multiple customer environments, or businesses needing secure remote access without the complexity of enterprise solutions.

Simple Interface, Professional Power

Simple Interface, Professional Power

Heimlane Realm centralizes all your remote access in a clear, intuitive interface. Create your targets in just a few clicks and connect instantly, straight from your browser.

The complete session history lets you track who accessed what, when, and for how long. Perfect for compliance, auditing, and incident response.

Take Back Control Now

Within minutes, your access is managed, audited, and compliant.

The Bastion in Detail: SSH, RDP, and VNC

Zero-knowledge access

Credentials never leave Heimlane Vault unencrypted.

Heimlane has no access to the credentials of your machines.

A bastion you reach from the browser

SSH, RDP, and VNC sessions directly in your browser, from any device. No jump server, client software, or VPN configuration: a modern HTML5 browser is all you need.

Vault integration

Automatic credential injection from Heimlane Vault.
Your administrators use the password without ever seeing it. Every use is logged for audit.

Session recording

Automatic recording of the complete session for audit, compliance, and your security reviews

Role-based permissions

Fine-grained control over who accesses what, based on actual and segmented needs, not ''because the VPN is configured that way''

Audited administration bastion

Grant controlled access to your teams and third parties following the principle of least privilege.

Use automatic recording of all actions for audit and investigation purposes

Multi-tenant ready

MSPs can manage multiple customer environments seamlessly

Easy setup, multi-protocol support

Setup in just a few clicks

Support for SSH, RDP, VNC protocols, all from one interface

Get the Realm Datasheet

Download our detailed product datasheet, covering features and technical specifications.

Download Datasheet

Frequently asked questions about Realm

Can Realm replace our current bastion?
In most cases, yes. Realm covers what an administration bastion is expected to do: strong authentication, access policies, credential injection, session recording, and audit. Migration happens target by target, with no forced cutover: both solutions can run side by side for as long as the transition takes.
Do we need a jump server or a firewall opening?
No. There is no jump server to expose and no inbound rule to create. A lightweight agent, Realm Connect, installed on the customer network, opens an outbound tunnel to the platform. That is what separates Realm from a legacy bastion, whose rollout usually starts with a negotiation with the network team.
Which protocols does the Realm bastion support?
SSH, RDP, and VNC, from the same interface: an SSH bastion for your Linux servers, an RDP bastion for your Windows servers and workstations, VNC for the rest. There is no client to install and no separate per-protocol gateway to maintain.
How are credentials protected during a session?
They are injected from Vault when the session opens. The user gets access without ever seeing the password, so they cannot write it down, reuse it elsewhere, or pass it on. That is what makes it possible to genuinely retire shared administrator accounts.
Does Realm suit a multi-customer bastion setup?
Yes. Realm is administered from Prism, whose multi-tenant hierarchy (VAD, partner, end customer) is built for MSPs. Each customer keeps its own scope, targets, and recordings under shared administration.

Ready to Get Started?

Request a trial or a demo to get started.