One identity, controlled access, on-premise
Identity and Access Management (IAM / PAM / SSO / MFA)
We deploy an access infrastructure in which users sign in securely with a single identity and privileged access is put on record, built on an open-source stack and running on your organization's own servers. Single sign-on (SSO) and multi-factor authentication (MFA) with Keycloak; privileged access management (PAM) and session recording with Teleport and Apache Guacamole. Identity data never leaves your organization; the infrastructure runs on-premise.
What is identity and access management?
Identity and access management centrally defines who every user in the organization is and what they may access. A well-built system gives users seamless access with a single identity while closing off unauthorized logins, forgotten accounts and excessive privileges. For most organizations the real risk is not an external attack but uncontrolled, unmonitored privileged access. In an environment where administrator accounts are not audited, a single compromised password opens the entire system.
C3T is not a product vendor; we are the implementing and integration partner. We securely deploy the open-source identity stack (Keycloak, Teleport, Apache Guacamole) on your organization's own servers, integrate it with your existing directories and applications, and operate it.
How do IAM and PAM work?
Identity and access management (IAM) centrally manages the identity of all users and their access to applications: single sign-on (SSO), multi-factor authentication (MFA) and role definitions with Keycloak. Privileged access management (PAM) separately controls the access of administrator and privileged accounts: session video recording, privilege restriction and time-limited access with Teleport and Apache Guacamole. C3T deploys this stack on your organization's own servers, offline (air-gapped) if required; identity and access data never leaves your organization. On-premise AI flags unusual sessions and privilege use. It provides the infrastructure for ISO 27001 A.9 access control, KVKK Article 12 prevention of unauthorized access and the privileged access requirements of BİGR (Turkey's Information and Communication Security Guide).
Scope: IAM and PAM together
We build access security on two axes: centralized identity (IAM) for all users and privileged access management (PAM) for privileged accounts. Both run on-premise and are fully auditable.
Identity management (IAM) — Keycloak
One identity, one sign-on: users securely access every application with a single account.
- Single sign-on (SSO) — one login across all applications
- Multi-factor authentication (MFA / 2FA)
- Centralized user and role management
- Active Directory / LDAP integration
- Per-application permission and access definitions
Privileged access management (PAM)
Controls, records and restricts administrator and privileged access.
- Administrator and server access control
- Session video and command recording (Teleport / Guacamole)
- Anomaly detection with on-premise AI
- Privilege restriction and time-limited access
- Auditable access trail (who, when, where)
Strong identity with multi-factor authentication
A password alone is not enough; without multi-factor authentication (MFA), a compromised password grants direct access. With Keycloak, a second verification step is enforced across all critical applications, conditional access policies are defined, and thanks to single sign-on, security is raised without degrading the user experience. The system runs on-premise on your organization's own infrastructure.
Open-source stack and on-premise AI
Instead of expensive licences, we deploy mature open-source tools and support them with on-premise AI. Your data never leaves your organization.
Keycloak (IAM · SSO · MFA)
Open-source identity provider; brings single sign-on, multi-factor authentication and centralized role management together on one backbone.
Teleport + Apache Guacamole (PAM)
Puts privileged access on record: video recording of administrator sessions, privilege restriction and an auditable trail.
On-premise AI (anomaly detection)
Analyzes access behaviour on-premise; flags unusual sessions and privilege use. Your data never leaves your organization.
What we have built
Concrete examples that show our scope and level of expertise, without naming organizations for confidentiality reasons.
Offline (air-gapped) SSO + MFA
A fully offline single sign-on and multi-factor authentication infrastructure connected to existing directories: dozens of applications secured under one identity, with password data never leaving the organization.
Privileged access session recording
A privileged access management deployment in which administrator access is recorded at video and command level, supported by privilege restriction and anomaly detection. Provides a complete trail for audit and compliance.
Compliance
Which compliance obligations it addresses
Access control sits at the heart of every audit framework. We deploy and operate the identity and access infrastructure so that it provides a practical foundation for the requirements below. For the full compliance scope, see the compliance consulting page.
ISO 27001 A.9
Access control: definition of user access, management of privileged rights and regular review.
KVKK Article 12
Technical measure for preventing unauthorized access: controlling and restricting who accesses which personal data.
BİGR (Information and Communication Security Guide)
A practical infrastructure for privileged access management and privileged account control requirements.
Frequently asked questions
What is the difference between IAM and PAM?
IAM (identity and access management) centrally manages the identity of all users and their access to applications: single sign-on (SSO), multi-factor authentication (MFA) and role definitions. PAM (privileged access management) separately controls, records and restricts the access of administrator and privileged accounts. We deploy both together and operate them on a single identity backbone.
Does it work with our existing Active Directory or LDAP directory?
Yes. Keycloak connects to your existing Active Directory / LDAP directories; single sign-on and multi-factor authentication can be rolled out without migrating users from scratch. Your applications are integrated through standard protocols (OIDC, SAML, LDAP).
Does identity data leave the organization?
No. The identity provider and access logs run on-premise on your own servers (your own hardware); if required, the deployment is fully offline (air-gapped). Password, session and access data never leaves your organization, so KVKK (Turkish Personal Data Protection Law) and data sovereignty requirements are preserved.
Are privileged sessions recorded?
Yes. With Teleport and Apache Guacamole, administrator and server sessions are recorded at video and command level, leaving an auditable trail of who accessed which system and when. Privilege restriction, time-limited access and anomaly detection with on-premise AI support this record.
Which compliance obligations does it address?
The access control solution provides the infrastructure needed to address ISO 27001 A.9 access control, the KVKK Article 12 technical measure for preventing unauthorized access, and the privileged access management requirements of BİGR (Turkey's Information and Communication Security Guide). C3T deploys, integrates and operates this infrastructure.
Let's assess your access infrastructure together
Let's review your existing identity directory, your applications and your privileged access needs. In a free feasibility call, we'll clarify what IAM and PAM can do for you, with your identity data never leaving your organization.