PAM-Pro - Security & Trust

Built to Protect.
Designed to Audit.

How PAM-Pro handles your data, secures your keys, and maps to the compliance frameworks your auditors require. This page is for security teams evaluating PAM-Pro for enterprise deployment.

Architecture Overview

PAM-Pro is built on a stateless, cloud-native foundation. We inherit security controls from Microsoft Entra ID and Azure rather than building parallel auth infrastructure.

Stateless by Design

No traditional credential database. All identity assertions are validated against your Microsoft Entra ID tenant in real time. We store policy metadata only - never plaintext credentials.

Key Management

All secrets are stored in Azure Key Vault with dual-keyed encryption (Microsoft-managed + customer-managed). HSM-backed FIPS 140-2 Level 3 key storage available as an add-on for regulated workloads.

Tenant Isolation

Each customer environment is provisioned as a logically isolated tenant. Shared compute is used for operational efficiency, but all data planes enforce strict boundary controls. No cross-tenant data access is architecturally possible.

Data Handling Practices

What we collect, what we do not collect, and how we store it.

What We Collect

  • Privileged account metadata (account names and UPNs only)
  • Session logs (who checked out, when, with what ticket ID)
  • Policy configuration (rotation schedules, checkout windows)
  • Billing and subscription data (via Stripe)

What We Do Not Collect

  • Microsoft Entra ID group memberships
  • Plaintext passwords or credential values
  • Protected Health Information (PHI) or PII beyond billing
  • Customer end-user data or application data
  • Network traffic or endpoint telemetry

Compliance Posture

PAM-Pro is architected to satisfy the technical controls required by the following frameworks. Detailed control mapping is available in our audit documentation.

HIPAA - 45 CFR 164.312

Technical safeguards for access control, audit controls, and transmission security for Protected Health Information environments.

View Control Mapping
SOC2 - TSC CC6.1 / CC6.3

Logical access boundaries and immutable audit trails satisfying Trust Services Criteria for Security and Availability.

View Control Mapping
NIST 800-53 - AC-6 / IA-2

Least Privilege enforcement and Multi-Factor Authentication controls for federal-grade compliance requirements.

View Control Mapping
HITRUST CSF - Control 01.0

Identity lifecycle management and privileged credential governance mapped to HITRUST access control requirements.

View Control Mapping
GDPR - Article 32

Pseudonymization and persistent confidentiality controls ensuring data processing security and resilience.

View Control Mapping
ISO 27001 - Annex A 5.15

Privileged access rights management and system utility governance for information security management excellence.

View Control Mapping

Shared Responsibility Model

PAM-Pro operates on a shared responsibility model standard to cloud SaaS. Huntoso is responsible for platform security, key management, and audit log integrity. The customer is responsible for their Microsoft Entra ID configuration, their Azure tenant security posture, and the administrative accounts they choose to vault.

Huntoso Owns

  • Platform availability and uptime
  • Key Vault encryption and HSM controls
  • WORM audit log integrity
  • Platform patching and vulnerability management

Customer Owns

  • Entra ID tenant configuration
  • Deciding which accounts to vault
  • Policy configuration and checkout windows
  • Underlying Azure subscription security

Security Inquiries

Security researchers, enterprise buyers, and compliance teams can reach our team directly. We respond to all security inquiries within one business day.