How PAM-Pro handles your data, secures your keys, and maps to the compliance frameworks your auditors require. This page is for security teams evaluating PAM-Pro for enterprise deployment.
PAM-Pro is built on a stateless, cloud-native foundation. We inherit security controls from Microsoft Entra ID and Azure rather than building parallel auth infrastructure.
No traditional credential database. All identity assertions are validated against your Microsoft Entra ID tenant in real time. We store policy metadata only - never plaintext credentials.
All secrets are stored in Azure Key Vault with dual-keyed encryption (Microsoft-managed + customer-managed). HSM-backed FIPS 140-2 Level 3 key storage available as an add-on for regulated workloads.
Each customer environment is provisioned as a logically isolated tenant. Shared compute is used for operational efficiency, but all data planes enforce strict boundary controls. No cross-tenant data access is architecturally possible.
What we collect, what we do not collect, and how we store it.
PAM-Pro is architected to satisfy the technical controls required by the following frameworks. Detailed control mapping is available in our audit documentation.
Technical safeguards for access control, audit controls, and transmission security for Protected Health Information environments.
View Control MappingLogical access boundaries and immutable audit trails satisfying Trust Services Criteria for Security and Availability.
View Control MappingLeast Privilege enforcement and Multi-Factor Authentication controls for federal-grade compliance requirements.
View Control MappingIdentity lifecycle management and privileged credential governance mapped to HITRUST access control requirements.
View Control MappingPseudonymization and persistent confidentiality controls ensuring data processing security and resilience.
View Control MappingPrivileged access rights management and system utility governance for information security management excellence.
View Control MappingPAM-Pro operates on a shared responsibility model standard to cloud SaaS. Huntoso is responsible for platform security, key management, and audit log integrity. The customer is responsible for their Microsoft Entra ID configuration, their Azure tenant security posture, and the administrative accounts they choose to vault.
Security researchers, enterprise buyers, and compliance teams can reach our team directly. We respond to all security inquiries within one business day.