Hybrid Deployment Model
PAM-Pro utilizes a "Shared Brain, Private Body" architecture, providing a unified SaaS control plane ("Shared Brain") for governance, while maintaining discrete customer infrastructure ("Private Body") for Key Vaults and Storage to ensure isolation and security.
SaaS: The Shared Brain
The central SaaS platform ("Shared Brain") serves as an unprivileged orchestrator tracking metrics, SLA expirations, and ticketing workflows, while your "Private Body" consists of discrete, isolated Key Vaults and Storage Accounts deployed specifically for your environment to broker physical credentials.
- Independent Policy Control
- Ephemeral Session Management
- Multi-Tenant Entra ID Connections
On-Prem: Total Sovereignty
The On-Premise model utilizes the exact same single-account architecture as SaaS, but delivers it as a full standalone deployment entirely within your physical infrastructure ensuring absolute air gapped isolation.
- Physical Infrastructure Ownership
- Ephemeral Session Management
- FIPS 140-2 Level 1-3 Support
SaaS Separation of Duties
Defining the boundary between Platform Hosting and Data Ownership.
- Platform Patching
- SaaS Infrastructure Hosting
- SLA Compliance
- Application Workflows
- Identity Synchronization
-
Entra ID Risk Integration
(Requires Microsoft P2 License)
- Tenant Root Encryption Key Ownership
- Per-Account Policy Definition
- Account Discovery & Management
- Audit Log Reviews
- Credential Custody
Tri-Layer Protection
Regardless of deployment model, PAM-Pro enforces a rigorous zero-knowledge custody chain. Vaults are mandatorily dual-keyed using Microsoft defaults alongside a dedicated Tenant Root Encryption Key, enveloping all payloads mathematically.
- Immutable Customer Audit Logs
- FIPS 140-2 Level 1 Compliance Minimum
Microsoft Platform Key
Secures the physical media volumes, ensuring total data extraction prevention in the event of hardware theft.
Tenant Root Encryption Key
The secondary layer of our Dual-Keyed strategy. The customer strictly owns the cryptographic key that secures vault payloads, preventing Microsoft from extracting the active data and limiting Huntoso's operational access.
Root Key Translation
Both the secret name and value are independently encrypted via the client's Tenant Root Encryption Key before transit, establishing a true zero-knowledge custody boundary for Huntoso staff.
SLA & Shared Responsibility
Understanding the operational constraints of mathematically enforced Zero-Knowledge.
Root Key Rotation & Reset
Rotating the Tenant Root Encryption Key will mathematically sever access to all currently enveloped payloads. This will force a mandatory password reset event across all managed devices.
Huntoso Mitigation: Configuration stores are backed by Azure Blob Versioning and native Immutability locked constraints to prevent accidental payload-locks.
Break-Glass IdP Reliance
Huntoso deliberately refuses to store local "back-door" Break-Glass credentials to ensure complete identity continuity. If Microsoft Entra ID experiences a global outage, PAM-Pro authentication is suspended until Microsoft SLA resolves.
The Benefit: The identity of your secrets remains entirely with you, preventing lateral Huntoso breach risks.
Default Audit Horizon (1-Day)
By default across all SaaS tiers, Huntoso maintains WORM-compliant Immutable Audit telemetry for a strict 1-day default retention window to maximize privacy.
Customers requiring prolonged retention can configure their environment for up to 365 days. Huntoso.ai will not be able to delete customer data while a retention policy is active.