Self-hosted · sold as an AWS Marketplace AMI

Your AWS server credentials, in your own bastion.

CloudBastn is a credential management platform you run inside your AWS account. Store server passwords and PEM keys envelope-encrypted, open SSM terminals and RDP straight from the browser, and audit every reveal — without a vendor in the data path.

One instance in your VPC. Your master key, your EBS volume, your audit log.
Built on the AWS you already run SSM Session Manager AES-256-GCM envelope encryption IAM AssumeRole + external ID In-browser RDP TOTP MFA + step-up Audited reveals
What it does

One console for the keys to every server.

Credentials, PEM keys, live terminals, RDP, and runbooks for your whole EC2 fleet — locked behind MFA and logged on every touch.

Envelope-encrypted vault

Every password and PEM key is encrypted with its own AES-256-GCM data key, wrapped by a master key your instance loads from AWS KMS or local config. Nothing is stored in plaintext, ever.

MFA + step-up re-auth

TOTP enrolment with single-use backup codes is part of first-boot setup. Revealing a credential or downloading a PEM requires a fresh password re-entry inside a sliding five-minute window.

In-browser SSM terminal

Open bash or PowerShell on any SSM-managed instance straight from the server page — no inbound ports, no client install, no PEM on a laptop. Direct-SSH fallback exists for legacy boxes, off by default.

In-browser RDP

Full Windows desktops rendered in the browser via Guacamole, tunnelled over SSM port-forwarding. Port 3389 stays closed to the internet; stored credentials are injected without being shown.

Roles & team access

Invite the team, assign roles, and scope who can view, reveal, or administer. Sessions are revocable server-side — sign someone out everywhere the moment they leave the on-call rotation.

Audit on every action

Reveals, rotations, logins, sessions, and admin changes are logged with actor, IP, severity, and metadata. Filter, export, and set retention floors per data type — the log is yours, on your disk.

How it works

From Marketplace to first session in an afternoon.

No SaaS onboarding, no sales call. Launch the AMI, run the setup wizard, connect an account.

Launch the AMI

Subscribe on AWS Marketplace and launch CloudBastn in your VPC — amd64 or arm64, a t3.small-class instance is plenty. A one-time token from the EC2 console unlocks the 4-step setup wizard: admin account, mandatory MFA, TLS.

Connect AWS accounts

Create an IAM role in each account you manage using the trust policy CloudBastn generates — your principal plus a per-account external ID. Paste the role ARN and your EC2 fleet syncs in, tagged and grouped.

Operate from the browser

Attach passwords, PEM keys, and runbooks to each server. Open SSM terminals and RDP sessions in a tab. Invite the team with scoped roles and watch the audit trail record every sensitive touch.

Read the full launch guide →

Security model

Designed so we can't read your secrets.

CloudBastn is software you run, not a service we host. There is no vendor account in your deployment, no phone-home in the data path, and no recovery backdoor. The boundary of trust is your AWS account — exactly where it already was.

Read the security model
Pricing

One plan. One price. Everything in it.

$49/mo — flat

Unlimited servers, unlimited users, every feature. Billed through AWS Marketplace on the bill you already pay. You cover the small EC2 instance it runs on (typically ~$15–25/mo to AWS). Cancel anytime — your data stays on your volume.

See what's included →

Put the bastion where your servers already live.

Subscribe on AWS Marketplace, launch in your VPC, and hand your team safer access by the end of the day.