SSH access, governed
Identity is the first security boundary.
Every control-plane session is tenant-bound and protected by built-in multi-factor authentication.
- Server-side, HttpOnly sessions
- Security key, passkey, TOTP, or recovery verification
- Optional Entra, Azure AD, Okta, Google, and Gmail sign-in
Direct OpenSSH remains outside the Tenvyr data path
Control-plane access