Sign in

Find your organisation

Every organisation has its own Inlinea address. Type the first word of yours, or the whole address, and we will take you there.

Take the tourBook a demo

Secure Sessions

Privileged access in a browser tab, with evidence.

RDP, SSH, VNC and Telnet open in the browser. The protocol ends at the ZERA gateway, never in the browser, which is what makes each control real: the person never sees the password, every session is recorded, and an administrator can end it.

protocols
4
RDP, SSH, VNC and Telnet, rendered by the session engine in your tenant.
passwords seen
0
Managed credentials are injected by the gateway, never sent to the browser.
recording per session
1
Session Evidence on the server, keystrokes optional, replayed in the Control Center.

See it

A managed credential, a watermark, a blocked paste, a recording

finance-desktop.example.com
Ledger
Accounts payable214 items
Approvals waiting12
Last closing30 Sep

Establishing a secure session

Inlinea is verifying your access and connecting you to the resource.

  • Play the sessionThe gateway signs in with a managed credential; the person never sees the password.
  • Switch protocolsRDP shows a desktop; SSH and Telnet show a terminal; the controls are the same.

The controls

Real because the protocol ends at the gateway

  • Managed credentialsStored by the administrator, injected by the gateway. The person signs in to the Workspace, never to the server.
  • Session EvidenceRecorded server-side, keystrokes optional, uploaded to your tenant and replayed with markers. Retention and size caps are yours to set.
  • Clipboard and file transferAllowed, one-way or blocked, enforced before data reaches the browser.
  • Durations and limitsIdle and maximum durations, concurrency limits per person and per resource, and end a live session from the Control Center.

How a session opens

Verified like any Protected Resource, then rendered

  1. 1WorkspaceClick a cardThe person opens a desktop or server card; nothing is installed and no client is configured.
  2. 2ZERA gatewayPolicy firstIdentity, Access Rule, country and network restrictions, and the attested-browser requirement are checked before anything is dialled.
  3. 3Session engineRendered in your tenantThe engine speaks RDP, SSH, VNC or Telnet to the target over the encrypted private network and sends drawing instructions to the browser.
  4. 4Control CenterWatched and recordedThe session appears in Live Sessions and the ZERA Access Log, and its evidence is kept for replay.

Governed access

From a jump host to governed privileged access

  • Credential vaulting and rotationCredentials kept in the vault, rotated on a schedule, never shared in a spreadsheet.
  • Approval workflowsJust-in-time access: a request, an approver, a window, then the session.
  • Live viewing and sharingWatch a session as it happens or invite a colleague into it.
  • Sign-in protectionTyped credential attempts limited, abusive addresses blocked, with named reasons and an unblock action.

Questions buyers ask

Do administrators still need a jump host?
No. The ZERA gateway in your tenant terminates the protocol and the session engine renders it. The target is reached over the encrypted private network through one connector that dials out.
Where is the recording stored?
In your tenant, with the retention and size caps you set. Replay happens in the Control Center; nothing is sent to Inlinea.
Can a person copy data out of a session?
Only if your policy allows it. Clipboard and file transfer are enforced at the gateway before data reaches the browser, and Browser Security adds in-page controls and a watermark.
Which targets work?
Any RDP, SSH, VNC or Telnet target reachable from a routing device or an agent in your private network, or a direct upstream you configure.

Open the application. Never the network.