Unified Access Control Platform for Public Sector & Finance

Janus DAC

PAM · DAC · KAC in one — closed-network complete, audit integrity, Zero Trust access

A unified access control platform that centrally governs privileged access to databases and servers in closed-network environments, audits every action, and enforces least privilege through policy. With insider threats now routine, regulations growing more precise, and control gaps that network separation alone cannot close — one gateway, one policy engine, and one audit log become the execution unit of Zero Trust.

Zero Trust Principles

Not 'connected = authorized' — enforced request, approval, and time-boxed sessions. JIT (Just-In-Time) grants replace standing privileges, structurally blocking insider threats

100% Audit of Every Action

Raw DB query text, result row counts, execution times, SSH command I/O, even screen recordings — stored in a tamper-proof hash chain, submittable as-is to FSS and Board of Audit inspections

Policy-Based Least Privilege

A declarative YAML policy engine combining roles, data sensitivity, time windows, and IPs evaluates and approves automatically — no query or command runs without approval

Control Gaps in the Field — Before and After

AS-IS · Limits of Legacy OperationsTO-BE · After Adopting Janus DAC
Shared accounts and standing privileges — communal IDs with indefinite rightsIndividually attributed JIT sessions — request → evaluate → approve → time-boxed issuance → automatic revocation
Scattered audit trails — evidence spread across servers, DBs, consoles, and SlackA single audit log — queries, commands, session recordings, and approval flows in one place
Manual approvals — email, approval systems, handwritten ledgersAutomated policy-based approvals — Slack/Email notifications, policy-driven auto approve/reject
Missing query text — only row counts remain, causality untraceableRaw SQL, result row counts, and timing — preserved 1+ years in a tamper-proof hash chain
Policy documents never made executableDeclarative YAML policy engine — the policy document is the execution rule

Five Core Modules — DB · SSH · K8s · Policy · Audit

DB Access Control · Query Console

Schema browser, Monaco SQL editor, and results grid in one screen — no user ever connects directly to a DB host; every session passes through Janus

SSH Bastion

A single gateway on a browser-based xterm — full-session asciinema recording and replay, real-time blocking/warnings for high-risk commands like rm -rf and sudo, multi-tab

Kubernetes Pod exec Control

All kubectl exec, logs, and port-forward routed through Janus — no kubeconfig distribution eliminates leakage at the source, namespace RBAC, session recording

Policy Engine — Allow · Warn · Block

Three-tier policy by command/query pattern, regex, and AST, plus user, resource, and time-window criteria — authored in the admin UI and deployed instantly (no restart)

Approval Workflow

Request → policy evaluation → approver review → TTL session execution — handled inside DAC without tickets, with approvals and session logs in a single transaction

RBAC · SSO · MFA

OIDC, SAML 2.0, LDAP (verified with Azure AD, Okta, Keycloak), TOTP, FIDO2, and push MFA, SoD rules, and temporary elevation with TTL auto-revocation

DB Access Control · Step-by-Step Strategy

01

Resource Registration

Admins register DB hosts, ports, DBMS, and accounts — connection credentials stored with AES-256-GCM encryption

02

Role & Policy Mapping

Map operations/inspection/development roles to DBs, query types, and time windows — Default Deny across the board

03

JIT Issuance

Request from 'My Resources' with a reason and duration — a time-boxed session is issued only upon approval

04

Console Execution

Queries run only in the Janus console — autocomplete, lint, result tabs, and Excel export

05

Full Activity Audit

Raw SQL, affected row counts, execution times, and source IPs preserved in tamper-proof logs (1+ year by default)

21 Supported DB Engines · Query Execution Across All

6 relational OLTP (MySQL, PostgreSQL, MariaDB, Oracle, SQL Server, CockroachDB) · 6 enterprise/DW (SingleStore, Vertica, SAP HANA, Snowflake, BigQuery, Redshift) · 2 Korean-domestic (Tibero, CUBRID) · 4 lakehouse/analytics (Databricks SQL, ClickHouse, Trino/Presto, DuckDB) · 3 NoSQL/KV (MongoDB, DynamoDB, Redis) — consistent query execution, auditing, and policy control across every engine over native protocols.

Expected Benefits (Measured Averages from 3–6 Month Public-Sector & Finance Pilots)

−70%

Audit response time — from manual tracing to one-click reports

100%

Insider threat visibility — unauthorized access structurally blocked

−50%

Account and privilege operations workload — automatic grant and revocation

Regulatory Requirements ↔ Janus Feature Mapping — Finance & Public Sector

Regulation / StandardSpecific Clause / ControlJanus DAC Capability
Electronic Financial Supervision Regulation §11Access control — identity verification, privilege management, 5+ year record retentionSSO · MFA · RBAC · session TTL + long-term audit log retention
Electronic Financial Supervision Regulation §13Segregation of duties & internal controls — prior approval for critical commandsSoD policy engine · approval workflow · high-risk command blocking
Electronic Financial Supervision Regulation §17Records of DB and OS account usage and control100% query and command auditing + session recording + hash-chain integrity
ISMS-P 2.6.1 / 2.6.2Access privilege management · user authenticationRole-based privileges · attribute mapping · re-authentication interval policies
ISMS-P 2.9.4Log generation, protection, and review — tamper preventionAppend-only hash chain · offline integrity verification
Personal Information Protection Act §29Access control, encryption, access recordsDB masking · query auditing · unified access records
MOIS Network Separation GuidelinesBusiness/Internet network separation · relay server controlClosed-network All-in-One · zero external calls · offline updates

Closed-Network Friendly · Zero External Dependencies — 30-Minute Install, Zero External Calls

All-in-One Binary

A single executable with no external dependencies — up and running on a single VM within 30 minutes

Offline Updates

Version distribution via USB or internal repository — no internet access required

Zero External Calls

No telemetry or remote license checks — zero internet domain calls at runtime

Standalone License

A perpetual file license with no online validation

Embedded DB Option

Built-in SQLite — runs without a separate RDBMS

Korean UI & Documentation

All operator and auditor documentation provided in Korean

How It Differs from Existing Solutions

Comparison CriterionLegacy PAMLegacy DB Access ControlJanus DAC
DB, server & K8s unificationPartialDB onlyFully unified
Proxy approachAgent installationNetwork relayBrowser console
Policy deploymentRestart requiredLimited patternsReal-time deployment
Log integritySeparate solutionDB storageBuilt-in hash chain
Approval workflowExternal ITSMNot supportedBuilt-in, audit-linked
Closed-network installationPossible (complex)PossibleSingle binary

PoC Package · Proven Results Within 2 Weeks

01

Day 1 · Install & Configure

All-in-One installation on a single VM

02

Day 2-3 · IdP & DB Integration

SSO and DB credential resource registration

03

Day 4-7 · Policy Design

Define prohibited commands and approval workflows

04

Day 8-10 · Pilot Operation

Live use and feedback with 5–10 users

05

Day 11-14 · Audit Report

Compile audit logs and integrity verification results

PoC success criteria (KPIs): 100% of target access recorded · policy violations allowed ≤ 2/week · new-user onboarding < 5 minutes. Three editions — Standard (up to ~50 users), Enterprise (finance, public sector, large enterprises; HA, SIEM integration, 24×365), and Sovereign (fully air-gapped, source escrow) — all on perpetual file licenses. SLAs range from P1 (critical) response within 30 minutes to P4 (general) within 1 business day — 24×365 on-call with Korea-based staff, a dedicated CSM, and detailed quotes with a 3-year TCO comparison delivered within 48 hours of request. Certification roadmap: GS certification planned · CC certification planned · materials prepared for the Financial Security Institute security review.

Contact Sales