Janus DAC
PAM · DAC · KAC in one — closed-network complete, audit integrity, Zero Trust access
A unified access control platform that centrally governs privileged access to databases and servers in closed-network environments, audits every action, and enforces least privilege through policy. With insider threats now routine, regulations growing more precise, and control gaps that network separation alone cannot close — one gateway, one policy engine, and one audit log become the execution unit of Zero Trust.
Zero Trust Principles
Not 'connected = authorized' — enforced request, approval, and time-boxed sessions. JIT (Just-In-Time) grants replace standing privileges, structurally blocking insider threats
100% Audit of Every Action
Raw DB query text, result row counts, execution times, SSH command I/O, even screen recordings — stored in a tamper-proof hash chain, submittable as-is to FSS and Board of Audit inspections
Policy-Based Least Privilege
A declarative YAML policy engine combining roles, data sensitivity, time windows, and IPs evaluates and approves automatically — no query or command runs without approval
Control Gaps in the Field — Before and After
| AS-IS · Limits of Legacy Operations | TO-BE · After Adopting Janus DAC |
|---|---|
| Shared accounts and standing privileges — communal IDs with indefinite rights | Individually attributed JIT sessions — request → evaluate → approve → time-boxed issuance → automatic revocation |
| Scattered audit trails — evidence spread across servers, DBs, consoles, and Slack | A single audit log — queries, commands, session recordings, and approval flows in one place |
| Manual approvals — email, approval systems, handwritten ledgers | Automated policy-based approvals — Slack/Email notifications, policy-driven auto approve/reject |
| Missing query text — only row counts remain, causality untraceable | Raw SQL, result row counts, and timing — preserved 1+ years in a tamper-proof hash chain |
| Policy documents never made executable | Declarative YAML policy engine — the policy document is the execution rule |
Five Core Modules — DB · SSH · K8s · Policy · Audit
DB Access Control · Query Console
Schema browser, Monaco SQL editor, and results grid in one screen — no user ever connects directly to a DB host; every session passes through Janus
SSH Bastion
A single gateway on a browser-based xterm — full-session asciinema recording and replay, real-time blocking/warnings for high-risk commands like rm -rf and sudo, multi-tab
Kubernetes Pod exec Control
All kubectl exec, logs, and port-forward routed through Janus — no kubeconfig distribution eliminates leakage at the source, namespace RBAC, session recording
Policy Engine — Allow · Warn · Block
Three-tier policy by command/query pattern, regex, and AST, plus user, resource, and time-window criteria — authored in the admin UI and deployed instantly (no restart)
Approval Workflow
Request → policy evaluation → approver review → TTL session execution — handled inside DAC without tickets, with approvals and session logs in a single transaction
RBAC · SSO · MFA
OIDC, SAML 2.0, LDAP (verified with Azure AD, Okta, Keycloak), TOTP, FIDO2, and push MFA, SoD rules, and temporary elevation with TTL auto-revocation
DB Access Control · Step-by-Step Strategy
Resource Registration
Admins register DB hosts, ports, DBMS, and accounts — connection credentials stored with AES-256-GCM encryption
Role & Policy Mapping
Map operations/inspection/development roles to DBs, query types, and time windows — Default Deny across the board
JIT Issuance
Request from 'My Resources' with a reason and duration — a time-boxed session is issued only upon approval
Console Execution
Queries run only in the Janus console — autocomplete, lint, result tabs, and Excel export
Full Activity Audit
Raw SQL, affected row counts, execution times, and source IPs preserved in tamper-proof logs (1+ year by default)
21 Supported DB Engines · Query Execution Across All
6 relational OLTP (MySQL, PostgreSQL, MariaDB, Oracle, SQL Server, CockroachDB) · 6 enterprise/DW (SingleStore, Vertica, SAP HANA, Snowflake, BigQuery, Redshift) · 2 Korean-domestic (Tibero, CUBRID) · 4 lakehouse/analytics (Databricks SQL, ClickHouse, Trino/Presto, DuckDB) · 3 NoSQL/KV (MongoDB, DynamoDB, Redis) — consistent query execution, auditing, and policy control across every engine over native protocols.
Expected Benefits (Measured Averages from 3–6 Month Public-Sector & Finance Pilots)
Audit response time — from manual tracing to one-click reports
Insider threat visibility — unauthorized access structurally blocked
Account and privilege operations workload — automatic grant and revocation
Regulatory Requirements ↔ Janus Feature Mapping — Finance & Public Sector
| Regulation / Standard | Specific Clause / Control | Janus DAC Capability |
|---|---|---|
| Electronic Financial Supervision Regulation §11 | Access control — identity verification, privilege management, 5+ year record retention | SSO · MFA · RBAC · session TTL + long-term audit log retention |
| Electronic Financial Supervision Regulation §13 | Segregation of duties & internal controls — prior approval for critical commands | SoD policy engine · approval workflow · high-risk command blocking |
| Electronic Financial Supervision Regulation §17 | Records of DB and OS account usage and control | 100% query and command auditing + session recording + hash-chain integrity |
| ISMS-P 2.6.1 / 2.6.2 | Access privilege management · user authentication | Role-based privileges · attribute mapping · re-authentication interval policies |
| ISMS-P 2.9.4 | Log generation, protection, and review — tamper prevention | Append-only hash chain · offline integrity verification |
| Personal Information Protection Act §29 | Access control, encryption, access records | DB masking · query auditing · unified access records |
| MOIS Network Separation Guidelines | Business/Internet network separation · relay server control | Closed-network All-in-One · zero external calls · offline updates |
Closed-Network Friendly · Zero External Dependencies — 30-Minute Install, Zero External Calls
All-in-One Binary
A single executable with no external dependencies — up and running on a single VM within 30 minutes
Offline Updates
Version distribution via USB or internal repository — no internet access required
Zero External Calls
No telemetry or remote license checks — zero internet domain calls at runtime
Standalone License
A perpetual file license with no online validation
Embedded DB Option
Built-in SQLite — runs without a separate RDBMS
Korean UI & Documentation
All operator and auditor documentation provided in Korean
How It Differs from Existing Solutions
| Comparison Criterion | Legacy PAM | Legacy DB Access Control | Janus DAC |
|---|---|---|---|
| DB, server & K8s unification | Partial | DB only | Fully unified |
| Proxy approach | Agent installation | Network relay | Browser console |
| Policy deployment | Restart required | Limited patterns | Real-time deployment |
| Log integrity | Separate solution | DB storage | Built-in hash chain |
| Approval workflow | External ITSM | Not supported | Built-in, audit-linked |
| Closed-network installation | Possible (complex) | Possible | Single binary |
PoC Package · Proven Results Within 2 Weeks
Day 1 · Install & Configure
All-in-One installation on a single VM
Day 2-3 · IdP & DB Integration
SSO and DB credential resource registration
Day 4-7 · Policy Design
Define prohibited commands and approval workflows
Day 8-10 · Pilot Operation
Live use and feedback with 5–10 users
Day 11-14 · Audit Report
Compile audit logs and integrity verification results
PoC success criteria (KPIs): 100% of target access recorded · policy violations allowed ≤ 2/week · new-user onboarding < 5 minutes. Three editions — Standard (up to ~50 users), Enterprise (finance, public sector, large enterprises; HA, SIEM integration, 24×365), and Sovereign (fully air-gapped, source escrow) — all on perpetual file licenses. SLAs range from P1 (critical) response within 30 minutes to P4 (general) within 1 business day — 24×365 on-call with Korea-based staff, a dedicated CSM, and detailed quotes with a 3-year TCO comparison delivered within 48 hours of request. Certification roadmap: GS certification planned · CC certification planned · materials prepared for the Financial Security Institute security review.