Public sector and regulated
Secure administration the way ANSSI describes it, on one device, with the evidence attached.
Administration, everyday work and analysis each run in a sealed room of their own on one laptop, and every privileged session is checked and recorded. ANSSI recommends the architecture.
One device. Administration in a room of its own.
Secure administration used to mean a second laptop. With ZT-Station, administration, everyday work, development and analysis each run in their own sealed room on one physical laptop, with no shared network and no shared clipboard.
Everyday work
E-mail, browsing, documents.
ContainedMalware contained here
Development
Install anything. There is no path to the rest.
Sealed
Administration
Privileged tools and sensitive applications.
Sealed
Analysis
Open the malware, then reset the room.
Sealed
A breach stays in one room
Malware stays in the room where it landed. Administration and business data are out of reach.
Back in minutes
A compromised room is reset to a known-good state. It is not rebuilt.
Every environment covered
ZT-Station is complete on its own, and the laptop is hardened by design. The UASR agent runs inside the sealed rooms, so each environment is covered too.
Origin and architecture
ZT-Station comes from Bitrustee Software, which has joined Cybershen.
It is built on the workstation architecture ANSSI recommends for secure administration.
Every privileged session checked, then recorded.
Administrators reach servers and databases through the ZT-SSE bastion. It checks who is asking, from which device and in what state. ZT-SSE takes that posture from UASR or from the ZT-Station.
No standing credentials
Administrators never hold a permanent password. Credentials are injected for the session, then gone.
Least privilege, by construction
No rule, no access. An intruder who lands on one machine cannot roam.
Evidence, not promises
Every decision is logged and every privileged session is recorded. When the auditor asks who did what, the proof is already there.
An administrator at work, start to finish.
What secure administration looks like on an ordinary day.
An administrator opens the admin room.
Privileged tools live in their own room, on the same laptop as everyday work.
The bastion checks who is asking.
The person, the device and its state are verified before anything opens.
A credential is issued for this session only.
The administrator never holds a permanent password, so there is none to steal.
The session is recorded.
When the auditor asks who did what, the proof is already there.
ZT-Station and ZT-SSE are sold separately, and each works on its own.
We help you become compliant and we give you the evidence.
LPM and OIV rules and ANSSI guidance ask for secure administration, segregated admin flows and hardening. NIS2 adds risk measures, incident handling and access control. This is what you hand the auditor.
What you hand the auditor
LPM, OIV and ANSSI
The multi-level workstation ANSSI recommends, an Active Directory audit against the ANSSI guide, bastion recordings.
NIS2
A compliance score per control, playbooks, recorded privileged sessions, secure administration.
Your data stays where your law says it should.
Sovereignty is a design decision here, not a line in a contract.
Hosted by your country's rules
We follow local sovereignty requirements. Outside France, we can host with a sovereign provider in your country.
On your premises
ZT-SSE and the ZT-Station management console can run on your own infrastructure.
UASR as a service
UASR is delivered as a service. An on-premises deployment is possible case by case.
Get the architecture guide.
Request our reference architecture for secure administration: one device, sealed rooms, and every privileged session on record.