Persona 3 • Security & Compliance Blueprint

Zero-Trust Network PAM &
Immutable Keystroke Forensics

Secure remote access and Zero-Trust network governance: Achieve SOC 2, ISO 27001, and PCI-DSS compliance. Eliminate exposed management ports, intercept prohibited commands at the kernel level, enforce native remote Winbox 2FA, and maintain complete audit trails.

Web Terminal Gateway

Zero-Client In-Browser HTML5 Terminal Gateway

Zero-footprint web CLI access with zero client software installation and zero port exposure.

  • Air-Gapped Access: Connect to MikroTik, Cisco, and Linux CLIs over WebSockets without exposing SSH/Telnet ports.
  • Native Emulation: High-performance xterm.js terminal with clipboard integration, customizable themes, and UTF-8 support.
Live Collaboration

Terminal Collaboration Rooms & Guest Sharing

Enable secure pair-engineering and vendor assistance with real-time observer and collaborator access control.

  • Granular Role Enforcement: Assign Owner, Collaborator (interactive typing), or Observer (view-only) permissions per participant.
  • Secure Guest Invites: Generate time-limited, password-protected guest links with host waiting-room approvals.
Forensic Recording

Keystroke Session Recording & Web Playback

Tamper-evident forensic replay of every operator keystroke and command response for SOC 2 and ISO 27001 compliance.

  • Asciinema v2 Storage: Microsecond-accurate recording of every input character and ANSI output stream.
  • Interactive Player: Web video player with timeline scrubbing, speed multipliers (1x to 8x), and text copy.
Session Console

Live PAM Console with 1-Click Emergency Killswitch

Complete real-time visibility and instant killswitch control over every active privileged connection in your network.

  • Real-Time Session Tracker: Monitor operator identities, source IPs, target devices, protocols, and durations.
  • Instant Socket Termination: Terminate rogue or compromised connections instantly with a single click.
Dynamic 2FA

Dual OTP: Panel TOTP + Native Winbox Dynamic 2FA

The industry's first native dynamic OTP solution for MikroTik RouterOS — protect Winbox, SSH, and WebFig with mobile authenticator tokens.

  • Embedded RADIUS Mule: Intercepts RouterOS MS-CHAPv2 auth requests and validates live 6-digit TOTP tokens.
  • Universal Desktop Protection: Protects standard Winbox desktop client and native SSH sessions transparently.
Audit Suite

Centralized 5-Tier Immutable Audit Log Suite

Full 360-degree audit coverage across authentication, accounting, commands, and device events to satisfy stringent security standards.

  • 5 Dedicated Audit Streams: RADIUS Auth, Accounting, CLI Commands (/pam/commands), Device Logs, and Syslog.
  • Forensic Search & Export: Filter by operator, device, or time range with one-click CSV and JSON exports for auditors.
Syslog Intelligence

Regex Syslog Pattern Classifiers & Incidents

Transform noisy router syslog streams into clean, actionable operational incidents with regular expressions.

  • Asynchronous Regex Engine: Match high-throughput router syslog streams against user-defined regex capture groups.
  • Structured Incident Categorization: Automatically classify BGP resets, interface flaps, and brute-force auth attempts.