ZenXPAM
PAM Capability Design · RFP Evidence · v1.0 · June 2026

Vaulting, Rotation
& Credential Management

Centralized vaulting, automated rotation on target systems, and governed management of privileged credentials.

Product ZenXPAM
Status Production capability
Prepared by Zenxsys
Zenxsys
ZenXPAMPAM
Section 1 · RFP Response

RFP Response Summary

Assessment requirement

Vaulting, rotation and management of privileged credentials.

✓ Capability: Yes - Supported
FieldResponse
CoverageEncrypted vault; scheduled and on-demand rotation across OS, AD/LDAP, DB, network targets
Approachvault-service + password-rotation-service: change on target → sync vault → audit
AuditStore, rotation, recovery events logged - never with secret values
Suggested RFP comment (≤150 chars)AES-256 encrypted vault stores privileged credentials; rotation service updates 40+ platform types on-target, syncs vault, and logs every step to audit.
Section 3 · Design Goals

Vault · Rotate · Manage

GoalDesign Choice
Vault-firstPasswords in vault only; DB/config hold vault:// references
EncryptionPBKDF2 + AES-256-CBC + HMAC; master password protection
Target rotationConnect to target, change password, then update vault
Governed recoveryAudited break-glass reveal; vault.admin permission
Zenxsys
ZenXPAMPAM
Sections 4–5 · Vaulting

Encrypted Credential Vault

All privileged passwords stored centrally - never in spreadsheets, config files, or application databases as plaintext.

vault-service · AES-256 at rest

Single Source of Truth

Keys like ACCOUNT_{id}_PASSWORD encrypted with PBKDF2-derived keys. Session broker and rotation service retrieve via service auth - not end-user UI.

StoreOnboard to Vault

Provision, manual store, or discovery onboard.

  • Strong password generation
  • Policy attachment
  • Plaintext not re-shown
InjectSession Broker

Retrieve at connect time only.

  • Zenx Gateway · tunneling-service
  • Zero user password handoff
  • Reconciliation on rotate
RecoverAudited Reveal

Governed break-glass access.

  • Justification required
  • vault.admin permission
  • Full audit trail

Onboarding Paths

  • Account provision → auto-vault
  • Store in vault from account UI
  • Discovery provision → vault secret
  • Unvaulted accounts queue

NHI & Integrations

  • NHI_WORKLOAD_{clientId}
  • REST Vault API for pipelines
  • Discovery SSH vault refs
  • Integration vault:// pattern
Zenxsys
ZenXPAMPAM
Section 6 · Rotation

On-Target Password Rotation

RotationOrchestrator changes passwords on the target system, then updates the vault - not vault-only updates.

WindowsWinRM · local
LinuxSSH
AD/LDAPDirectory
DatabasesPG · MySQL · Oracle
NetworkDevices
MainframeConnector
Generate → Change Target → Update Vault → Audit
Audit EventStep
ROTATION_STARTEDJob begins
TARGET_PASSWORD_CHANGEDTarget accepts new password
VAULT_UPDATEDSecret synced in vault
ROTATION_COMPLETED / FAILEDOutcome recorded in history

Rotation Workspace

  • /vault/rotation-workspace
  • Rotate now · policy mapping
  • Failed rotations retry queue
  • History export for compliance

Policies & Schedules

  • Interval · complexity rules
  • NextRotationDate per secret
  • Post-rotation credential validation
  • 40+ platform catalog (marketing)

No secrets in audit logs. Connectors and orchestrator never log passwords. Every rotation step produces identifiable, exportable evidence for regulators.

Zenxsys
ZenXPAMPAM
Sections 7–9 · Management & API

Credential Management Surface

TaskNavigationPermission
Vault overviewVault → Overviewvault.read
Initialize vaultSetup wizardSuperAdmin
Rotate accountRotation → Accountsvault.write
Recover passwordRotation → Recovervault.admin
Unvaulted accountsRotation workspacevault.read
MethodEndpointPurpose
POST/api/v1/vault/secretsStore secret
GET/api/v1/vault/secrets/{key}Retrieve (gated)
POST/api/v1/rotation/run-accountRotate single account
GET/api/v1/rotation/historyRotation history

Supporting documentation: user-guide/12-vault-and-rotation.md · SECRETS-IN-VAULT.md · PASSWORD-ROTATION-SERVICE-PLAN.md · encryption-details-26-may-26.md · ENCRYPTION-KEY-ROTATION-RUNBOOK.md

Zenxsys
ZenXPAMPAM
Sections 11–12 · Validation

Security & PoC Checklist

ControlImplementation
Encryption at restAES-256 vault; master password / seal model
No secrets in logsRotation connectors audited without password fields
Least privilegevault.read · vault.write · vault.manage
ComplianceSOC 2 · ISO 27001 · PCI-DSS Req. 8 rotation evidence
Section 12 · Acceptance Criteria

Evaluator PoC Checklist

Version 1.0Date June 2026Author Zenxsys