Privileged Access Security (PAS) Cloud Infrastructure

Imprivata Privileged Access Security (PAS) is a secure privileged access platform that enables organizations and enterprises to securely manage privileged access for internal administrators, internal users, vendors, contractors, and third-party support teams.

Available as an Imprivata-hosted SaaS offering or as a customer-managed deployment, PAS is built on a security-first architecture, PAS combines identity verification, privileged session management, credential protection, and comprehensive audit capabilities with a globally distributed cloud infrastructure designed for resiliency, availability, and regional deployment flexibility.

Whether supporting routine vendor maintenance, emergency access, or highly regulated environments, PAS provides secure remote access without exposing internal networks or privileged credentials.

Global Cloud Infrastructure

For Imprivata-hosted deployments, PAS is hosted in a single-tenant Amazon Web Services (AWS) environment.

Customer-managed deployments can be installed on supported virtual infrastructure, including private data centers or cloud-hosted virtual machines. In both deployment models, customer resources remain protected behind outbound-only connections established by Gateways or Gatekeepers.

Imprivata PAS is deployed across multiple geographic regions to support customer requirements for performance, availability, and data residency.

Each deployment is designed around regional resiliency principles, including:

  • Regional deployment options

  • High Availability architecture

  • Disaster Recovery capabilities

  • Encrypted communications

  • Continuous monitoring

Cloud Availability

Imprivata PAS Cloud is currently hosted on Amazon Web Services (AWS). Customers may select an appropriate deployment region based on proximity, organizational requirements, and service availability.

Use AWS Regions and Availability Zones to discover where the Imprivata PAS Cloud can be deployed.

Platform Availability and Resiliency

PAS is designed to provide resilient privileged access for business-critical environments.

For Imprivata-hosted PAS Cloud deployments, infrastructure resiliency is managed by Imprivata.

For customer-managed deployments, organizations may implement High Availability (HA) and Disaster Recovery (DR) architectures to meet business continuity objectives.

  • High Availability (HA) is an optional PAS deployment architecture designed for customer-managed environments. It provides automatic failover within a local clustered deployment to minimize service interruption caused by localized hardware or software failures. In PAS, High Availability refers to a specific clustered architecture and should not be confused with the general use of the term "high availability" to describe cloud services.

  • Disaster Recovery (DR) is designed to protect customer-managed deployments from site-level failures by maintaining a replicated standby environment. While High Availability minimizes downtime caused by localized infrastructure failures, Disaster Recovery enables service restoration following a catastrophic outage affecting an entire location. Many organizations deploy both capabilities together to support comprehensive business continuity objectives.

Although each capability addresses different operational risks, they are complementary and are commonly deployed together in customer-managed environments requiring maximum service continuity.

Depending on the deployment model, PAS supports:

  • Gateway redundancy

  • Failover-capable Gateway instances

  • Disaster Recovery architectures

  • Continuous health monitoring

  • Secure encrypted communications

  • Backup and recovery processes

NOTE:

Contact Imprivata to get help on High Availability and Disaster Recovery deployments.

Security Architecture

Gateways and Gatekeepers are deployed and managed within customer-controlled environments. These components establish secure outbound connections to PAS and broker access to protected resources without requiring inbound connectivity to the customer network. Their deployment, sizing, redundancy, and lifecycle management remain under the customer's control.

Rather than relying on traditional VPN access, PAS brokers secure, policy-driven connections between authorized users and protected resources.

Key architectural principles include:

  • Zero standing privileged access

  • Least privilege

  • Encrypted communications

  • Session isolation

  • Identity federation

  • Continuous auditing

  • Centralized policy enforcement

The PAS architecture separates authentication, authorization, session brokering, and target system connectivity to reduce attack surface while maintaining operational flexibility.

Platform Capabilities

The following sections contain high-level descriptions of the key core security capabilities in PAS.

Frequently Asked Questions (FAQs)