When you pick a managed path to a set of hosts, databases, and accounts, there is usually more than one way to do it.
This page puts five of them on the same ten aspects, so you can judge which one your environment needs.
What is compared is the approach, not the brand. The four columns on the left describe the common shape of each kind of approach and point at no particular product;
the implementation you hold may already have extra components added, so read each cell against the criteria column to its right.
The Custodexa column describes how this product behaves, and the capability domain behind it is named in the same cell.
- The summary column says what the approach looks like in an ordinary deployment. The four columns on the left use “usually”, “mostly”, and “depends on the implementation” to show that these are descriptions of a shape rather than product specifications verified one by one.
- The criteria column says what each cell was judged against, for example “the default configuration of the remote login service built into the operating system”. Where a situation is excluded by the criteria (an added component, a paid edition, a control system above it), the description does not apply.
- In the Custodexa column the criteria position names the capability domain that behavior belongs to, and the product’s own documentation and specifications govern its meaning.
- The verification date is when this comparison was last checked, shown above the tables.
Verified on2026-09-04
Access boundary
| Approach | Common shape | Reading criteria |
|---|
| SSH jump host | Usually admits the whole login host | Judged against the default configuration of the remote login service that comes with the operating system; installations with an added authorization component fall outside this. |
|---|
| VPN | Mostly admits a whole network segment | Judged against the general shape of a network layer tunnel; deployments with an access control system above the tunnel fall outside this. |
|---|
| Open source bastion | Mostly grants per single target | Judged against what a community edition offers by default; paid editions and self-modified forks fall outside this. |
|---|
| Commercial PAM | Mostly grants per single target or account | Judged against the shape common to commercial privileged access management products; differences between editions and modules are not separated out. |
|---|
| Custodexa | Every asset can be set to direct connection, reason required, or approval required | Spec:access-policy |
|---|
Client installation
| Approach | Common shape | Reading criteria |
|---|
| SSH jump host | Users bring and configure their own connection client | Judged against the general practice of users connecting themselves; installations with an added web entrance fall outside this. |
|---|
| VPN | Tunnel software is installed on the user's device | Judged against the shape that builds a tunnel on the user's device; browser-hosted access services fall outside this. |
|---|
| Open source bastion | Mostly connects through a browser | Judged against the web interface a community edition offers by default; additional desktop clients are not counted. |
|---|
| Commercial PAM | Depends on the implementation; some need a dedicated client | Judged against the deployment prerequisites in a product's public documentation; where one product offers several access modes, the common one is taken. |
|---|
| Custodexa | A browser is enough to connect, and users install nothing | Spec:session-workspace |
|---|
Approval before connecting
| Approach | Common shape | Reading criteria |
|---|
| SSH jump host | Usually no approval step before a connection | Judged against the general practice where an account and a key are the authorization; installations wired to a ticketing system fall outside this. |
|---|
| VPN | Usually authorized once, when the tunnel is built | Judged against the tunnel's own authentication; deployments where an upper system carries per-connection approval fall outside this. |
|---|
| Open source bastion | Depends on the implementation; mostly no per-connection approval | Judged against the flow a community edition offers by default; ticketing integration plugins are not counted. |
|---|
| Commercial PAM | Mostly carries a request and approval flow | Judged against the request flow described in a product's public documentation; whether it is turned on depends on how it was rolled out. |
|---|
| Custodexa | A multi-asset task approves account scope and time window per item, creating time-limited authorization at approval | Spec:access-request |
|---|
Session recording
| Approach | Common shape | Reading criteria |
|---|
| SSH jump host | Usually leaves system login records | Judged against the login and audit logs built into the operating system; installations with an added capture tool fall outside this. |
|---|
| VPN | Usually leaves connection start and end records | Judged against the tunnel device's own connection logs; application behavior inside the tunnel is recorded by each target system. |
|---|
| Open source bastion | Text and graphical session recording is common | Judged against the recording a community edition offers by default; the protocols it covers vary by implementation. |
|---|
| Commercial PAM | Mostly carries session recording and playback | Judged against the recording described in a product's public documentation; the protocols covered and the retention vary by licensed module. |
|---|
| Custodexa | SSH, RDP, VNC, and the database console are recorded end to end and play back | Spec:session-recording |
|---|
Database statement auditing
| Approach | Common shape | Reading criteria |
|---|
| SSH jump host | Database access mostly falls outside its reach | Judged against what the login host itself can observe; the target database's own audit settings are counted separately. |
|---|
| VPN | Bounded at the network layer, with no parsing of application statements | Judged against the shape of a tunnel passing packets; separately deployed database audit appliances fall outside this. |
|---|
| Open source bastion | Depends on the implementation; mostly covers some protocols | Judged against the database protocols a community edition supports by default; the coverage and statement granularity vary by implementation. |
|---|
| Commercial PAM | Depends on the edition; some carry statement-level auditing | Judged against the database module described in a product's public documentation, mostly a separately licensed item. |
|---|
| Custodexa | Database statements are recorded before they run, and dangerous ones can be blocked as they happen | Spec:db-query-console |
|---|
Evidence packaging
| Approach | Common shape | Reading criteria |
|---|
| SSH jump host | Mostly assembled from logs by hand | Judged against the general practice of taking host logs as raw material and having people assemble an audit deliverable. |
|---|
| VPN | Connection logs are assembled by hand | Judged against the connection logs the tunnel device emits; merging evidence across systems is carried by external tools. |
|---|
| Open source bastion | Mostly offers export of records and recordings | Judged against the export a community edition offers by default; whether integrity evidence comes with it varies by implementation. |
|---|
| Commercial PAM | Mostly offers reports and exports | Judged against the reporting described in a product's public documentation; the output format and its verifiability vary by product. |
|---|
| Custodexa | One ZIP holding a manifest and a signature, with per-file hashes that verify offline | Spec:audit-workflows |
|---|
Offsite copies
| Approach | Common shape | Reading criteria |
|---|
| SSH jump host | Mostly carried by the backup mechanism already in place | Judged against host-level file backup, where audit evidence takes the same backup path as any other file. |
|---|
| VPN | Carried by the log forwarding already in place | Judged against the general practice of forwarding connection logs to an external log system. |
|---|
| Open source bastion | Depends on the implementation; some support object storage | Judged against the storage backends a community edition can be configured with; the custody ledger and retrieval verification vary by implementation. |
|---|
| Commercial PAM | Depends on the edition; mostly offers archiving options | Judged against the archiving and retention described in a product's public documentation. |
|---|
| Custodexa | Uploads to S3-compatible or GCS object storage, with a custody ledger | Spec:evidence-offsite-storage |
|---|
Credential rotation
| Approach | Common shape | Reading criteria |
|---|
| SSH jump host | Target account passwords are mostly maintained by hand | Judged against the general practice of administrators changing passwords themselves or writing their own scripts. |
|---|
| VPN | Tunnel accounts are mostly maintained by a directory service | Judged against the tunnel's own user credentials; accounts on the target hosts fall outside its reach. |
|---|
| Open source bastion | Depends on the implementation; mostly maintained by hand | Judged against what a community edition offers by default; scheduled password changes mostly belong to paid or plugin territory. |
|---|
| Commercial PAM | Mostly carries scheduled rotation | Judged against the automatic rotation described in a product's public documentation; the target types covered vary by module. |
|---|
| Custodexa | Scheduled password rotation for Linux and Windows accounts, with a rotation evidence report | Spec:change-secret |
|---|
Deployment shape
| Approach | Common shape | Reading criteria |
|---|
| SSH jump host | One login host exposed to the outside | Judged against the general shape where a single host carries all traffic in and out. |
|---|
| VPN | A gateway appliance or a cloud service | Describes both common shapes together, a self-hosted gateway and a subscription service. |
|---|
| Open source bastion | Mostly a single self-hosted service | Judged against the deployment a community edition's documentation suggests; clustered deployment varies by implementation. |
|---|
| Commercial PAM | Mostly an appliance or a subscription service | Judged against the delivery shape described in a product's public documentation; where self-hosted and managed coexist, the common one is taken. |
|---|
| Custodexa | Linux packages for two architectures with verified images and offline bundles; source deployment is also available | Spec:deployment-configuration |
|---|
License
| Approach | Common shape | Reading criteria |
|---|
| SSH jump host | Follows the license of the operating system components already in place | Judged against the remote login service shipped with the operating system, and excludes separately purchased add-ons. |
|---|
| VPN | Depends on the implementation; open source and commercial both exist | Describes the fact that both kinds of supply exist in the market, without pointing at any implementation. |
|---|
| Open source bastion | Mostly under an open source license | Judged against the community edition whose source is public; the commercial edition of the same project carries its own terms. |
|---|
| Commercial PAM | A commercial subscription or a perpetual license | Judged against the general pricing shape of commercial products; the actual terms follow the contract. |
|---|
| Custodexa | Open source under AGPL-3.0, with source you can review yourself | Spec:release-snapshot |
|---|
This page is not audit evidence in itself. To show an auditor the facts in the Custodexa column above, the evidence is on these pages: