Cloudanix Joins AWS ISV Accelerate Program

Cloudanix – Your Partner in Cloud Security Excellence

VM JIT for Production VMs Across GCP and Azure: Time-Boxed, Recorded Access for a Multi-Cloud FinTech

  • Monday, Oct 05, 2026

Customer Snapshot

AttributeDetails
IndustryFinTech / SaaS
Cloud EnvironmentGCP (70%), Azure (30%)
WorkloadsGKE for most services, plus a fleet of VMs
VM PlatformsGCP Compute Engine, Azure Virtual Machines
Access Method BeforeSSH with shared keys, standing bastion access
Console Access10–15 people with cloud and host access
CommunicationSlack
ComplianceISO 27001, SOC 1, SOC 2, GDPR
Primary InterestTime-bound, recorded VM access across both clouds

The Situation: GKE Gets the Attention, VMs Carry the Risk

This FinTech runs most of its services on GKE, so Kubernetes naturally gets the lion’s share of the security conversation. But underneath the orchestration layer sits a fleet of virtual machines that quietly carries a disproportionate amount of risk: GCP Compute Engine instances and Azure Virtual Machines running databases, batch jobs, legacy services, build agents, and the occasional “we’ll containerise it later” workload that has been running for two years.

VMs are where engineers go when something breaks in a way kubectl cannot fix. They SSH in to inspect logs, restart a stuck process, run a migration, or debug a networking issue. And because that access is occasional but urgent, it tends to be governed worst of all. The team’s reality looked familiar:

  • SSH with shared keys distributed across the team, sitting on laptops indefinitely.
  • Standing bastion access that, once granted, was never revisited.
  • No record of which human SSH’d into which host, when, or what they did once inside.
  • The same key granting access to development and production hosts because splitting them was more work than anyone had time for.

For a company under ISO 27001, SOC 1, SOC 2, and GDPR, with VMs that touch financial data and production systems, this was the softest part of an otherwise maturing security posture — and the part an auditor’s “show me who accessed production hosts in the last 90 days” question lands on hardest.

The Core Tension

VM access is occasional, urgent, and spread across two different clouds with two different native access models — GCP’s OS Login and IAM, and Azure’s SSH extensions and RBAC. Securing it properly usually means either standing up a heavyweight bastion architecture per cloud (operational burden the team cannot carry) or living with shared keys and standing access (the risk they already have). The team needed a third option: time-bound, approved, recorded host access that works identically across GCP and Azure, with no standing credentials and no new bastion to maintain.

Where the Gaps Were

Shared SSH Keys That Never Expire

The most immediate exposure. SSH keys were generated once, distributed to whoever needed host access, and never rotated — because rotating them means re-distributing to everyone and breaking whatever automation depends on them. So the keys accumulate on laptops, in dotfiles, in password managers, and occasionally in a repository where they should never have been committed.

A single stolen laptop or leaked key is a direct path to production hosts. And because the keys are shared, even if the team detects misuse, they cannot tell which holder of the key was responsible. The credential proves access to a machine, not to a person.

Standing Bastion Access With No Expiry

Where the team used a bastion host to reach private VMs, access to the bastion itself became standing. Once an engineer could reach the bastion, they could reach everything behind it, indefinitely. The bastion solved the network-reachability problem and created a new access-governance problem: a single always-on entry point into the production network, protected by credentials that never changed and were held by more people than anyone could list from memory.

No Attribution, No Recording

When an engineer SSH’d into a production VM and ran commands, nothing recorded who they were or what they did. The host’s own logs, if shipped anywhere, showed a shared username. There was no session recording, no command history tied to a named human, and no way to reconstruct — during an incident or an audit — the sequence of actions taken on a production machine. “Who restarted that service at 2 AM and what else did they touch?” had no answer.

Two Clouds, Two Access Models, Double the Work

GCP and Azure handle host access differently. GCP has OS Login, IAM roles, and IAP-based tunnelling; Azure has its own SSH extensions, Just-in-Time VM access through Defender, and RBAC. Managing both meant maintaining two separate access workflows, two sets of policies, and two audit sources — for a two-person security team that could not afford to be experts in both clouds’ native access tooling simultaneously. Azure’s native JIT VM access, in particular, is scoped to Azure alone and does not extend to the GCP side where most of the fleet lives.

How Cloudanix Addresses This Situation

Cloudanix VM JIT replaces standing SSH access, shared keys, and always-on bastions with time-bound, approved, session-recorded host access — delivered through one engine that works identically across GCP Compute Engine and Azure Virtual Machines.

One-Click, Time-Bound Host Access

  1. Engineer requests VM access via Slack or the Cloudanix Console, selecting the host (or group of hosts), the access level, and the duration, with a reason or incident ID attached.

  2. Approval routes by sensitivity. Access to a development host can auto-approve; access to a production VM carrying financial data requires an approver. For on-call incidents, a PagerDuty-triggered auto-approval can grant access immediately so a live incident is never blocked waiting on a human.

  3. Access is granted for the window only. The engineer connects to the host and works normally — the same SSH-based workflow they already know. No new client to learn.

  4. No standing key ever lives on the laptop. Access is brokered per session with short-lived credentials, so there is no durable key to steal, leak, or forget to rotate.

  5. When the timer expires, access is revoked automatically. No manual cleanup, no “we forgot to remove that engineer’s key,” no standing bastion session left open.

Session Recording for Every VM Session

This is the control the team most lacked. VM JIT records the session — the commands run and the actions taken on the host — and ties the recording to the specific human, the approved request, and the time window. Recordings land in the customer’s own cloud storage, never in Cloudanix infrastructure, and are linked to the request and approval that authorised them.

For incident response, this turns “who touched this host and what did they do?” into a replayable timeline. For ISO 27001 and SOC 2 audits, it turns “we have SSH access controls” into “here is the recorded, attributed session for every production host access in the audit period, each one time-bound and auto-revoked.”

Cloudanix JIT Access — Slack-based request and approval workflow with time-bound access

Private VMs Without a Standing Bastion

For VMs in private subnets, Cloudanix reaches the host through a scoped, outbound connection into the customer’s own VPC — so engineers get access to private instances without maintaining an always-on bastion with standing credentials. The network-reachability problem is solved per session, not by a permanent entry point that itself becomes a target. The private VM stays private; the access is ephemeral.

One Engine Across GCP and Azure

The decisive advantage for this profile: the same VM JIT workflow covers GCP Compute Engine and Azure Virtual Machines through one policy model, one Slack approval flow, and one audit trail. The team does not maintain GCP’s native access tooling and Azure’s separately. A request for a production host in GCP and a request for a production host in Azure look identical to the engineer and to the approver, and both produce the same attributed, recorded, auto-expiring session. For a two-person security function spanning two clouds, that single workflow is the difference between a sustainable control and one that erodes under operational pressure.

Part of One Access Lifecycle, Not a Point Tool

VM JIT is one surface of the same engine that governs this team’s GKE clusters, cloud consoles across GCP and Azure, and MySQL databases. The request → approve → time-boxed grant → auto-revoke lifecycle is identical everywhere, so the team builds the governance model once and applies it to every surface. An engineer requesting SSH to a VM, kubectl to a cluster, or a database session uses the same Slack flow and generates the same quality of audit trail.

Cloudanix JIT Access — Session expired with full audit trail

Platform Impact

DimensionBeforeAfter (VM JIT)
SSH keysShared, long-lived, on laptopsNone — brokered per session
Bastion accessStanding, always-onScoped, per-session reachability
AttributionShared usernameEvery session stamped to a real human
Session recordingNoneFull recording linked to request + identity
Private VM accessStanding bastion with broad reachEphemeral outbound tunnel into the VPC
GCP vs AzureTwo native access models to manageOne engine, one workflow across both
RevocationManual, often skippedAutomatic at expiry
Compliance evidenceLittle to noneRecorded, attributed, time-bound per access

Why VM Access Deserves the Same Rigor as Everything Else

It is tempting, in a GKE-first shop, to treat VMs as a legacy afterthought. But the hosts engineers SSH into are frequently the ones running databases, holding credentials, or sitting closest to production data — which makes them a high-value target precisely because they are governed loosely. A shared SSH key is, in practice, often the weakest credential in an otherwise well-run estate: it never expires, it names no person, and it tends to grant more reach than any single task requires.

Bringing VM access under the same time-bound, recorded, auto-revoking model as the rest of the platform closes that gap without asking engineers to change how they work. They still SSH in and do their job. What changes is that the access expires, the session is recorded, and the audit trail names a person instead of a key. For a FinTech under four compliance frameworks across two clouds, that is how the softest part of the access surface finally gets the same treatment as the loudest.

Key Outcomes

  • ✅ No Standing SSH Keys: Host access brokered per session; nothing durable to steal or leak.
  • ✅ Session Recording: Every VM session recorded and tied to a named human, in your own storage.
  • ✅ One Engine, Two Clouds: Identical workflow across GCP Compute Engine and Azure VMs.
  • ✅ No Always-On Bastion: Private VMs reached through scoped, ephemeral tunnels.
  • ✅ Auto-Revocation: Access disappears at expiry — no manual cleanup.
  • ✅ Incident-Ready Approvals: PagerDuty-triggered auto-approval so live incidents are never blocked.
  • ✅ Audit Evidence by Default: Attributed, time-bound, recorded access for ISO 27001 and SOC 2.

Securing SSH Access to Production VMs Across GCP and Azure?

If your engineers still reach production hosts with shared SSH keys and standing bastion access — and you cannot prove who did what on which machine — Cloudanix VM JIT gives them the same SSH workflow with time-bound, approved, session-recorded access, across GCP and Azure, with no standing credentials and no bastion to maintain.

Book a Free Assessment to see VM JIT working across your GCP and Azure instances — including private hosts — in a single session.

Related Resources

What Our Users Are Saying

Customer Reviews

Cloudanix is trusted by security leaders worldwide to deliver proactive, reliable, and cutting-edge cloud security.

One day, I changed the password of a root account, and my CTO called me within less than a minute to confirm if I did so. I was not expecting a reaction this quick. He told me Cloudanix alerted him of this password change and that he wanted to confirm as it was a critical security notification. I couldn't believe it!

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Compliance is one way of staying secure, but what I want is the ability to go deeper and attain 'true security.' Cloudanix provides us the capability to do so.

Vishal Madan
Vishal Madan
Head of Engineering, iMocha

Cloudanix is building for the future of the cloud, which makes the product all the more desirable.

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Cloudanix gave us the visibility we were missing. Being able to move from permanent access to a robust Just-In-Time (JIT) workflow has fundamentally changed our security posture without slowing down our engineering velocity.

Pavan Kumar Lekkala
Pavan Kumar Lekkala
SRE Lead, HugoHub

We are excited to leverage Cloudanix's comprehensive multi-cloud DevSecOps solution to secure our production workloads on AWS. Cloudanix has demonstrated that it can solve many challenges that DevSecOps teams face while continually adding new features such as SOC2 compliance and drift detection.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Managing third-party partner access was once a major concern for our security posture. With Cloudanix JIT Cloud, we've effectively achieved zero third-party risk. We can now grant access confidently, knowing that it is temporary, audited, and automatically revoked, resulting in a 100% reduction in our privileged access exposure.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

The snooze feature and responsible alerts have helped us save time and prioritize what to tackle first.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Implementing Cloudanix JIT internally allowed us to practice what we preach. By eliminating permanent access to our own clouds and databases, we've neutralized the risk of standing privileges, ensuring our own 'keys to the kingdom' are never left exposed.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

The problem with permissions is a lot of times, the gaps are left open due to oversights from inside the organization itself. With Cloudanix's CIEM, we get a complete view of user permissions and access. This enables us to update the permissions, reducing the attack surface.

Nilesh Pethani
Nilesh Pethani
Application Architect, iMocha

In the world of Fintech, trust is our currency. Cloudanix provided the frictionless visibility we needed to secure our EKS workloads across AWS, ensuring we stay audit-ready for SOC2 and GDPR without slowing down our engineering velocity.

Amol Naik
Amol Naik
Head of Security & Infrastructure, HugoHub

Cloudanix delivered value within 5 minutes of onboarding. Continuous monitoring, timely detection, and excellent documentation helped us attain a great cloud security posture.

Divyanshu Shukla
Senior DevSecOps, Meesho

Technology strategies and business strategies are in a state of constant change which includes centralization and decentralization of responsibilities. Regardless of strategic shift, we still have intellectual property to protect. Cloudanix are critical partners for us in our public cloud security posture across our three cloud providers.

Jerry Locke
Jerry Locke
Senior Director Global Solutions Engineering, Eversana

Cloudanix has been amazing. They opened up a common Slack channel with us — and it feels like we are talking to our own team and getting things done with Cloud security. The support team is always available, friendly, helpful, and ready to go out of their way.

Satish Mohan
Satish Mohan
CTO, Airgap Networks

Beyond just access management, Cloudanix CSPM has given us a unified view of our AWS environment. The real-time alerting and anomaly detection allow us to prevent any untoward activity before it happens, which is critical for a marketplace connecting 50+ financial institutions.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

For a Fintech company, data is our most valuable — and most sensitive — asset. Cloudanix DAM hasn't just improved our visibility; it has given us control. The ability to mask data and prevent unauthorized queries in real-time is a game-changer for our compliance and customer trust.

Jiten Gala
Jiten Gala
President Engineering and Product, Kapittx

Our clients, especially in the Middle East financial sector, demand absolute accountability. Cloudanix JIT Cloud has been a competitive differentiator for us, allowing us to provide secure, governed access to customer accounts that meet their strictest audit and compliance requirements.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

Cloudanix is always on my team's lips because of its exceptional support. Be it a small or big query, Cloudanix has gone above and beyond to resolve them. This one's a keeper for us.

Sujit Karpe
Sujit Karpe
CTO, iMocha

For a long-lasting partnership, great support goes a long way. Cloudanix has delivered exceptional support whenever required. Their edge is their team is always ready to go beyond to solve any issues that we have. This speaks volumes about the culture at Cloudanix.

Akash Maheshwari
Akash Maheshwari
Co-founder, MoveInSync

Beyond the technology, Cloudanix feels like an extension of our own team. Their willingness to stand up a dedicated Middle East tenant for us and provide exceptional support at a sensible price makes them a long-term partner for Hugosave.

Surya Tamada
Surya Tamada
CTO, HugoHub

The real-time notifications that Cloudanix provides are a real lifesaver. Their adaptive notifications ensure that my team stays productive and doesn't get interrupted all the time.

Digvijay Singh
Staff Security Engineer, Meesho

The whole point in technological evolution is to help improve the world we live in. We must protect that and to do so requires an effective and efficient security strategy. The Cloudanix team helped make our public cloud security posture management strategy a reality. The symbiotic relationship we have allows for a continuous feedback loop which is how business should operate.

Larry Wheat
Larry Wheat
Staff Solutions Engineer, Eversana

Ready to see your graph?

Connect a cloud account in under 30 minutes. See every finding rooted in identity, asset, and blast radius — with a fix path attached.

Book a Demo