Automate Rotation and Reduce Credential Risks
BeyondTrust Password Safe stores, rotates, and controls access to privileged credentials to protect sensitive assets and meet compliance requirements. Use Password Safe's credential management tools to:
Keep Passwords Fresh
Rotate SSH Keys
Eliminate Application Credentials
Ensure Password Strength
Eliminate Old Passwords
Active Password Change
Use Access Policies for Advanced Credential Management
In Password Safe, Access Policies associate groups of users with groups of accounts. Access Policies define when, where, and how access is granted, and determines approval requirements.
Inject credentials into applications within an SSH or RDP session. Managed Accounts include configuration that indicates whether credentials have been rotated. This feature allows for bulk password changes as determined by policy. This granularity level in access and password change propagation makes Password Safe a robust, flexible, and scalable solution for organizations of all sizes

Secure Application Credentials
Password Safe automatically eliminates hard-coded or embedded application credentials, simplifying the management responsibility of IT and better securing the organization from exploitation of those credentials. Additionally, Password Safe's credential management features enable:
Removal of hard-coded passwords from applications and scripts.
Extensible REST interface that supports many languages, including C/C++, Perl .NET, and Java.
Automatic password reset protocols upon release.
Enforcement of extensive security controls to lockdown access to authorized applications.
Simplify SSH Key Management
Traditional methods of SSH key management are labor-intensive, with many organizations improperly rotating or sharing keys. This leads to a loss in accountability over systems, which could lead to those systems being vulnerable to exploits.
Password Safe adds security and simplifies SSH management by:
Storing private keys like any other privileged credential and rotating SSH keys according to defined schedules.
Allowing designated ‘secondary’ accounts and SSH keys to be grouped to a ‘primary’ account to manage rotation interval, complexity and duration of SSH keys.
Enforcing granular access controls and alerting when keys are released.
Automatically logging users onto Unix & Linux systems through the proxy with no user exposure.
Recording privileged sessions with full playback and key usage auditing.
Offering failover to a managed password for complete redundancy.
Allowing SSH sessions to be established via existing desktop tools without having to initiate with a web interface.

