Enforcement inside your environment.
The Authesta Private Gateway runs where your systems are. Agents call the gateway, the gateway enforces their authority locally, and your target-system credentials never leave your environment.
How it fits
What stays local, and what Cloud does
Stays in your environment
- Target-system credentials
- The execution connection to the target system
- Local integration configuration and secrets
- The allow and deny decision for each call, made against signed policy
Provided by Authesta Cloud
- Signed policy and agent identity
- Signed entitlement for the gateway
- The human authorization workflow
- Evidence synchronization and history
- Gateway health in the Authesta console
Deployment
- Docker-based. One container, started with a single command from the Authesta console.
- Registers once. After first registration it restarts on its own persisted state, without a new registration token.
- Local integration configuration. Credentials are referenced from environment variables, files or Docker secrets on your side.
- Health and readiness. The gateway reports whether it is ready to serve, and why not when it isn’t.
Signed state, bounded offline operation
The gateway only enforces policy, agent identity and entitlements signed by Authesta, and refuses to roll back to an older policy.
If Authesta Cloud is unreachable, the gateway keeps enforcing the policy it already holds — for a bounded window only. Actions that need human authorization fail closed while Cloud is unreachable, and once the window passes, the gateway stops serving protected actions rather than act on stale authority.
Agent authentication
Agents call the gateway with their own Authesta credential. The gateway verifies each credential locally against signed identity from Authesta Cloud.
You choose which agents a gateway serves. With enforcement turned on, the gateway refuses any agent you haven’t assigned to it.
Pilot with a Private Gateway.
Run the 30-day pilot with the gateway inside your environment from day one.