Skip to content
Gatehouse
Contractor access control

The contract ended. The account did not.

Gatehouse gives contractors and remote engineers temporary access to your cloud, code, servers and databases. No permanent accounts. One click to revoke.

Set up with you

Before the next contract ends.

Your name and work email. A person replies and helps you connect your first cloud account.

Nothing is connected until you say so.

Too many accounts reach straight into your infrastructure.

Every cloud user, server login and database login is a direct line into production.

Never switched off

Used for a day. Kept for a year.

Outlives the contract

Slow to close. Some stay open.

One login, five people

Nobody can say who did what.

48%
of all breaches involved a third party, up 60% on the year before.
Verizon, 2026 Data Breach Investigations Report
64%
of exposed credentials confirmed valid in 2022 still worked in January 2026.
GitGuardian, The State of Secrets Sprawl 2026
28%
of leaked-secret incidents start entirely outside code repositories, in places like Slack, Jira and Confluence.
GitGuardian, The State of Secrets Sprawl 2026

Issued when needed. Expired within the hour.

Connect each platform once. There is no user to create for each engineer.

Choose what each engineer may reach.

The engineer opens it and is in. No password to see, no account to keep.

One click, across everything you granted. Anything already issued expires within the hour.

Recorded whenever access is issued: who, what, which laptop, when.

Cloud, code, servers and databases.

Cloud accounts

AWS, Google Cloud and Azure.

Code

GitHub, repository by repository.

Servers

Any server over SSH, on any host.

Databases

The databases running on your cloud.

What teams ask before they try it.

One click, across everything you granted. No new access is issued from then on, and what was already issued expires within the hour, or at once where the platform allows it. There are no leftover accounts to hunt down.

You tell your AWS account, once, to trust identities issued by Gatehouse. After that, AWS itself issues each engineer temporary access that expires within the hour. Nobody gets a permanent AWS user or an access key. Google Cloud and Azure work the same way. Engineers get temporary access for the command line, and a sign-in to the AWS and Google Cloud consoles with no password.

Every contractor and remote engineer gets a cloud user, a server login and a database login, and each one is a direct line into production that stays open until someone remembers to close it. An account nobody is using still works for whoever gets hold of it. When someone leaves, their accounts are spread across your cloud, your servers and your databases, and closing every one is slow, so some stay open.

Gatehouse covers the databases running on your cloud. The engineers you grant reach the database with temporary access, not a shared database login.

Every time access is issued, it is recorded: who, which system, which laptop, when, and when it expired. The same access shows up in your own cloud and GitHub logs, so you can check one against the other. On servers, each SSH session gets its own certificate, so your server logs show who connected.

Just-in-time access means an engineer gets access only when they need it, and it expires on its own. Gatehouse works this way: temporary access is issued when the engineer opens what you granted and expires within the hour, so nobody keeps a permanent account on your infrastructure.

You need to control who can reach your cloud accounts, code, servers and databases, and for how long, and to have a record of it. Gatehouse does that for engineering access and follows least privilege: each engineer reaches only what you granted, and only while they need it.

No. For AWS, Google Cloud, Azure and GitHub, your own platform issues the temporary access, so we store no password or key to your cloud. It does not open encrypted traffic and installs no root certificate on anyone’s laptop.

No. git, the cloud command lines and SSH keep working as they are. A small app on the engineer’s laptop supplies the temporary access.

Leave your name and work email. A person gets in touch, gives you access and helps you connect your first cloud account.

Somewhere, an old contractor account still works.

Leave your name and work email. We set it up with you.

Request access.