Cloak

Instant zero-trust vendor access with automated audit compliance

Enterprise security teams spend over 20 hours per week supervising third-party vendor sessions to prevent customer PII exposure and maintain SOC2 standards.

Cloak provides an isolated, web-based remote support session broker that automatically redacts sensitive screen data live during vendor control. It records cryptographic, tamper-proof session ledgers and instantly revokes administrative privileges the moment support tickets close. Compliance teams eliminate breach risks while technical vendors resolve complex enterprise issues in minutes rather than days.

Cloak is building the global standard for secure ephemeral vendor access across regulated software industries.

COMMENTS — Community Discussion
Loading comments...
cloak.dest.page
#CYBER#OPS#AUTO#DevTools
Problem
  • When I manage external vendor access during live infrastructure outages, I want to grant immediate desktop control, but legacy remote access tools bypass perimeter controls and expose raw PII.
  • Why Now: Regulators are handing out massive fines for third-party vendor breaches, making unmonitored TeamViewer and VPN access a major corporate liability.
  • When I undergo annual SOC2 and HIPAA audits, I want to prove zero unauthorized database or screen exposure, but session logs from traditional tools are incomplete and easily altered.
  • When I onboard contract engineers for rapid bug fixes, I want to give them immediate local debugging capabilities, but IT security provisioning takes up to 14 days of back-and-forth approvals.
  • Existing Alternatives: Manual Zoom screen shares with IT minders sitting on calls, clunky jump boxes with high latency, or blanket VPN access that risks total network infection.
Solution
  • High-Level Concept: Teleport for live remote desktop support and third-party vendor access.
  • Ephemeral session links that spin up isolated, browser-based desktop environments with zero client software installation.
  • Real-time screen sanitization that blurs credit card numbers, passwords, and user PII before pixel transmission.
  • Immutable cryptographic audit trails that generate instant compliance logs for SOC2, ISO27001, and HIPAA.
Distribution
  • Early Adopters: Chief Information Security Officers (CISOs) and IT Operations Managers at mid-market FinTech and HealthTech companies with 200 to 2,000 employees.
  • Sponsor high-intent technical podcasts and security newsletters targeted directly at DevSecOps leads.
  • Host interactive sandbox security benchmarks comparing traditional remote access leak risks against encrypted ephemeral sessions.
  • Direct outbound social engineering resistance audits offered for free to security directors on LinkedIn.
Pricing
  • Value Ladder: Starter tier at $0 per month for 3 concurrent sessions, Professional tier at $490 per month for up to 25 vendor seats, Enterprise tier at $2,500 per month with dedicated relay servers and SSO.
  • One Metric That Matters: Number of verified zero-breach vendor support sessions completed per month.
  • Market Sizing: 12k regulated SaaS firms in North America x $15k average annual contract value = $180M SAM. Target 1% market share in Year 1 = $1.8M ARR SOM.
Scale Costs
  • High-bandwidth multi-region TURN and WebRTC relay server network infrastructure for low-latency worldwide screen streaming.
  • Hardware-backed hardware security module key management for cryptographic session signatures.
Expert Opinions
Avg: 9.5
  • Chief Information Security Officer and Enterprise Risk Architect with $500M+ infrastructure oversight
    9.6
  • SOC2 Compliance Director and Cyber Audit Expert
    9.4
  • VP of Enterprise Infrastructure and Managed IT Operations
    9.5
CommunityGitHub