Skip to content
ANCHORDocumentation
About Anchor

Explore Anchor

The Big Picture

Credential management, privileged sessions, and security insight—connected through shared policy and evidence.

Each component has a focused role. Together, they connect the request, the work, and its outcome.

Anchor architectureDeployment design · default ports
Users & administratorsBrowser · CLI · API
HTTPS / WSS 443
Anchor WebUI, API proxy & session entry
Public entry
Web → Core mTLS · 8444
Core

Authorization · policy · canonical state

Accepts results and governs audit intake
Private · 8444
Compass, Engine & Connect → Core mTLS · 8444
Compass

Deterministic posture

State, findings & evidence Outbound only · no listener
Engine

Credential management

Admitted jobs / results Outbound only · no listener
Connect

Privileged sessions

Session authority & evidence Private listener · TCP 8090
Session path

Web → ConnectProtected WSS · 8090

Live session traffic bypasses Core. Connect checks authority with Core.
Private data stores

Core → each storePostgreSQL TLS · 5432

Vault

Protected operational state

Evidence

Audit & historical records

Separate service addresses and identities. Other components have no direct database access.
Managed target networks

Engine → targetsApproved management protocols

Connect → targetsApproved session protocols

Target-defined ports; allow only protocols required by the selected profile or session.
Design reference, not live configuration. All numbered ports are TCP destinations. Single-host evaluation places the roles together; distributed placement separates them. Private flows remain protected in both. Ports and supported flows must be confirmed in the v1 installation plan—not by opening every port shown here.

Open a component to explore its role and how it connects with the rest of Anchor.

Your WorkspaceWebA shared console for administration and access.

Web brings the platform into a consistent interface. Your team can work with resources, accounts, policy, and activity without piecing together separate operating views.

Connected WithCore · Connect

Policy & AuthorityCoreConnects requests, decisions, and results.

Core checks authorization, applies policy, and accepts the results of work. This gives the other components a shared foundation for governed operations and connected evidence.

Connected WithWeb · Engine · Connect · Compass · Vault · Evidence

Credential OperationsEngineHandles credential rotation and verification.

Engine performs credential-management jobs through the appropriate profiles and integrations. Manual and scheduled work follow the same controlled path, with results returned to Core.

Connected WithCore · Managed Systems

Privileged SessionsConnectCarries interactive privileged sessions.

Connect provides the session path to target systems and checks session authority with Core. Credential-management work stays with Engine, keeping the two responsibilities clear.

Connected WithWeb · Core · Target Systems

Posture & RatingsCompassMakes security posture easier to understand.

Compass uses authoritative state and evidence to produce findings and ratings. It connects the technical picture to affected resources, helping your team see what needs attention and why.

Connected WithCore · Evidence · Insights

Protected RecordsVaultStores the operational records behind Anchor.

Vault holds protected operational state. Core manages access to these records as part of the platform’s authorization and policy decisions.

Connected WithCore

History & AccountabilityEvidenceKeeps actions connected to their outcomes.

Audit, event, and session history provides a record of activity across the platform. Components report through Core so the evidence stays connected to the work that produced it.

Connected WithCore · Activity · Compass

Advisory IntelligenceInsightsAdds context to findings and evidence.

Insights helps explain what deserves attention and what to investigate next. It is an advisory capability, not another deployment node; your team retains authority over changes.

Connected WithCompass · Curated Evidence