IMTerm Security

Enterprise-grade security built in from the ground up

Authentication Methods

MethodDescriptionConfig
Local / Built-inBcrypt password hashing, per-user accounts managed via admin consoleauth.mode: local
LDAP / Active DirectoryBind authentication, group-to-role mapping, supports TLS and StartTLSauth.mode: ldap
Azure AD / Entra ID (OIDC)OpenID Connect redirect flow for Microsoft Entra ID. Group-to-role mapping from Azure AD group membership claims. "Sign in with Microsoft" button on the login page. Configured via imterm-setup Phase 6 or IMTERM_OIDC_* env vars.auth.mode: oidc
OIDC / OAuth2OpenID Connect, Okta, Google Workspace, and any compliant IdPauth.mode: oidc
SAML 2.0SP-initiated SSO, ADFS, PingFederate, Okta. Signature validation via goxmldsigauth.mode: saml
Kerberos SPNEGOKeytab-based, transparent browser SSO on Windows domain machinesauth.mode: kerberos
mTLS client certificatesMutual TLS, client certificate presented at TLS handshake, mapped to userauth.mode: mtls

RBAC Model

RolePermissions
AdminFull access, user management, configuration, audit log, session monitoring, all terminal operations
UserSessions, file transfer, printing, macros, scripting, Agent Mode
View-OnlyObserve active sessions, no keyboard input, no transfer, no print

All roles are enforced server-side. There is no client-side bypass path.

TLS

FIPS 140-2: A FIPS build is available using BoringCrypto (certificate 3678). Build with make build-fips. The FIPS binary uses BoringSSL for all cryptographic operations and refuses non-compliant cipher suites.

Audit Logging

Session Security

Data Protection

Independent Security Review

IMTerm v2.3.x underwent an independent AI-assisted code security review (Fable5) covering all Critical, High, Medium, and Low findings. All findings were remediated before customer delivery.

Security contact: security@infomanta.com

The only terminal emulator with built-in capacity management

Every other terminal emulator accepts connections until the server runs out of memory - then crashes, hangs, or starts dropping sessions silently. IMTerm is different.

PowerTerm WebConnect had none of this. When the server was overloaded, users experienced slow response or could not connect - with no warning and no automatic recovery. IMTerm turns capacity management from a crisis into a routine operation.

Calculate your cluster size →

Security Disclosure

To report a security vulnerability in IMTerm, contact support@infomanta.com. Please include a description of the issue, steps to reproduce, and the IMTerm version. We respond to all reports within 2 business days.