Ekran System® Structure and Architecture


Ekran System is an agent-based software product supporting various deployment options. Ekran System has the flexibility to deploy as SaaS, on-premise, or in hybrid environments. We deliver monitoring and protection Clients for different types of endpoints, centralize and store data on the Ekran System Application Server side and provide a centralized Web-based management panel.



Ekran System Clients


Ekran System Clients help to deter, detect, and disrupt insider threats on any type of desktops and servers:

  • Infrastructure servers,
  • Terminal servers,
  • Jump servers,
  • Physical and virtual desktops.

The most complete set of supported platforms:

  • Windows,
  • Linux,
  • macOS,
  • UNIX,
  • X Window System,
  • Citrix, and
  • VMware.

The Client captures user screens with mouse moves according to the recording settings and simultaneously logs important metadata such as application names, titles of active windows, keystrokes, etc.


The monitored data is sent to the Ekran System Application Server for storage and analysis, or, if there is no network connection, is stored in the Client protected cache until the connection is restored.


You may configure the Client depending on how intensive security monitoring should be, up to making screen captures every second or based on each mouse click or key pressure. You may enable the special Protected mode to ensure the safety of Client work and integrity of monitored data.


Ekran System enables easy solution deployment providing remote Client installation options.

Ekran System Application Server


Ekran System Clients send monitored data to the Ekran System Application Server, which analyzes the data and stores it in a central database. If the monitored data contains events that correspond to user-defined rules, the Server generates instant alerts and initiates automated incident response if needed.


The Server is also responsible for storing the configuration data, sending the update packages to Clients, performing database cleanup, and creating reports and corresponding statistics.


Ekran System Application Server can optionally work with third-party MS SQL or PostgreSQL databases, allowing for a flexible choice depending on your security, economical, and processing speed needs.

Web Management Tool


The Management Tool is the primary Ekran System user interface. It allows you to manage Clients, configure security alerts to potential incidents, define and assign permissions to Ekran System users, manage access to endpoints, as well as view and analyze monitored security data received from Clients.

Solution Architecture


Combining various types of Ekran System Clients, you can protect and increase the visibility of each part of your particular IT infrastructure. For large deployments, we provide high availability and disaster recovery to improve system stability and multi-tenant mode to meet data segmentation and isolation requirements.


Basic Deployment Scheme


You can achieve maximum visibility and control of any activity performed within your infrastructure by installing a Client of the corresponding type to each endpoint.

Full agent-based deployment scheme

Jump Server Deployment


You can install just one Ekran System Terminal Server Client on a jump server to monitor all sessions that come through it and, if needed, manage access to endpoints within the protected perimeter using Ekran System PAM toolset.

Jump server deployment scheme


Scale for Growth with the Master Panel


These days, security personnel from organizations that have data centers distributed over various different geographical locations face many challenges while managing the risk of insider threats.


The Master Panel is a component of Ekran System which is used for viewing the sessions of all of an organization’s Clients. This component combines the data from all isolated Ekran System Application Servers or deployments into a single user interface.

Jump server deployment scheme

Multi-Tenant Mode


Multi-tenant mode was developed for professional service companies managing the security of their clients and for large organizations with geographically separated offices and independent departments.


This deployment mode allows multiple independent tenants to operate in Ekran System environment. Data of each tenant including monitored data, user credentials, Client names, System configuration, etc. is completely independent and not accessible by other tenants.

Multi-tenant cybersecurity deployment scheme


Multi-tenant mode is available in Enterprise Edition. See licensing details.