LICENSEWARE

Imprivata privileged access licensing

This article is about licensing Imprivata's privileged access products: Privileged Access Management (PAM) for internal users, Vendor Privileged Access Management (VPAM, formerly Enterprise Access and SecureLink Enterprise) and Customer Privileged Access Management (CPAM, formerly Customer Connect). Imprivata Enterprise Access Management (SSO and MFA) is a different product line with its own article.

On This Page

Imprivata privileged access licensing covers three products built on a shared platform, which Imprivata calls Privileged Access Security (PAS). Privileged Access Management (PAM) serves internal users. Vendor Privileged Access Management (VPAM) serves outside vendors that connect into the customer. Customer Privileged Access Management (CPAM) lets a software or service provider connect out to its own customers’ systems.[1][9] Each product has its own unit: named users for PAM, Vendor entities for VPAM, and concurrent connections for CPAM. Legally, VPAM and CPAM still appear under their older names. The Managed Services terms say “VPAM formerly known as Enterprise Access and CPAM formerly known as Customer Connect”, and the Product Specific Terms pages still use the old names.[6][2][3] Their Vendor, Concurrent Connections and Average Peak Usage definitions also appear in the SecureLink End User License Agreement, which Imprivata archived on 2026-08-31.[5]

Editions

Imprivata does not publish PAM editions. It documents which capabilities need which licence:

Capability PAM VPAM 
Vault and credential management, rotation, injection Yes Yes 
Approval and access controls; session management and auditing Yes Yes 
Service and credential discovery Yes Yes 
Account Discovery (endpoints and accounts) Yes No 
Just-In-Time Privilege Elevation Yes No 
Break-Glass offline access Yes No 
Personal Vault Yes No 
Vendor and third-party access; third-party identity management; Nexus No Yes 

Source: Privileged Access Security Offering.[1] “A PAM license is required to obtain the Break-Glass client”, and Personal Vault “is available only with PAM”.[1] The products “can be deployed independently”. When licensed together they extend one environment to internal users and external vendors.[1] Catalog proof: PAM-only features: Account Discovery, JIT, Break-Glass, Personal Vault.

VPAM is sold in eight SLE tiers by number of Vendors, and CPAM in four SLINK tiers by concurrent connections:

VPAM SKU Monthly network usage (GB) S3 storage (GB) 
SLE - Cloud - 5 Vendor 500 50 
SLE - Cloud - 10 Vendor 840 90 
SLE - Cloud - 15 Vendor 1,345 140 
SLE - Cloud - 25, 35 or 50 Vendor 2,690 290 
SLE - Cloud - 75 or 100 Vendor 4,035 430 

Every SLE tier runs on a c5.xlarge machine with 50 GB of local storage.[2]

CPAM (Customer Connect) tier Machine Monthly network usage (GB) S3 storage (GB) 
5-20 Concurrents c5.xlarge 3,364 200 
21-50 Concurrents c5.xlarge 8,410 450 
51-100 Concurrents c5.2xlarge 16,819 900 
101+ Concurrents c5.2xlarge 33,638 1800 

Source: Customer Connect Appendix.[3]

Metrics

  • User (PAM). The archived EULA granted “a license for each User license purchased for Privileged Access Manager”. It defined “Privileged Access Management” as PAM and the Imprivata Enterprise Password Vault.[4] Users are named and not concurrent.[4] The current MLSA keeps the User metric. The legal index publishes no PAM-specific Product Specific Terms, so the Order Form sets the quantity.[7]
  • Vendor (VPAM). ““Vendor” means a single entity using the Cloud Service to access Customer’s systems.”[2] The VPAM documentation separates the Vendor, a company or organization, from its Vendor Representatives, the team members who register on the VPAM server.[8] The licence counts the organization, not each representative.
  • Concurrent Connections (Average Peak Usage) (CPAM). “Concurrent Connections” are “the total number of simultaneous connections on the Cloud Service at any one time”. “Average Peak Usage” is “the number calculated by averaging the peak number of Concurrent Connections during the three highest months of the applicable twelve-month period”.[3]

Counting / floors

Base Statistics and in-term invoicing

Both cloud appendices start from Base Statistics, the quantity documented in the initial Order Form. For VPAM, “Imprivata will review Customer’s number of Vendors throughout the Subscription Term”. If the number of Vendors “at any point exceeds the Base Statistics”, the difference is invoiced “for the remainder of the Subscription Term”.[2] For CPAM, if “Average Peak Usage exceeds the Base Statistics”, the difference is invoiced for the rest of the term in the same way.[3] Neither appendix provides for a reduction during the term. With a three-month averaging window, a single busy month raises the CPAM figure but does not set it alone. Catalog proof: Vendors above Base Statistics invoiced for rest of term; Average Peak Usage above Base Statistics is invoiced.

A licence manager can count VPAM from the server’s own vendor list. The View Vendors page lists every Vendor configured in the system.[8] Vendors that are no longer used should be removed before the count is taken, because the appendix counts any entity “using the Cloud Service”.[2]

Under the archived SecureLink EULA, fees were “typically determined based on the usage of the Software during the preceding Contract Year”. More Concurrent Connections or more Vendors meant higher fees for the next Contract Year.[5] Imprivata could change per-unit pricing for a Contract Year or renewal with at least ninety days’ notice. The agreement renewed for one-year periods unless either party gave sixty days’ notice.[5] The same EULA also defined a “Site” as “a single physical location unless otherwise defined in the Quote”.[5] The current appendices instead invoice increases during the term.

Use restrictions

The archived SecureLink EULA stated that the Software “may not be used by Company to facilitate remote access by its employees or contractors to Company’s own systems unless Company has purchased an internal use license”.[5] Under the MLSA, VPAM customers lose the general Affiliates right: “Customer’s Affiliates shall have no rights under this Agreement without Imprivata’s express written consent.”[2] A group that runs one VPAM tenant for several subsidiaries therefore needs that consent in writing. Catalog proof: Affiliate usage counts toward subscription compliance.

Virtualization & partitioning

The current appendices describe cloud services hosted by Imprivata, so there is no customer host to count. The archived SecureLink EULA licensed “a single instance of the Software”. A business continuity package added up to two high-availability instances and one disaster recovery instance, and a Sandbox purchase added one non-production instance. Software “provided on an Imprivata server” could be used only on that server.[5] Under that EULA, a customer that licensed “Imprivata for Vendors” could install part of the software on its own customers’ systems.[5] Catalog proof: SecureLink: one instance plus HA, DR and sandbox options.

Cloud / BYOL

Each VPAM and CPAM tier carries a Service Allocation of monthly network usage and storage. Imprivata “will use commercially reasonable efforts to notify Customer in writing if Customer has reached 80 percent (80%)” of it, and the customer may then increase the allocation.[2] If the network allocation is exceeded, access “will be throttled”. If storage limits are exceeded, “audit data will automatically be deleted”.[2][3] Where session audit data is kept as compliance evidence, the storage allocation therefore works as a retention limit as well as a commercial one. Catalog proof: Exceeding a Service Allocation throttles or deletes audit data.

Programs

  • Managed Services packages. “Privileged Access Management (PAM) Services” is part MS-MGMT-iPAM-SUB. “Vendor/Customer Privileged Access Management” Services are parts MS-MGMT-VPAM-SUB and MS-MGMT-CPAM-SUB. Each runs for the Order Form term and renews for one-year periods unless notice is given at least 30 days before the term ends.[6] Catalog proof: Managed Services auto-renew yearly with 30 days notice.
  • Support. Support is included in the subscription cost of Cloud Services and On-Premise Software.[7]
  • Audit. The MLSA audit right covers “the number of Users, and any other applicable metric used in pricing”. That includes Vendors and Concurrent Connections.[7]

Out of scope

This article does not cover Imprivata Enterprise Access Management, the SSO and MFA product line. That name is easy to confuse with the “Enterprise Access” appendix that governs VPAM. See Imprivata Enterprise Access Management licensing. Prices, PAM edition SKUs and any per-vendor-representative limits are not published.

References

  1. Privileged Access Security Offering (VPAM documentation)Topic updated: August 21, 2026.Effective 2026-08-21. Retrieved 2026-10-01.
  2. Enterprise Access Cloud Services AppendixVendor metric, Base Statistics, SLE Service Allocation table, Affiliates restriction. Undated.Retrieved 2026-10-01.
  3. Customer Connect Cloud Service AppendixAverage Peak Usage, Concurrent Connections, SLINK tiers. Undated.Retrieved 2026-10-01.
  4. End User License Agreement for Imprivata Software (archived)Archived as of 2026-08-31; s.2(d) Privileged Access Manager.Retrieved 2026-10-01.
  5. Imprivata End User License Agreement for SecureLink Software (archived)Archived as of 2026-08-31.Retrieved 2026-10-01.
  6. Managed Services AppendixPAM and VPAM/CPAM service packages. Undated.Retrieved 2026-10-01.
  7. Imprivata Master License and Services AgreementUndated.Retrieved 2026-10-01.
  8. Vendor Management (VPAM documentation)Topic updated: August 19, 2026.Effective 2026-08-19. Retrieved 2026-10-01.
  9. Overview (CPAM documentation)Topic updated: June 22, 2026.Effective 2026-06-22. Retrieved 2026-10-01.

See also

Catalog Rows Cited

7Rules3Metrics2Programs

Esc