📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Lavawall®: The BeyondTrust (Bomgar) Alternative

BeyondTrust terminates the session at an appliance it operates. Lavawall encrypts the session end to end, so the relay in the middle holds no key for it. Here is what that changes, and where each product is the better fit.

BeyondTrust Secure Remote Access, the product formerly sold as Bomgar, is a serious platform with a large install base in regulated enterprises. Lavawall® delivers MSP-grade multi-tenant remote support with no operator agent, browser-based mobile and desktop access, and built-in device health context, all bundled with patching, security, and GRC at a fraction of the cost.

What BeyondTrust does well

BeyondTrust has mature privileged-access workflows: credential vaulting and injection, session recording, granular Jump Client and Jumpoint routing for complex enterprise networks, and deep ties to the rest of the BeyondTrust privileged-access portfolio. If you have standardized on BeyondTrust for privileged access across staff, vendors, and contractors, it is doing real work, and this page is not an argument that it is unsafe.

Its architecture terminates the session at the B Series appliance, which is what makes session recording, data-loss inspection, and credential injection possible. That is a legitimate design with real benefits. It also means the appliance handles the session in plaintext, and that single fact is where Lavawall differs.

The difference in one line, and one picture

BeyondTrust’s appliance terminates the session and handles plaintext. Lavawall’s relay carries ciphertext and holds no session key. Everything else on this page follows from that.

BeyondTrust: where the plaintext is

Endpoint
B Series appliance
session terminates: plaintext here
Technician

The appliance decrypts the session to do its work. Anyone who can reach the appliance can reach the plaintext.

Lavawall: where the plaintext is

Endpoint
encrypts here
Relay
ciphertext only, no key
Technician
decrypts here

The endpoints hold the keys. The relay routes ciphertext and cannot open it. Session keys rotate during the session.

Why that matters, in practice

None of the following is a knock on BeyondTrust’s engineering. Each one follows from where the plaintext sits, and it is the same for any product whose session terminates at a vendor-operated box.

A compromised box. If the component that holds plaintext is breached, the intruder is inside the session. An appliance that terminates the session holds plaintext. A relay that holds no session key yields ciphertext it cannot open.

A subpoena to the vendor. A vendor can only produce what it can read. A relay that holds no session key has no session content to hand over.

An insider at the vendor. Someone with access to the plaintext box can watch sessions. Where the relay carries only ciphertext, there is nothing to watch.

CJIS in-scope personnel. Under the CJIS Security Policy, anyone who can reach unencrypted criminal justice information is in scope for fingerprinting and security-awareness training. When the plaintext lives on an appliance, the people who operate that appliance can fall in scope, which is a real and recurring cost for whoever runs it. When the relay carries only ciphertext, that surface is smaller.

Where Lavawall® wins for MSPs

Session content is encrypted between the endpoint and the technician, and the relay routes ciphertext it holds no key for. Screen frames, keystrokes, the clipboard, file transfers, shell output, and script bodies all travel inside that channel.

Every device has its own key, held in the TPM on Windows or the Secure Enclave on Mac, and it cannot be exported. There is no shared account key that unlocks a fleet.

Scripts run from a signed library that ships inside the agent’s Authenticode-signed executable. The server sends a script identifier and typed parameters, never a script body.

No operator agent to install: Lavawall® remote support runs in the technician’s mobile or desktop browser, and sessions start without waiting for a heavy local client.

Intelligent Backstage: where the aging Backstage in ScreenConnect-style tools has grown incompatible with Windows 11, Lavawall extends the real built-in Windows admin apps, a grouped Task Manager with live CPU, memory, disk, network, and thread stats, per-process detail, an enriched file explorer you can run or download from, Services, Startup, and a classified Event Log, all without the user seeing a thing.

Live device health surfaced in the session: patch status, refresh priority, temperature, disk, RAM, CPU, and last reboot reason.

Tickets and timekeeping fill in directly from the remote-support screen.

Country-level access restrictions on by default, and technicians can be required to hold a hardware key, the YubiKey 5 FIPS, before a session will start.

Tenants can be pinned to US-only infrastructure, with no CDN in the session path.

Per-named-agent pricing: US$45/month for unlimited remote sessions, or US$89/month bundled with Help Desk Pro.

Where BeyondTrust (Bomgar) wins

Mature privileged-access workflows for large enterprises with strict change-control, vault, and credential-injection requirements.

Deep integration with the privileged-access-management products in the BeyondTrust portfolio.

Session recording and data-loss inspection at the appliance, which are made possible by terminating the session there.

Granular Jump Client and Jumpoint routing for complex enterprise networks.

Feature comparison

Feature Lavawall® BeyondTrust (Bomgar)
Who can read the session contentThe two endpoints; the relay holds no session keyThe appliance terminates the session and handles plaintext
Operator agent requiredNo, runs in the browserTypically yes
Mobile-friendly technician interfaceYes, phone browserLimited
Multi-tenant designed for MSPsYesEnterprise-first
Live endpoint health inside the sessionYes: patch, refresh, temperature, disk, RAM, CPULimited
Bundled helpdesk and ticketingYes, Help Desk Pro on the same licenceNo
Bundled RMM, patching, GRC, breach detectionYesNo
Session crypto by a validated moduleYes: FIPS 140-3, CMVP #5247Own certificate #3881 is FIPS 140-2, now historical
Enforce FIPS 140-3 validated login keysYes: checked against the CMVP list at every loginNot published
Appliance to buy and runNoYes, the B Series appliance
Pricing modelUS$45/agent/month unlimited; $89 bundled with helpdeskEnterprise, per-seat
Native CAD billingYesLimited

FIPS 140-3, in detail

If FIPS is the reason you are comparing the two, the difference is in the detail an assessor checks. BeyondTrust’s own FIPS 140-3 statement says its compliance is ensured by the use of exclusively FIPS 140-3 compliant, third-party cryptographic algorithms (BeyondTrust FIPS 140-3 compliance statement). That is a statement about algorithms. It names a library, “FIPS compliant-OpenSSL” version 3.1, and cites no CMVP certificate number. Lavawall names a validated module and a certificate for each component.

Lavawall®BeyondTrust Secure Remote Access
Session cryptographic moduleGo Cryptographic Module v1.0.0, certificate #5247, FIPS 140-3, current“FIPS compliant-OpenSSL” 3.1, with no certificate number given
Technician hardware sign-inYubiKey 5 FIPS Series, certificate #5291, FIPS 140-3Not addressed in the FIPS statement
Own CMVP certificateNone; Lavawall is not itself a cryptographic module, so it runs on validated modules rather than claiming to be oneCertificate #3881, FIPS 140-2 Level 1, validated 3 April 2021, now on NIST’s historical list, which NIST says “should not be included by Federal Agencies in new procurements”
What the FIPS statement coversEach component named separately, with its own certificateThe B Series appliance; the client software and the browser are not addressed
Who can read the session contentThe two endpoints; the relay holds no session keyThe appliance terminates the session and handles plaintext
Appliance to buy and runNone; Lavawall runs in the browser and deploys in minutesA B Series appliance, hardware or virtual, to license, host, and keep patched

Sources: NIST CMVP certificate #3881 and BeyondTrust’s FIPS 140-3 compliance statement, as published, accessed September 2026. FIPS 140-2 validations should not be used in new procurements after 21 September 2026. Confirm the current status before you rely on it.

Who should pick which?

Pick Lavawall® if…

The plaintext question matters to you: you would rather the vendor in the middle could not read a session even if it wanted to.

You are an MSP supporting many tenants and want one console where remote support, the ticket, the device health, and the time entry all live together.

You want to avoid buying, hosting, and patching an appliance, and you want a trial that is a login rather than a hardware order.

You have a FIPS 140-3 obligation and want a named module and certificate number for the session, not a statement about approved algorithms.

Pick BeyondTrust (Bomgar) if…

You need formal privileged-access management, with credential vaulting and injection, mapped to BeyondTrust’s architecture.

You require session recording or data-loss inspection at a broker you operate, which is exactly what terminating the session at the appliance enables.

You have regulatory references or an existing standard that call out BeyondTrust by name.

Moving off BeyondTrust

You can run Lavawall alongside your current tool during the evaluation. Nothing about BeyondTrust has to come down first, and because there is no appliance to procure, a proof of concept is a login and an agent install rather than a hardware order.

Your existing session history stays in BeyondTrust for retention. Export and archive it before you retire the platform. Lavawall keeps its own session logs from day one, with full logging of GUI desktop sessions, shell sessions, and shell commands.

Frequently asked

What is the real difference between Lavawall and BeyondTrust?
Where the plaintext lives. BeyondTrust’s Secure Remote Access terminates the session at a B Series appliance, so that appliance handles the session in the clear. Lavawall encrypts the session between the endpoint and the technician, and the relay in the middle routes ciphertext it holds no key for. Both protect the connection with strong cryptography; they differ on who at the vendor can read the session.
Is Lavawall’s FIPS position stronger than BeyondTrust’s?
They are different in a way an assessor can check. Lavawall names a FIPS 140-3 validated module for the session, the Go Cryptographic Module v1.0.0, certificate #5247, and a FIPS 140-3 validated key for technician sign-in, certificate #5291. BeyondTrust’s own CMVP certificate, #3881, is FIPS 140-2 and now on NIST’s historical list, and its FIPS 140-3 statement cites no certificate number. FIPS 140-2 validations should not be used in new procurements after 21 September 2026.
Can users see when a technician is watching their screen?
Yes. The end-user gets a consent prompt and an active-watching notification bar, and consent requirements can be configured per company or per computer.
How do I move off BeyondTrust?
Run Lavawall alongside your current tool during the trial; nothing has to come down first. There is no appliance to procure, so a proof of concept is a login and an agent install. Your existing session history stays in BeyondTrust for retention, and you export and archive it before you retire the platform.