Authenticated browser
Branded HTTPS access, application sign-in, opaque HttpOnly session, and only the user’s granted IBM i profiles.

IBM i terminal, tools, and AI agent
Public entry, private host boundary
PristineScreen400 authenticates each person at the application boundary, resolves only their approved IBM i grants, and keeps host credentials and connection controls on the server.
Plan a security reviewPublic HTTPS entry
Managed application identity
Private IBM i connectivity
Typed, audited operations
The connection boundary
A browser sends a selected grant identifier. It cannot submit an IBM i profile, password, host, port, TLS option, command string, SQL string, or connector object.
Branded HTTPS access, application sign-in, opaque HttpOnly session, and only the user’s granted IBM i profiles.
Grant resolution, credential decryption, workspace ownership, redaction, typed capabilities, approvals, and activity.
One server-configured, explicitly allow-listed target reached only over certificate-validated TLS services.
Defense in depth
Users sign in to PristineScreen400 rather than sharing or repeatedly entering IBM i credentials. Application passwords use salted, versioned PBKDF2-HMAC-SHA256 records.
IBM i passwords use AES-256-GCM with per-record nonces and an external encryption key. Stored values are never redisplayed or returned by browser APIs.
An administrator grants an IBM i identity to an application user. Disabling the user or identity, or revoking the grant, closes affected workspaces.
The IBM i target is configured and allow-listed by the operator. Certificate and endpoint identity validation remains mandatory for terminal and management connections.
Non-display terminal values are removed before the connector boundary returns a browser-safe screen projection. Password fields never become accessible terminal text.
Agent chat starts paused and uses only the terminal and tools assigned to the current workspace. The owner can watch, stop, take control, reject an approval, revoke access, or disconnect.
Supported public ingress
Supported public deployments expose the reviewed PristineScreen400 HTTPS entry while IBM i remains on private networking. Each customer deployment is isolated with its own brand, user store, grants, presentation assignments, credential material, and active IBM i target.Review the current deployment facts.
Beyond the terminal
People, built-in Agent chat, and approved local MCP clients use the same assigned IBM i actions. Agent work does not create a wider route around the current grant, resource limits, approvals, or Activity.
The operator decides which compiled capabilities and maximum risk can exist in a deployment.
Each exact user and IBM i grant receives visible capabilities, approvals, and resource allow-lists.
Every invocation rechecks ownership, grant, capability, resource, revision, screen sequence, and approval.
Activity records safe actor, operation state, and outcome without logging credentials or sensitive payloads.
Security facts
Review it with your team