RemoteGympSecurity

Security

How RemoteGymp protects access, sessions and administrative actions.

Security in practice

Encrypted remote sessions

Screen data is encrypted in transit. Direct cloud video uses an encrypted WebRTC data channel; relay delivery remains encrypted too.

MFA and Microsoft SSO

Account protection includes multi-factor authentication and Microsoft sign-in, with fresh MFA required for sensitive actions.

Server-side permission checks

The relay authorizes sessions, control and input. A browser link or visible screen is never treated as permission by itself.

Auditable actions

Remote sessions and consequential administrative actions create an audit trail so you can see who did what and when.

Scoped customer access

Organizations, companies and sites stay separated throughout the dashboard, services and session paths.

Cloud or self-hosted

Use RemoteGymp Cloud, or run the service on your own infrastructure while keeping the same agent and dashboard.

Stored secrets are protected

TOTP credentials, Microsoft SSO configuration and stored BitLocker recovery keys are protected at rest with ASP.NET Core Data Protection rather than saved as readable values.

Certificate-protected key handling

Cloud Data Protection keys are stored in shared PostgreSQL and encrypted with the cluster certificate. Readiness fails if the shared key ring cannot protect and unprotect data.

Where Cloud data runs

Cloud uses US, EU and AP relay regions. Regional routing is not a promise that data stays in a customer-selected country. Self-Hosted runs its Relay and operational database on infrastructure you control; licensing check-ins still apply.

Breach notification

The Data Processing Agreement commits RemoteGymp to notify affected customers without undue delay after becoming aware of a personal-data breach and to provide the available information they reasonably need.

Written commitments for subprocessors

The current subprocessor list is available from support. Customers receive reasonable advance notice of a new subprocessor that will materially process their personal data and have 14 days to object on reasonable data-protection grounds.

WebRTC

Some cloud sessions send the picture straight to your browser.

With one viewer on a cloud session, the picture can travel straight from the machine to your browser, encrypted. Permissions, control and input still go through the relay, so the session can be ended there. Multi-viewer, Android and self-hosted sessions send the picture through the relay.

Cloud or self-hosted

Cloud

Hosted by us, three regions, nothing to run.

  • Fully managed, multi-region relay
  • Unattended + attended access
  • File transfer, remote command, drive browsing
  • No install for the visitor. No RemoteGymp account. Just a browser link that expires.

Self-Hosted

Run the service on your own infrastructure.

  • Your infrastructure, your data
  • Same agent, same dashboard
  • Same device-count brackets, on your own infrastructure

Stop requesting quotes. Start a session.

We think it's the best remote access tool in the world. We would, obviously. Thirty days, no card, no call — go and prove us wrong.

Start free trial