Security
How we keep your computers safe
Remote access is powerful, so security is built in on every plan, including Free.
Architecture
End-to-end encryption
Sessions use WebRTC with DTLS and SRTP between your browser and the device. Keys are negotiated per session; our servers never see them.
Relays carry ciphertext only
When a direct connection is not possible, traffic goes through TURN relays on Cloudflare's network. Relays forward encrypted packets and cannot read them.
Device identity
Each agent creates an Ed25519 key pair at install. The private key never leaves the device, and the agent proves its identity with it on every connection.
Single-use session tokens
Each connection gets a short-lived, single-use token issued only after an authorised user with two-factor sign-in clicks Connect.
Accounts
Required two-factor sign-in
Remote access is locked until an authenticator app is set up, and codes cannot be reused.
Strong password storage
Passwords are stored with PBKDF2-SHA256 and a unique salt; many users sign in with a one-time email code or Google instead.
Bot protection
Sign-up and sign-in are protected with Cloudflare Turnstile and rate limiting.
Alerts and audit log
New-device emails and an audit log of every sign-in, device change and session.
Data
- We store account, device and session metadata. We do not record or store your screen unless your plan's session recording is switched on by your admin.
- Data is stored on Cloudflare's platform. See our subprocessors.
- You can export or delete your account and workspace data at any time by contacting support@remotehub.app.
Abuse prevention
Remote access tools are misused by scammers. Free accounts can only add their own computers, quick support shows the technician's verified company, the person being helped can end a session at any time, and every consent screen links to our abuse report form. We can suspend an account and disconnect all of its sessions immediately.
Responsible disclosure
Found a vulnerability? Email security@remotehub.app. We acknowledge reports within two business days and will not take legal action against good-faith research. Our security.txt has the details. An independent penetration test is planned before general availability, and a summary will be published here.
Start free. Upgrade when you need to.
Free for personal use with no card. Paid plans start with a 14-day trial.