Skip to content

Built in, not a paid add-on

Ready for the security review

Access is a permission check all the way down, sessions can be pulled the moment someone leaves, sensitive actions ask again before they run, and consequential changes are written to a log you can export.

The flow
  1. Meet
  2. Capture
  3. Act

Sign-in

Two-factor that a company can actually mandate

A member can switch on email two-factor for themselves, and an organisation can require it for everyone, a floor no individual can lower. A browser that has already passed can be trusted for thirty days, and that trust is dropped the moment a password changes or is reset.

  • Organisation-wide requirement, not just a personal preference
  • Trusted devices for thirty days, cleared on password change or reset
  • Codes stored only as hashes, with a ten-minute life and a hard attempt cap

Sessions and boundaries

Access you can take back, from anywhere you choose

Sessions are tracked rather than implied by a token, so disabling an account or forcing a logout takes effect on the next request. Every login attempt is recorded with its source, and IP allow and deny lists put a hard boundary in front of the whole platform.

  • Revoke one session or every session for an account
  • Step-up reauthentication before sensitive changes
  • Login attempts recorded; IP allow and deny lists enforced

Evidence

An audit trail, exportable

Consequential actions are written with their actor, target and time, queryable per organisation. When someone asks who changed a permission six weeks ago, the answer is an export rather than a fortnight of log searching.

  • Per-organisation activity, filterable by actor and action
  • Export for whoever is asking
  • Written by the same service the product uses
See how self-hosting fits in

FAQ

Questions about security

Something else on your mind? Write to hello@remotedesk.space.

Can we require two-factor for everyone in our organisation?

Yes. An organisation can mandate email two-factor, and members cannot switch it off for themselves while that setting is on. Individuals can also opt in on their own.

What happens to an account when someone leaves?

Disable the account and its sessions stop working on the next request, rather than lingering until a token expires. You can also revoke a single session if someone has lost a device but is staying.

Is access controlled below the level of the whole app?

Yes. Permissions are checked per capability, and room access is enforced on the server for every seat someone takes, so a modified client still cannot sit in a room it is not allowed in.

Do you keep our data if we self-host?

No. In a self-hosted deployment the database, the uploads and the media server all run on your infrastructure.

Ask us the hard questions

Send the security questionnaire. We would rather answer it now than halfway through a rollout.