Dimension
ThinRemote
Tosibox
Primary purpose
Remote management & device operations
Secure connectivity (industrial VPN)
What you deploy
A software agent on each Linux host you want to manage
A Lock / Node gateway per site (hardware appliance or software Lock for Container), plus a Key per user
Device targets
Linux hosts directly: 16 architectures, kernel 2.6+, containers, servers, edge and industrial PCs
LAN devices behind a gateway (PLCs, HMIs, IPCs), including equipment that can't run any agent of its own
Minimum footprint
<10 MB static binary, one outbound connection, no open ports, no hardware
A Node/Lock gateway at the edge (also outbound, no open ports); hardware models add 4G / WiFi / Ethernet
Trust & pairing
Cloud RBAC and tokens; onboard a device with an install command, nothing to ship
A Key (physical USB crypto-processor, SoftKey or mobile client) matched to a Lock, physically or via remote matching
Connection model
Outbound-only, TLS 1.3; brokers scoped access to a specific device's services
Outbound-only; end-to-end encrypted Layer-3 VPN that joins you to the site LAN
Remote SSH & terminal
Built-in in-browser terminal and CLI SSH, per device
Reach SSH over the tunnel with your own client
Remote desktop & files
File explorer, and remote desktop when the device has a GUI
Reach RDP/VNC and FTP over the tunnel with your own client
Web / HTTP service access
On-demand HTTP/TCP/TLS proxy to a device's local services
Reach web (WWW) services over the tunnel with a browser
Monitoring & metrics
Per-host CPU, memory, disk, network, temperature and uptime, plus custom metrics you define
Network monitoring and OT analytics via TosiControl / TosiANTA, plus Node hardware stats (CPU, RAM, storage)
Alarms & thresholds
Native, over any metric or event (email / webhook)
Prioritised alerts on network monitoring & analytics
Fleet automation
Playbooks (YAML, check mode, batched rollout, failure kill-switch) and parallel product exec
Not its focus; automate device software with your own tooling over the tunnels
CI/CD & scripting
JSON envelope, exit codes, ad-hoc & stored playbooks
Geared to provisioning connectivity, not per-device operations
AI agents (MCP)
Built-in MCP server to drive the whole fleet in natural language
None built in
Access control & audit
RBAC, tokens, SSO and audit; ISO 27001 certified
Organisations, users and roles in TosiControl; two-factor via the Key
Where it runs
Private single-tenant instance, region of your choice, on-premise option; open-source agent & protocol
MatchMaker relay service; self-hosted aggregation via (Virtual) Central Lock you run yourself