THINREMOTE vs TOSIBOX

Reach the site, or operate every device

Tosibox matches a key to a lock and gives you a plug-and-go encrypted tunnel to a site's network. ThinRemote installs a software agent on each Linux device and gives you SSH, monitoring, remote desktop, filesystem and fleet automation on top. One connects you to a location; the other operates the machines on it.

VS
A key-and-lock VPN reaches
Node · Plant Amatched · gateway
PLC 192.168.1.10on the site LAN
HMI 192.168.1.24on the site LAN
IPC 192.168.1.31on the site LAN
a secure tunnel to the site's network
ThinRemote operates
Plant A · gatewayonline · CPU 12% Disk 91%
Line 3 · controlleronline · SSH ready
Kiosk 07 · lobbyoffline · 40m ago
Charger 12 · bayonline · 7.2 kWh
each device, observable and operable

Two different jobs

This isn't a feature war. Tosibox and ThinRemote solve different problems, and the real question is whether you need to reach a site or operate the devices once you're there.

Tosibox: secure connectivity

A plug-and-go industrial VPN. You match a Key (a physical USB crypto-processor, a SoftKey or the mobile client) to a Lock / Node gateway, and the whole LAN behind that gateway (PLCs, HMIs, IPCs) becomes reachable over an encrypted tunnel, brokered by the Tosibox MatchMaker relay. Excellent, no-IT-skills connectivity to a location, but what you do once the tunnel is up is up to your own client tools.

ThinRemote: device operations

A remote management platform. One outbound software agent on each Linux host gives you live telemetry, alarms, shell, file transfer, remote desktop, web-service proxy, device APIs, fleet automation and an MCP server for AI agents, all out of the box. No gateway to install in front of the device and no key to match: you manage what the machine is doing, not just whether you can reach its network.

Where it installs

On the device, not a box in front of it

Tosibox anchors on a gateway. A hardware Node (with 4G, WiFi and Ethernet) or the software Lock for Container sits at the edge of a site and bridges the LAN behind it into the VPN. That's the right shape for industrial equipment that can't run software of its own, but it means the thing you deploy and match is the gateway, not each machine.

ThinRemote is a tiny agent, a single static binary under 10 MB, that you install on the Linux host itself. It runs on almost anything, from a modern server to a years-old industrial box (kernel 2.6 and up, 16 architectures), inside containers, and makes one outbound connection that changes nothing about the device's own networking. Every device is a managed asset with a stable identity, not just an IP behind a gateway.

thinr-agent< 10 MB
1 static binarykernel 2.6+16 architecturesno gateway neededno open ports
Installs directly on
Pi / SBC Industrial PC Edge gateway Docker / container Cloud VM
Tiny footprintOne static binary under 10 MB, kernel 2.6+, 16 architectures.
Every device is an assetStable identity, human name, site and serial, not an IP behind a gateway.
No network surgeryNo appliance to rack, no TUN device, no changes to routes or DNS.
Built-in operations

Not just a tunnel: the tools come with it

Tosibox gives you the encrypted path. Once the Key is matched to the Lock, any service on the site LAN, Remote Desktop (RDP), web (WWW), FTP or SSH, is reachable over the tunnel using your own client software. Powerful and protocol-agnostic, but the terminal, the file browser and the desktop client are all bring-your-own.

ThinRemote ships the operating surfaces over the same agent. A web console with an in-browser terminal, file explorer, remote desktop and live dashboards; a scriptable CLI with JSON output; and a built-in MCP server so AI agents drive the fleet in natural language. Same authentication, roles and audit across all three, nothing for an operator to install locally.

Web console
Dashboards Terminal Files Remote desktop Alarms RBAC
CLI
SSH Tunnels Exec Logs Playbooks JSON
MCP server
AI agents Natural language Same RBAC
One agent, three surfacesClick it in the browser, script it in CI, or let an AI agent do it.
Nothing to install locallyTerminal, files and desktop run in the browser, no per-operator client.
Service proxy includedHTTP, TCP and TLS tunnels to a device's local services on demand.
Observability & alarms

See what each device is doing, not just the network

Tosibox has grown a strong monitoring story: TosiControl gives a topological view of the network and its gateways, and TosiANTA adds OT traffic analytics, asset inventory and prioritised alerts. That view is centred on the network and the Tosibox devices themselves, CPU, RAM and storage of each Node, plus what's moving across the wire.

Every ThinRemote agent reports a structured monitoring resource per host: CPU and load, memory and swap, per-filesystem usage, network throughput, temperature and uptime, wired straight into threshold alarms over email or webhook. And you define the criteria: expose any value from a small script on the device, a fault code from a PLC, the kWh a charger delivered, units left in a machine, and it becomes a first-class metric you can chart, roll up across the fleet and alarm on like any built-in one.

Monitorplant-a-gw Online
12%
CPU
38%
Memory
91%
Disk
Network 210 B/s 188 B/s
Disk almost fulldisk.usage 91.4
PLC fault codeplc.fault 0x21
Define your own metricsTurn any value your device or PLC reports into a tracked metric.
Roll up the fleetAggregate across a product or group with sum, average or distribution.
Alarm on anythingBuilt-in or custom metric, with severity and email or webhook notifications.
Automation & scale

Fix it once, roll it out to the whole fleet

Tosibox scales by sites and matched keys: add a Node, match the keys that should reach it, and the site is on the network. That model is a great fit for connecting many locations, but applying a change to the software on hundreds of devices is a separate problem you solve with your own tooling over the tunnels.

ThinRemote makes the whole fleet programmable. Playbooks describe a change once, try it on a single device first, then roll it out across the product in controlled batches that stop on their own if too many devices fail. The same flow runs from your terminal, your CI/CD pipeline or an AI agent over the built-in MCP server, so operating ten thousand endpoints looks the same as operating ten.

Rollout · agent-config400 devices
Batch 1100 ✓
Batch 2100 ✓
Batch 358 / 100
Batch 4queued
Failure rate 1.2% kill-switch at 25%
Fleet playbooksDescribe a change once and run it across the whole product.
Safe by defaultDry-run on one device, then batch the rollout with a kill-switch if too many fail.
Pipeline-nativeDriven from CI/CD, cron or an AI agent over the built-in MCP server.
Security & connection model

Two outbound models, two units of trust

Both products are firewall-friendly: a Tosibox Lock dials out to the MatchMaker relay, and a ThinRemote agent dials out to its cloud, so neither needs an inbound port opened on the device side. The difference is what a connection grants. Tosibox matches a Key to a Lock and joins the operator to the site's LAN over a Layer-3 VPN, exactly what OT teams want when they need to reach the equipment behind a gateway.

ThinRemote brokers scoped access to a specific device through the cloud, authenticated with tokens and governed by RBAC and audit logging, over TLS 1.3, without placing the operator on a network. There are no physical keys to distribute or match, roles and tokens are managed centrally, and ThinRemote is ISO 27001 certified.

Tosiboxkey → lock → site LAN
relayKeyNodesite LAN
reaches the whole network behind the gateway
ThinRemoteagent → cloud → scoped access
agentscloudops / CI / AI
scoped, brokered access per device with RBAC
Outbound-only agentDials out over TLS 1.3: no inbound port, no listening service to attack.
RBAC, tokens & auditScoped roles and tokens, with an audit trail, instead of keys to hand out.
ISO 27001 certifiedISO 27001 certified, with single-tenant and on-premise options.
Device APIs

Every device becomes an API you can call

Over a Tosibox tunnel you reach a device's existing services and drive them with the tools those services already speak. There's no notion of a portable, named operation you can invoke the same way on every device in a fleet without knowing its address.

With ThinRemote each agent exposes resources, named operations you call by name that return JSON. Run diagnostics, read a meter, push new firmware, restart a service, with no interactive session and no bespoke glue. Turn any script into a resource and it's instantly callable across the fleet, from a CI/CD step, a cron job, a webhook, an incident runbook, or an AI agent over the built-in MCP server.

plant-a-gwAPI
CALLdiagnostics→ json
CALLrestart-service
CALLpush-firmware→ json
READplc.fault
CI/CD cron webhook AI agent
Callable by nameNamed operations with typed inputs and outputs that return JSON.
Plugs into your stackInvoke from the CLI, webhooks, CI/CD or the MCP server.
Defined once, fleet-wideStored in the cloud and callable on any device in the product.

The full breakdown

How the two approaches line up, side by side, once you're operating more than a handful of machines.

Dimension
ThinRemote
Tosibox
Primary purpose
Remote management & device operations
Secure connectivity (industrial VPN)
What you deploy
A software agent on each Linux host you want to manage
A Lock / Node gateway per site (hardware appliance or software Lock for Container), plus a Key per user
Device targets
Linux hosts directly: 16 architectures, kernel 2.6+, containers, servers, edge and industrial PCs
LAN devices behind a gateway (PLCs, HMIs, IPCs), including equipment that can't run any agent of its own
Minimum footprint
<10 MB static binary, one outbound connection, no open ports, no hardware
A Node/Lock gateway at the edge (also outbound, no open ports); hardware models add 4G / WiFi / Ethernet
Trust & pairing
Cloud RBAC and tokens; onboard a device with an install command, nothing to ship
A Key (physical USB crypto-processor, SoftKey or mobile client) matched to a Lock, physically or via remote matching
Connection model
Outbound-only, TLS 1.3; brokers scoped access to a specific device's services
Outbound-only; end-to-end encrypted Layer-3 VPN that joins you to the site LAN
Remote SSH & terminal
Built-in in-browser terminal and CLI SSH, per device
Reach SSH over the tunnel with your own client
Remote desktop & files
File explorer, and remote desktop when the device has a GUI
Reach RDP/VNC and FTP over the tunnel with your own client
Web / HTTP service access
On-demand HTTP/TCP/TLS proxy to a device's local services
Reach web (WWW) services over the tunnel with a browser
Monitoring & metrics
Per-host CPU, memory, disk, network, temperature and uptime, plus custom metrics you define
Network monitoring and OT analytics via TosiControl / TosiANTA, plus Node hardware stats (CPU, RAM, storage)
Alarms & thresholds
Native, over any metric or event (email / webhook)
Prioritised alerts on network monitoring & analytics
Fleet automation
Playbooks (YAML, check mode, batched rollout, failure kill-switch) and parallel product exec
Not its focus; automate device software with your own tooling over the tunnels
CI/CD & scripting
JSON envelope, exit codes, ad-hoc & stored playbooks
Geared to provisioning connectivity, not per-device operations
AI agents (MCP)
Built-in MCP server to drive the whole fleet in natural language
None built in
Access control & audit
RBAC, tokens, SSO and audit; ISO 27001 certified
Organisations, users and roles in TosiControl; two-factor via the Key
Where it runs
Private single-tenant instance, region of your choice, on-premise option; open-source agent & protocol
MatchMaker relay service; self-hosted aggregation via (Virtual) Central Lock you run yourself

A fair reading: Tosibox is deliberately a connectivity layer, so most "partial" cells reflect that you bring your own tools over an excellent tunnel. ThinRemote's value is that the operations ship as one product, installed on the device itself.

Where Tosibox is the better fit

Different jobs, remember. If your problem is secure connectivity to a site, reach for Tosibox.

Plug-and-go OT connectivity

You want secure remote access to a site in minutes, with no IT skills, no network config and a matched-key trust model with a strong OT and critical-infrastructure pedigree.

Whole-LAN reach behind a gateway

Your PLCs, HMIs and controllers can't run software of their own. A Node bridges the entire LAN into the VPN, so you reach equipment that could never host an agent.

Appliance with cellular failover

You need a rugged edge box with 4G, WiFi and Ethernet and Layer-3 site-to-site networking, rather than software running on the hosts themselves.

Plenty of teams run both: Tosibox for the secure path to the site, ThinRemote agents on the Linux hosts to operate what's on it.

So, which one?

Pick by the question you're actually trying to answer.

DEVICE OPS

Choose ThinRemote

"I need to operate, observe and fix a fleet of Linux devices."

  • Operations built inSSH, terminal, remote desktop, files and web proxy over one agent, no client to install.
  • Telemetry & automationMetrics, custom values, alarms, playbooks, device APIs and a built-in MCP server.
  • No hardware, no keysTiny outbound agent per device, RBAC and tokens, scales programmatically.
Get Started
CONNECTIVITY

Choose Tosibox

"I need a dead-simple, secure tunnel to a site's network."

  • Plug-and-go setupMatch a key to a lock and reach the site in minutes, no IT skills required.
  • Whole-LAN reachBridge PLCs, HMIs and controllers behind one gateway, agent or not.
  • Rugged edge applianceHardware Nodes with 4G, WiFi and Ethernet and Layer-3 site networking.
See how ThinRemote pairs

Frequently asked questions

The questions OT and IoT teams ask when they compare the two.

Is Tosibox better than ThinRemote for OT and critical infrastructure?

For plug-and-go secure connectivity to a plant or substation, Tosibox is an excellent, purpose-built fit, especially when you need to reach equipment behind a gateway and want a matched-key trust model with no IT skills. ThinRemote fits the other half of the problem: operating the Linux devices themselves, with SSH, monitoring, remote desktop and fleet automation at scale. Many teams run both.

Do I need special hardware or a physical key to use ThinRemote?

No. ThinRemote is a software agent you install on the device with a single command, and access is controlled with cloud RBAC and tokens. There is no gateway appliance to rack and no physical key to match or ship. Tosibox, by design, anchors trust in a Key (a physical USB crypto-processor, a SoftKey or the mobile client) matched to a Lock or Node.

Can Tosibox do remote SSH, monitoring and remote desktop?

Tosibox provides the encrypted VPN tunnel, and once it's up you can reach SSH, RDP/VNC, web and FTP services on the site LAN using your own client software; TosiControl and TosiANTA add network monitoring and OT analytics. ThinRemote ships those surfaces built in, per device: an in-browser terminal, remote desktop, file explorer, per-host metrics with custom values, and threshold alarms, with nothing for an operator to install locally.

Which scales better across thousands of individual devices?

They scale along different axes. Tosibox scales by sites and matched keys, ideal when you're connecting many locations. ThinRemote installs a per-host agent and manages fleets programmatically, with playbooks, batched rollouts, a JSON CLI for CI/CD and an MCP server, so operating ten thousand individual endpoints looks the same as operating ten.

Does ThinRemote open inbound ports or put me on the device's network?

No. Like Tosibox, the ThinRemote agent only dials out, over TLS 1.3, so no inbound port is needed. Unlike a Layer-3 VPN, it doesn't join you to the device's LAN: it brokers scoped access to a specific device's services through the cloud, governed by RBAC, tokens and audit logging. ThinRemote is ISO 27001 certified.

Can I use ThinRemote and Tosibox together?

Yes. A common pattern is to keep Tosibox for the secure network path to a site and run ThinRemote agents on the Linux hosts at that site to observe, operate and automate them. The two layers complement each other rather than compete.

Operate every device, not just reach the site

Install the agent in seconds and get SSH, telemetry, alarms, device APIs and automation from one outbound connection, with no hardware or keys to provision.