Outbound-only
The agent opens one connection out and keeps it alive. No listening socket, no inbound port, no lateral movement between devices.
ThinRemote devices only dial out. No inbound port, no listening service, no route from one device to the next. Access is brokered through the cloud with TLS, short-lived signed tokens and resource-scoped RBAC, so a single outbound connection replaces the VPNs, jump hosts and open ports you would otherwise have to defend.
Every connection is initiated toward the server. Operators reach the server; devices reach the server; the server brokers each session after authorizing it. Devices never reach each other.
A compromised device has no network neighbours to scan and no route to another device, so its blast radius is itself. There is no ACL policy to get right and keep right.
The controls that make remote access safe, each grounded in how the platform actually works.
The agent opens one connection out and keeps it alive. No listening socket, no inbound port, no lateral movement between devices.
TLS over OpenSSL 3.5.x for device and console traffic, legacy protocols off by default, SNI per-host certs and automatic (ACME) renewal.
Signed JWTs (HS256) with short lifetimes and per-token keys, salted PBKDF2 credential hashes, OIDC federation and MFA (TOTP, WebAuthn, passkeys).
Every action is checked against a resource-scoped, deny-before-allow policy with multi-tenant isolation across users, projects, members, roles and groups.
Connection state, per-device metrics and security events feed dashboards and threshold alarms, with a first-class access-audit trail on the roadmap.
Run your own instance in the region you choose, on-premise or in your cloud, from one statically-linked binary. The agent and IOTMP protocol are open source.
The agent dials the server and holds a single persistent TLS connection open, sending a keep-alive on an interval and reconnecting automatically if the link drops. All remote-access features share that one socket, multiplexed as independent streams tagged with a stream id.
Shell sessions run over a local pseudo-terminal on the device, file transfer is confined to a configured base path (traversal rejected), and TCP tunnels for SSH, VNC, RDP or a local web service are opened outbound by the device to the target you name. The server brokers each session but never reaches into the device's network stack.
Device and console traffic is carried over TLS provided by OpenSSL 3.5.x (an LTS release supported through 2030), wrapped by Boost.Asio. Legacy protocols are disabled by default, certificates are selected per host by SNI (wildcards supported), and issuance and renewal can be automated with ACME. Optional mutual TLS supports certificate-based device identity.
Access is mediated by signed JWTs. User access tokens are short-lived (two hours), refresh sessions are tracked server-side, and device tokens can be pinned to an explicit list of allowed resources on a specific device. Each token class is signed with its own key.
On every request the server checks the token against a resource-scoped permission model that evaluates deny rules before allow rules, supports wildcards and sub-resource scoping, and isolates tenants across users, projects, members, roles and groups. The web console, the CLI and the MCP server all pass through the same authorization path.
Where we are today, stated plainly. We do not claim certifications or tests we have not completed.
Your own dedicated instance in the region you choose, on-premise or in your cloud. Your data and credentials are not shared with other tenants.
The device agent and the IOTMP protocol are open source, so the connection model is auditable rather than a black box.
Build, release and continuity procedures are documented as part of our ISO 27001 certified Information Security Management System.
A technical deep-dive into the outbound-only connection model, transport security, token and credential management, RBAC, observability, the threat model and hardening guidance.
Install the outbound-only agent in seconds and broker every session through RBAC, tokens and TLS.