SECURITY ARCHITECTURE

Security by architecture, not by configuration

ThinRemote devices only dial out. No inbound port, no listening service, no route from one device to the next. Access is brokered through the cloud with TLS, short-lived signed tokens and resource-scoped RBAC, so a single outbound connection replaces the VPNs, jump hosts and open ports you would otherwise have to defend.

Security posturesingle-tenant
  • Outbound-only agent, nothing listens
  • TLS transport (OpenSSL 3.5.x)
  • Signed JWTs, scoped & short-lived
  • Deny-before-allow RBAC
  • No device-to-device path
ISO 27001 certified

The outbound-only trust model

Every connection is initiated toward the server. Operators reach the server; devices reach the server; the server brokers each session after authorizing it. Devices never reach each other.

ThinRemote outbound-only connection and trust modelOperators connect to the ThinRemote server over HTTPS. Devices connect outbound to the same server over IOTMP with TLS. The server sits in the middle and brokers every session. There is no direct path between two devices.OPERATORSWeb consolebrowserCLIscripts & CI/CDMCP serverAI agentsHTTPS · TLS 443ThinRemote serversingle-tenant · RBAC brokerIOTMP · TLS · outboundDEVICES · agents dial out, nothing listensdevice Ano inbound portdevice Bno inbound portdevice Cno inbound port

A compromised device has no network neighbours to scan and no route to another device, so its blast radius is itself. There is no ACL policy to get right and keep right.

Five pillars

The controls that make remote access safe, each grounded in how the platform actually works.

Outbound-only

The agent opens one connection out and keeps it alive. No listening socket, no inbound port, no lateral movement between devices.

Encrypted transport

TLS over OpenSSL 3.5.x for device and console traffic, legacy protocols off by default, SNI per-host certs and automatic (ACME) renewal.

Tokens & credentials

Signed JWTs (HS256) with short lifetimes and per-token keys, salted PBKDF2 credential hashes, OIDC federation and MFA (TOTP, WebAuthn, passkeys).

Identity & RBAC

Every action is checked against a resource-scoped, deny-before-allow policy with multi-tenant isolation across users, projects, members, roles and groups.

Observability

Connection state, per-device metrics and security events feed dashboards and threshold alarms, with a first-class access-audit trail on the roadmap.

Single-tenant

Run your own instance in the region you choose, on-premise or in your cloud, from one statically-linked binary. The agent and IOTMP protocol are open source.

Connection model

One outbound connection, many streams

The agent dials the server and holds a single persistent TLS connection open, sending a keep-alive on an interval and reconnecting automatically if the link drops. All remote-access features share that one socket, multiplexed as independent streams tagged with a stream id.

Shell sessions run over a local pseudo-terminal on the device, file transfer is confined to a configured base path (traversal rejected), and TCP tunnels for SSH, VNC, RDP or a local web service are opened outbound by the device to the target you name. The server brokers each session but never reaches into the device's network stack.

device connection1 socket · TLS
#1 shell (PTY)live
#2 file get / putlive
#3 tcp tunnel :22live
#4 monitoringlive
no listening port on the device
Any linkWorks behind NAT, CGNAT, firewalls and cellular. Nothing to open.
Multiplexed streamsShell, files, tunnels and telemetry over one connection.
Brokered accessPer-tunnel IP allow-lists and session timeouts on top of RBAC.
Transport security

Encrypted with a modern crypto stack

Device and console traffic is carried over TLS provided by OpenSSL 3.5.x (an LTS release supported through 2030), wrapped by Boost.Asio. Legacy protocols are disabled by default, certificates are selected per host by SNI (wildcards supported), and issuance and renewal can be automated with ACME. Optional mutual TLS supports certificate-based device identity.

TLS sessionOpenSSL 3.5.x
TransportTLS over TCP
Legacy protocolsdisabled by default
CertificateSNI per-host · ACME
Mutual TLSoptional (device identity)
Console / APIHTTPS · 443
Identity & access

Every action authorized, every token scoped

Access is mediated by signed JWTs. User access tokens are short-lived (two hours), refresh sessions are tracked server-side, and device tokens can be pinned to an explicit list of allowed resources on a specific device. Each token class is signed with its own key.

On every request the server checks the token against a resource-scoped permission model that evaluates deny rules before allow rules, supports wildcards and sub-resource scoping, and isolates tenants across users, projects, members, roles and groups. The web console, the CLI and the MCP server all pass through the same authorization path.

device tokenscoped
devedge-gw-17
exp2h
res$fs/*, monitoring
allow · Device:AccessDeviceResources
deny · Device:DeleteDevice
deny evaluated before allow
Short-lived tokens2-hour access tokens, revocable refresh sessions.
MFA & SSOOIDC federation plus TOTP, WebAuthn and passkeys.
Hashed at restSalted PBKDF2-HMAC-SHA256, never plaintext.

Compliance & trust

Where we are today, stated plainly. We do not claim certifications or tests we have not completed.

ISO 27001 certified Third-party penetration test: planned

Single-tenant by design

Your own dedicated instance in the region you choose, on-premise or in your cloud. Your data and credentials are not shared with other tenants.

Open source agent & protocol

The device agent and the IOTMP protocol are open source, so the connection model is auditable rather than a black box.

Certified ISMS

Build, release and continuity procedures are documented as part of our ISO 27001 certified Information Security Management System.

Whitepaper

Get the Security Architecture whitepaper

A technical deep-dive into the outbound-only connection model, transport security, token and credential management, RBAC, observability, the threat model and hardening guidance.

  • The connection and trust model, at the protocol level
  • Attack surface analysis and threat model
  • Deployment and hardening checklist

Request the PDF

Tell us where to send it. We will email you the whitepaper.

We only use your details to send the whitepaper and follow up. No spam.

Ready to give your fleet a smaller attack surface?

Install the outbound-only agent in seconds and broker every session through RBAC, tokens and TLS.