Remote Security

Public active gate

Screen viewing is live. Native input is owner-gated.

One-time trusted-device enrollment, rotating viewer credentials, renewable host rooms, visible desktop consent, TURN-backed WebRTC, owner-approved native input, allowlisted commands, audit events, device revoke, and emergency stop are implemented. Passkey enrollment and signed notarized packaging remain future hardening.

Gate

Pairing code expiration

required

Gate

Visible desktop consent banner

required

Gate

Phone and desktop emergency stop

required

Gate

MFA or passkey before active control

required

Gate

Device registry with revoke

required

Gate

Session audit trail

required

Gate

Allowlisted CLI commands only

required

Gate

No public owner credentials

required

Gate

No unattended control by default

required

Gate

Security review before screen input ships

required