Remote desktop and remote support

Remote access that answers to your rules.

ModiDesk gives IT teams end-to-end encrypted remote control with a control plane they can audit. The ID server, relay and console run as a managed service inside the EU. Every connection is logged with source, target and IP, and checked against your access rules before it is allowed.

Free for personal use Windows and Linux today macOS, Android and iOS in development

Remote support for teams that must account for every connection, across regulated sectors

  1. 01End-to-end encryptedKeys negotiated between the two endpoints. The relay forwards bytes it cannot read.
  2. 02No session content storedThe control plane holds connection metadata only. Screens, input and files are never written anywhere.
  3. 03Server-enforced access controlBlock by device, user or IP. Refused by the server even if a password leaks.
  4. 04Full connection logSource and target device ID and IP, user, outcome and duration, for every attempt.
Platform architecture

Five modules. One managed control plane.

ModiDesk is organized as five capability modules around a central hub: the ID server, relay and admin console, operated by ModibusTech inside the EU. Every session is introduced, policy-checked and logged by that hub before it exists.

  • 01Remote Control
  • 02Unattended Access
  • 03Access Control
  • 04Connection Audit
  • 05Admin Console
Module 01

Remote Control

Full keyboard, mouse and clipboard control with multi-monitor switching and file transfer, direct or through the relay.

  • Adaptive quality, direct peer-to-peer when possible
  • Multi-monitor and clipboard sync
  • Two-way file transfer inside the session
Explore module
Module 02

Unattended Access

Permanent-password access to servers, kiosks and workstations with nobody at the other end, controlled per device and user.

  • Installer option for unattended setup
  • Policy-controlled in Pro
  • Every use written to the connection log
Explore module
Module 03

Access Control

Block or allow by device ID, user or IP range. Evaluated by your ID server before a session is brokered.

  • Refused even when the password is correct
  • Centrally managed, instantly revocable
  • Refusals logged with the matching rule
Explore module
Module 04

Connection Audit

A connection log that names both ends of every attempt, plus an audit log of every admin action.

  • Source and target device ID + IP
  • Established, ended and refused outcomes
  • Actor and timestamp on console changes
Explore module
Module 05

Admin Console

Devices with live status, users and roles, groups and address books, SSO and TOTP 2FA, custom client builder, web client.

  • Device dashboard with live online status
  • Google, Microsoft and Apple sign-in with TOTP
  • Custom client builder and browser client
Explore module
Delivered as a service

One platform. Nothing to host.

Every module runs against the same ID server, relay and console, operated by ModibusTech. No server to install, no second agent, no separate vendor.

Talk to sales
Why ModiDesk

Built for organizations that answer for their remote access.

The properties security and compliance teams ask about first, and how ModiDesk delivers each one without a vendor in the middle.

Data sovereignty by design

Session content is end-to-end encrypted between the two endpoints and never written anywhere. The control plane holds connection metadata only, inside the EU, with dedicated regional or private deployment available to enterprise customers on request.

Enforced at the server

Access rules are decided by your ID server before a session exists. A leaked password gets a refusal and a log entry, not a session.

Evidence for every session

Both endpoints, IPs, user, outcome and duration for every attempt. Admin actions in a separate audit log. What an auditor asks for, already written.

Your identity provider

Google, Microsoft or Apple sign-in with TOTP two-factor authentication, so leavers lose access when their account does.

Your brand on the client

A portable client with your name, logo and organization settings embedded. Users run it; it connects straight to your ModiDesk organization.

Honest platform coverage

Windows and Linux clients and a browser client today. macOS, Android and iOS in development, stated as such.

Data sovereignty

The hub introduces the peers. The relay carries ciphertext. Your content touches no one.

Most remote-access products can read what they relay. ModiDesk negotiates keys between the two endpoints, so the managed relay forwards bytes it cannot decrypt and the control plane holds connection metadata only, inside the EU. Clients verify the service by its public key.

ID server
Registers devices and introduces the two endpoints. Holds policies, never session keys.
Relay
Forwards encrypted bytes when a direct connection is not possible. Blind to content.
Console
Devices, users, groups, address books, access rules, connection log and audit log.
Data residency
Admin console

The control plane your auditors will ask about.

Live device status, a connection log that names both ends of every session, and policies that are enforced where it matters: at the server, before a session exists.

Connection log

Who connected to what, from where, and how it ended. Refusals are recorded with the rule that fired.

TimeSource ID · IPTarget ID · IPUserResultDuration
09:41:07847 219 30510.4.12.31118 554 920192.168.7.21m.kellerestablished14m 22s
09:38:51219 740 18810.8.0.14931 402 11710.8.1.42opsestablished2m 05s
09:36:02773 210 945203.0.113.88660 391 07210.4.90.5unknownrefusedip rule
09:31:44502 118 634172.16.40.9847 219 30510.4.12.31d.raudended41m 10s
09:12:19931 402 11710.8.1.42219 740 18810.8.0.14a.novakended7m 48s

Access rules

Block or allow by device ID, user or IP range. Evaluated by your ID server.

Access rulesevaluated by the ID server
IP203.0.113.0/24Blockall devices
Device118 554 920Allowgroup Retail only
Usercontractor-07Blockuntil reviewed
IP10.4.0.0/16AllowFinance devices

Audit log

Every admin action with actor and timestamp.

SSO and 2FA

Google, Microsoft or Apple sign-in with TOTP.

Groups and address books

Organize devices by team, customer or site. Share with the people who need them.

Server-enforced access control

Refused at the server. Even with the right password.

A password proves someone knows a secret. It does not prove they should be connecting. ModiDesk evaluates your block rules on the ID server before any session is brokered, so a leaked unattended password gets a refusal and a log entry, and nothing else.

  • Block by device ID, by user account or by IP address and range
  • Enforced centrally, independent of client settings
  • Every refusal lands in the connection log with the matching rule
How enforcement works
Remote control

The session itself is what technicians expect.

Full keyboard, mouse and clipboard. Switch monitors, transfer files mid-session, and reach unattended machines without anyone at the other end. Direct peer-to-peer when the network allows, the relay when it does not. No inbound firewall rules on the client side.

Multi-monitorSwitch displays without leaving the session.
File transferTwo-way, inside the encrypted channel.
Unattended accessPermanent password, policy-controlled in Pro.
Web clientConnect from a browser with nothing installed.
Getting started

Up and running, with nothing to host.

The service is already running. Install the client, create your organization in the console, and set the rules your policy demands.

  1. 01
    Install the clientSigned Windows installer or MSI for fleet rollout, native Linux packages. Choose unattended access at install time where needed.
  2. 02
    Create your organizationInvite users, connect Google, Microsoft or Apple sign-in, and require TOTP two-factor authentication.
  3. 03
    Set the rules, read the logBuild groups and address books, add access rules by device, user or IP, and watch the connection log fill in.
Read the documentation
Comparison

ModiDesk versus vendor-cloud remote access.

The same remote-control experience technicians expect, with the broker, the log and the policy decision in a control plane you can audit.

CapabilityModiDeskTypical vendor-cloud tool
Where sessions are brokered and relayedEU control plane operated by ModibusTech; dedicated regional or private options for enterpriseVendor infrastructure, vendor region, no alternative
Session contentEnd-to-end encrypted, never storedDepends on vendor policy
Connection logSource and target ID + IP, user, outcome, durationVaries by tier
Access controlBlock by device, user or IP, enforced by the control planeClient-side settings or paid add-on
IdentityGoogle, Microsoft, Apple OIDC with TOTP 2FAVendor account, SSO on upper tiers
Client brandingCustom client builder in ProPaid add-on
Device limitsUnlimited on ProPer-device caps
PricingFree for personal use, Pro at €3 per user per monthStacked tiers, annual increases
Service options

Managed by ModibusTech, with enterprise options on request.

The standard service runs in the EU. Organizations with residency or isolation requirements can arrange a dedicated regional instance or a private deployment. In every option, session content is never stored.

OptionOperated byWhere metadata livesBest forAvailability
Managed serviceThe standard ModiDesk serviceModibusTechEuropean UnionTeams that want remote access running today, with nothing to hostAll plans
Dedicated regional instanceA control plane reserved for your organization, pinned to a regionModibusTechRegion of your choiceData residency and isolation requirementsEnterprise, on request
Private deploymentIn your own jurisdiction or network, set up with our teamModibusTech with your teamYour jurisdictionRegulated and isolated environmentsEnterprise, on request

Private and regional options are arranged through an enterprise agreement. Contact us to discuss requirements.

Clients

Every endpoint you support.

Native clients for the platforms available today, and an honest status for the ones in development. Any supported platform connects to any other.

Pricing

Free for one person. €3 per user for the team.

Personal use is free. Pro adds the console, logging, access control and identity features. Enterprise covers residency, topology and formal support.

Free

Personal

For personal use, home labs and trying ModiDesk with your own devices.

€0forever
Download
  • Remote control with keyboard, mouse and clipboard
  • End-to-end encrypted sessions
  • File transfer
  • Unattended access
  • Runs on the ModiDesk managed service (EU)
  • Up to 3 managed devices
  • Community support
Enterprise

Organizations

For data residency, multi-relay topologies and formal support requirements.

Customannual agreement
Talk to sales

Everything in Pro, plus

  • Dedicated regional instance, or private deployment on request
  • In-country data residency
  • Multiple relay servers with regional routing
  • Operator panel for multi-organization fleets
  • Support agreement, onboarding and a named contact
  • Volume licensing

Prices exclude VAT. Full plan comparison

Questions

Straight answers.

More in the full FAQ, or ask us directly.

Is ModiDesk free?

Yes, for personal use. The Free plan includes end-to-end encrypted remote control, file transfer and unattended access on the managed service. Pro adds the admin console and team features for €3 per user per month.

Where does my data live?

Session content never leaves the two endpoints: it is end-to-end encrypted and never written anywhere. Connection metadata, users and policies are held by the ModiDesk control plane, operated by ModibusTech inside the European Union. Enterprise customers can request a dedicated regional instance or a private deployment.

What does the connection log record?

Every attempt, successful or refused, with the source device ID and IP, the target device ID and IP, the authenticated user where known, the outcome and the duration. It is available in the Pro console.

What happens if an unattended password leaks?

Access rules are evaluated by your ID server before any session is brokered. If the source device, user or IP is blocked, the connection is refused and logged even when the password is correct.

Which platforms are supported?

Windows (signed installer, MSI, 64-bit and 32-bit, portable) and Linux (.deb, .rpm, AppImage) are available today. macOS, Android and iOS clients are in development. Any supported platform can connect to any other.

Remote access you can account for.

Download the client, create your organization, and add Pro when the team needs the console.

Download for Windows Talk to sales

Free for personal use. No account required to start.