Private by architecture, not by policy document.
ModibusTech operates the relay and still cannot read a session, because the design gives it nothing to read. This page describes what the control plane sees, what it cannot, and what it enforces.
Keys are negotiated between the two devices and nowhere else.
When a technician connects, both clients perform a public-key handshake and derive a session key. Screen frames, input, clipboard and files are encrypted with that key before they leave the device. The ID server introduces the peers; the relay forwards ciphertext. Neither holds a key.
- Direct peer-to-peer when the network allows, relay as fallback
- Clients verify the service by its public key
- Session content is never written to disk on any server
What the control plane sees. What it cannot.
The console records what an audit needs and is structurally unable to record what it should not.
- Device IDs, names, groups and last-seen IPs
- Each connection attempt: source ID and IP, target ID and IP, user, outcome, duration
- Access rule matches, including refusals
- Admin actions in the audit log, with actor and time
- User accounts, roles, SSO identities and 2FA state
- Screen content
- Keystrokes and mouse input
- Clipboard contents
- Transferred file contents
- Session keys
Enforced before a session exists.
Block rules by device ID, user account or IP range live on the ID server and are evaluated when a connection is requested. The decision does not depend on client settings, and a correct password does not override it. Refusals are written to the connection log with the rule that matched.
- Block or allow by device, user or IP range
- Centrally managed, instantly revocable
- Every refusal logged with source, target and IP
Your identity provider, plus a second factor.
Console and client sign-in use OpenID Connect with Google, Microsoft or Apple, so leavers lose access when their account is disabled. TOTP two-factor authentication can be required for every user in the organization.
- Google, Microsoft and Apple OIDC
- TOTP two-factor authentication, enforceable organization-wide
- Roles and groups control what each user can reach
Metadata lives in the EU. Content lives nowhere.
The managed control plane runs inside the European Union, operated by ModibusTech, an Estonian company. Enterprise customers can request a dedicated instance pinned to a region, or a private deployment in their own jurisdiction. Session content is never stored in any case.
- Managed service
- Inside the European Union, operated by ModibusTech OÜ. Connection metadata only; session content is never written.
- Enterprise options
- A dedicated regional instance, or a private deployment in your own jurisdiction or network, arranged through an enterprise agreement. Contact us.
- Disclosure
- Found a security issue? Report it through the contact form and we will respond directly.
See it in the log.
Install two clients, connect, and read the connection log in the console yourself.