How VitaRemote is secured
What holds, for every session, whoever is connecting.
At the device
- Every session asks first: "VITABYTE support (name) wants to view this screen." Nothing is seen, typed, read or run before Allow. No answer in time counts as Deny.
- Unattended access needs two things: the technician's permission for that device, and the client's own setting on that device, meant for servers and kiosks.
- The person at the device can block remote access there. A block cannot be lifted from the console.
- While anyone is connected, a banner names them, with End session one tap away.
People and permissions
- One login for the whole VITABYTE platform, always with a second factor: a security key or an authenticator app. VitaRemote keeps no passwords.
- Security settings at three layers: organization, role and person. A lower layer can tighten a setting, never loosen it. Networks, hours, session length and idle time can all be limited.
- Sensitive actions, such as running commands or restarting a device, ask for the second factor again.
- Nobody can grant a permission they do not hold, and a client's own staff only ever see their own company.
- When recording is on, sessions are recorded and sealed with the organization's own key. If the recording fails, the session ends.
Your organization's data
- Each organization is kept apart by the database itself, with row-level security, not only by the application. The service connects with a role that cannot bypass it.
- Every allow of a sensitive action and every refusal is written to an audit that is append-only and chained, so a changed or removed entry shows.
- A refused person sees "Not permitted". The exact reason is in your audit.
- VitaRemote runs on servers of its own, apart from VITABYTE's other systems.
Devices and updates
- Each device makes its own key when it is enrolled. The private key never leaves the device, and every connection signs a fresh challenge.
- Enrolment codes work once, expire within hours and are stored only as a hash.
- Agents install only updates signed by VITABYTE. The downloads are listed with their SHA‑256 in a signed list.
- Uninstalling the agent ends the device's identity: its key never connects again.
- Card readers and other payment terminals are never enrolled, listed, captured or controlled.