Signed device identity
A device creates its key locally in Windows DPAPI or Android Keystore-backed storage. Its public ID routes requests but never authorizes them.
SV_REMOTE / SERVICE IT
An independent Service IT remote-support product for Windows and Android. Pair authorized devices, organize them as a tree, see online state and request an end-to-end encrypted screen session. Optional remote input is available only for a Windows target and requires a second local approval.
WORKING VERTICAL SLICE
A device creates its key locally in Windows DPAPI or Android Keystore-backed storage. Its public ID routes requests but never authorizes them.
The target shows an eight-digit code valid for five minutes. A controller uses it once to create the managed relationship.
Paired devices can be grouped into nested folders, given local aliases and shown as online or offline with last heartbeat.
The target first chooses Continue or Reject for screen viewing. If a controller requested input on a Windows target, a separate prompt asks whether to enable it; refusal keeps the session screen-only.
The target encrypts screen frames and, only when granted, input events with independent ephemeral per-session keys before direct or relay transport. The server receives neither content key.
The pilot includes Windows agent/controller builds and an Android app as controller. Android targets remain visible screen-view targets and never grant remote input in this stage.
HOW A SESSION STARTS
The client signs registration with the device key and accepts the current B2B legal version.
The target shows a one-time code to the intended controller.
The controller requests one paired target. Screen viewing is required; Windows input is an optional switch that is off by default.
The target approves screen viewing and, if requested, Windows input separately. The permanent indicator can stop both immediately.
DELIBERATE PILOT LIMITS
PostgreSQL stores necessary device, relationship, requested/granted permission, session and audit metadata. Redis holds short-lived presence, rate-limit and signalling state. STUN discovers network paths and TURN relays encrypted packets when direct connectivity fails. The endpoints, not the control plane or relay, encrypt and decrypt screen frames and approved input events with separate keys.
LEGAL · 2026-08-25-input-pilot
The B2B terms, product privacy notice and security/retention page are versioned together. Continue authorizes only screen viewing for that session; Windows input needs a second prompt and refusal leaves screen-only access. Neither action is blanket GDPR consent.