Skip to Content

SV_REMOTE / SERVICE IT

sv_remote: consent-first remote support for managed devices

An independent Service IT remote-support product for Windows and Android. Pair authorized devices, organize them as a tree, see online state and request an end-to-end encrypted screen session. Optional remote input is available only for a Windows target and requires a second local approval.

WORKING VERTICAL SLICE

What the controlled pilot already does

IDENTITY

Signed device identity

A device creates its key locally in Windows DPAPI or Android Keystore-backed storage. Its public ID routes requests but never authorizes them.

PAIRING

One-time pairing

The target shows an eight-digit code valid for five minutes. A controller uses it once to create the managed relationship.

TREE

Device tree and presence

Paired devices can be grouped into nested folders, given local aliases and shown as online or offline with last heartbeat.

SESSION

Two explicit target decisions

The target first chooses Continue or Reject for screen viewing. If a controller requested input on a Windows target, a separate prompt asks whether to enable it; refusal keeps the session screen-only.

CONTENT

Separated encrypted channels

The target encrypts screen frames and, only when granted, input events with independent ephemeral per-session keys before direct or relay transport. The server receives neither content key.

PLATFORMS

Windows and Android

The pilot includes Windows agent/controller builds and an Android app as controller. Android targets remain visible screen-view targets and never grant remote input in this stage.

HOW A SESSION STARTS

A device ID is an address, not permission

01

Register

The client signs registration with the device key and accepts the current B2B legal version.

02

Pair

The target shows a one-time code to the intended controller.

03

Request

The controller requests one paired target. Screen viewing is required; Windows input is an optional switch that is off by default.

04

Approve and stop

The target approves screen viewing and, if requested, Windows input separately. The permanent indicator can stop both immediately.

DELIBERATE PILOT LIMITS

No hidden access and no overclaiming

  • No unattended access or hidden start-up
  • Remote input is Windows-target only, off by default and separately approved; no remote shell
  • No clipboard or file transfer
  • No server-side screen or input recording
  • Verified pilot downloads are public; the Google Play listing and trusted Windows signing are still pending
  • No SLA, CRA conformity declaration or CE claim in the pilot

The control plane coordinates; endpoints hold separate screen and input keys

PostgreSQL stores necessary device, relationship, requested/granted permission, session and audit metadata. Redis holds short-lived presence, rate-limit and signalling state. STUN discovers network paths and TURN relays encrypted packets when direct connectivity fails. The endpoints, not the control plane or relay, encrypt and decrypt screen frames and approved input events with separate keys.

sv_remote is not an AI system and makes no automated employment or access decision.

LEGAL · 2026-08-25-input-pilot

Legal documents for the current pilot

The B2B terms, product privacy notice and security/retention page are versioned together. Continue authorizes only screen viewing for that session; Windows input needs a second prompt and refusal leaves screen-only access. Neither action is blanket GDPR consent.