Legal
Security Policy and Technology Overview
Remotly is a remote access and control solution designed to meet enterprise‑grade security, reliability and confidentiality requirements. This document outlines the security mechanisms, operational standards and compliance principles that govern the platform's architecture and usage. You can contact us by mail at the company address or via the contact form on remotly.com.
- 01
Encryption and connection security
Remotly employs a comprehensive end‑to‑end encryption model to protect all transmitted data. Session content is encrypted using AES-256, while RSA-4096 is utilized for secure key exchange and handshake procedures. Although communication is already encrypted at the application layer, the platform additionally supports TLS 1.2 and TLS 1.3 to accommodate environments that require standardized transport‑level security. The software also supports TPM 2.0 for secure cryptographic key storage. Remote connection codes are generated as strong, 14-character alphanumeric values.
- 02
Secure communication via IPsec VPN
Communication between user devices and corporate networks can be secured using an IPsec‑based VPN tunnel. When Remotly operates over IPsec, all screen data, audio, video and input signals are protected within an encrypted tunnel and remain resistant to interception and man‑in‑the‑middle attacks.
- 03
Access control and device authorization
All new devices must be explicitly authorized by the user. Administrators may disable code‑based authentication, enforce stricter access policies and revoke authorization at any time.
- 04
Servers and infrastructure
Remotly supports dedicated relay servers for private infrastructure deployments. All platform infrastructure operates on secure, redundant cloud systems and CDNs. Custom relays support private SSL certificates, encapsulating the AES-256 end‑to‑end stream within TLS 1.2 or TLS 1.3 for interoperability with strict firewalls, and can be secured with a strong 32-character access password so that only authorized clients can use the infrastructure.
- 05
Additional security and privacy features
Blank Remote Display Mode hides the remote screen during active sessions. Remote Audio Muting prevents exposure of sensitive sound information. Integration with MaxMind IP scoring enables early detection of potentially malicious connections.
- 06
Customer responsibilities and best practices
Customers are responsible for keeping all software updated, protecting login credentials and applying the principle of least privilege when assigning access.
- 07
Data protection and compliance
Remotly does not conduct keylogging, persistent screen capture or camera monitoring beyond what is required for session operation. User data is processed in compliance with GDPR and protected through legal mechanisms for cross‑border data transfers.
Security controls matrix
| Control area | Description |
|---|---|
| Encryption | AES-256, TLS 1.2 / 1.3, RSA-4096, IPsec VPN tunneling. |
| Access control | Device authorization, administrator revocation, policy enforcement. |
| Infrastructure security | Dedicated relay servers, private cloud options, redundancy. |
| Session privacy | Blank display mode, audio muting. |
| Threat detection | MaxMind IP scoring and monitoring. |