Legal

Security Policy and Technology Overview

Remotly is a remote access and control solution designed to meet enterprise‑grade security, reliability and confidentiality requirements. This document outlines the security mechanisms, operational standards and compliance principles that govern the platform's architecture and usage. You can contact us by mail at the company address or via the contact form on remotly.com.

  1. 01

    Encryption and connection security

    Remotly employs a comprehensive end‑to‑end encryption model to protect all transmitted data. Session content is encrypted using AES-256, while RSA-4096 is utilized for secure key exchange and handshake procedures. Although communication is already encrypted at the application layer, the platform additionally supports TLS 1.2 and TLS 1.3 to accommodate environments that require standardized transport‑level security. The software also supports TPM 2.0 for secure cryptographic key storage. Remote connection codes are generated as strong, 14-character alphanumeric values.

  2. 02

    Secure communication via IPsec VPN

    Communication between user devices and corporate networks can be secured using an IPsec‑based VPN tunnel. When Remotly operates over IPsec, all screen data, audio, video and input signals are protected within an encrypted tunnel and remain resistant to interception and man‑in‑the‑middle attacks.

  3. 03

    Access control and device authorization

    All new devices must be explicitly authorized by the user. Administrators may disable code‑based authentication, enforce stricter access policies and revoke authorization at any time.

  4. 04

    Servers and infrastructure

    Remotly supports dedicated relay servers for private infrastructure deployments. All platform infrastructure operates on secure, redundant cloud systems and CDNs. Custom relays support private SSL certificates, encapsulating the AES-256 end‑to‑end stream within TLS 1.2 or TLS 1.3 for interoperability with strict firewalls, and can be secured with a strong 32-character access password so that only authorized clients can use the infrastructure.

  5. 05

    Additional security and privacy features

    Blank Remote Display Mode hides the remote screen during active sessions. Remote Audio Muting prevents exposure of sensitive sound information. Integration with MaxMind IP scoring enables early detection of potentially malicious connections.

  6. 06

    Customer responsibilities and best practices

    Customers are responsible for keeping all software updated, protecting login credentials and applying the principle of least privilege when assigning access.

  7. 07

    Data protection and compliance

    Remotly does not conduct keylogging, persistent screen capture or camera monitoring beyond what is required for session operation. User data is processed in compliance with GDPR and protected through legal mechanisms for cross‑border data transfers.

Security controls matrix

Control areaDescription
EncryptionAES-256, TLS 1.2 / 1.3, RSA-4096, IPsec VPN tunneling.
Access controlDevice authorization, administrator revocation, policy enforcement.
Infrastructure securityDedicated relay servers, private cloud options, redundancy.
Session privacyBlank display mode, audio muting.
Threat detectionMaxMind IP scoring and monitoring.

This website uses cookies to improve your experience while you navigate through the website. Out of these, those that are categorized as necessary are stored on your browser and are used to run basic functionalities of the website.

We also use third‑party cookies that help us analyze and understand how you use this website. They will only be stored in your browser with your consent and you have the opportunity to opt out of them. However, opting out may affect your browsing experience.

NecessaryAlways active

Necessary cookies are absolutely necessary for the website to function properly. These cookies ensure basic functionalities and security features of the website on an anonymous basis.

CookieRetention periodDescription
cookie_consent1 yearStores whether or not the user has consented to the use of cookies. It does not store any personal data.
NEXT_LOCALE1 yearStores language setting selected by user.
themeuntil clearedStores the light or dark theme selected by user (browser storage).
hCaptchasessionSet by the hCaptcha service on the contact and order forms to identify bots and protect the website against spam.
device_token6 monthsCookie used for user/device verification.
session_idsession / 1 monthCookie used to keep user session alive.
logged_insession / 1 monthCookie used to keep user session alive.