RoomlerDocs

security

Every Roomler documentation page tagged “security”.

Enrollment and device identity

How an enrollment token turns a machine into a device row, what machine identity means, and how re-installing or removing a device behaves.

Get started

Verify your install

Confirm the Roomler agent is running, enrolled, reachable and on the mesh — and verify the artifact you installed was really signed by us.

Get started

Consent

Who gets asked before a remote session starts, which surface the prompt appears on, and what happens when nobody is there to answer.

Remote desktop

Exit nodes

Route all of a device's internet traffic through a machine you trust — with split-default routing designed so it can never lock you out of your own box.

Private network

SSH without sshd

Get a real shell on any enrolled machine by its mesh address — with no sshd installed, no port bound and no firewall rule, on Linux, macOS and Windows.

Private network

Files

Share files in rooms, browse a per-room library, and search across everything — with content types resolved from the bytes rather than the uploader's claim.

Chat & video

Architecture

How Roomler is put together — one control plane, three data planes, one agent per machine, and a server that coordinates without ever carrying your traffic.

Architecture

System overview

The pieces of a Roomler deployment — agent, CLI, server and browser — and how a remote session travels through them without the server carrying it.

Architecture

What the server sees

Precisely what the Roomler control plane can and cannot observe — including the one feature that is deliberately an exception to the rule.

Architecture

Security & access control

How Roomler decides who may reach what — end-to-end encryption, roles and permissions, network ACLs, device-held gates, consent and audit.

Security & access control

Security model

What is encrypted, what the server can see, where trust sits, and which properties are structural rather than promised.

Security & access control

Users, roles and permissions

How membership, roles and permissions decide what someone can do in an organization — and which powerful ones are deliberately not granted by default.

Security & access control

Network access control

Control which machines may reach which machines on the mesh, on which ports and protocols — default-deny, enforced at both ends, and audited.

Security & access control

Device policies

The per-machine gates for remote command execution, SSH and relaying — four independent layers, each owned by a different party, all default-deny.

Security & access control

Consent and audit

Who is asked before a session starts, what is recorded afterwards, and why the record of a decision is kept separately from a machine's own account of itself.

Security & access control

Signed releases

Every Roomler artifact is signed — Authenticode on Windows, GPG and notarisation elsewhere — and the auto-updater verifies the publisher, not just the hash.

Security & access control

Self-host hardening

What to get right when running Roomler yourself — secrets, TLS, the origin setting, storage, backups and the checks worth doing after every upgrade.

Security & access control

Configuration reference

The agent's config.toml — where it lives per platform, the settings worth knowing, and which ones the server can and cannot change.

Reference

Frequently asked questions

Short answers about Roomler — what it is, what it costs, whether it can see your screen, how it compares to Tailscale and RustDesk, and how to self-host it.

FAQ

Last updated

to navigate · Enter to open · Esc to close