security
Every Roomler documentation page tagged “security”.
Enrollment and device identity
How an enrollment token turns a machine into a device row, what machine identity means, and how re-installing or removing a device behaves.
Get startedVerify your install
Confirm the Roomler agent is running, enrolled, reachable and on the mesh — and verify the artifact you installed was really signed by us.
Get startedConsent
Who gets asked before a remote session starts, which surface the prompt appears on, and what happens when nobody is there to answer.
Remote desktopExit nodes
Route all of a device's internet traffic through a machine you trust — with split-default routing designed so it can never lock you out of your own box.
Private networkSSH without sshd
Get a real shell on any enrolled machine by its mesh address — with no sshd installed, no port bound and no firewall rule, on Linux, macOS and Windows.
Private networkFiles
Share files in rooms, browse a per-room library, and search across everything — with content types resolved from the bytes rather than the uploader's claim.
Chat & videoArchitecture
How Roomler is put together — one control plane, three data planes, one agent per machine, and a server that coordinates without ever carrying your traffic.
ArchitectureSystem overview
The pieces of a Roomler deployment — agent, CLI, server and browser — and how a remote session travels through them without the server carrying it.
ArchitectureWhat the server sees
Precisely what the Roomler control plane can and cannot observe — including the one feature that is deliberately an exception to the rule.
ArchitectureSecurity & access control
How Roomler decides who may reach what — end-to-end encryption, roles and permissions, network ACLs, device-held gates, consent and audit.
Security & access controlSecurity model
What is encrypted, what the server can see, where trust sits, and which properties are structural rather than promised.
Security & access controlUsers, roles and permissions
How membership, roles and permissions decide what someone can do in an organization — and which powerful ones are deliberately not granted by default.
Security & access controlNetwork access control
Control which machines may reach which machines on the mesh, on which ports and protocols — default-deny, enforced at both ends, and audited.
Security & access controlDevice policies
The per-machine gates for remote command execution, SSH and relaying — four independent layers, each owned by a different party, all default-deny.
Security & access controlConsent and audit
Who is asked before a session starts, what is recorded afterwards, and why the record of a decision is kept separately from a machine's own account of itself.
Security & access controlSigned releases
Every Roomler artifact is signed — Authenticode on Windows, GPG and notarisation elsewhere — and the auto-updater verifies the publisher, not just the hash.
Security & access controlSelf-host hardening
What to get right when running Roomler yourself — secrets, TLS, the origin setting, storage, backups and the checks worth doing after every upgrade.
Security & access controlConfiguration reference
The agent's config.toml — where it lives per platform, the settings worth knowing, and which ones the server can and cannot change.
ReferenceFrequently asked questions
Short answers about Roomler — what it is, what it costs, whether it can see your screen, how it compares to Tailscale and RustDesk, and how to self-host it.
FAQ