Self-hosted · browser-native · end-to-end encrypted

Your desktops. Anywhere.
Provably private.

An enterprise remote desktop you run on your own relay. Operators work from any modern browser — no client install — over end-to-end encrypted sessions. Who can reach which machine is decided by your admin, not by us.

See how it works
End-to-end encrypted Self-hosted relay No client install Admin-owned access
Features

A full control plane, in a browser tab

Install software once — on the host machines. Everyone else just signs in.

Browser console

Runs in any modern browser. Zero install for operators, admins, and managers — the console is the product.

One-time host wiring

A Device ID and a single-use enrolment token wire each machine once. It auto-registers under its real machine name.

Admin-owned access matrix

Every user sees only the devices your admin granted them — nothing else exists in their console.

Sealed input channel

Mouse and keyboard are sealed with XSalsa20‑Poly1305 under a password-derived key the relay never holds.

Encrypted video

Screen video travels over WebRTC's mandatory DTLS‑SRTP. There is no unencrypted mode to misconfigure.

Live team control

Roles, live presence, team-wide announcements, direct messages, and force sign-out — applied in real time.

Security

Private even from the infrastructure

The design goal is simple: a compromised relay should learn nothing useful.

The relay does signaling only.

It brokers connections and stores state — it holds no decryption keys, for video or for input. Ever.

Device passwords are sealed per-user, in the browser.

When an admin grants a device, its password is encrypted in the admin's browser to that user's key. The relay stores ciphertext only.

Input stays private under relay compromise.

Control input is sealed end-to-end with a key derived from the host password — which the relay never sees.

SSO authenticates. Your admin authorises.

Google sign-in only proves who someone is. An unprovisioned Google account gets nothing — access exists only where your admin granted it.

Cryptography XSalsa20-Poly1305 sealed input· DTLS-SRTP media· Argon2id account passwords· NaCl box per-user escrow
How it works

Three steps to a private fleet

From a fresh machine to a sealed session in minutes.

1

Wire a host

Run the installer on the machine and paste its one-time credentials. No login happens on the machine — it enrols itself and appears under its real name.

2

Grant access

Your admin locks devices to people. Granting a device seals its password to that user — nobody else can even see it.

3

Connect

One click in the browser. The session is sealed end-to-end: encrypted video down, sealed input up, relay blind throughout.

Roles

One portal, four ways in

Everyone signs in at the same door. What they see is decided by their role.

Admin

Owns the access matrix

Systems, people, and device passwords. Wires hosts, invites users, grants devices, runs the team live.

Manager

Grants & revokes access

Handles device access grants — and nothing else. No invites, no role changes, no passwords, no system control.

User

Connects and works

Sees only the devices they were granted, by machine name. One click to a sealed session — nothing to type.

Host

Wires machines

Generates wiring credentials and enrols machines. The machine itself enrols with no sign-in at all.

One sign-in portal serves all four. Internal roles map onto these personas — your console adapts the moment you sign in.

Walkthroughs for every seat

Role-by-role written tutorials — and a video slot for each — live inside the console: Admin, Manager, User, and Host, step by step against the real UI.

Your machines. Your relay. Your keys.

Sign in to your team's console — or create a team on day 0 with your relay's admin token.

Console

Connecting…

Systems

Enrolled remote desktops. Install only the host — everything else is here.

Team

Users, roles, and live messaging.

NameEmailRoleDevicesStatusActions

Access grants

Decide which devices each person can reach. Changes apply live.

As a Manager you handle access grants only. You can grant or revoke device access for people on your team — you can't invite users, change roles, set device passwords, or revoke systems.

NameEmailRoleDevicesActions

My devices

The systems your administrator granted you access to. Pick one and connect.

No active session

Pick an online device above, or enter a device ID — your granted devices unseal automatically.

Wire a host

Generate one-time credentials and enrol a Windows machine as a remote host.

Tutorials

Step-by-step walkthroughs for every seat. Pick your persona.

Video walkthrough — coming soon

The written guide below covers every step.

Quick start

  1. Create your team (day 0) with the relay admin token.
  2. Add a System — you get a Device ID and a one-time enrolment token.
  3. Run neekOS-Host-Setup.exe on the target machine and paste both values.
  4. Set the device password in the console.
  5. Invite your people and pick their roles.
  6. Grant devices — sealing happens automatically.
  7. Connect from Remote control.

1 · Create your team (day 0)

  1. Open the portal and click Sign in, then switch to the Create team tab.
  2. Paste the relay admin token — you'll find it in apps/relay/.env on the relay host.
  3. Enter a team name, your name and email, and a password (≥ 12 chars).
  4. Accept the Terms & Conditions and click Create team & sign in. You are now the owner — the Network Admin.

2 · Add a System

  1. Go to Systems and click + Add a System.
  2. Give the machine a label (you can rename it later).
  3. The console shows a Device ID and a one-time enrolment token. The token is single-use — treat it like a password.

3 · Install the host on the target machine

  1. On the target Windows machine, run neekOS-Host-Setup.exe.
  2. In the first-run wizard, paste the Device ID and the enrolment token.
  3. Set the machine's permanent host password — it stays on the machine and is used to approve sessions.
  4. That's it. The host auto-registers and appears Online in Systems under its real machine name. No account sign-in ever happens on the machine.

4 · Set the device password in the console

  1. In Systems, open the system's Password action and enter the host password you set in the wizard.
  2. The password is sealed in your browser to each granted user's key — the relay only ever stores ciphertext, so granted users connect with one click and nothing to type.

5 · Invite people

  1. Go to Team and click + Invite user.
  2. Password flow: the console gives you an invite code and a temporary password — hand both over out-of-band (in person, phone, your own chat).
  3. Google flow: provision their email address; they just click Continue with Google on the portal. SSO authenticates — your provisioning authorises.
Role guide
  • admin full console — systems, team, grants, passwords.
  • manager access grants only.
  • operator connects to and drives granted devices.
  • viewer watches granted devices — no input.
  • host wires machines only — no remote control.
  • auditor reads the full audit trail — no control.

6 · Grant devices

  1. In Team, open a user's Access action.
  2. Tick the devices they should reach and save. Granting a device auto-seals its password to that user in your browser.

7 · Connect

  1. Open Remote control, pick an online device, and click Connect.
  2. Video arrives over DTLS-SRTP; your input goes up the sealed channel. Fullscreen and end-session controls sit in the stage bar.

8 · Operate day-to-day

  1. 📣 Announce broadcasts to everyone signed in.
  2. Use a user's Message action for a direct message, and Sign out to force-end their session.
  3. Rename or revoke systems from their cards in Systems. Revoking a device force-ends any in-flight session to it.

Troubleshooting

  • Host shows offline. The machine is off, the installer hasn't been run yet, or the enrolment token was already used — tokens are single-use; add a fresh System to re-issue.
  • Google user gets "not provisioned". You must add their email in Team first. Google only proves identity — access exists once you provision it.
  • Relay pill is red. The console can't reach your relay — check the relay service and the relayUrl in the portal config.
Video walkthrough — coming soon

The written guide below covers every step.

Quick start

  1. Sign in at the portal — your console opens on Access grants.
  2. Pick a user from the list.
  3. Check or uncheck the devices they should reach.
  4. Click Save access — changes apply live.

What the Manager role is

A Manager handles access grants only. You decide which people can reach which devices — the admin keeps everything else: people, roles, passwords, and the systems themselves.

Granting and revoking

  1. Open the Access grants tab.
  2. Pick a user — their current device grants are shown as checkboxes.
  3. Check devices to grant, uncheck to revoke, then click Save access.
  4. Changes apply live: if someone is mid-session on a device you just removed, that session is force-ended immediately.

What you can't do

  • Invite or remove users.
  • Change anyone's role.
  • Set or change device passwords.
  • Add, rename, or revoke systems.

If a task needs any of those, hand it to a Network Admin.

Connecting yourself

Managers can also be granted devices, just like users. Anything granted to you appears under My devices — click Connect and work exactly as a user would.

Troubleshooting

  • A person isn't in the list. Only invited team members appear — ask an admin to invite them first.
  • A device is missing. It may have been revoked by an admin or never enrolled — device inventory is admin-owned.
  • Save fails. Check the relay pill in the top bar; if it's red the console can't reach the relay.
Video walkthrough — coming soon

The written guide below covers every step.

Quick start

  1. First sign-in: email + the temporary password from your admin, then the invite code when prompted.
  2. Choose a permanent password (≥ 12 chars) — or use Continue with Google if your admin provisioned your email.
  3. Open My devices — you see only what you've been granted.
  4. Click Connect. Nothing to type — your browser unseals the device password for you.

First sign-in

  1. Password flow: sign in with your email and the temporary password your admin handed you. The portal then asks for your invite code (format 123-456-789).
  2. Choose your permanent password — at least 12 characters.
  3. Google flow: if your admin provisioned your Google email, skip all of the above and just click Continue with Google.

My devices

My devices lists only the machines your admin granted you, by their real machine names. If a machine isn't listed, you don't have access — that's by design.

Connecting

  1. Click Connect on a device card (or pick it from the quick-pick list in Remote control).
  2. Your browser unseals the device password automatically — there is nothing to type.
  3. If you are asked for a host password, your admin hasn't set one in the console yet — type it if you know it, or ask your admin to set it.
  4. Reopened the tab? Unlock device access asks for your account password once — it re-derives your keys locally, and the relay never sees it.

In the session

  1. Hover the stage to reveal the session bar: Fullscreen and End session.
  2. A view-only badge means your role can watch this device but not drive it.

Troubleshooting

  • Device greyed out. The host is offline or still awaiting enrolment — ask whoever wired it to check the machine.
  • "No access yet." Your admin hasn't granted you any devices. Only an admin or manager can change that.
  • Unlock keeps failing. That prompt takes your account password — not a device or host password.
Video walkthrough — coming soon

The written guide below covers every step.

Quick start

  1. Get a Device ID + enrolment token (from an Admin, or generate your own under Wire a host).
  2. Run neekOS-Host-Setup.exe on the machine and paste both values.
  3. Set the permanent host password — done. The machine enrols itself; it never signs in.

Path A · Wire the machine (no sign-in on the machine)

  1. Get a Device ID and enrolment token from an Admin — or generate them yourself if you hold a host-operator account (Path B).
  2. On the target machine, run neekOS-Host-Setup.exe.
  3. Paste both values into the first-run wizard.
  4. Set the permanent host password for the machine.
  5. Done — the host auto-registers at every logon and appears in the console under its machine name. No account ever signs in on the machine.

Path B · Host-operator account

  1. Sign in at the portal with your host-operator account.
  2. Open the Wire a host tab.
  3. Label the machine, then click Generate wiring credentials.
  4. Follow Path A on the machine with the credentials you just generated.
  5. Watch the machine flip to Online under Your hosts (use Refresh if needed).

Good to know

  • The host role wires machines only — it cannot remote-control devices or manage users.
  • The host password never leaves the machine or the browser unsealed; every session is approved by challenge/response.

Troubleshooting

  • Token rejected. Enrolment tokens are single-use — generate fresh credentials and try again.
  • Machine never flips Online. Check the machine's network and that the installer finished; then hit Refresh under Your hosts.
  • "Your account can't enrol hosts." Your account lacks host access — ask a Network Admin to wire the machine or upgrade your account.

Settings

Your account and session.

End-to-end encryption

Control input (mouse / keyboard) is sealed with a key derived from the host password — which the relay never sees — so it stays private even if the relay is compromised. Video is carried over WebRTC's mandatory DTLS-SRTP. Your relay does signaling only; it never holds a decryption key.

Powered & Managed by eVamb Labs - An eVamb Technologies Inc Initiative.