Security

A system that controls hundreds of computers has to be the best-guarded thing on the network.

This is the page a security officer, a privacy officer or a tender consultant looks for before approving an RMM. No marketing words: how the system is built, who can reach what, what is encrypted, what is logged, what is backed up, and what happens when something goes wrong.

Architecture

Three parts, one direction of traffic

An agent is installed on every endpoint. The agent opens an encrypted outbound connection to the management system and keeps it open. No port is opened on the endpoint, no endpoint address is exposed to the internet, and nothing connects to the endpoint directly - including us. Remote control also runs through the system, never from the internet to the computer.

The management system is installed in an Israeli cloud or on a server at the customer's site. It exposes a single port (HTTPS) behind a firewall and brute-force protection. The database and the internal services are not reachable from the network at all.

The team works with the system through the browser, on a personal account, with two-factor authentication. There are no shared accounts and no "system password" that passes between people.

Controls

What protects the system, one item per control

Encryption in transit

All traffic - agent, browser, remote control, API - over TLS with valid certificates. There is no unencrypted channel.

Two-factor login for everyone

Mandatory for every user, our own team included. Login can be connected to your organisation's identity system.

Role-based permissions

Who can view, who can run a script, who can connect to a screen, who can change settings - each gets only what they need, and a user can be limited to one site or one client.

A complete action log

Every login, every screen connection, every script, every command: who, when, on which endpoint, and what came back. Exportable and handed over on request.

Separation between clients

Each client is a separate entity in the system with its own permissions. Anyone who requires full separation gets a dedicated instance, or an installation on their own server.

Backup and restore

A daily encrypted backup of the management system, kept apart from the server. The restore is tested in practice, not only documented.

System and agent updates

Security updates for the system are applied in a fixed window. The agent update goes out from the system itself to the endpoints, in groups, never as a free download from the internet.

The agent does not peek

It does not log keystrokes, does not read files, and does not show the screen without a deliberate support session that is displayed to the employee and recorded.

Transparency towards the employee

A connection to an employee's screen is shown on that screen. We recommend keeping it that way even where the system allows otherwise.

Our access

What SrvIT staff may do, and what is recorded

  • AccountsPersonal only. Every technician on their own account with two-factor login. A person who leaves has the account closed the same day.
  • PermissionsLeast privilege. A support technician does not change system settings; a system administrator does not need access to an employee's screen.
  • RecordsEvery action. There is no way to do something on an endpoint without a record of who and when. A customer can receive their log at any time.
  • AccountabilityA named security officer and a named privacy officer at the company, with a phone number, also on the privacy page.
  • MethodWritten procedures based on the principles of ISO 27001 and the Israeli data security regulations. Not a certificate - procedures that are followed.
When something goes wrong

Vulnerabilities, incidents and retention

A vulnerability published in a component of the system is handled within a fixed window by severity, and the customers it affects are notified. A report of a weakness is received at [email protected] and answered within one business day.

A security incident is handled under a written procedure: containment, investigation, notice to the affected customers and a report to the Privacy Protection Authority where the law requires it.

Monitoring data is kept for the duration of the service and up to 90 days after it ends; system and security logs up to 12 months. The full detail, including exactly what is collected from each endpoint, is in the privacy policy.

Documents

What we provide for procurement or a vendor review

  • A technical description of the architecture with a traffic diagram
  • A data processing agreement (DPA) under the Protection of Privacy Law and Amendment 13
  • A security statement, and your organisation's questionnaire, completed
  • The list of controls on this page as a signed document
  • The security and privacy officers' details for direct contact
And if you need more
  • A dedicated instance, or an installation on a server at your site
  • Login connected to your organisation's identity system
  • A periodic export of the action log to your own logging system
Questions from security officers

What is asked before approval

Does the agent open a port on the computer?
No. The agent creates an outbound connection to the system and keeps it. Your firewall needs to allow HTTPS out to the system's address, nothing else. Nothing comes in.
Who can connect to an employee's screen?
Only a user who explicitly holds that permission, after two-factor login, and the connection is shown to the employee and logged with the name and the time. The permission can be limited to your own team.
What happens if the system goes down?
The endpoints keep working as usual - the agent is not needed for the computer to run. When the system returns, the agents reconnect on their own. The daily backup allows the system to be rebuilt on another server.
Can login be connected to our identity system?
Yes. The system supports single sign-on (OIDC), so your users sign in with the corporate account, and blocking a person who left is done in one place.
Does the data leave Israel?
The management system, the database and the logs sit on a server in an Israeli cloud or at your site. If a service component sits outside Israel (e-mail services, for example), it is listed in the agreement and in the privacy policy, and no monitoring data passes through it.
Do you hold an ISO 27001 certificate?
Not at present. We work under written procedures based on the principles of the standard and the data security regulations, with a named security officer and privacy officer. We say this plainly because you should hear it from us.

Need this as a document for a procurement committee or a vendor review?

We send a technical description, a data processing agreement and a signed list of controls within one business day. Or a call with our security officer.