A system that controls hundreds of computers has to be the best-guarded thing on the network.
This is the page a security officer, a privacy officer or a tender consultant looks for before approving an RMM. No marketing words: how the system is built, who can reach what, what is encrypted, what is logged, what is backed up, and what happens when something goes wrong.
| 09:14 | o.meiri | remote screen | CITYHALL-014 |
| 09:31 | system | backup verified | SRV-FILES-01 |
| 10:02 | m.weisman | script: clear temp | CC-SEAT-37 |
| 10:05 | unknown | blocked, 2FA failed | login |
| 11:40 | o.meiri | patch approved | SCHOOL-B-08 |
Three parts, one direction of traffic
An agent is installed on every endpoint. The agent opens an encrypted outbound connection to the management system and keeps it open. No port is opened on the endpoint, no endpoint address is exposed to the internet, and nothing connects to the endpoint directly - including us. Remote control also runs through the system, never from the internet to the computer.
The management system is installed in an Israeli cloud or on a server at the customer's site. It exposes a single port (HTTPS) behind a firewall and brute-force protection. The database and the internal services are not reachable from the network at all.
The team works with the system through the browser, on a personal account, with two-factor authentication. There are no shared accounts and no "system password" that passes between people.
What protects the system, one item per control
All traffic - agent, browser, remote control, API - over TLS with valid certificates. There is no unencrypted channel.
Mandatory for every user, our own team included. Login can be connected to your organisation's identity system.
Who can view, who can run a script, who can connect to a screen, who can change settings - each gets only what they need, and a user can be limited to one site or one client.
Every login, every screen connection, every script, every command: who, when, on which endpoint, and what came back. Exportable and handed over on request.
Each client is a separate entity in the system with its own permissions. Anyone who requires full separation gets a dedicated instance, or an installation on their own server.
A daily encrypted backup of the management system, kept apart from the server. The restore is tested in practice, not only documented.
Security updates for the system are applied in a fixed window. The agent update goes out from the system itself to the endpoints, in groups, never as a free download from the internet.
It does not log keystrokes, does not read files, and does not show the screen without a deliberate support session that is displayed to the employee and recorded.
A connection to an employee's screen is shown on that screen. We recommend keeping it that way even where the system allows otherwise.
What SrvIT staff may do, and what is recorded
- AccountsPersonal only. Every technician on their own account with two-factor login. A person who leaves has the account closed the same day.
- PermissionsLeast privilege. A support technician does not change system settings; a system administrator does not need access to an employee's screen.
- RecordsEvery action. There is no way to do something on an endpoint without a record of who and when. A customer can receive their log at any time.
- AccountabilityA named security officer and a named privacy officer at the company, with a phone number, also on the privacy page.
- MethodWritten procedures based on the principles of ISO 27001 and the Israeli data security regulations. Not a certificate - procedures that are followed.
Vulnerabilities, incidents and retention
A vulnerability published in a component of the system is handled within a fixed window by severity, and the customers it affects are notified. A report of a weakness is received at [email protected] and answered within one business day.
A security incident is handled under a written procedure: containment, investigation, notice to the affected customers and a report to the Privacy Protection Authority where the law requires it.
Monitoring data is kept for the duration of the service and up to 90 days after it ends; system and security logs up to 12 months. The full detail, including exactly what is collected from each endpoint, is in the privacy policy.
What we provide for procurement or a vendor review
- A technical description of the architecture with a traffic diagram
- A data processing agreement (DPA) under the Protection of Privacy Law and Amendment 13
- A security statement, and your organisation's questionnaire, completed
- The list of controls on this page as a signed document
- The security and privacy officers' details for direct contact
- A dedicated instance, or an installation on a server at your site
- Login connected to your organisation's identity system
- A periodic export of the action log to your own logging system
What is asked before approval
Does the agent open a port on the computer?
Who can connect to an employee's screen?
What happens if the system goes down?
Can login be connected to our identity system?
Does the data leave Israel?
Do you hold an ISO 27001 certificate?
Need this as a document for a procurement committee or a vendor review?
We send a technical description, a data processing agreement and a signed list of controls within one business day. Or a call with our security officer.
