Skip to content

Security

Remote access, under your control

Remote support means trusted access to other people’s computers. VeyraDesk is designed so that every connection is authorised, limited in time, tied to a person and recorded.

Authorised remote sessions

  • No remote session proceeds without a prior VeyraDesk authorisation for that specific device.
  • An authorisation must be taken up within 5 minutes and an active session is limited to 60 minutes.
  • Sessions can be cancelled or revoked, and the device re-checks the authorisation before connecting.

Attended and unattended access

  • Attended mode (the default for new devices): the person at the computer approves each request on screen.
  • Unattended mode: a fresh one-time password is generated for each session — there is no standing, shared password.
  • Only owners and admins can change a device’s access mode.

Role-based access

  • Owner, Admin, Technician and Staff roles control what each person can see and do.
  • Administrative and destructive actions are limited to the appropriate roles.
  • Role checks are enforced by the VeyraDesk service, not only in the user interface.

Workspace and customer separation

  • Each organisation’s data is kept in its own workspace.
  • Workspace separation is enforced where data is accessed, and is covered by automated tests.
  • Customers, sites and devices are organised so technicians work on the right records.

Secure sign-in

  • Passwords are stored using Argon2, a modern one-way hashing algorithm — never in readable form.
  • A minimum password length of 12 characters is required.
  • Sign-in endpoints are rate-limited to slow down password-guessing attempts.

Device enrolment and revocation

  • Devices enrol with time-limited, limited-use enrolment tokens tied to a specific site.
  • Each device agent uses its own credential, separate from user accounts.
  • A revoked device is immediately blocked from new remote sessions.

Audit logging

  • Sign-ins (successful and failed), remote sessions, ticket activity and administrative changes are recorded.
  • Session authorisation, confirmation, revocation, cancellation and end are each logged.
  • Audit records help with internal reviews and incident investigation.

Signed integrations

  • Webhooks are signed with HMAC-SHA256 so receivers can verify they came from VeyraDesk.
  • Incoming webhook requests are checked for freshness and duplicates to resist replay.
  • Integration secrets are encrypted at rest and not shown again after creation.

Operational safeguards

  • Sensitive values such as session passwords and integration secrets are encrypted at rest (AES-256-GCM) and excluded from API responses.
  • All API input is validated, and standard HTTP security headers are applied.
  • Third-party dependencies are checked for known vulnerabilities.

Shared responsibility

Security is a partnership

VeyraDesk provides the controls; how they are used matters too. We recommend that every customer:

  • Uses strong, unique passwords and keeps them private.
  • Gives each person the least-privileged role they need, and removes access promptly when people leave.
  • Only connects to devices it is authorised to support, and uses attended mode where appropriate.
  • Reviews audit activity regularly and revokes devices that are no longer supported.
  • Keeps the computers it supports updated and protected.

Transparency

What we do not claim

No online service can be guaranteed to be completely secure, and we do not claim that VeyraDesk is. We describe the controls that exist today and improve them over time.

VeyraDesk does not currently hold third-party security certifications such as ISO/IEC 27001 or SOC 2. Multi-factor authentication and single sign-on are on our roadmap and are not yet available.

Found a security issue? Please contact us at sales@erazemsdnbhd.com with “Security report” in the subject. See also our Privacy Policy and Acceptable Use Policy.

Help your clients better

Deliver faster support with VeyraDesk

Start on the Free plan — no credit card required — and bring your customers, sites, devices and tickets into one workspace.

  • Fewer on-site visits
  • Authorised, time-limited sessions
  • Every customer and site in one place
  • Built for support teams