01 - Isolate
Tenant boundaries
Every endpoint, session, and technician action is scoped to a customer tenant. Cross-tenant access is not part of the operational model.
Security & governance
Remvx LLC is built for MSP remote operations - tenant isolation, technician attribution, encrypted sessions, and exportable audit trails. Documentation is shared during evaluation and certificate authority review, not buried in marketing copy.
Published security, signing, and transparency documentation for certificate authority review, MSP security questionnaires, and IT administrators.
TLS, encryption, RBAC, and session governance.
DocumentationPublisher verification and Authenticode integrity.
DocumentationReport vulnerabilities to our security team.
PolicyDeployment traceability and licensing context.
DocumentationValidate Remvx packages before deployment.
DocumentationAuthorized Windows agent removal.
Documentation01 - Isolate
Every endpoint, session, and technician action is scoped to a customer tenant. Cross-tenant access is not part of the operational model.
02 - Attribute
Remote sessions record who connected, when, and under which policy - so MSPs can answer client audits without reconstructing events from logs.
03 - Export
Audit trails and security documentation are available on request during guided evaluation - structured for questionnaires, not slide decks.
Control plane
Six operational controls that form the Remvx security posture. Scope and rollout timing are confirmed during onboarding.
All control-plane traffic uses TLS 1.3. Remote session payloads are encrypted with AES-256. Certificate pinning and rotation procedures are documented in the security pack for DigiCert and enterprise reviews.
Role-based access scoped per tenant and technician. MFA for console access. SAML/OIDC federation is in controlled rollout for enterprise MSPs - confirmed during onboarding, not assumed GA.
Session start/end, technician, tenant, endpoint, and permitted tool usage are logged. Export formats support client security questionnaires and internal MSP reviews.
Every enrolled Windows endpoint maps to a tenant, agent build, and last-seen signal. Inventory reflects what is installed - unified under Remvx governance for MSP fleet reviews.
Structured pack covering data flows, subprocessors, retention, and operational controls - provided on request to partners, auditors, and certificate authorities.
Good-faith vulnerability reports welcome at [email protected]. Include reproduction steps. We aim to acknowledge within five business days.
Session governance
The flow government and regulated clients review during evaluation - from scoped request through policy enforcement to exportable audit records.
Request
A technician initiates a session against an endpoint already scoped to their tenant and role.
Policy
Tenant RBAC and any configured approval workflow are evaluated before the session can proceed.
Session
An encrypted channel opens - AES-256-GCM session payload over TLS 1.3 transport.
Audit
Session events are tied to the technician identity and available for export when your policy requires it.
Published documentation for auditors, IT administrators, and software validation reviewers - focused on authenticity, licensing, and authorized deployment.
Deployment traceability for authenticity and licensing - not surveillance.
DocumentationVerify Remvx LLC publisher and Authenticode signatures before install.
DocumentationAuthorized Windows removal for endpoints no longer requiring the agent.
DocumentationAvailable during guided evaluation - scoped to your tenant rollout, FedRAMP-adjacent requirements, and CA review timelines.