Security & governance

Operations you can review and prove

Remvx LLC is built for MSP remote operations - tenant isolation, technician attribution, encrypted sessions, and exportable audit trails. Documentation is shared during evaluation and certificate authority review, not buried in marketing copy.

Control plane online TLS 1.3 AES-256 sessions Per-tenant RBAC Audit export Session attribution

01 - Isolate

Tenant boundaries

Every endpoint, session, and technician action is scoped to a customer tenant. Cross-tenant access is not part of the operational model.

02 - Attribute

Named technicians

Remote sessions record who connected, when, and under which policy - so MSPs can answer client audits without reconstructing events from logs.

03 - Export

Reviewable evidence

Audit trails and security documentation are available on request during guided evaluation - structured for questionnaires, not slide decks.

Control plane

Security capabilities

Six operational controls that form the Remvx security posture. Scope and rollout timing are confirmed during onboarding.

Transport

TLS encryption

All control-plane traffic uses TLS 1.3. Remote session payloads are encrypted with AES-256. Certificate pinning and rotation procedures are documented in the security pack for DigiCert and enterprise reviews.

TLS 1.3 AES-256 Agent ? console ? technician
Identity

Secure authentication

Role-based access scoped per tenant and technician. MFA for console access. SAML/OIDC federation is in controlled rollout for enterprise MSPs - confirmed during onboarding, not assumed GA.

RBAC MFA Per-session identity
Compliance

Audit logging

Session start/end, technician, tenant, endpoint, and permitted tool usage are logged. Export formats support client security questionnaires and internal MSP reviews.

Exportable Pilot retention scoped
Fleet

Device tracking

Every enrolled Windows endpoint maps to a tenant, agent build, and last-seen signal. Inventory reflects what is installed - unified under Remvx governance for MSP fleet reviews.

Tenant mapped Health + version drift
Documentation

Security reporting

Structured pack covering data flows, subprocessors, retention, and operational controls - provided on request to partners, auditors, and certificate authorities.

Security pack On request
Disclosure

Responsible disclosure

Good-faith vulnerability reports welcome at [email protected]. Include reproduction steps. We aim to acknowledge within five business days.

Session governance

How sessions are approved, attributed, and logged

The flow government and regulated clients review during evaluation - from scoped request through policy enforcement to exportable audit records.

Request

A technician initiates a session against an endpoint already scoped to their tenant and role.

Policy

Tenant RBAC and any configured approval workflow are evaluated before the session can proceed.

Session

An encrypted channel opens - AES-256-GCM session payload over TLS 1.3 transport.

Audit

Session events are tied to the technician identity and available for export when your policy requires it.

Request the security pack

Available during guided evaluation - scoped to your tenant rollout, FedRAMP-adjacent requirements, and CA review timelines.