AI-agent desktops

Many AI agents. Each with its own desktop. One relay you run.

Put a fleet of agent runtimes on Windows machines you already operate. Each agent gets an isolated desktop session. The relay you host pairs them and forwards ciphertext it cannot read.

Parallel desktops, not a shared console

An AI agent that drives a Windows desktop is an unattended machine with nobody at the keyboard. The usual answer — RDP through a jump host — opens inbound access to the exact machines you least want exposed. Desk keeps each agent on its own enrolled desktop. Sessions do not share a screen, a keyboard, or a session key.

Any agent runtime that can sit on Windows fits. Desk does not name, host, or orchestrate the runtime. You bring the agents. You run the relay.

The same pipe as web VDI

The browser console, the enrolled Windows service, and the relay you operate are the same path used for web VDI. Persistent desktops in the browser. Support is one use case on that path, not a requirement. Nothing is streamed from a vendor desktop farm.

Enrol each desktop once

The installed service runs as LocalSystem from boot with its own enrolled device token. An agent VM is reachable across logon and lock — whether or not a human has ever signed into it. Windows endpoints only.

Backstage: a SYSTEM shell, no desktop

Backstage opens cmd or PowerShell as SYSTEM with no desktop attached. Read logs, restart a stuck service, or fix a dependency while the agent keeps running on screen, undisturbed. You do not take the agent's keyboard to repair the box.

No inbound RDP to the agent subnet

Both ends dial out over WSS to the relay you run. An agent fleet can sit in a locked-down subnet with no public IP and no inbound exception. The relay pairs them and nothing else.

The relay cannot watch

After pairing, each session runs its own ECDH P-256 exchange and derives AES-256-GCM keys. Both ends show the same 6-digit SAS. The relay forwards ciphertext it holds no key for. Desk does not watch sessions with AI.

Reach, inspect, repair

Attach to the live desktop and see what the agent is actually doing. Multi-monitor machines let you pick the screen. Pull traces, screenshots and output files back over the same encrypted channel, verified by SHA-256 on arrival. Roles decide who may connect. The portal records who opened which session and when. A technician can save a local WebM from the console; there is no server-side recording.

What this is not

Secure Desk does not run or orchestrate your agents. It is how you reach, watch and repair the desktops they run on. Device caps by plan are 3, 100 and 1,000. Tell us about your fleet if you need more than that. This is not Citrix, Omnissa or Azure Virtual Desktop — no published app stacks, no GPU pools.

Read web VDI, how a session works, the security model, or Get a free license.