Remote support · remote desktop

Self-hosted remote support so your team can fix Windows PCs without a vendor cloud

Secure Desk is remote support and remote desktop for Windows endpoints, with the console in a browser. You run the portal and relay on infrastructure you control — not a TeamViewer-style vendor cloud, and not a hosted multi-tenant Desk cloud.

Free Starter: self-hosted remote support on a relay you run — 1 operator, 1 concurrent session, 3 enrolled Windows devices. Same end-to-end encryption as paid tiers.

Secure self-hosted remote desktop software

Searching for secure remote desktop software that is self-hosted? Secure Desk keeps the portal and Linux relay on infrastructure you control. Secure Desk runs on an open-source stack on a Linux relay you host (you bring the OS and services). Built with open-source components on infrastructure you control. Shipping Access endpoints are Windows only; the operator console is browser-only.

Compare soft, factual alternatives: vs RustDesk · vs Apache Guacamole · vs MeshCentral · vs TeamViewer · vs AnyDesk.

Windows endpoints, browser console

Shipping endpoints are Windows only. The operator console opens in a browser — there is no macOS or Linux Access client as a shipping product, and we do not claim remote desktop that “works on any OS.” Sign-in and lock-screen capture yes; UAC and Ctrl-Alt-Del (CAD) no. File transfer either direction — not a remote Explorer.

Endpoints dial out; relay still needs 80/443

The user runs the portable client; the console opens in a browser. Each side connects outbound over WSS to the relay you run and presents the session id plus its token. Neither endpoint needs a public IP or an inbound firewall rule on the machines you reach. The relay you host still needs ports 80/443 (TLS and WSS). Unqualified “zero inbound ports” is wrong — that claim applies to endpoints, not to the relay host.

E2E required, 6-digit SAS, ciphertext only

End-to-end encryption is required (requireE2e). Both ends derive the same 6-digit short authentication string from the agreed key material. Read it aloud. The endpoints then run ECDH through the relay and derive AES-256-GCM keys. The relay never gets a key — it only forwards ciphertext. Quality presets top out at 15 / 12 / 8 fps, not 60.

Access is not RDP; Control is gated

Access is Secure Desk's own session pipe — not Windows RDP or RDS. Control (attended input) defaults off until you gate it on. Attended remote support is the Starter default path; unattended enrollment is a separate, deliberate choice.

Web VDI on your relay — not AVD, Citrix, or Omnissa

The console opens in a browser on a persistent Windows desktop you already operate. That is web VDI through the same pipe on a relay you run. Azure Virtual Desktop, Citrix and Omnissa still sit in a vendor control plane. Desk does not publish app stacks or GPU pools. There is no hosted multi-tenant Desk cloud — you host the portal and the relay. You run a self-hosted relay on infrastructure you control.

Free Starter caps

Free Starter: self-hosted remote support on a relay you run — 1 operator, 1 concurrent session, 3 enrolled Windows devices. Same end-to-end encryption as paid tiers. Hub prices: Starter $0 · Team $249/yr · Business $499/yr. Unlicensed installs run as Starter.

AI only as agent-desktop access

Secure Desk does not run AI agents. The named use case is reaching many agent Windows desktops on one relay you run: enrol once, isolated sessions, backstage SYSTEM, no inbound RDP to the agent subnet. That page is AI-agent desktops.

FAQ — self-hosted remote desktop

Is Secure Desk open-source software like RustDesk?

No. RustDesk is open-source software; Secure Desk is a commercial self-hosted product that runs on an open-source stack you operate. Secure Desk runs on an open-source stack on a Linux relay you host (you bring the OS and services).

What does Free Starter include?

Free Starter: self-hosted remote support on a relay you run — 1 operator, 1 concurrent session, 3 enrolled Windows devices. Same end-to-end encryption as paid tiers.

Do endpoints need inbound ports?

No. Endpoints dial out. The relay you host still needs 80/443. “Zero inbound including the relay” is not accurate.

Is Access the same as RDP or Guacamole?

No. Access is Desk's console session pipe — not RDP/RDS and not a Guacamole-style gateway into existing RDP/VNC/SSH. See vs Apache Guacamole and vs MeshCentral.

Walk through a session on how it works. Get started · Download · Get a free license · Security model.