Security and trust at Vexaro Desk
A plain-language overview of how we protect remote-desktop sessions and the data behind them: the architecture, the providers we rely on, how we handle your data and what to expect from availability.
Vexaro Desk is in early access. This page is a summary of how the product works today, not a contract. Formal legal documents (DPA, terms) are published separately and take precedence where they apply.
01Security architecture
Every connection is encrypted in transit. Where the network allows, a session runs directly between the two computers; where it does not, it falls back to an encrypted relay. Sensitive account fields are encrypted before they are stored. The essentials, without the jargon:
Encrypted in transit
Console, API and session traffic is encrypted in transit. Traffic to our websites, console, API and browser viewer passes through our edge provider (Cloudflare, below), which decrypts it at its edge. The browser viewer reaches a session through a Vexaro server that bridges it for the browser: every leg is encrypted, but that server decrypts the stream, so browser sessions are not end-to-end encrypted.
Verified session identity
A direct session checks the other computer's cryptographic identity before any session data flows. If the check fails, the connection is refused. It is never silently downgraded to an unverified path.
Direct peer-to-peer
Where the network allows, your screen data travels directly between the two computers, end-to-end encrypted. When a network forces a relayed connection, traffic stays encrypted in transit through Vexaro-operated relays.
Read the Encryption OverviewEncrypted at rest
Sensitive fields are encrypted at rest: multi-factor secrets, webhook, directory and single sign-on secrets, and the email address on each account.
Controlled access
Console access is governed by roles and per-organisation scoping. Each device decides who may connect: consent for attended sessions, and an access password for unattended ones, optionally limited to named Vexaro IDs. Multi-factor authentication is available on every account.
Auditable by design
Session and administrative events are recorded to the audit trail, which you can export or forward to a SIEM. Each session's evidence pack brings together consent, the event timeline, the recording details and file transfers.
02Subprocessors
The third-party providers that process personal data for us: what each one does, the data it receives and the safeguard we rely on when it processes data outside the European Economic Area (EEA). Account, device and connection data and the details of recordings are held in one location, on Vexaro-operated servers. Recording files stay on your own computers.
| Provider | Purpose | Data it receives | Safeguard outside the EEA |
|---|---|---|---|
| NSP LLC | Hosting of the servers, operated by Vexaro, that run the service and store its data | All service data, including recording details | Standard Contractual Clauses |
| Serverius | Hosting of Vexaro relay servers | IP addresses and connection metadata; the content of relayed sessions, held in memory while the session lasts | Standard Contractual Clauses |
| OVHcloud | Hosting of Vexaro relay servers | IP addresses and connection metadata; the content of relayed sessions, held in memory while the session lasts | Standard Contractual Clauses |
| Cloudflare, Inc. | DNS, TLS termination, edge delivery, bot protection and DDoS protection for our websites and API | IP addresses, connection metadata, and traffic to our websites, console, API and browser viewer, which it decrypts at its edge | EU-US Data Privacy Framework; Standard Contractual Clauses |
| Stripe | Card payment processing | Your organisation's Vexaro reference and the payment details entered in Stripe's checkout | Standard Contractual Clauses |
| Plus Five Five, Inc. (Resend) | Sending our email and receiving mail sent to @vexaro.cloud addresses | Sender and recipient addresses, names where given, and message content | EU-US Data Privacy Framework; Standard Contractual Clauses |
Personal data is processed outside the EEA, the United Kingdom and Switzerland, including in countries without an adequacy decision. Where the GDPR, the UK GDPR or the Swiss Federal Act on Data Protection applies, we rely on an adequacy decision where one exists (including the EU-US Data Privacy Framework for providers certified under it), and otherwise on the Standard Contractual Clauses. On request to [email protected], we tell you the countries in which your personal data is processed. If this table differs from the Subprocessor List in the Legal Center (vexaro.cloud/en/legal/subprocessors), the list prevails. Card details go directly to the payment processor; Vexaro does not store them.
03Data processing summary
A short summary of how we handle personal data on your behalf. It is not the full Data Processing Addendum, which is published separately and governs if the two differ.
- Roles
- For data you put into the service, you are the controller and Vexaro is the processor, acting on your documented instructions.
- Scope of processing
- We process account and session data only to provide, secure and support the remote-desktop service. We never use it to advertise to your users.
- Subprocessors
- We use the subprocessors listed above. When we add or replace one, we update the list and notify you.
- Data-subject rights
- We support your obligations to handle access, correction and deletion requests, and provide tooling to export or remove account data.
- Incident notification
- We aim to notify affected customers of a confirmed personal-data breach without undue delay, with the facts as we establish them.
- Return & deletion
- On account closure we delete or return your data within a defined retention window, subject to legal retention requirements.
Need a signed DPA for your organisation? Contact us and we will share the current document.
04Availability
Availability targets depend on your plan. Business has a 99.5% monthly availability target for the console, API and relay. Enterprise commitments are set in the Order Form, and the Service Availability Policy explains how they are measured and credited. The other plans carry no uptime commitment.
- How it is measured
- Uptime is measured per calendar month, with maintenance announced in advance excluded, as set out in the Service Availability Policy.
- Service status
- We do not publish a live status page yet; report service problems to [email protected].
- Maintenance
- Planned maintenance is scheduled to minimise disruption and announced ahead of time where it may affect sessions.
- Support response
- Support channels and response targets scale with your plan; higher tiers include priority and dedicated support, as listed on the pricing page.
The Service Availability Policy in the Legal Center governs; Enterprise terms are set in the Order Form.
Questions about security or compliance?
Our team is happy to walk through the architecture, share documentation under NDA, or help with a vendor-security review.