Skip to main content
Trust Center

Security and trust at Vexaro Desk

A plain-language overview of how we protect remote-desktop sessions and the data behind them: the architecture, the providers we rely on, how we handle your data and what to expect from availability.

Vexaro Desk is in early access. This page is a summary of how the product works today, not a contract. Formal legal documents (DPA, terms) are published separately and take precedence where they apply.

01Security architecture

Every connection is encrypted in transit. Where the network allows, a session runs directly between the two computers; where it does not, it falls back to an encrypted relay. Sensitive account fields are encrypted before they are stored. The essentials, without the jargon:

Encrypted in transit

Console, API and session traffic is encrypted in transit. Traffic to our websites, console, API and browser viewer passes through our edge provider (Cloudflare, below), which decrypts it at its edge. The browser viewer reaches a session through a Vexaro server that bridges it for the browser: every leg is encrypted, but that server decrypts the stream, so browser sessions are not end-to-end encrypted.

Verified session identity

A direct session checks the other computer's cryptographic identity before any session data flows. If the check fails, the connection is refused. It is never silently downgraded to an unverified path.

Direct peer-to-peer

Where the network allows, your screen data travels directly between the two computers, end-to-end encrypted. When a network forces a relayed connection, traffic stays encrypted in transit through Vexaro-operated relays.

Read the Encryption Overview

Encrypted at rest

Sensitive fields are encrypted at rest: multi-factor secrets, webhook, directory and single sign-on secrets, and the email address on each account.

Controlled access

Console access is governed by roles and per-organisation scoping. Each device decides who may connect: consent for attended sessions, and an access password for unattended ones, optionally limited to named Vexaro IDs. Multi-factor authentication is available on every account.

Auditable by design

Session and administrative events are recorded to the audit trail, which you can export or forward to a SIEM. Each session's evidence pack brings together consent, the event timeline, the recording details and file transfers.

02Subprocessors

The third-party providers that process personal data for us: what each one does, the data it receives and the safeguard we rely on when it processes data outside the European Economic Area (EEA). Account, device and connection data and the details of recordings are held in one location, on Vexaro-operated servers. Recording files stay on your own computers.

ProviderPurposeData it receivesSafeguard outside the EEA
NSP LLCHosting of the servers, operated by Vexaro, that run the service and store its dataAll service data, including recording detailsStandard Contractual Clauses
ServeriusHosting of Vexaro relay serversIP addresses and connection metadata; the content of relayed sessions, held in memory while the session lastsStandard Contractual Clauses
OVHcloudHosting of Vexaro relay serversIP addresses and connection metadata; the content of relayed sessions, held in memory while the session lastsStandard Contractual Clauses
Cloudflare, Inc.DNS, TLS termination, edge delivery, bot protection and DDoS protection for our websites and APIIP addresses, connection metadata, and traffic to our websites, console, API and browser viewer, which it decrypts at its edgeEU-US Data Privacy Framework; Standard Contractual Clauses
StripeCard payment processingYour organisation's Vexaro reference and the payment details entered in Stripe's checkoutStandard Contractual Clauses
Plus Five Five, Inc. (Resend)Sending our email and receiving mail sent to @vexaro.cloud addressesSender and recipient addresses, names where given, and message contentEU-US Data Privacy Framework; Standard Contractual Clauses

Personal data is processed outside the EEA, the United Kingdom and Switzerland, including in countries without an adequacy decision. Where the GDPR, the UK GDPR or the Swiss Federal Act on Data Protection applies, we rely on an adequacy decision where one exists (including the EU-US Data Privacy Framework for providers certified under it), and otherwise on the Standard Contractual Clauses. On request to [email protected], we tell you the countries in which your personal data is processed. If this table differs from the Subprocessor List in the Legal Center (vexaro.cloud/en/legal/subprocessors), the list prevails. Card details go directly to the payment processor; Vexaro does not store them.

03Data processing summary

A short summary of how we handle personal data on your behalf. It is not the full Data Processing Addendum, which is published separately and governs if the two differ.

Roles
For data you put into the service, you are the controller and Vexaro is the processor, acting on your documented instructions.
Scope of processing
We process account and session data only to provide, secure and support the remote-desktop service. We never use it to advertise to your users.
Subprocessors
We use the subprocessors listed above. When we add or replace one, we update the list and notify you.
Data-subject rights
We support your obligations to handle access, correction and deletion requests, and provide tooling to export or remove account data.
Incident notification
We aim to notify affected customers of a confirmed personal-data breach without undue delay, with the facts as we establish them.
Return & deletion
On account closure we delete or return your data within a defined retention window, subject to legal retention requirements.

Need a signed DPA for your organisation? Contact us and we will share the current document.

04Availability

Availability targets depend on your plan. Business has a 99.5% monthly availability target for the console, API and relay. Enterprise commitments are set in the Order Form, and the Service Availability Policy explains how they are measured and credited. The other plans carry no uptime commitment.

How it is measured
Uptime is measured per calendar month, with maintenance announced in advance excluded, as set out in the Service Availability Policy.
Service status
We do not publish a live status page yet; report service problems to [email protected].
Maintenance
Planned maintenance is scheduled to minimise disruption and announced ahead of time where it may affect sessions.
Support response
Support channels and response targets scale with your plan; higher tiers include priority and dedicated support, as listed on the pricing page.

The Service Availability Policy in the Legal Center governs; Enterprise terms are set in the Order Form.

Questions about security or compliance?

Our team is happy to walk through the architecture, share documentation under NDA, or help with a vendor-security review.