Security & trust

Powerful endpoint actions, with boundaries you can see.

CoreTech RMM can reboot machines, push software, run remote sessions, and deploy operating systems. Capabilities like that are only safe when isolation, least privilege, approval, and evidence are part of the data model — not settings someone might forget to turn on.

Principles

Four properties we design every action around.

Isolation by default

A workspace is a hard boundary. Operators, clients, sites, devices, and sessions belong to a tenant and do not leak across one.

Least privilege

Roles scope what an operator can see and do down to client and site level, so technicians get exactly the reach a job needs.

Approval before reach

New devices and elevated actions can pass through an approval gate before they ever touch production.

Evidence, not memory

Remote sessions, endpoint actions, and deployments are recorded as history the next operator — or an auditor — can read.

Access & identity

Who can reach what is a structural decision.

Access is modeled, not improvised. Tenant, client, site, and role boundaries are first-class concepts, and people enter through scoped invitations rather than shared logins.

Tenant → client → site → role Every operator, device, and session resolves to a scope. Visibility and actions follow that scope.
Scoped invitations Operators join through tokenized invitations tied to a workspace and role, not a recycled credential.
Session accountability Remote and administrative sessions are attributed to a named operator and kept in history.

Devices & transport

An endpoint earns trust before it is managed.

Agents identify themselves cryptographically and devices are admitted deliberately. A machine you have not approved does not silently become something you operate.

Enrollment approval queue New agents land in a pending state. They become managed endpoints only after an operator approves them.
Certificate-based agent identity Agent connections are authenticated with client certificates, so endpoint identity is verified, not assumed.
Encrypted connections Control-plane and remote traffic run over TLS; remote sessions negotiate a direct or relayed encrypted path.

Auditability

If it happened to an endpoint, it left a record.

Audit is not a separate logging product bolted on later. Operational actions are written as history at the point they occur, so accountability survives staff turnover and post-incident review.

Remote & admin sessions Who connected, to which endpoint, under which scope, and when.
Change actions Patches, software changes, reboots, and deployments recorded against the endpoint record.
Governance events Enrollment approvals, invitations, and administrative operations kept as evidence.

Operational safety

Destructive power should never be one careless click away.

Context at the point of action

Remote support, reboot, patching, and deployment surface the target, its client, and its policy before the action runs.

Elevation is explicit

Sessions that need elevated rights show it, so technicians and reviewers can tell routine work from privileged work.

Failures stay visible

Failed updates and jobs are not swept under a green dashboard — they stay in the queue until they are resolved.

Compliance posture

An honest picture of where we are.

We would rather tell you the truth than imply a badge we have not earned. Here is the current state of our formal posture.

See it in context

Walk the controls against real operational flows.

We will show isolation, approval, remote session accountability, and audit evidence using the same workspace your technicians would use day to day.

Request product demo Sign in to the console

Have a specific security questionnaire? Send it over.