Security and session records
A remote support session is a controlled, one-off connection that a person at the computer approves. This page sets out how it is controlled and what happens to the records afterwards.
Consent and session model
- A session starts only with a single-use code entered by the person at the computer, and only after that person confirms the connection on screen.
- Codes expire after 24 hours or on first use, whichever comes first, and are issued to a named technician. A code cannot be reused or shared between sessions.
- The person at the computer can pause sharing or end the session at any moment, and the technician cannot prevent it.
- Unattended access is off by default on every account in the portal. It is enabled only where a client organisation has agreed to it in writing, for named devices, with the client’s IT contact able to switch it off without asking us.
Technician identity
- Every technician uses a named account with multi-factor authentication and a hardware security key; shared accounts do not exist.
- Connection is least privilege: a first-line technician can view a screen, while file transfer and administrative changes require a role that the service desk manager grants per ticket.
- Technicians are background checked before they start, sign a confidentiality agreement, and are re-checked every three years.
- The technician’s name appears on the connection screen before you approve it. If the name does not match the person who gave you the code, decline and call us.
What a technician can and cannot see
| Visible during the session | Notes |
| Your screen and open windows | Yes | Only what is on the screen you share; sharing can be paused. |
| Files on the computer | Only when you open or approve them | Nothing is indexed, searched or copied in the background. Transfers are listed in the session record. |
| Saved passwords in applications | Hidden by design | We ask you to close password managers and private mailboxes before a session. |
| Personal devices at home | Not part of the service | We connect to client-managed devices, or to a personal device only when your IT contact requests it in writing. |
| Microphone, camera, webcam feed | Never | The session covers screen, mouse and keyboard only. |
Session records
Each session writes a record: client organisation, technician account, ticket reference, start and end time, the confirmation given by the person at the computer, files transferred, and the reason if elevated rights were used. Records are kept 12 months and are available to the client’s IT contact on request, in CSV or as a PDF extract for one session.
Sessions are not recorded by default — no screen capture, no keystroke log. Recording happens only where a client has asked for it in writing and the person at the computer is told before the connection starts.
Data handling
- TLS 1.3 between the portal, the connector and our service desk; AES-256 at rest.
- Session records and connector logs are hosted in AWS eu-west-1 (Ireland). No session data is copied outside the European Economic Area.
- Files transferred through our encrypted channel are deleted 30 days after the ticket closes unless the client asks for them to be kept as ticket attachments.
- Portal accounts, session records and codes are purged when a client contract ends; a written confirmation of deletion is issued.
Assurance and contacts
- ISO/IEC 27001:2022 certified, with surveillance audits each year. Certificate summary available on request under NDA.
- Annual penetration test of the portal and the connector by an external firm.
- Confirmed security incidents affecting a client are reported to the client’s IT contact within 24 hours, with a written report within five working days.
- Vulnerability reports: security@remotedeskportal.com. We acknowledge within one working day.