FeaturesPricingCompareIntegrationsSecurityMigrationContact usVersion française Let's talk →

Built, hosted and supported in Quebec

The Quebec RMM.Devices, servers, patches.

OKTO RMM is a remote monitoring and management platform built in Quebec for IT service providers. One agent for Windows, Linux and macOS watches every device, installs patches, runs scripts and opens a remote desktop. Every subscriber gets a dedicated instance hosted in Quebec, from $100 a month in Canadian dollars.

No 50-device minimum. No three-year contract. We look at your fleet and tell you plainly whether the tool does the job.
Library350 ready scripts
OKTO RMM · Dashboard Live
Devices online247 / 251
Open alerts3 2 auto
Patches tonight412 0 failed
Heartbeat60 s stable
02:20:14PC-ACCT-03Patch KB5041585 installed, reboot scheduled for 10 p.m.
02:20:11SRV-FILESDisk C: at 88%, threshold 85%, cleanup script started
02:20:08LAP-SALES-11Chrome 128 updated silently, no session interrupted
02:20:05SRV-AD-01Heartbeat received, 38 ms latency, all normal
Alerts281 ready templates

What you get

What does OKTO RMM do on a device?

One agent, one console, six families of capabilities. Every number below is measured in the product, not in a brochure.

Monitoring and alerts

21 condition types, AND/OR groups, 281 ready alert templates and 58 monitoring packs by role: Windows server, domain controller, SQL Server, Hyper-V, Linux, macOS, Docker.

  • Email, SMS, Teams, Slack, webhook, PagerDuty
  • Escalation, cooldown, root-cause correlation
  • Maintenance windows that silence the noise

Patching

Windows Update, apt, Homebrew, Chocolatey, winget and Apple updates, all driven from the same place. Automatic approval by severity, scheduling by policy, controlled reboots.

  • Third-party patches for 14,000 applications
  • The agent closes the Windows automatic channel
  • Rollback and per-device history

Automation

350 PowerShell, Bash, Python and CMD scripts, 92 ready automations, and four ways to run them: on a schedule, on an event, by webhook or by hand. An alert can fix itself.

  • Versioned, parameterized scripts with statistics
  • Triggers: sign-in, non-compliance, device offline
  • Auto-remediation attached to the policy

Remote desktop

Native WebRTC in the agent, NVIDIA, AMD and Apple hardware encoding, a native viewer for Windows and macOS. Unattended access, terminal, file transfer and chat with the user, in the same session.

  • In-house TURN relay when the network blocks
  • Clipboard controlled in each direction
  • History of every session, duration and bytes

Inventory and device page

Hardware, software, processes, services, registry, scheduled tasks, event logs, warranty, IP address history. About thirty tabs per device, all readable and all actionable without opening a session.

  • Start, stop or restart a service remotely
  • Windows registry read and written from the console
  • Wake-on-LAN, lock, safe mode

Multi-tenant by design

Organizations, sites, enrolment keys per client. Roles with 55 permissions, isolation at the database level, and a client access where your customer sees only their own devices, with two-factor authentication enforced.

  • Client portal with your logo, colours and domain
  • Audit trail with a checksum on every entry
  • SSO OIDC and SAML, Entra ID proven
350ready scripts, shared with all your clients
281alert templates, 39 families
134commands the agent runs remotely
432console releases shipped since June 2026

Remote desktop

You are on the device before the user finishes the sentence.

The video stream is encoded by the device's graphics card in H.264 and travels over WebRTC straight between you and the machine. When a firewall blocks it, our relay takes over. The wallpaper stays in place, the user sees you are there, and you can write to them without leaving the session. The native viewer shows bitrate, latency, jitter, codec and network path live.

  • Native viewer for Windows and macOS, launched from a link in the console
  • Unattended access, with a consent gate you set by policy
  • Terminal, file transfer and screenshot without opening the desktop
  • Idle timeout and maximum session length, enforced by the agent

Device page

The whole device on one screen. Every action traced in its activity.

Current session, logged-in user, CPU and memory for the last hour, hardware, warranty, addresses, agent version: the page tells you everything before you open anything. On the right, the device's activity: every command, patch, reboot and remote session, with who did it and when. Some thirty tabs behind it: software, services, registry, scheduled tasks, logs, security, compliance, scripts, changes.

  • Actions at the top of the page: run a script, open a terminal, take the desktop, see the alerts
  • Per-device documentation and runbook, custom fields, change history
  • The same screen for a Windows desktop, a Linux server or a Mac

Configuration policies

One policy, fifteen sections, and inheritance does the rest.

Patches, alerts, monitoring, maintenance, automations, event logs, software policy, warranty, remote system tools, vulnerability scanning, OKTO panel, software, tools, assignments. Each section is set once in a baseline policy, inherited down to the organization and the device, and overridden only where needed. A policy is bound to a device class: a server never inherits a rule written for a laptop.

  • 39 alert conditions in a single workstation policy, each with its severity, cooldown and remediation
  • Patch approval rings by severity, schedule by day and hour, reboot behaviour
  • Maintenance windows that mute alerts, scripts and reboots, with notices to the user
  • Automations attached to the policy: on a schedule, on an event, or triggered by an alert

The sections cycle on their own; click one to keep it on screen.

Patching

Patches install overnight. You read the report in the morning.

A patch policy says what to approve (by severity and by category), when to install (daily, weekly, monthly, at the hour you choose) and how to reboot. It is inherited from a partner baseline down to the device. The Windows agent closes Microsoft's automatic channel so nothing happens behind your back.

  • Six package managers: Windows Update, apt, Homebrew, Chocolatey, winget, Apple
  • A patch of unknown severity is never approved on its own
  • Maintenance windows: alerts, scripts and reboots muted
  • Rollback, hold and per-device install history
Policy “Servers, Tuesday night” · 2:00 a.m. · 38 devices
KB5041585Windows Server 2022 cumulative · criticalInstalled
Chrome 128.0winget · important · 31 devicesInstalled
7-Zip 24.08Chocolatey · moderateInstalled
openssl 3.0.13apt · Ubuntu 24.04 · criticalInstalled
Realtek driverunknown severity · awaiting approvalPending
SRV-SQL-02Reboot postponed: backup running until 3:10 a.m.Postponed

35 of 38 devices done · 0 failures · 3 reboots scheduled

Automation

What you do twice, the agent does forever.

The library arrives full: 350 scripts proven on a real fleet, in PowerShell, Bash, Python and CMD, for Windows, Linux and macOS. You run them on a device, an organization or the whole fleet, on a schedule or when an event happens. And when an alert has a remediation script, it is fixed before you read it.

  • 92 ready automations: cleanup, DISM and SFC, DNS cache, SMBv1, BitLocker, RDP, Docker, Let's Encrypt
  • Scripts run as SYSTEM or in the user's session, with no flashing window
  • On failure: stop, continue or notify, with the log of every device
  • Credentials encrypted in a vault, never in clear text inside a script
Automation “Disk full, clean it up” · triggered by an alert
02:14:07 Alert SRV-FILES · C: at 88%, threshold 85%
02:14:08 Remediation Disk-Cleanup-Windows.ps1 as SYSTEM
02:14:09   Recycle bin emptied 3.1 GB
02:14:21   Windows Update cache purged 6.8 GB
02:14:33   Memory dumps removed 1.2 GB
02:14:40   IIS logs older than 30 days archived 4.4 GB
02:14:41 Re-check C: at 71% below threshold
02:14:42 Alert closed automatically, note posted to the PSA ticket

Software library

24,160 applications, installed silently, without disturbing anyone.

The catalogue brings WinGet and Chocolatey into a single search: Chrome, Firefox, VLC, 7-Zip, Notepad++, Visual Studio Code, Zoom, Acrobat Reader and 24,000 others, installed in the background, as SYSTEM, with no interaction. Your own installers, in-house MSI or EXE, go under “My installers” and deploy the same way, to one device, one organization or the whole fleet.

  • Packs: a group of applications for a role, a new accounting desktop or a shop-floor PC, in one deployment
  • Tracking: who has what, in which version, and what is waiting for an update
  • Software policies: allow list, banned software, requirements per organization
  • Approved applications show up in the user's assistant, self-service
Software library · Catalogue · 24,160 applications · 3 sources
Background install, SYSTEM context, no interaction: users are not disturbed.
AllWinGetChocolateyMy installers
Search an application (Firefox, 7zip, Mozilla.Firefox...)24,160 apps
CGoogle Chrome WinGetv151.0.7922+ Add
FMozilla Firefox WinGetv153.0.1+ Add
VVLC media player WinGetv3.0.23+ Add
77-Zip Chocolateyv26.02Added
NNotepad++ Chocolateyv8.9.7+ Add
SSage 50 Accounting My installersin-house MSI, signedAdded
ZZoom Workplace WinGetv7.1.43453+ Add

Assistant on the device

Your users get a button. Not your cell number.

In the notification area of every device, the OKTO assistant opens a menu the user understands at first glance: ask for help, see the device's status, install an approved application, update their software, manage their access. The help request becomes a ticket in OKTO PSA, HaloPSA, ConnectWise or Autotask, with the device already attached and its diagnostics.

  • Approved applications install self-service, through the agent, without giving the user administrator rights
  • Available updates install when the user decides, in their own window
  • Client portal and support one click away, dark mode, no flashing black window
  • Works with OKTO PSA and with the ticketing system you already use

Click the menu to close it and open it again.

Vulnerabilities and compliance

Every flaw has a name, a fix and a priority. Every device has a score.

The software inventory of every device is matched against four vulnerability feeds: CISA KEV and EPSS, Microsoft MSRC, NIST's NVD and SOFA for Apple. Each CVE is prioritized by real risk, a CVSS score adjusted by KEV (actively exploited) and EPSS (likelihood of exploitation), with the affected software, the fix that resolves it and the devices concerned. Next to it, CIS benchmarks score each device's configuration and propose the remediation, under your approval.

  • A feed that stops updating is flagged: silently frozen results are worse than no results
  • CIS benchmarks for Windows, macOS and Linux, score over time, remediation approved by you
  • Audit compliance baselines, USB peripheral control, sensitive data discovery
  • “Critical vulnerability” and “non-compliance” alerts wired into your automations
Vulnerabilities · whole fleet · prioritized by risk
CISA KEV and EPSS Healthysync 2026-09-04
Microsoft MSRC Healthysync 2026-09-04
NVD (NIST) Healthysync 2026-09-04
SOFA (Apple) Healthysync 2026-09-04
CVESoftware · fixCVSSDevicesKEV
CVE-2026-1041Google Chrome 150 · fixed in 151.09.812 devicesExploited
CVE-2026-0873Windows 11 24H2 · KB50415857.841 devicesNo
CVE-2026-05127-Zip 24.08 · fixed in 26.027.09 devicesNo

One-time secrets

A password, a key or an identifier sent to the client through a link that expires and opens only once. The content is encrypted in your browser: the console cannot read it, and a stolen database gives up nothing.

Link sent to the client:
https://rmm.your-domain.ca/s/7kd9-Qx2m-...
Expires in 23 hOpens onceEncrypted in your browser

Audit trail

Every action by a user, an API key, an agent or the system: who, what, on which resource, from where, with which result. Every entry carries an integrity checksum. Filter by actor, action, device or period.

  • Completed commands, reported sessions, policy changes
  • Configurable retention, never under 30 days

Event logs

The Windows event logs of every device, forwarded by the agent and searchable from the console without opening a session. An event ID, a source or a word is enough, and 63 ready alert templates build on them.

  • System, Application, Security, custom logs
  • Query one device, one organization or the whole fleet

And everything else

Forty-four things we did not have room to detail.

All included in the price, all in version 34.83, none of them “on the roadmap”.

Windows, Linux, macOS, one agent per system, amd64 and arm64
134 agent commands, processes, services, registry, files, tasks
WebRTC remote desktop, hardware encoding, native viewer, relay
Remote terminal, PowerShell, Bash, as SYSTEM or as the user
File transfer, explorer, agent-side recycle bin, resume
Screenshot, without opening a session
Session chat, technician and user, with images
Windows patching, native WUA, Microsoft channel closed
Linux and macOS patching, apt, Homebrew, Apple updates
Third-party patching, winget and Chocolatey, by severity
24,160 applications, catalogue, packs, tracking, your own installers
350 ready scripts, PowerShell, Bash, Python, CMD, versioned
92 automations, schedule, event, webhook, manual
Auto-remediation, an alert carries its own script
281 alert templates, 39 families, in French and English
58 monitoring packs, by role: AD, SQL, Hyper-V, Linux, Docker
Network monitoring, SNMP, ping, TCP, HTTP, DNS, discovery
Vulnerabilities, CISA KEV and EPSS, MSRC, NVD, SOFA
CIS benchmarks, Windows, macOS, Linux, approved remediation
Compliance baselines, audit policies, score over time
Antivirus and encryption, Defender, third-party, BitLocker, firewall
Peripheral control, USB by policy
Temporary elevation, privileges granted, revoked, logged
Sensitive data, discovery, encryption, secure deletion
One-time secrets, expiring link, encrypted in the browser
Audit trail, checksum on every entry
Event logs, Windows, centralized and searchable
DNS filtering, NextDNS deployed by policy
Maintenance windows, muting, reboots, notices
Wake-on-LAN, wake, lock, safe mode
Warranty and hardware, age, warranty end, make, model
IP address history, and sessions, per device
Custom fields, per device and per organization
Per-device documentation, runbook, notes, tracked changes
Inherited policies, partner baseline, organization, device
Roles with 55 permissions, 21 resources, cloneable
Scoped client access, MFA enforced, their devices only
Client portal, logo, colours, domain, CSS
SSO OIDC and SAML, Entra ID proven, passkeys
API with 1,009 routes, OpenAPI, permission-scoped keys, webhooks
Desktop assistant, help, apps, updates, access
PSA integrations, OKTO PSA, HaloPSA, ConnectWise, Autotask
Antivirus integrations, Bitdefender, SentinelOne, Huntress
French and English UI, full catalogues, per user

Pricing

One price per device, in Canadian dollars. No 50-device minimum.

$100 a month to start, then $2.99 per device. Past 500 devices, the whole fleet drops to $1.99. Slide the cursor: the comparison uses the public price of the big American RMMs, $5.50 per device with a 50-device minimum, without even counting the exchange rate.

OKTO RMM
$359/ month

$2.99 per device per month · Standard tier

Big American RMM, public price
$660/ month

$5.50 per device, billed on a 50-device minimum, before conversion to Canadian dollars

$30146%

less every month, or $3,612 a year

See the full pricing

Against the big RMMs

What we do differently, without naming them.

You know them. They bill in US dollars, require a minimum number of devices, sign you up for three years and answer in English from another time zone. Their console is excellent. The rest, less so.

OKTO RMMThe big ones
CurrencyCanadian dollarsUS dollars
Minimum$100 a month50 devices, about US$275
CommitmentMonthly1 to 3 years
SupportIn French or English, from QuebecTicket portal, other time zone
Your dataDedicated instance, with usShared, in the United States
The full comparison

Security and hosting

Your clients trust you with their devices. We take that seriously.

  • Dedicated instance and database per subscriber, hosted in Quebec on our own servers
  • Two-factor authentication by app or passkey, enforceable for the whole team, with step-up required for risky actions
  • Secrets and credentials encrypted with AES-256-GCM, isolation at the database level per organization
  • Audit trail with a checksum on every entry: who, what, when, from where, result
  • Agent, watchdog and helper signed with Azure Trusted Signing in OKTO Solutions' name, fingerprints published
  • CIS benchmarks for Windows, macOS and Linux, remediation under approval, score over time
Everything about security

Straight questions

What we get asked before signing.

Can I migrate from my current RMM without rebuilding everything?
Yes, in four guided steps: we install the OKTO agent alongside the old one (both coexist), import your organizations and sites, rebuild your patch and alert policies from our 58 packs by role, then remove the old agent by script when you are ready. Your PowerShell and Bash scripts paste in as they are. Details on the Migration page.
Is it really $2.99 per device, with no hidden fees?
Yes. $100 a month minimum, $2.99 per device or server beyond that, $1.99 for the whole fleet past 500 devices. No setup fee, no paid add-on module, no invoice in a foreign currency. Taxes apply, as everywhere. Remote desktop, third-party patching and integrations are included.
Where is my data and who can access it?
Every subscriber has their own instance and their own database, hosted in Quebec on OKTO Solutions' servers. Inside your instance, every organization is isolated in the database itself, not only in the interface. We only go in for support, at your request, and every action is in the audit trail.
Does it work on Linux and macOS?
Yes. The agent exists for Windows, Linux (amd64 and arm64) and macOS (Intel and Apple Silicon). Patching goes through apt on Linux, Homebrew and Apple updates on macOS. Remote desktop works on all three.
What if I only manage 30 devices?
You pay $100 a month, full stop. That is the typical case that costs the most elsewhere: billed on a 50-device minimum when you have 30. With us, the minimum is in dollars, not in devices, and it covers a whole fleet.
Who answers when it breaks?
The team that runs OKTO RMM on its own fleet, in French or English, from Trois-Rivières. No ticket opened in a portal that comes back three days later. The product ships continuously: 432 console releases since June 2026, and whatever blocks you goes to the top of the list.

Next step

Tell us how many devices you manage. We do the rest.

We look at your fleet and your current tool, give you the exact price and what migrates as is. Reply within the business day. If it does not do the job, we will be the ones to tell you.