Dedicated instance, hosted in Quebec
Every subscriber gets their own instance and PostgreSQL database, on OKTO Solutions' servers, in Quebec. No data shared between subscribers. Docker images pinned by digest, TLS terminated by us.
Security and hosting
An OKTO RMM subscriber's data lives in a dedicated instance and a dedicated PostgreSQL database, hosted in Quebec on OKTO Solutions' servers. Two-factor authentication by passkey or app can be enforced for the whole team, secrets are encrypted with AES-256-GCM, every organization is isolated in the database, and every action is written to an audit trail with a checksum.
Every point on this page corresponds to code in console version 34.83 or agent 25.77.
Every subscriber gets their own instance and PostgreSQL database, on OKTO Solutions' servers, in Quebec. No data shared between subscribers. Docker images pinned by digest, TLS terminated by us.
TOTP by app or WebAuthn passkey. The partner can enforce it for the whole team; the client role always has it. Step-up MFA is required again before a risky action: isolating a device, acting on a threat, touching an integration.
Every action carries the actor (user, API key, agent, system), the action, the resource, the IP address, the result (success, failure, denied) and an integrity checksum. Configurable retention, never under 30 days.
Integration credentials, two-factor secrets and the device lock vault are encrypted with AES-256-GCM, in a versioned format with a key identifier for rotation. Nothing in clear text in the database.
Every client table carries PostgreSQL row-level security policies. An organization's token cannot read another organization, even through a coding mistake in the interface.
The Windows agent, watchdog and user helper are signed with Azure Trusted Signing in OKTO Solutions' name and timestamped. Distribution manifests are signed; SHA-256 fingerprints are recorded in the console.
Sessions and access
Trusted devices, one-click sign-out of every session, revocable refresh-token families, rate limiting of 5 attempts per 5 minutes on two-factor verification. Remote desktop relay credentials are temporary, HMAC-signed and valid ten minutes. Outbound requests to your integrations go through a client that refuses redirects and pins the resolved address.
On the devices
What we do not claim
OKTO RMM is not SOC 2 or ISO 27001 certified today. Our controls line up with those frameworks and we keep the documentation ready for a cyber-insurance or end-client questionnaire. If your contract requires a formal attestation, tell us before rather than after.
A subscription agreement, a data processing addendum compliant with Quebec's Law 25 and a service level agreement come with every subscription.
Ask a security question →Questions