Security

Your privacy is not optional. Security without compromise.

Remio's zero-knowledge architecture means we can't see your data — even if we wanted to. No account, no middleman, nothing stored.

E2E
encrypted, every session
Zero
accounts stored
P2P
direct by default
PFS
forward secrecy
Architecture

Eight principles, plainly stated.

Zero-knowledge is a property of how Remio is built — not a policy we ask you to trust.

Zero-knowledge architecture

We cannot see what we're not given the keys to decrypt. Keys are derived between your devices and never leave them — even a court order couldn't produce a copy we don't hold.

No account, no target

No email, no password, no user database to breach. When AnyDesk was breached in 2024 and TeamViewer hit by APT29, they had credentials to lose. Remio has nothing on file.

Direct device-to-device

Your data flows directly between your devices. The connection server only performs the handshake; when a relay is unavoidable it forwards packets it cannot read.

End-to-end encryption

DTLS-SRTP — the same WebRTC security model trusted across the industry. Keys are negotiated only between your devices; even the relay sees nothing but ciphertext.

Perfect forward secrecy

Every session derives a fresh, single-use ephemeral key, destroyed when you disconnect. Past sessions stay protected even if a future key leaks.

Physical-presence pairing

A six-digit code you read off the host screen authorises a device, not an identity — rotate it anytime, closer to an in-person key exchange than an account.

Hardware-backed keys

Your OS protects Remio's secrets with its own hardware — Secure Enclave on Apple, secure elements on Android, the trust chip on Windows. Nothing extractable without unlocking the device.

Open, auditable protocol

Public FlatBuffers schemas are the single source of truth — the exact binary format is reproducible, generating the same code for iOS, macOS, Android, Windows and the Go server. No proprietary black boxes.

Why go account-free? Read the zero-account philosophy essay →

Threat model

What changes when the vendor gets breached?

The honest test of any remote-desktop tool is what a break-in exposes. With Remio, the answer is nothing.

DimensionRemioAnyDesk / TeamViewer
Stream routingDirect peer-to-peerThrough vendor servers
Account requiredNone — PIN onlyYes, email + password
Can the vendor decrypt?Impossible by designTechnically possible
What a breach exposesNo user data to leakAll users (2024 incidents)
Past-session protectionPerfect forward secrecyUnclear
Protocol auditPublic schemasProprietary, closed
Ads & data brokersNeverVaries by vendor
Cryptography

The keys never leave your devices.

The stream is protected with DTLS-SRTP and ECDHE key negotiation — the same key-exchange family behind Signal, WireGuard and modern HTTPS. Session keys live only in memory, for the length of a session, then vanish.

No ads, no data brokers, no account profile — your screen content is never logged, inspected, or decryptable on our side.

Remio device list on iPhone — paired by PIN, no account
Compliance

Nothing to leak, nothing to report.

Some protections are already in place; others are on the way. We only claim what we can prove.

Already in place

GDPR by architecture, hardware-backed keys, forward secrecy

No personal data is collected, so there is nothing to protect — plus rate-limiting at the signalling edge, platform secure-vault storage on every device, and an open protocol anyone can verify.

Planned 2026

Independent penetration test

A third-party red-team assessment with a public transparency report.

Planned 2026

SOC 2 Type II

Independent audit of security controls, availability, and confidentiality.

Roadmap

Bug bounty programme

Responsible-disclosure rewards. Until it launches, reports go to security@remio.net.

Reference

Full technical whitepaper

Encryption, threat model, transport, pairing and key lifecycle in depth — read the whitepaper →

Locked machines

A locked computer, reachable on your terms.

Remio does not bypass your computer's lock — it streams the real lock screen and passes your keystrokes to it, so the machine asks for your password exactly as it would if you were standing in front of it.

The lock stays the lock

Your operating system validates the password, not Remio. Your account password is never stored, never seen by our servers, and never transmitted as anything other than the encrypted keystrokes of the session.

Unlocking is a setting

Each host decides whether a connected device may type at its lock screen. Switch it off and your device can still see that the machine is locked — but no keystroke reaches it, and the client says so plainly instead of pretending to work.

Only devices you paired

A device reaches a host only if it has already been paired, with a six-digit code you can rotate or a QR scan. The host lists every paired device and removing one disconnects it on the spot — it has to pair again before it can get back in.

More detail on reaching a locked machine — including a lid-closed MacBook — on remote unlock at the lock screen →

Teams & individuals

Right for one person or a small team.

The same zero-knowledge design that protects a single Mac scales cleanly to a handful of paired devices. Because Remio has no central account store, there's nothing to provision and nothing to leak — every pair of devices holds its own keys. We're an independent project, so we don't yet offer enterprise support, SOC 2 attestation, or SLAs; what we do offer is an architecture you can verify yourself through the open protocol and whitepaper.

Questions

Frequently asked questions

Can Remio see my screen?
No. Remio uses end-to-end encryption with DTLS-SRTP and ECDHE key negotiation. Encryption keys are derived between your devices and never leave them. Our server only introduces your devices — it cannot decrypt the stream, even if compelled to. The cryptographic keys do not exist on our side.
Is there a Remio account or password?
No. There is no email, password, or central account database. Devices pair using a six-digit code displayed on the host computer. The code authorises a specific device, not an identity. Nothing about you is stored on our servers.
What happens if Remio's servers are breached?
Our signalling server only relays connection-setup messages — it never holds streaming data, encryption keys, or user credentials. There is no user database to leak. A breach of Remio's infrastructure would not expose past sessions because each session uses unique ephemeral keys (perfect forward secrecy).
What encryption does Remio use?
DTLS-SRTP — the industry-standard WebRTC security model — with ECDHE key negotiation between your devices. Each session uses unique ephemeral keys, providing perfect forward secrecy — past sessions remain protected even if a future key were somehow compromised. The exact protection profiles are documented in the security whitepaper.
Is the Remio protocol open?
Yes. Remio's wire protocol is defined in public FlatBuffers schemas — every message type is documented, the binary layout is reproducible from the schema, and the same definition generates code for iOS, macOS, Android, Windows, Linux, and the Go signalling server. No proprietary black boxes.
Has Remio been independently audited?
Independent penetration testing and SOC 2 Type II are planned for 2026. Until then, the open FlatBuffers protocol lets anyone verify exactly what is sent over the wire. A bug-bounty programme for responsible disclosure is on the roadmap.
Remio app icon

Privacy should not be premium.

Your computer from anywhere — completely free, no account, nothing stored on our side.