Security

Your privacy is not optional. Security without compromise.

Remio's zero-knowledge architecture means we can't see your data — even if we wanted to. No account, no middleman, nothing stored.

AES-256
GCM, end-to-end
Zero
accounts stored
P2P
direct by default
PFS
forward secrecy
Architecture

Eight principles, plainly stated.

Zero-knowledge is a property of how Remio is built — not a policy we ask you to trust.

Zero-knowledge architecture

We cannot see what we're not given the keys to decrypt. Keys are derived between your devices and never leave them — even a court order couldn't produce a copy we don't hold.

No account, no target

No email, no password, no user database to breach. When AnyDesk was breached in 2024 and TeamViewer hit by APT29, they had credentials to lose. Remio has nothing on file.

Direct device-to-device

Your data flows directly between your devices. The connection server only performs the handshake; when a relay is unavoidable it forwards packets it cannot read.

Bank-grade encryption

AES-256-GCM authenticated encryption — the same standard that guards banking and government traffic. Brute-forcing it would outlast the age of the universe.

Perfect forward secrecy

Every session derives a fresh, single-use ephemeral key, destroyed when you disconnect. Past sessions stay protected even if a future key leaks.

Physical-presence pairing

A 4-digit PIN you read off the host screen authorises a device, not an identity — valid for minutes, single-use, closer to an in-person key exchange than an account.

Hardware-backed keys

Your OS protects Remio's secrets with its own hardware — Secure Enclave on Apple, secure elements on Android, the trust chip on Windows. Nothing extractable without unlocking the device.

Open, auditable protocol

Public FlatBuffers schemas are the single source of truth — the exact binary format is reproducible, generating the same code for iOS, macOS, Android, Windows and the Go server. No proprietary black boxes.

Why go account-free? Read the zero-account philosophy essay →

Threat model

What changes when the vendor gets breached?

The honest test of any remote-desktop tool is what a break-in exposes. With Remio, the answer is nothing.

DimensionRemioAnyDesk / TeamViewer
Stream routingDirect peer-to-peerThrough vendor servers
Account requiredNone — PIN onlyYes, email + password
Can the vendor decrypt?Impossible by designTechnically possible
What a breach exposesNo user data to leakAll users (2024 incidents)
Past-session protectionPerfect forward secrecyUnclear
Protocol auditPublic schemasProprietary, closed
TelemetryNone — zeroUsage + device analytics
Cryptography

The keys never leave your devices.

The stream is protected with AES-256-GCM for confidentiality and integrity, ECDHE over Curve25519 for key exchange, and DTLS-SRTP for transport — the same key-exchange family behind Signal, WireGuard and modern HTTPS. Session keys live only in memory, for the length of a session, then vanish.

No telemetry, no cookies, no analytics — GDPR-compliant by architecture, not by policy page.

Remio device list on iPhone — paired by PIN, no account
Compliance

Nothing to leak, nothing to report.

Some protections are already in place; others are on the way. We only claim what we can prove.

Already in place

GDPR by architecture, hardware-backed keys, forward secrecy

No personal data is collected, so there is nothing to protect — plus rate-limiting at the signalling edge, platform secure-vault storage on every device, and an open protocol anyone can verify.

Planned 2026

Independent penetration test

A third-party red-team assessment with a public transparency report.

Planned 2026

SOC 2 Type II

Independent audit of security controls, availability, and confidentiality.

Roadmap

Bug bounty programme

Responsible-disclosure rewards. Until it launches, reports go to security@remio.net.

Reference

Full technical whitepaper

Encryption, threat model, transport, pairing and key lifecycle in depth — read the whitepaper →

Teams & individuals

Right for one person or a small team.

The same zero-knowledge design that protects a single Mac scales cleanly to a handful of paired devices. Because Remio has no central account store, there's nothing to provision and nothing to leak — every pair of devices holds its own keys. We're an independent project, so we don't yet offer enterprise support, SOC 2 attestation, or SLAs; what we do offer is an architecture you can verify yourself through the open protocol and whitepaper.

Remio app icon

Privacy should not be premium.

Your computer from anywhere — completely free, no account, nothing stored on our side.