How Pointrus protects sign-in and data
An RMM is a high-value target, so we publish what is in place and what we are still hardening.
In place today
- Two-step login. A password check issues a short-lived signed challenge, and only a valid authenticator code creates a session. Failed codes are throttled.
- Secure sessions. Session cookies are marked Secure, and the console sends HSTS and standard security headers.
- Per-device credentials. Each agent has its own credential after enrollment, and enrollment tokens work once.
- Audit trail. Sign-ins, alert acknowledgements, installer downloads and control actions are logged with user, address and time.
- Rate-limited recovery. Password reset needs an authenticator code and limits failed attempts.
Next on the security roadmap
- Single sign-on and SCIM, so identity lives in your directory
- A code-signed Windows installer, so SmartScreen can verify the publisher
- Tighter file permissions on endpoint credential files
- An uninstaller that also cleans up remote-control components
Report a concern
If you find a vulnerability, email [email protected]. We read every report.