Pointrus/Security

Security you can check, including the gaps

What protects Pointrus today, and what we are hardening next.

How Pointrus protects sign-in and data

An RMM is a high-value target, so we publish what is in place and what we are still hardening.

In place today

  • Two-step login. A password check issues a short-lived signed challenge, and only a valid authenticator code creates a session. Failed codes are throttled.
  • Secure sessions. Session cookies are marked Secure, and the console sends HSTS and standard security headers.
  • Per-device credentials. Each agent has its own credential after enrollment, and enrollment tokens work once.
  • Audit trail. Sign-ins, alert acknowledgements, installer downloads and control actions are logged with user, address and time.
  • Rate-limited recovery. Password reset needs an authenticator code and limits failed attempts.

Next on the security roadmap

  • Single sign-on and SCIM, so identity lives in your directory
  • A code-signed Windows installer, so SmartScreen can verify the publisher
  • Tighter file permissions on endpoint credential files
  • An uninstaller that also cleans up remote-control components

Report a concern

If you find a vulnerability, email [email protected]. We read every report.