Desktop infrastructure you can actually reason about.
Managed thin-client fleet for the enterprise LAN — one server, dozens of fully-customized endpoints, zero per-seat licensing.
Open any device, remote in
Live metric history, violations and the command log — then VNC in, push a login, or force-clear a stuck session.
Watch the whole fleet's vitals
Fleet-wide CPU, memory and temperature trends plus real-time server load — no Prometheus or Grafana to bolt on.
Update every endpoint, one click
Signed OTA packages, auto-pulled by each client on heartbeat. Stragglers catch themselves up.
Cloud storage, mounted on login
Per-user NAS drives over an encrypted tunnel — assigned in the console, auto-connected at sign-in.
Every action, logged forever
An immutable trail — actor, target, timestamp — for every change across the fleet.
Completely yours, top to bottom.
Custom fleet image
Your apps, branding and desktop baked into one signed image, flashed to every endpoint.
Hardened, filtered browser
Kiosk-locked, ad-blocked at DNS, content-filtered through the proxy, sandboxed.
Approved apps per role
AppArmor-confined app sets — each role gets exactly what it needs, nothing else.
Login, splash & wallpaper
Push branded login, boot splash and wallpaper to the whole fleet in one click.
Push anything, anywhere
Run any script or install on one, many, or all endpoints from the library.
Thin, fat, or hybrid
Centralized, local, or mixed desktops — one console manages every mode.
The whole control room.
Published controls. No security-through-obscurity.
Argon2id · AES-256-GCM
Storage configs encrypted at rest. Passwords salted SHA-512. Admin tokens with rotation.
Default-drop firewall
nftables on server and clients. /32 routes so tunnels never carry non-target traffic.
AppArmor lockdown
Kiosk users non-login, no-home, confined. Browser in a sandboxed wrapper.
FreeIPA + device binding
Centralized users. Per-user allowlists. Cloned images rejected on unapproved hardware.
No leaked state
Session save/restore disabled, polkit authorizes only active local sessions, force-clear wipes processes, locks and caches between users.
Secrets handled clean
Mount credentials written only during mount, then securely overwritten and unlinked. A torn-down tunnel leaves no mounted trace.
Ready to see it running?
20-minute demo — I'll screen-share a live fleet and walk the console.