Short and without marketing: how RudyDesk works, what our server sees and what it never sees.
Screen, sound, camera, chat and files travel directly between your devices over WebRTC, encrypted with DTLS-SRTP. Keys are created on the devices for every session; the server never has them. The server only helps devices find each other.
A device’s permanent password never goes to the server or to the other side. The device being connected to sends a random challenge, and the connecting one answers with an HMAC-SHA-256 signature derived from the password. The signature is bound to this session’s encryption key fingerprints, so an intercepted answer cannot be replayed or used by a man in the middle.
If a direct link is impossible (strict NAT, corporate firewall), traffic goes through our relay. It forwards packets that are already encrypted and cannot decrypt them. Relay access is issued to devices for a limited time.
Device IDs, IP addresses, connection and session times (who connected to whom, for how long) — a security log kept for 12 months to investigate abuse. The server has no session content — no image, sound, messages, files or keystrokes. We do not collect names, phone numbers or ID documents.
Nobody connects without your consent: an incoming request must be accepted, or the permanent password known, or the device must be one you trust. Access can be view-only. Password guessing is rate-limited, IDs can be blacklisted, and the connection log on the device shows who connected and what they did.
Every release is signed with an Ed25519 key and files are checked by SHA-256. The app installs an update only if the signature and hash match and the file came from rudydesk.com. It will not run a tampered installer.
Service data (accounts, licenses, settings) is backed up daily, encrypted with AES-256 and stored in two places. Restoring is verified automatically.
Write to abuse@rudydesk.com with the subject “Security”: what you found and how to reproduce it. We reply within three business days. Please do not publish details until we ship a fix, and do not touch other people’s data while testing.