Security

The way into your servers deserves a careful tool

This page says what PluggedDesk enforces, how, and where its protection ends. We would rather you knew the limits from us than found them yourself.

Defaults

Locked down until you decide otherwise

A new connection starts from the safe side of every choice. Opening something up is always a deliberate act, made per folder or per connection, and visible in the properties pane.

SettingDefaultWhy
Network Level AuthenticationOnThe server checks who you are before it shows a desktop.
Server certificateStrictA certificate your computer cannot verify ends the attempt before any credential is sent. For a server with a self-signed certificate you can choose, per connection, to accept it.
Ignore certificate errorsDoes not existThere is no permanent switch for it, by design.
Drives, printers, sound, smart cardsOffNothing of your computer is offered to the remote one unless you turn it on.
Clipboard filesOn, separableFiles can be refused while text and images still pass.
Remember a passwordOffA password is kept only when you tick Remember, each time.

Credentials

A remembered password is stored in Windows Credential Manager, under your Windows account, and nowhere else. It is not in the workspace file, not in PluggedDesk's own database, and never on a command line, where other programs on the computer could read it.

  • A password you do not remember is used for one connection attempt, and the copies PluggedDesk made of it are wiped when the attempt ends
  • It reaches the engine through a private pipe, and the engine wipes its copy when the attempt ends
  • Forget removes it from the vault

An isolated engine

The code that speaks RDP to a server handles data that server controls. It runs as a separate process for each session, so a fault in it ends that session and cannot take the workbench, your other sessions or your workspace with it.

  • FreeRDP, pinned to a reviewed version, with a published list of what ships beside it
  • A file list from a server naming any path outside the paste folder is refused whole

Updates

A release is trusted through its signature and through nothing else. The manifest is signed with ECDSA P-256; the public half of the release key is compiled into PluggedDesk. The installer is then checked against the size and SHA-256 in that signed manifest before it runs.

  • This site holds no key that can sign a release, and refuses to publish one that is not signed
  • Only a strictly newer version is offered, so an old release cannot be replayed
  • The update channel is read over HTTPS only

Sign-in

Signing in to PluggedHub goes through your identity provider in your own browser: authorization code with PKCE. PluggedDesk never sees your password and never asks for it, and your second factor is checked where it belongs.

  • The answer comes back to an address on your own computer that exists only for that sign-in
  • What PluggedDesk holds afterwards is a token that can be revoked, kept in the operating system's vault

Built into the application; being switched on for Exprezoe staff first.

Privacy

What PluggedDesk sends, and to whom

PluggedDesk has no analytics and no usage tracking. It talks to the computers and services you connect it to, and to this site for these things only.

To this siteWhat
The update channelIts entitlement and its version. The answer is the signed manifest.
The license serviceThe license key once, at activation, with the computer's name, the platform, the version, and a hash of an identifier made for that installation.
Staff sign-inFor Exprezoe staff: the proof of sign-in from Exprezoe Identity, once, in place of a license key.

Never the names or addresses of your servers, never a credential, never what is on a screen, a keyboard or a clipboard. Its diagnostics stay on your computer.

Limits

What we do not claim

  • The installer is not yet signed with a publisher certificate. Windows will say the publisher is unknown. Verify the SHA-256 shown on the downloads page.
  • When you set a connection to accept a certificate your computer cannot verify, PluggedDesk does not yet remember that certificate, so it would not notice a different one later. Keep the strict setting wherever the server has a certificate your computer trusts.
  • PluggedDesk runs with your rights. It cannot protect a session from software already running as you on your computer.
  • A license is tied to an installation to count seats. That is bookkeeping, not a security boundary.
  • No outside party has audited PluggedDesk. When one has, the result will be linked here.
  • Only the Windows build exists. Nothing on this page has been shown for another platform.
Reporting

Found something?

Tell us before you tell anyone else, and give us the chance to fix it. Every report is read by the people who build PluggedDesk.

Report through your contact at Exprezoe. A public address for reports will be published here and in /.well-known/security.txt.

Please include the version of PluggedDesk (Help › About), what you did, what happened, and what you expected. Please do not include real credentials or data from a production system.

PluggedDesk is in early access

Licenses are issued to teams we can support well while the product takes shape. Tell us about your team and what you look after. Every request is read by a person.