Connection security

Host identity, encrypted sessions and access revocation.

PrimalDesk authorizes each connection against the account, host membership and access rules before issuing a short-lived connection ticket. Keep the host connected to the backend so that policy changes, revocations and session-management commands can reach it. A direct network path does not replace this check.

  • Client to host: session traffic is encrypted. The client checks the host identity supplied during authorization instead of accepting an arbitrary peer.
  • Host to backend: the control connection carries presence, policy and management messages over HTTPS and a secure WebSocket.
  • Account access: owners choose who may use a host. A Windows account remains a separate boundary: give each person their own Windows credentials.

After rotating a host certificate, wait for the host to publish its new identity before reconnecting clients. Correct an expired certificate or identity mismatch; do not tell users to bypass the warning. Protect private keys and administrator access on the Windows machine.

A relay forwards encrypted session traffic but can observe connection metadata such as endpoint addresses, packet sizes and timing. The backend also processes account, host and session metadata as described in the Privacy Policy.