---
title: "Connection security | PrimalDesk Docs"
description: "Host identity, encrypted sessions and access revocation."
url: "https://docs.primaldesk.com/articles/transport-security"
---

# Connection security

Host identity, encrypted sessions and access revocation.

PrimalDesk authorizes each connection against the account, host membership and access rules before issuing a short-lived connection ticket. Keep the host connected to the backend so that policy changes, revocations and session-management commands can reach it. A direct network path does not replace this check.

-   **Client to host:** session traffic is encrypted. The client checks the host identity supplied during authorization instead of accepting an arbitrary peer.
-   **Host to backend:** the control connection carries presence, policy and management messages over HTTPS and a secure WebSocket.
-   **Account access:** owners choose who may use a host. A Windows account remains a separate boundary: give each person their own Windows credentials.

After rotating a host certificate, wait for the host to publish its new identity before reconnecting clients. Correct an expired certificate or identity mismatch; do not tell users to bypass the warning. Protect private keys and administrator access on the Windows machine.

A relay forwards encrypted session traffic but can observe connection metadata such as endpoint addresses, packet sizes and timing. The backend also processes account, host and session metadata as described in the [Privacy Policy](https://primaldesk.com/legal/privacy.md).

This guide describes the current development and testing phase.

[Back to documentation](https://docs.primaldesk.com/docs.md)

## Explore PrimalDesk

- [PrimalDesk Docs: all pages](https://docs.primaldesk.com/llms.txt)
- [PrimalDesk: all pages](https://primaldesk.com/llms.txt)
- [Product overview](https://primaldesk.com/index.md)
- [Documentation](https://docs.primaldesk.com/docs.md)
- [Help center](https://docs.primaldesk.com/help-center.md)

## Other pages on this site

- [PrimalDesk Docs | Multi-user Windows remote desktop](https://docs.primaldesk.com/index.md)
- [Connection overview | PrimalDesk Docs](https://docs.primaldesk.com/articles/connection-overview.md)
- [Early access and availability | PrimalDesk Docs](https://docs.primaldesk.com/articles/early-access.md)
- [Make your first connection | PrimalDesk Docs](https://docs.primaldesk.com/articles/first-connection.md)
- [GDPR and data requests | PrimalDesk Docs](https://docs.primaldesk.com/articles/gdpr.md)
- [Windows compatibility | PrimalDesk Docs](https://docs.primaldesk.com/articles/host-compatibility.md)
- [Firewall and ports | PrimalDesk Docs](https://docs.primaldesk.com/articles/host-firewall.md)
- [Technical requirements | PrimalDesk Docs](https://docs.primaldesk.com/articles/host-requirements.md)
- [Install and manage a Windows host | PrimalDesk Docs](https://docs.primaldesk.com/articles/install-and-manage-host.md)
- [Mouse and keyboard controls | PrimalDesk Docs](https://docs.primaldesk.com/articles/mouse-keyboard.md)
- [Work with multiple monitors | PrimalDesk Docs](https://docs.primaldesk.com/articles/multiple-monitors.md)
- [Connect across different networks | PrimalDesk Docs](https://docs.primaldesk.com/articles/nat-traversal.md)
- [Network quality and frame rate | PrimalDesk Docs](https://docs.primaldesk.com/articles/network-quality.md)
- [RDS role and licensing | PrimalDesk Docs](https://docs.primaldesk.com/articles/rds-licensing.md)
- [Third-party notices | PrimalDesk Docs](https://docs.primaldesk.com/articles/third-party-notices.md)
- [Connection security | PrimalDesk Docs](https://docs.primaldesk.com/articles/transport-security.md)
- [TURN relay | PrimalDesk Docs](https://docs.primaldesk.com/articles/turn-relay.md)
- [Windows sessions | PrimalDesk Docs](https://docs.primaldesk.com/articles/windows-sessions.md)
- [Windows host setup and network documentation | PrimalDesk](https://docs.primaldesk.com/docs.md)
- [Remote desktop help center | PrimalDesk](https://docs.primaldesk.com/help-center.md)
