
TLS with per-device certificates, outbound port 443 and connection approvals — how Tenvo protects a remote session, and what the relay can and cannot see.
Every remote desktop session is, by nature, a potential attack surface. You're sending keystrokes, mouse movements, and screen content across the internet. That's why encryption isn't optional, it's the foundation. Tenvo encrypts every connection with TLS, using a certificate issued per device. On a direct peer-to-peer connection that is end-to-end and we cannot read it. When a direct connection is impossible and the session goes through our relay, TLS terminates at the relay: we do not record or store session content, but we do not claim it is technically unreadable there.
Passwords are handled locally: when you set a permanent password for unattended access, it's hashed on the machine before being stored. The password never leaves your device in plaintext, and our servers never see it. During connection, authentication happens via a challenge-response protocol, the actual password is never transmitted over the network.
We route all traffic through port 443 (the same port used by HTTPS) for two reasons. First, it's almost never blocked by firewalls or corporate proxies, so your connections just work. Second, the traffic is indistinguishable from regular HTTPS traffic to network observers, adding a layer of privacy.
Beyond encryption, Tenvo includes practical security features: connection approval prompts (so no one can silently connect to your machine), session logging with timestamps, and temporary one-time passwords for support sessions. Security isn't a feature we bolt on, it's how we build everything.
Get Tenvo
Ready to try it yourself?
Free for 30 devices, no credit card. Up and connected in two minutes.