Security and trust

Controls that remain visible to users, administrators and security teams

LanRemoteAssist is designed to support authorized computers without evading Windows protections or obscuring its processes, service, files or network activity.

01
Exact-target operation

The Console operates on the computer or address explicitly entered or selected by an authorized user.

02
Windows remains authoritative

Authentication, firewall, application control, RDP, VNC and domain policies are respected rather than silently changed.

03
One-time credentials

Windows connection passwords are kept only for the active attempt and are never saved to settings or logs.

04
Visible support state

Attended approval and active-session indicators keep the supported user informed when local policy requires them.

Authorization

Attended and organization-managed access are separate choices

Attended sessions require local approval. Organization-managed access requires explicit administrator-selected enrollment for the confirmed target.

ATTENDED

Local approval for every session

Best for employee assistance and situations where the person at the target should review each request.

ORGANIZATION-MANAGED

Policy-based access for enrolled targets

Best for approved servers, kiosks or managed workstations where a documented support role is authorized.

Controlled Agent deployment

Review before transfer

The Console confirms the exact resolved target, package identity, version, filename, size, SHA-256 and selected access mode before an authorized installation.

1Authenticate the administratorUse Windows administrative channels already permitted by organization policy.
2Validate the embedded MSIRecheck package metadata and hash immediately before transfer.
3Install the exact serviceTransfer only the validated Agent MSI and verify the Agent service identity.
4Clean temporary filesRemove temporary deployment material after success, failure, cancellation or timeout.
Operational evidence

Metadata-only audit records

Record what action was attempted, against which exact target, when it occurred and whether it succeeded. Passwords, screen content, clipboard content and typed input do not belong in the audit trail.

09:42:18Session authorizedSuccess
09:39:02Agent identity verifiedSuccess
09:38:44Target authenticationSuccess

Preparing for SOC or EDR review?

Request the current hashes, dependencies, expected behavior, ports, network flows and audit-event definitions.

Request review package