Front Desk · Secure remote operations for field devices
Remote access for devices that should not be exposed to the internet.
Kiosks, cash machines, safes, signage, Windows PCs, Linux boxes, small boards in the field. Your devices call out. Your team connects through Front Desk — approved, logged, and limited to the session.
02 — How it works
The device calls out.
Nothing calls in.
Inside your own office, remote access is easy. Field devices are different — they live behind customer firewalls, store routers, and networks someone else owns. Front Desk changes the direction of trust.
-
1
Allow outbound
The device makes outbound contact to Front Desk. Inbound ports stay closed. The site firewall stays untouched.
-
2
Request access
Your operator asks for a session through the web portal — identity-bound, scoped to that device.
-
3
Approve when required
A customer contact, store manager, or your own desk can approve or deny the attempt before it starts.
-
4
Work the session
GUI session, terminal, local admin page, logs, file transfer, commands, diagnostics — whatever the account enables.
-
5
End it
The session closes. The access path disappears. The audit record stays.
03 — Built for your fleet
Hundreds of devices.
Someone else's networks.
You may own the device and the support responsibility — but someone else owns the network it sits behind. Front Desk is built for exactly that arrangement, at fleet scale.
Kiosks & self-service
Ticketing, ordering, check-in — screens that support needs to see without a truck roll.
Cash machines & terminals
ATMs, payment terminals, time-delay safes — devices that must never be public servers.
Digital signage
Players mounted in ceilings and cabinets, at sites with a different network every time.
Rental equipment
Controllers that wake, check in over Wi-Fi, report usage, and sleep again.
Industrial & lab
Test rigs and controllers in facilities where inbound access is simply not negotiable.
OEM devices
Hardware you ship into customer facilities — supported by you, hosted by them.
Your devices stay private. Your team still gets in.
04 — On guard
Every session is
a business event,
not an open port.
Wherever a device sits on the planet, it stays private behind its firewall — and your team can still reach it from one place, on the record.
No open inbound ports
Sites only allow outbound traffic to approved Front Desk domains.
Controlled sessions
Access is identity-bound, scoped to the device, and limited to the session.
Human approval
Sessions can require a person to approve or deny the attempt first.
Audit trail
Approved, denied, observed, ended — every access attempt leaves a record.
05 — One desk, every device
Run the whole fleet
from a single front desk.
One web portal for the entire estate: find a device, see when it last called in, open a session, move a file, pull the logs, send a command — then close it and move on.
- GUI session
- Terminal
- Local admin page
- Logs
- File transfer
- Commands
- Diagnostics
- Fleet installers
Devices that sleep are first-class citizens: a low-power board can wake, check in, report status or usage, take supported actions, and sleep again. The portal always shows last contact and whether a device is reachable right now.
06 — Questions
Asked, answered.
Does Front Desk require inbound firewall ports?
No. The model is outbound-only from the device to Front Desk. The site does not open inbound VNC, SSH, RDP, or admin ports.
Is Front Desk a VPN?
No. It is a controlled remote-access path for specific devices and services — deliberately narrower than a VPN, and much easier to repeat across many customer premises.
Is it just remote desktop?
No. Remote GUI is one access mode. Front Desk is aimed at field-device operations: GUI, terminal, local HTTP, logs, file transfer, commands, diagnostics, approval, and audit.
Is it an IoT platform?
No. Front Desk complements telemetry, billing, monitoring, and RMM systems as the secure device contact path they can rely on — not a replacement for them.
Will it work behind a customer's firewall?
Yes — that is the design target. The customer network normally only needs to allow outbound traffic to approved Front Desk domains.
Can a customer approve access?
Yes. A customer contact, store manager, supervisor, or your own support lead can approve or deny access attempts before a session starts.
What if the device is offline?
Then no live session is possible — and that is visible. The portal shows last contact time and current status, so support knows whether the device is reachable.
What about devices that sleep?
If a device can wake and call out, it fits. It checks in when it has connectivity, reports state or usage, receives supported actions, and sleeps again.
Why not just expose VNC or SSH?
Then the device becomes a public server, with all the patching, password, and firewall exposure that brings. Front Desk exists so the device can stay private.
Can it support ATMs and cash machines?
The model is a strong fit for cash machines, kiosks, and field terminals. Exact deployment depends on the device OS, security policy, and access method needed.
Different question? Browse the full Q&A — or ask the Front Desk AI.
See it live.
The Demo Lab runs real machines. Open a session and watch the whole flow.