Front Desk Open Front Desk

Front Desk · Secure remote operations for field devices

Remote access for devices that should not be exposed to the internet.

Kiosks, cash machines, safes, signage, Windows PCs, Linux boxes, small boards in the field. Your devices call out. Your team connects through Front Desk — approved, logged, and limited to the session.

02 — How it works

The device calls out.
Nothing calls in.

Inside your own office, remote access is easy. Field devices are different — they live behind customer firewalls, store routers, and networks someone else owns. Front Desk changes the direction of trust.

  1. 1

    Allow outbound

    The device makes outbound contact to Front Desk. Inbound ports stay closed. The site firewall stays untouched.

  2. 2

    Request access

    Your operator asks for a session through the web portal — identity-bound, scoped to that device.

  3. 3

    Approve when required

    A customer contact, store manager, or your own desk can approve or deny the attempt before it starts.

  4. 4

    Work the session

    GUI session, terminal, local admin page, logs, file transfer, commands, diagnostics — whatever the account enables.

  5. 5

    End it

    The session closes. The access path disappears. The audit record stays.

A device sending a single outbound connection through a firewall toward Front Desk
One outbound thread. That's the whole surface.
Diagram of the outbound control-plane flow from device to Front Desk to operator

03 — Built for your fleet

Hundreds of devices.
Someone else's networks.

You may own the device and the support responsibility — but someone else owns the network it sits behind. Front Desk is built for exactly that arrangement, at fleet scale.

A panther walking a rooftop line above a skyline of kiosks and machines at dusk

Your devices stay private. Your team still gets in.

A black panther's face in darkness, amber eyes watching

04 — On guard

Every session is
a business event,
not an open port.

Wherever a device sits on the planet, it stays private behind its firewall — and your team can still reach it from one place, on the record.

  • No open inbound ports

    Sites only allow outbound traffic to approved Front Desk domains.

  • Controlled sessions

    Access is identity-bound, scoped to the device, and limited to the session.

  • Human approval

    Sessions can require a person to approve or deny the attempt first.

  • Audit trail

    Approved, denied, observed, ended — every access attempt leaves a record.

05 — One desk, every device

Run the whole fleet
from a single front desk.

One web portal for the entire estate: find a device, see when it last called in, open a session, move a file, pull the logs, send a command — then close it and move on.

A laptop on a sunlit desk with light threads reaching out to miniature field devices

Devices that sleep are first-class citizens: a low-power board can wake, check in, report status or usage, take supported actions, and sleep again. The portal always shows last contact and whether a device is reachable right now.

06 — Questions

Asked, answered.

Does Front Desk require inbound firewall ports?

No. The model is outbound-only from the device to Front Desk. The site does not open inbound VNC, SSH, RDP, or admin ports.

Is Front Desk a VPN?

No. It is a controlled remote-access path for specific devices and services — deliberately narrower than a VPN, and much easier to repeat across many customer premises.

Is it just remote desktop?

No. Remote GUI is one access mode. Front Desk is aimed at field-device operations: GUI, terminal, local HTTP, logs, file transfer, commands, diagnostics, approval, and audit.

Is it an IoT platform?

No. Front Desk complements telemetry, billing, monitoring, and RMM systems as the secure device contact path they can rely on — not a replacement for them.

Will it work behind a customer's firewall?

Yes — that is the design target. The customer network normally only needs to allow outbound traffic to approved Front Desk domains.

Can a customer approve access?

Yes. A customer contact, store manager, supervisor, or your own support lead can approve or deny access attempts before a session starts.

What if the device is offline?

Then no live session is possible — and that is visible. The portal shows last contact time and current status, so support knows whether the device is reachable.

What about devices that sleep?

If a device can wake and call out, it fits. It checks in when it has connectivity, reports state or usage, receives supported actions, and sleeps again.

Why not just expose VNC or SSH?

Then the device becomes a public server, with all the patching, password, and firewall exposure that brings. Front Desk exists so the device can stay private.

Can it support ATMs and cash machines?

The model is a strong fit for cash machines, kiosks, and field terminals. Exact deployment depends on the device OS, security policy, and access method needed.

Different question? Browse the full Q&A — or ask the Front Desk AI.

See it live.

The Demo Lab runs real machines. Open a session and watch the whole flow.

How it works, in full

Businesses deploy devices into places they do not fully control: convenience stores, branches, clinics, industrial sites, kiosks, cabinets, customer offices, and remote equipment rooms. Those devices need support, configuration, diagnostics, a GUI session, terminal access, or an HTTP admin page.

The simple answer is to expose VNC, SSH, RDP, or a web server to the internet. That works — until it becomes a security problem, a firewall problem, a dynamic-IP problem, a VPN problem, or a customer-approval problem.

Front Desk changes the direction of trust. Devices make outbound contact to Front Desk. Operators request access through Front Desk. The account owner can require approval for sessions. The device never needs to become a public server, and the customer site never needs inbound rules.

VPNs stay useful — but they join networks. Front Desk is narrower on purpose: controlled access to the specific devices you are responsible for. That narrower scope is what security teams can actually review and sign off.

Who Front Desk is for

The target customer rarely has one device. They have dozens, hundreds, or thousands, spread across many sites they do not control — stores, branches, clinics, plants, other companies' back rooms.

Typical fits: kiosk and self-service operators, digital signage networks, rental-equipment fleets with billing-relevant usage reporting, industrial and lab equipment vendors, OEMs shipping hardware into customer facilities, and operators of cash machines and payment terminals.

It also fits smaller teams: a few remote machines or boards where opening ports was never an acceptable answer.

The security model

Front Desk follows a zero-trust-style direction: authenticate the device, authenticate the user, avoid broad network trust, scope access to the session, and make every access visible.

Devices sit behind the site's existing firewall and only ever dial out to approved Front Desk domains. Operators come in through the web portal with their own identity. Where policy requires it, a human approver reviews the attempt — seeing who is asking and for which device — before the session can start.

A session is scoped and short-lived: when the work ends, the path is gone. What remains is the record — who asked, who approved, what was accessed, and when it ended. A support session becomes a business event, not an invisible open port.

What operators get

One portal for the estate: search devices, see status and last contact, and open the access mode the job needs — GUI session, terminal, or the device's local admin page — without exposing any of them publicly.

Beyond live sessions: file transfer, log retrieval, commands, diagnostics, and account-scoped installers for activating new fleet devices. Approvers get their own console for pending, active, and past sessions.

Intermittently connected devices keep the same model — they check in when they can, report state and usage, and pick up supported actions. The portal always shows what is reachable right now.