Solisys Remote Manager · Technical specifications

Desktop, server and
security architecture.

Technical details for deploying Solisys Remote Manager in multi-user environments, including architecture, authentication, credential storage and infrastructure requirements.

View architecture

Architecture

Desktop client. Central server.

In multi-user mode, SRM uses a desktop application backed by a central API and SQL Server database. Users work from the desktop client; authentication, connection assignments, credential storage and administrative controls are handled by the server.

Desktop users do not require direct access to the SRM database.

Current implementation · Reviewed 30 September 2026
Component SRM desktop SRM server
Technology .NET 10 with Avalonia UI. .NET 10 ASP.NET Core API with SQL Server.
Connections Search, groups, connection details and native RDP launch. Shared connection catalogue with per-user assignments.
Authentication Password and authenticator sign-in. Authentication, session management and account recovery.
Credentials Retrieves authorised credentials when an RDP session is launched. Stores remote credentials using authenticated encryption.
Administration Administration interface for authorised users. User, connection, assignment and licence management.
Connectivity Requires access to the SRM API and target RDP systems. Self-hosted and requires SQL Server.

Security

Access is enforced by the server.

The desktop application does not decide which credentials a user may access. Authentication and authorisation are performed by the SRM server before credentials are released.

Two-factor authentication

Server users sign in using a password and time-based authenticator code.

Encrypted credentials

Stored remote credentials are encrypted using AES-GCM. Encryption keys remain on the server and are not distributed to desktop users.

Per-user access

Connections can be assigned to individual users. The API verifies access before returning credentials.

Central session control

User sessions can expire or be revoked centrally. Account recovery and deactivation invalidate affected SRM sessions.

Deployment

Designed for self-hosted environments.

SRM Server is deployed within your own infrastructure and requires SQL Server plus HTTPS connectivity from SRM desktop clients.

HTTPS API

Desktop clients communicate with the SRM API over HTTPS when used across a network.

SQL Server

SRM uses SQL Server for configuration, users, assignments, sessions and audit records.

Docker deployment

A Docker Compose deployment is available for the SRM API. Alternative deployment arrangements can be discussed with Solisys.

Database permissions

Runtime database access can be separated from schema migration privileges so the running API does not require administrative SQL credentials.

Security boundaries

What SRM does — and what it doesn't.

SRM controls access to stored connection credentials. It is not an RDP proxy, privileged access gateway or session-recording platform.

RDP remains direct

RDP sessions run directly between the user's computer and the target system. SRM does not proxy the connection.

Credentials reach the client

An authorised desktop receives the remote credential when a connection is launched. Removing access prevents future retrieval but cannot retract credentials already supplied.

Infrastructure remains yours

Database backups, HTTPS certificates, SQL security and protection of the SRM encryption key remain deployment responsibilities.

Local mode is separate

Single-user local mode does not provide the central authentication, assignment and audit controls described on this page.

Detailed security implementation
Password storage
PBKDF2-HMAC-SHA256 with 600,000 iterations and randomly generated salts.
Credential encryption
AES-GCM authenticated encryption using a server-managed encryption key.
Sessions
Access and refresh tokens use cryptographically random values. Stored refresh tokens are hashed and rotate when used.
Default session lifetime
Access tokens expire after 60 minutes and refresh tokens after 14 days. These settings are configurable.
Account protection
Configurable account lockouts and client attempt limits are available to reduce repeated authentication attempts.
Audit records
SRM records authentication activity, credential retrieval and administrative changes.

Technical questions

Planning an
SRM deployment?

Talk to Solisys about infrastructure requirements, networking, authentication or deploying SRM within your environment.