Security
Security posture.
VDO is configured for access-controlled remote review and workstation access. The important security boundaries are account-scoped access, host registration, authenticated session links, encrypted live transport, and avoiding default media storage.
Access model
Accounts, invitations, and scoped links.
Account sign-in
Existing users authenticate before managing rooms, hosts, sessions, or workstation access. Public account creation is closed for the current access-controlled deployment.
Invites and join links
Invite, team registration, room join, and native auth flows remain available, but access is scoped to the intended account, team, room, or session context.
Registered hosts
Workstation access depends on agents registered to VDO, rather than exposing open anonymous desktop control endpoints. Host availability is mediated by the account and room model.
Admin-created users
Directly provisioned and invited users are supported without reopening public self-serve account creation.
Transport and storage
Live paths first; no default media library.
Encrypted transport
Browser, native, and host-agent connections use encrypted live transports for review, workstation display, input, and control traffic. Depending on the workflow, paths may use WebRTC/LiveKit or VDO QUIC transport.
Direct plus relay fallback
Where networks allow it, VDO attempts direct routing. When direct paths are blocked or unreliable, traffic can fall back through VDO relay infrastructure.
No default media copies
VDO does not create default recordings, transcripts, archives, or CDN media copies for live sessions. Operational metadata still exists for accounts, rooms, hosts, audit, and service health.
Current limits
Current assurance boundary.
VDO is not presented as SOC 2, ISO 27001, TPN, or studio-certified infrastructure. Sensitive workflows should be scoped deliberately: who can join, which host is registered, whether relay fallback is acceptable, and whether any recording or external capture is enabled outside VDO.
Ask a security question