Skip to main content
VDO

Security

Security posture.

VDO is configured for access-controlled remote review and workstation access. The important security boundaries are account-scoped access, host registration, authenticated session links, encrypted live transport, and avoiding default media storage.

Access model

Accounts, invitations, and scoped links.

01

Account sign-in

Existing users authenticate before managing rooms, hosts, sessions, or workstation access. Public account creation is closed for the current access-controlled deployment.

02

Invites and join links

Invite, team registration, room join, and native auth flows remain available, but access is scoped to the intended account, team, room, or session context.

03

Registered hosts

Workstation access depends on agents registered to VDO, rather than exposing open anonymous desktop control endpoints. Host availability is mediated by the account and room model.

04

Admin-created users

Directly provisioned and invited users are supported without reopening public self-serve account creation.

Transport and storage

Live paths first; no default media library.

Encrypted transport

Browser, native, and host-agent connections use encrypted live transports for review, workstation display, input, and control traffic. Depending on the workflow, paths may use WebRTC/LiveKit or VDO QUIC transport.

Direct plus relay fallback

Where networks allow it, VDO attempts direct routing. When direct paths are blocked or unreliable, traffic can fall back through VDO relay infrastructure.

No default media copies

VDO does not create default recordings, transcripts, archives, or CDN media copies for live sessions. Operational metadata still exists for accounts, rooms, hosts, audit, and service health.

Current limits

Current assurance boundary.

VDO is not presented as SOC 2, ISO 27001, TPN, or studio-certified infrastructure. Sensitive workflows should be scoped deliberately: who can join, which host is registered, whether relay fallback is acceptable, and whether any recording or external capture is enabled outside VDO.

Ask a security question