Those handsets hold accounts, balances and conversations. In plain terms: what protects them, and what we deliberately do not do.
Each rack has its own identity and credential, created at the factory and never reused. It belongs to one account and only that account sees it.
Everything between your rack, our servers and your browser travels over TLS. Nothing crosses the network in the clear, video included.
The management channel is separate from the network the accounts operate on. The marketplace sees an ordinary phone on an ordinary line.
This is the part we have been most careful with, because it is the one that cannot be fixed after the fact.
An open session does not become trusted. Every order — open a screen, send a key, take a snapshot — is verified against the account that owns that rack.
Three roles, so the person who operates the handsets day to day is not the person who can change how the system works.
These are decisions, not gaps.
Video is relayed live and never written to disk. There is no archive of your handsets, because there is nothing to archive.
Unlock codes and text reach the phone and are gone. The log says a command was sent — never its contents.
No custom firmware, no rooting, nothing installed on the handsets. Unplug the rack and they are exactly as they were.
Only a one-way fingerprint. Reading our database would not let anyone impersonate your rack.
It is consumed when the rack is linked. Refurbishing issues fresh credentials and wipes the previous device list.
In production the technical interfaces are closed and the health check reveals no numbers about our customers.
Argon2, the algorithm recommended today for exactly this. Not even we can read them.
Twelve characters, a number and a symbol. Common passwords are rejected, including their obvious variants.
Sign-ins, sign-ups and rack pairings are rate limited per address. Guessing is not a viable route.
Access is renewed continuously and expires on its own. A forgotten open tab is not a permanent door.
Servers and backups stay in the EU. Nothing is transferred outside for processing.
Your account, your racks, your device list and the activity log. We do not want the contents of your phones.
Unlinking a rack deletes its device list. Closing your account removes your data. No hidden copies.
Activity and fault logs download as CSV whenever you want, in a format any spreadsheet opens.
Screens are relayed only to browsers signed in to your account and are never stored. Access to production systems is limited to what keeping the service running requires, and it is logged.
The rack keeps working and reconnects on its own. Your phones carry on as normal — the rack does not control them, it lets you reach them. The gap is recorded in the fault log.
No. The code links a rack to an account once and is consumed in the process. After that it is worthless, and pairing attempts are rate limited anyway.
Not yet. It is the next thing we are building, and we would rather say so than imply otherwise. Meanwhile password requirements are enforced and every sign-in is logged.
The rack notices immediately and it appears in the fault log with the exact time. Nothing about that handset is stored on our side beyond its entry in your device list.
We hold no certification today. We are a young product and we prefer to describe what we do rather than point at a badge. Everything on this page is implemented and you can verify it in the product.
If your situation needs an answer we have not given, ask before you buy. We would rather tell you no than sell you a surprise.
See pricing