JisrDesk← Back to home
Security

Consent is the first control.

JisrDesk is built for attended remote support: the person at the computer sees the request, approves the requested permissions, and can end the session.

Version 0.1.1-beta.1 is beta software and has not had an independent security audit. Do not use it for emergencies, privileged administration, or sensitive production systems.

What the beta protects

  • Numeric IDs are derived from device public keys and are not treated as passwords.
  • Devices must be enrolled and approved by the beta administrator.
  • Each session needs a visible host decision and a temporary password.
  • Production builds verify short-lived, server-signed session grants.
  • Relay credentials are issued only to approved devices and expire automatically.
  • Remote input is limited to the permissions approved for the active session.

Deliberately not included

JisrDesk has no unattended access, stealth mode, clipboard sync, file transfer, remote shell, command execution, privilege escalation, security bypass, keylogging, or surveillance features.

Important limitations

  • A compromised signaling service can interrupt service and misroute metadata.
  • A person you approve can misuse the view or input access you grant.
  • Malware or a compromised operating system can bypass app-level protections.
  • The input helper cannot control UAC prompts or the Windows secure desktop.
  • The beta has no MFA, account recovery, managed fleet policy, or automatic updates.
  • Local activity history can be changed or deleted by the local user or malware.

Report a security issue

Email security@usaimisoft.com with the minimum information needed to reproduce the issue. Never include passwords, private keys, session grants, relay credentials, screen captures, keystrokes, or personal data. Do not open a public issue for a vulnerability.