RelayDesk
Security

Your AI gets the access you explicitly connect — not an anonymous shell.

RelayDesk is built around explicit pairing, authenticated AI connections and local safety boundaries for the machines you choose to expose.

Core controls

What protects a RelayDesk connection.

Explicit device pairing

RelayDesk can reach only computers, servers and VMs that you explicitly pair with your account.

OAuth-protected AI access

Supported AI apps connect through OAuth. Connected AI apps can be reviewed and revoked from your RelayDesk account.

Sensitive paths stay guarded

Recognized credentials, private keys, browser credential stores and other high-risk locations remain separately protected from normal file access.

Device-scoped access

AI access is routed to devices owned by the signed-in RelayDesk account, rather than exposing an anonymous remote shell.

Revocable connections

You can remove a paired device or revoke a connected AI app. Removing a device also removes RelayDesk-owned local credentials and runtime state from that machine.

Real machine output

Tool results are returned from the paired machine into the AI conversation so you can see what the machine actually reported.

What RelayDesk does not claim

Trust should be specific.

RelayDesk does not present itself as SOC 2 or ISO 27001 certified. The controls described here are product behaviors you can verify in the current service, not certification claims.

Connection model

OAuth for AI apps. Pairing for machines.

Compatible AI clients connect to RelayDesk through the hosted MCP endpoint at https://getrelaydesk.space/mcp. The user signs in, authorizes the AI connection, and chooses the RelayDesk device access available to that connection.

See the full access flow →

Need to disconnect something?

Access is revocable.

Connected AI apps can be revoked from your RelayDesk account. Paired devices can also be removed, which stops RelayDesk access to that machine and removes RelayDesk-owned local state associated with the agent.

Ready

Pair one device and keep the boundary explicit.

Get started