Identity and records
Locate the identity provider, access events and recordings. Name the people and systems allowed to read them.
Run desktops in your OCI, Google Cloud, Azure or AWS account, or on Neverinstall Private Cloud at a fully disconnected site. Applications and data stay on the desktop. Only display, sound, input and the transfers you allow cross the network.
When applications run on laptops, client data sits on each device. Every endpoint needs its own controls, and every review covers them all.
On Neverinstall Private Cloud, a fully disconnected site runs its own local Management Console, deployed separately. Nothing phones home, and updates arrive signed and offline.
Your cloud account
Supported clouds
Air-gapped sites
Neverinstall Private CloudNothing phones home
OCI, Google Cloud, Azure or AWS, with the hosted Management Console
Neverinstall Private Cloud with a local Management Console and no phone-home
Browser or any RDP client, over WebTransport with WebSocket fallback
SOC 2 Type II attested, ISO 27001 certified, HIPAA in progress
Each member’s role, groups, multi-factor status and sign-in method, on one profile.
Each workspace shows which transfer settings follow the organization default and which it overrides.
With downloads turned off, files stay in the desktop, and the workspace’s file browser shows why.
Workspace, user and settings changes, each with the person or system that made it and the time.
Locate the identity provider, access events and recordings. Name the people and systems allowed to read them.
Agree on maintenance approvals and support access. For disconnected sites, include local management, identity and signed update procedures.
Run every test on the browsers and RDP clients the group will use.
Connect single sign-on over SAML or OIDC, including Entra ID, Okta and Google. Assign the pilot group, then test access removal.
Allow or block clipboard, file upload, file download and printing for the group. Groups inherit organization defaults, so set the strict default first and add exceptions per group.
Turn on Session Recording for the groups in scope. Set retention and name the reviewers allowed to watch recordings.
Forward Audit Trail records to your SIEM. Check that access and session events arrive where your security team reads them.
Yes, on Neverinstall Private Cloud. A fully disconnected site runs a separately deployed local Management Console. Nothing phones home, and updates arrive as signed offline bundles.
Only where you allow it. Clipboard, file upload, file download and printing are set per group, and groups inherit organization defaults. Test each rule on the browsers and RDP clients in scope.
A browser or any RDP client. The browser client uses WebTransport and falls back to WebSocket where a firewall or proxy blocks it. Test through your own network configuration.
Yes. Connect single sign-on over SAML or OIDC, including Entra ID, Okta and Google. Assign desktop access by user and role.
You choose the recorded groups, retention period and reviewers. Audit Trail records forward to your SIEM. Storage depends on the deployment, so the deployment review confirms where each record sits.
Neverinstall is SOC 2 Type II attested and ISO 27001 certified. HIPAA is in progress. Request the SOC 2 report under NDA.
Tell us the user groups, record locations and transfer controls in scope. We will map the deployment and plan the controls review.