Security, by design

Remote access is only as trustworthy as its foundations. Here's what protects every DaniLink session — stated plainly, with no hype.

End-to-end encrypted

Your screen travels peer-to-peer over encrypted WebRTC (DTLS-SRTP) — it never passes through our servers. A TURN relay only ever carries encrypted traffic, and only when a direct path isn't possible.

You approve every connection

The person at the machine grants access with an explicit Accept. There's no shared, guessable password to leak or crack.

Cryptographic device identity

Every host proves who it is with its own cryptographic key, so trust is anchored to the device itself — not to a password anyone could type in.

Passwordless accounts

Sign in with a magic link sent to your email. We never ask you to create a password, and we never store one.

Unattended access, deliberately authorized

Reaching your own device without someone present requires a cryptographically authorized, deliberate opt-in — and you can revoke any device's access remotely, anytime.

Post-quantum-ready

Post-quantum-hybrid TLS and AES-256 protect your traffic today, with a crypto-agile signature path so we can keep pace as standards evolve.

Private by design

We never log or store session content. Your account data is hosted in the EU, and you can delete your account at any time.

Signed updates

The installer and every update are cryptographically signed and verified before they run — nothing reaches your device unverified.

Continuously reviewed

The architecture undergoes regular, rigorous security review as we build — security is treated as an ongoing practice, not a one-time checkbox.