GoMyid Trust Center

Remote desktop security built as a shared operational responsibility

GoMyid combines encrypted remote connections, explicit access modes, centralized administration, deployment choice, and operational visibility. These controls are most effective when they are supported by secure endpoints, least-privilege access, documented procedures, monitoring, and trained users.

GoMyid remote desktop administration console with sensitive values concealed

Defense in depth

Security is a system of controls, not a single feature

Connection protection, authorization, infrastructure, endpoints, administration, and review each address a different part of remote access risk.

Connection protection

GoMyid uses RSA-based key exchange and AES 256-bit encryption to protect supported remote session traffic in transit.

Access boundaries

Credentials, permissions, operator scope, device assignment, and session mode help define who can perform approved work.

Infrastructure choice

Cloud and On-Premise deployments provide different ownership and operating models for different risk requirements.

Reviewable activity

Available administrative and activity views can support authorized operational review when configured and retained appropriately.

Cloud security responsibilities

DeskGate operates the hosted GoMyid platform environment. Customers remain responsible for authorized account use, administrator assignment, endpoint protection, connection credentials, user approval, business data, and internal policies governing remote activity.

  • Use named accounts where available and review administrator access regularly.
  • Protect account and remote connection credentials from unnecessary disclosure.
  • Maintain supported Windows and Android devices with current security updates.
  • Authorize file transfer, remote command, and control modes according to business need.
  • Report suspected account compromise or unexpected platform behavior promptly.

On-Premise security responsibilities

An On-Premise customer controls the selected hosting environment and network path. The customer also owns hardening and operation of the servers, database, web access, service identities, certificates, firewall rules, backups, monitoring, updates, capacity, and recovery procedures.

  • Restrict platform exposure and segment administrative services appropriately.
  • Limit database, server, and web-console access to authorized personnel.
  • Protect secrets and certificates and define a controlled renewal process.
  • Monitor platform health, security events, storage, and unusual access patterns.
  • Test restoration, failover, and incident procedures before production dependence.
GoMyid activity reporting view for authorized operational review

Visibility and accountability

Use records to investigate and improve

Connection and activity information can help authorized teams understand service use, investigate reported events, support users, and review policy effectiveness. Availability and detail depend on deployment, configuration, licensing, product version, and the customer’s retention choices.

Logs do not replace prevention and should not become an unrestricted surveillance tool. Access to records should be limited, review activity should have a documented purpose, and retention should be proportionate to contractual, operational, and legal requirements.

Read the Transparency & Audit Policy

Deployment checklist

Before remote access goes live

Document ownership and verify controls with representative users, endpoints, and network conditions.

Identity and permission

Approve users and devices, assign the minimum required role, separate administrative duties, and remove access promptly when responsibilities change.

Endpoint readiness

Patch operating systems, use endpoint protection, restrict local privilege, control physical access, and confirm the device is suitable for the data involved.

Data handling

Classify information, define whether file movement is permitted, protect credentials, and align retention with a documented business and legal purpose.

Response and recovery

Assign escalation contacts, protect evidence, establish containment steps, test backups, and document how normal service will be restored.

Important: No remote access product can secure an unmanaged endpoint, weak credential practice, excessive permission, or incorrectly exposed infrastructure by itself. Security depends on product configuration and the customer’s surrounding technical and organizational measures.

Review GoMyid against your security model

Share your deployment boundary, user roles, access modes, data sensitivity, and operational responsibilities with our team.