End-to-end encryption
Control and media are encrypted between endpoints
Relay forwards ciphertext and connection metadata needed for routing. It does not need screen, keyboard, clipboard or file plaintext.
JDesk combines device identity, short-lived connection grants, end-to-end encryption, minimal Relay visibility and explicit audit boundaries. The browser manages access; trusted native clients hold remote-session keys.

Relay forwards ciphertext and connection metadata needed for routing. It does not need screen, keyboard, clipboard or file plaintext.
Account state, device identity, entitlement, policy and target authorization are checked before a short-lived grant is issued.
Enterprise audit media is produced by endpoints and stored through the audit-storage path; Relay remains blind to remote-session plaintext.
Core remote access remains simple; advanced performance and governance are enabled by published entitlements.