ES
Secure remote access · On-premise + Cloud

Secure OT remote access.
With real auditing.

Tridenty SRA is a secure remote access platform for industrial OT/IT environments: SSH, RDP, VNC and HTTP sessions from the browser, with no VPN and no agents on target machines, per-access approval, on-premise recording and an immutable audit log. Session traffic never touches the cloud.

AES-256-GCM · RSA-2048 · Access Request Flow · Multi-site

Get started See features
AES-256-GCM
Credential encryption
RSA-2048
Communication signing
0
Agents on target servers
100%
On-premise traffic
Access Request Flow

No technician connects without admin approval

Every connection goes through a real-time authorization flow. The admin decides who gets in, when and to what. Without approval, the session never opens.

1

Technician requests access

From the dashboard, the technician selects the connection they need and submits the request, including the reason for access.

2

Admin receives a real-time notification

The administrator sees the request instantly on their screen, with the technician's name, the requested connection, and the reason.

3

Admin approves or denies

One click decides. If approved, the session opens automatically for the technician. If denied, the technician is notified with the reason.

4

Everything is logged

Every request, decision and session is recorded in the audit log with timestamp, user and duration. Nothing happens without a trace.

Why does this matter? In most companies, technicians have permanent access to servers. With Tridenty SRA, access is one-time, justified and approved. The admin knows in real time who is connected, why, and can revoke access at any moment.

What Tridenty SRA includes

Each feature exists because remote access without auditing is a risk, not a tool.

SSH · RDP · VNC · HTTP from the browser

Open interactive remote sessions with nothing installed on target servers, including internal device-management web panels. The session stream goes directly from the browser to your infrastructure.

Session recording

SSH text and RDP/VNC video stored on-premise. Optionally uploaded to the cloud at session close. Retention configurable per plan.

Dual RSA pair + AES-256-GCM

Two independent key pairs guarantee identity and non-repudiation between backend and agent. Connection credentials travel encrypted with AES-256-GCM.

Multi-site · Multi-tenant

Deploy agents across multiple physical sites from a single platform. Full per-organization isolation: no tenant sees another's data.

2FA / TOTP

Mandatory second factor for all users. Compatible with any standard authenticator app.

Full audit log

Immutable record of every action: session open/close, access requests, role changes, admin operations.

No agent on target servers

The Tridenty SRA agent runs in your infrastructure, not on the servers you want to protect. Native SSH, RDP and VNC: no changes to your existing systems.

Granular roles

Admin, technician and observer with connection permissions per user and per role. Each role defines exactly what can be seen and done.

Connection Groups

Group related connections and assign permissions by group instead of one connection at a time.

Time-slot reservations

Each connection supports one-time requests, permanent access, time-slot reservations, or a combination. Reservations open and close on their own, no manual step required.

Shared clipboard

Copy and paste text between your machine and the remote session, without leaving the browser.

File transfer

Upload and download files directly during the session, without leaving the remote workflow.

Hybrid architecture: cloud + on-premise

The frontend and API backend run on Vercel. The Tridenty SRA agent runs on your server, inside your network. Session traffic (SSH/RDP/VNC) goes directly from the browser to the agent through a secure tunnel, bypassing the cloud. The backend only processes HTTPS REST.

Frontend + Backend API
Vercel · cloud
Agent + guacd + Nginx
Your server · on-premise
Target servers
Nothing installed

Security model

AES-256-GCM end-to-end encrypted credentials
Auth Grant signed with backend RSA private key
RSA X-Signature on every agent → backend request
Session JWT never circulates between agent and backend
Rate limiting · strict CORS · CSP on the frontend
Full multi-tenant isolation by organization_id

Plans

From exploring the platform to covering multiple sites with full retention.

Free
$0/mo
$0/yr
  • 3 users · 5 connections · 1 site
  • SSH · RDP · VNC
  • 2FA + Access Request
  • Basic audit log
  • Automatic backend RSA rotation
  • ✗ Session recording
  • ✗ Agent RSA rotation
Get started
Basic
$300/mo
$3,600/yr
  • 10 users · 25 connections · 1 site
  • Everything in Free +
  • Full audit log
  • On-premise recording (30 days)
  • ✗ Cloud recording
  • ✗ Agent RSA rotation
Get started
Most popular
Pro
$600/mo
$7,200/yr
  • 30 users · 75 connections · 2 sites
  • Everything in Basic +
  • On-premise recording (60 days)
  • Cloud recording (90 days)
  • ✗ Agent RSA rotation
Get started
Max
$1,000/mo
$12,000/yr
  • 80 users · 200 connections · 4 sites
  • Everything in Pro +
  • On-premise recording (90 days)
  • Cloud recording (180 days)
  • Agent RSA rotation included
  • Priority technical support
Get started

Add-ons — Capacity extensions

Available for Basic, Pro and Max plans. Activated and deactivated monthly.

Base capacity

  • +10 extra users $48/mo
  • +10 extra connections $36/mo
  • Unlimited connections $220/mo
  • +1 extra site $88/mo

Recording & retention

  • Enable cloud recording (Basic) $72/mo
  • +30 days on-premise retention $32/mo
  • +30 days cloud retention $56/mo
  • Unlimited cloud retention $196/mo

RSA security

  • Agent RSA rotation (Basic/Pro) $60/event

Backend RSA rotation is included in all plans at no extra cost.

FAQ

Tridenty SRA FAQ

What is Tridenty SRA?

Tridenty SRA is a secure remote access platform for industrial OT/IT environments. It opens SSH, RDP, VNC and HTTP sessions from the browser, with approval of every access, on-premise session recording and an immutable audit log of every action.

Do I need a VPN or to install anything on target machines?

No. The Tridenty SRA agent runs on a server in your network, not on the machines you want to protect. Target servers, HMIs and PLCs are reached over native SSH, RDP, VNC or HTTP, with nothing installed on them and no VPN.

Does session traffic go through the cloud?

No. The frontend and API run in the cloud, but session traffic goes directly from the browser to the agent in your network through a secure tunnel. Connection credentials travel encrypted with AES-256-GCM.

How is technician and vendor access controlled?

With the Access Request Flow: the technician requests the connection with a reason, the admin sees the request in real time and approves or rejects it. Each connection also supports permanent access or scheduled reservations, and everything is logged with user, time and duration.

Are remote sessions recorded?

Yes. SSH sessions are stored as text and RDP/VNC as video, on-premise and optionally in the cloud. Retention depends on the plan: from 30 days on-premise on Basic to 90 days on-premise and 180 in the cloud on Max.

How much does Tridenty SRA cost?

There is a free plan (3 users, 5 connections, 1 site) and Basic (USD 300/mo), Pro (USD 600/mo) and Max (USD 1,000/mo) plans, with add-ons for users, connections, sites and retention.

Start for free today

Create your account, deploy the agent on your server, and open your first secure remote session in under 15 minutes.

Get started