Security
The consent model, what is never recorded, and where the data sits. The questions a business buyer asks, in order.
Consent is a step that cannot be switched off
Approval is asked again on every session, and it is not a setting; there is no place to turn it off. If the connection drops, so does the permission. This is the product's behaviour, not its marketing line.
There is no recording feature
SessiONN does not record video. This is not an option that ships disabled; no such capability was written into the product. There is no keylogger either.
Clipboard and file content are not stored
The text you copy and the content of files you transfer are never written anywhere. Only the event is logged: direction, type, size, time. So it is known that a file moved, not what was inside it.
Passwords are irreversible
Account passwords, the terminal secret and the unattended access password are stored only as hashes. The plain values are not in the database; we cannot read a forgotten password back to you, only reset it.
The address is encrypted, the trail is hashed
The network address needed to connect is stored encrypted with AES-256-GCM, and the key is not in the database. The address in the audit trail is an irreversible hash. If a database backup left the building on its own, the addresses would be unreadable.
The address is live data, not history
When a terminal goes offline its connection address is cleared. SessiONN keeps no record of where a user was on any given date.
Transport is encrypted with TLS
All traffic is encrypted in transit with TLS. The relay does not inspect content and does not record frames; its log holds only a masked connection code, the channel and the time.
Not end to end, yet
To be straight about it: today the stream is decrypted at the server. An end to end layer, where the server can never see the content, is planned but not live. We do not present an unbuilt safeguard as if it existed; in a business evaluation you need to know that difference.
Data stays in Türkiye
The servers are in Istanbul and there is no onward transfer abroad. For users in the European Union this means processing outside the EU; the detail is in the privacy policy.
Unattended access is never hidden
Connecting without asking each time is possible only if the device owner sets it up themselves. It is tied to a person, needs a separate password, and can be revoked at any moment. There is no mode of access concealed from the user.