Remote Support + Endpoint Operations

    See every device.
    Fix it from here.

    One console for help-desk sessions and autonomous endpoint ops. Zero-trust by default, every enterprise control included, no per-seat surprises.

    P2P, TURN fallback  ·  AES-256 encrypted  ·  Sub-500ms sessions  ·  SSO + SCIM standard

    Windows
    Android
    Linux
    iOS
    macOS
    This PC
    This PC
    Desktop
    Downloads
    Documents
    Pictures
    This PC
    Folders (4)
    Desktop
    Documents
    Downloads
    Pictures
    Devices and drives (2)
    Local Disk (C:)
    Data (D:)
    9:41

    Windows

    Not just screen sharing.
    Endpoint operations.

    Everything between "I can see your screen" and actually fixing the problem, built into one session.

    1 agentCross-PlatformSOC 2 Type II audited
    Live Remote View + Control

    A direct line between two screens.

    Technician
    10.0.4.21
    Endpoint
    198.51.100.7
    relay.server
    RTT 142 ms
    4.2 Mbps · adaptive

    Peer-to-peer streaming with adaptive bitrate. Peer-to-peer by default, with an encrypted TURN relay fallback when networks require it. Sub-500ms on typical networks.

    Android Remote Support

    Any Android. Any manufacturer.

    Pixel 8 · Android 14 · OEM-agnostic
    tap here
    2-way voice

    Live screen, two-way voice, and on-screen annotations. Diagnostics and file transfer included. One agent, deployed via MDM.

    Remote Shell + Scripting

    A shell on every endpoint. Even the headless ones.

    shell · edge-controller-07sess #a8f3
    tech@edge-07:~ $ run compliance/cis-l1.sh
    → pulling from managed library …
    142 / 142 controls passed
    tech@edge-07 $ tunnel tcp://localhost:8443 :8443
    tunnel open · forwarding
    tech@edge-07 $ journalctl -u nexus-agent -f
    scripts · 38port-fwdtcp-tunnelheadless OK

    Drop into a session on any desktop, edge device, or robotic controller. Run scripts from a managed library. Forward ports. Tunnel TCP.

    File Transfer + Diagnostics

    Pull what you need. Ship what they need.

    ↓ pulling diagnostics
    bugreport-2026-05-06-0942.zip12.4 MB68%
    logcat-radio.txt848 KB
    tombstone_0342 KB
    ↑ pushing fix
    patch-config.yaml2.1 KB42%

    Bidirectional transfer with progress. Pull diagnostics, logs, and bugreports without asking the user to navigate menus.

    Voice + Annotations

    Talk. Then draw.

    TTech
    UserU
    "tap this one →"

    Two-way voice and live ink on the user's screen. Cuts average resolution time.

    Technician WorkflowsOn the roadmap

    L1 → L2 → L3 without dropping the user.

    L1
    Triage
    Maya R.
    L2 · live
    Specialist
    Devon K.
    L3
    Engineer
    on-call
    #0421A. Patel● live · L2
    #0422M. Choqueued · 0:42
    #0423R. Silvaqueued · 1:15
    4 live2 queuedload-balanced

    Hand off tiers, collaborate live, queue and load-balance.

    Session Recording + Audit

    Every session, indexed and replayable.

    RECsess#0421 · 14:02:1814:32 / 22:51
    Exportaudit.csvevents.jsonvideo.mp4Audit export · JSON / CSV

    Full timeline with chat, events, and escalations. Exportable audit logs in CSV and JSON.

    Unattended Access

    Reach a machine no one is sitting at.

    zZz
    Asleep
    magic packet
    FF·FF·FF·FF·FF·FF
    Awake · ready
    UAC elevation handled · admin prompt auto-acknowledged

    Linux on Wayland as shipped, at the GDM or SDDM greeter, a locked screen, or a device fresh from reboot. No Xorg fallback, no WaylandEnable=false. Windows and macOS unattended included.

    On the roadmap Wake-on-LAN, automatic UAC acknowledgement.

    Device Fleet Management

    From a handful to a hundred thousand.

    Tags & groups
    prod / kiosk1,284
    region · EU412
    edge-compute96
    policy-violation3
    enrollQR
    enrollCLI
    enrollOAuth

    Groups, tags, group-based policies. Enrollment via QR, CLI, managed app config, or OAuth device-code. Bulk provisioning for fleet rollouts.

    → one session

    Every operation above runs through the same agent and the same secured channel, so a session that begins as a chat can end with a fleet-wide policy push, without re-authenticating, re-installing, or re-explaining.

    See the full session →

    Linux + Edge

    Linux fleet operations for edge AI and robotics.

    See, control, script, and repair unattended Linux devices from a browser. One native agent for Ubuntu, Debian, Yocto, and custom images. Desktop or headless. x86_64 and arm64.

    0 desk visits1 agentWayland-native
    Reach

    A session on every device. Even the ones with no display.

    edge-node-14 · headless · arm64no display
    root@edge-node-14 # systemctl restart vision-inference
    vision-inference.service active (running)
    streams cam0 (USB) · cam1 (RTSP) · virtual-display-1
    tunnel tcp://localhost:8554 → :8554 open
    root@edge-node-14 # journalctl -u vision-inference -f
    GDM / SDDM greeterlocked screenpost-rebootheadless OK

    On a desktop, at the login screen, or on a device with no display at all: a terminal as any login account, file transfer, service and process control, TCP tunnels, and diagnostics.

    multi-stream viewUSB camerasvirtual displaysyour RTSP feedslocal or cloud recordingPAM / polkit still required
    Self-heal

    The rule engine runs on the device. Nobody has to be watching.

    vision-inference-recoverrisk L2
    triggerprocess exitedKilled (OOM)
    step 1restart-vision.sh✓ exit 0
    step 2if/branch service active?✓ true
    step 3notify PagerDutyskipped
    cooldown 10mmax 6/hrauto-disable after 3

    A crash is matched on the agent, in-process, in microseconds. Remediate and verify, so the next step branches on whether the fix actually worked.

    OOM killservice stoppedperformance thresholddevice offlinerisk L0 to L4email · PagerDuty · Opsgenie · webhooks
    Operate

    Enroll at image time. Run the fleet by tag.

    # .deb, one line$ curl -sSL https://get.deviceview.ai | sudo bash -s -- --token nxhe_a8f2…
    # or baked into your Yocto image at build timeenrollment token · limit 500 devices · expires 30d
    dispatch--tag edge-ai-nodespush-model-v14.sh
    result412 targeted · 412 dispatchedstreaming

    Tags, groups, and group policies, with batch dispatch to any device group. Model rollouts use the same primitives: push, restart, verify by script.

    versioned Bash libraryevery run auditedone-line .debYocto image baketoken limits + expiry
    Trust

    Operator identity, not OS bypass.

    14:02:18session.startedge-node-14 · greeter · operator m.tan (SSO: Okta)
    14:02:19auth.pamsudo · root · granted on device
    14:06:41script.runrestart-vision.sh · exit 0 · recorded (local)
    14:07:02session.end3m 44s · export: json
    SOC 2 Type II passedISO 27001 certified

    SSO (SAML / OIDC), SCIM, RBAC, and exportable audit logs in every tier, including the free one. No OS bypass: privileged actions still require PAM or polkit on the device.

    org-scoped data isolationAES-256 sessionsTLS 1.3 control planeWebRTC P2P + TURN

    The Pilot tier is self-serve: 5 devices, every Standard feature, no card. Standard is $1 per device per month. Install on a test device with a one-line command, then bring your stack to a DeviceView Linux engineer for compatibility validation: distribution, desktop environment and login manager, or your headless image. A technical conversation, not a sales demo.

    Zero-Trust Security

    Passes your security review.
    Not eventually. Today.

    SSO, SCIM, RBAC, and audit log in every tier, including the free Pilot.

    • SSO via SAML 2.0 / OIDC: Okta, Azure AD, Google Workspace, OneLogin, Ping, or any compliant provider
    • SCIM provisioning and deprovisioning for automated user lifecycle management
    • Role-based access control
    • Org-scoped data isolation, not row-level filtering
    • Consent-to-connect prompts, visible session indicators, and end-user session termination

    DeviceNexus, the company behind DeviceView, is SOC 2 Type II audited, and DeviceView is in scope of that audit. DeviceNexus holds ISO 27001 certification. The report and certificate are available under NDA.

    On the roadmap

    • Adaptive MFA with impossible-travel detection and org-level enforcement
    • Just-in-Time access: time-bound, approval-gated access to sensitive endpoints
    Security Audit LogReal-time
    Filter
    CSV
    TimeEventActionUserRoleDetail
    Just nowauth.ssoSSO login via Okta SAMLschen@acme.ioOperatorSAML assertion
    1m agoscim.syncSCIM provisioned from Azure ADmlopez@acme.ioViewerAuto-assigned
    3m agosession.startubuntu-edge-07 · Wayland · operator m.tan (SSO)mtan@acme.ioOperatorUnattended
    5m agoconsent.acceptend-user prompt accepted · policy: attendedjtan@acme.ioOperatorIndicator shown
    8m agoscript.runrestart-vision.sh · exit 0 · recorded (local)mtan@acme.ioOperatorLocal recording
    12m agorbac.updateRole: Viewer → Operatordpark@acme.ioOperatorBy admin@acme.io
    15m agoaudit.exportjson · 1,204 eventsadmin@acme.ioAdminExported
    Showing 1-7 of 12,489 events
    Previous
    1 / 1,784
    Next

    Integrations

    Plugs into your stack. Doesn't replace it.

    Launch sessions from tickets. Write results back automatically. Export audit logs as JSON or CSV. Connect to your MDM.

    ServiceNow
    Launch sessions from incidents. Auto-log session data back to the ticket.
    Zendesk
    Initiate remote support from any Zendesk ticket. Session details sync automatically.
    Jira Service MgmtOn the roadmap
    Session launch and writeback. Bidirectional sync between JSM and DeviceView.
    Preferred EMM
    Launch sessions from MDM device views. Inherit compliance state. See policy violations in context.
    SIEM / SyslogOn the roadmap
    Export session audit logs to Splunk, Datadog, Sentinel, or any syslog endpoint. Natively.
    Webhooks + REST API
    Public API with session, device, and org endpoints. Webhooks for real-time event integration.
    SSO Providers
    Okta, Azure AD, Google Workspace, OneLogin, Ping, or any SAML 2.0 or OIDC provider.
    SCIM Provisioning
    Automated user lifecycle. Create, update, and deprovision technician accounts from your IdP.

    Honest Comparison

    How DeviceView stacks up

    We ship what others roadmap. Claimed features are what's live today, not what's "coming soon."

    Swipe to compare →
    FeatureDeviceViewIncumbent AIncumbent B
    SSO (SAML / OIDC) included✓ All plansEnterprise onlyEnterprise only
    SCIM provisioning✓ IncludedAdd-on
    Session recordingLocal in every tier; cloud in EnterpriseEnterprise only
    Android remote support✓ Screen sharing + voice + annotationsOEM dependent✕ View only
    Peer-to-peer WebRTC✓ Direct P2PServer-relayedServer-relayed
    Cross-platform (Android, iOS, macOS, Win, Linux)✓ All fiveDesktop focusDesktop + Android
    Multi-tenant with org-scoped data isolation✓ Org-scopedRow-level onlyLogical separation
    Remote shell + script execution✓ With library
    EMM / MDM integration✓ Preferred EMM bridge✕ Third-party only✕ Third-party only
    Pricing

    Pricing simple enough to fit on a sticky note.

    Pilot

    Free

    5 devices, every Standard feature, no card required.

    StandardMost popular

    $1 per device

    $20/month covers your first 20. Billed on actionable devices only.

    Enterprise

    Custom

    Advanced RBAC, cloud recording, self-hosted options, SLA.

    SSO, SCIM, RBAC, and audit log are in every tier, including the free one.

    Why it's different

    Designed around today's endpoints, identities, and networks.

    Mobile-minded, peer-to-peer, identity-native.

    Mobile included, not upsold

    Live remote screen sharing, two-way voice, and annotations on Android and iOS. Full remote control on macOS, Windows, and Linux. No hidden fees.

    Sessions stay peer-to-peer

    Peer-to-peer by default, with an encrypted TURN relay fallback when networks require it. Org-scoped data isolation by default.

    Enterprise identity, standard tier

    SSO, SCIM, RBAC, and audit log in every tier, including the free Pilot.

    Calculate your savings

    Architecture

    Built right. Measured.

    Built for enterprise-grade remote operations, from mobile fleets to edge AI infrastructure.

    P2P
    Connection Model
    WebRTC direct, TURN relay fallback
    <500ms
    Session Start
    Typical network conditions
    AES-256
    Encryption
    WebRTC + REST + SSE paths
    TLS 1.3
    Control Plane
    Console, API, and signaling transport
    RS256
    Token Signing
    JWT with asymmetric keys

    Built for MSPs

    Multi-tenant from day one.
    Not bolted on after.

    Every organization gets org-scoped data isolation, not a shared database with permission filters. Built for providers managing hundreds of client orgs.

    • Org-scoped data isolation with dedicated key material
    • Group-based policies: access rules, recording requirements, and compliance settings per device group
    • SCIM-driven user lifecycle. Onboard and offboard technicians automatically from your IdP
    • Org branding with logo and primary color.
    • Enrollment tokens with usage limits and expiry for controlled device onboarding
    • Domain auto-join with DNS TXT verification
    Start free
    enrollment: deployment options
    # QR enrollment (mobile)$ deviceview enroll --qr --org acme-west# CLI enrollment (headless)$ deviceview enroll --token nxhe_a8f2... \ --group "warehouse-scanners"# Edge device enrollment (headless Linux)$ deviceview enroll --token nxhe_a8f2... \ --group "edge-ai-nodes" --tags "vision,floor-2"# MDM managed config (bulk)$ deviceview config --generate plist deviceview.mobileconfig # deploy via MDM# Device-code flow (OAuth, headless desktop)$ deviceview enroll --device-code Visit: deviceview.ai/activate Code: ABCD-1234

    EMM / MDM Integration

    Standalone or integrated.
    Your call.

    DeviceView slots into whatever EMM or MDM you already run. No rip-and-replace required. For the deepest integration, pair it with our preferred EMM and launch sessions from the device inventory with compliance state already in view.

    • Works alongside your existing EMM, MDM, or UEM. Deploy agents via managed app config
    • With our preferred EMM, launch remote sessions straight from the device inventory
    • Compliance context flows into every session. See policy state before you touch anything
    • One fleet, one identity layer, one audit trail regardless of stack
    Preferred EMM
    Native bridge, not a plugin
    Warehouse-Scanner-14
    Android 14 · Compliant · Last check 2m ago
    MacBook-S.Chen
    macOS 15.2 · Non-compliant: disk encryption
    Edge-Inference-Node-3
    Ubuntu 22.04 · Compliant · Last check 5m ago

    HIPAA-READY REMOTE SUPPORT

    Fix the kiosk. Not your compliance posture.

    Privacy Mode blacks out patient-facing screens the instant you connect remotely. No PHI exposed to the waiting room, no audit findings, no incident reports. Your team keeps full visibility. The device shows nothing but your desired message.

    Clinical carts, imaging workstations, telehealth endpoints: when remote access touches devices that handle PHI, the controls are the point.

    • Screen goes dark before a single byte renders publicly. Zero PHI exposure window
    • Touch and input locked so walk-up patients can't interrupt mid-session
    • Every activation logged with operator, device, timestamp. Export-ready for compliance audits
    • Custom overlay with your facility branding and multilingual messaging
    08:17
    Privacy Mode ActiveAuthorized maintenance in progress
    Screen locked
    Touch disabled
    Audit logged
    YourFacility

    Get Started

    One platform. Every device.
    No surprises.

    Contact us for a live demo or to discuss your deployment.

    DeviceView is a product of DeviceNexus, Inc. Submissions are processed by DeviceNexus.

    DeviceView on PeerPush

    We use cookies to understand how you use DeviceView.