This page summarises how Sunlogin approaches transport encryption, authentication, permission control and auditability, for security review and compliance checks.
Transport security
Session data is encrypted end to end; direct and relayed paths use equally strong channels, and relay nodes cannot decrypt content.
- Encrypted end to end
- Equal protection direct and relayed
- Relay nodes cannot read content
- Configurable encryption policy
Identity and permissions
Connections require account verification and the device can demand an access code; capability-level permissions (files, command line, camera) switch separately.
- Two-way account and device verification
- Device-level access code
- Capability-level switches
- Two-factor authentication and time policies
Auditing and traceability
Session records, sensitive operations and recordings can be searched and exported, with retention and access control for audit needs.
- Session and operation trails
- Recordings retained as needed
- Searchable, exportable logs
- Access to audit data requires authorisation
FAQ
Is private deployment available?
Enterprise can evaluate private or dedicated-environment deployment; confirm scope with the business team.
How are security incidents handled?
Change credentials, force sessions offline and review logs immediately. For vulnerabilities, report through official channels and the security team follows up.