Credentials never reach the browser
Secrets are injected server-side. The tab never sees a password.
clientless · zero inbound ports
Browser-based RDP, VNC, and SSH to any host — even behind firewalls and NAT. Nothing to install. Credentials never leave the gateway.
01the old way
VPNs & jump boxes
LazyConMan
02how it works
One outbound TLS tunnel, multiplexed — private hosts reachable with zero inbound ports.
A small agent opens the reverse tunnel. Firewalls only see outbound TLS — nothing to open.
Pick a target; the gateway authorizes you, mints a short-lived token, and routes through the right connector.
RDP and VNC paint to a canvas, SSH to a real terminal — credentials injected gateway-side, never sent down.
04security model
Secrets are injected server-side. The tab never sees a password.
Connectors dial out over mutual-TLS. The gateway never reaches into your network.
TOTP before any access — and every session gets its own short-lived token.
Every row scoped by org with Postgres row-level security and a per-org encryption key.
Who connected to what, when, and for how long — recorded per tenant.
Only the control plane is public. Engine, database, and targets stay hidden.
05what you get
GUI desktops
Windows, Linux, and macOS desktops in the browser — no plugin, no client.
Shells
Full xterm — copy, paste, resize, scrollback — over the same tunnel.
Reach
If the connector can dial out, you can reach the host. No public IP, no port forwarding.
Teams
Owners, admins, operators — each scoped to only the targets they're granted.
06pricing
For a single team getting started.
Room to grow across environments.
For broad, multi-environment access.
Converts to a paid plan via Stripe when you're ready. Cancel anytime.
Up in minutes — no inbound ports, no client install, no credentials on the wire.
Start your free trial7-day trial · no card required