Browse documentation
AvailableSecurity & Privacy

Remote Access Security

The bounded security design behind remote dashboard access.

Applies to
OZVO Remote Portal
Product area
Security & Privacy
Audience
Owners and Administrators
Last reviewed
September 17, 2026
Status
Available

Guidance

  • OIDC, MFA, secure short-lived sessions, and exact authorization protect the browser path.
  • The appliance uses an outbound-only authenticated relay.
  • Routes are allowlisted and local authorization is rechecked.

How the remote path works

The browser signs in to the OZVO Remote Portal with OIDC and MFA. The portal applies tenant, site, and role authorization, then relays only allowlisted dashboard routes through the authenticated broker to the outbound connection initiated by OZVO Edge.

Security controls

  • OIDC authorization-code flow with PKCE
  • MFA and fresh authentication for sensitive changes where implemented
  • Exact tenant, site, and role authorization
  • Short-lived, secure, HttpOnly sessions
  • TLS and authenticated appliance identity
  • Outbound-only appliance relay and route allowlisting
  • Auditing, revocation, local authorization rechecks, and fail-closed behavior

What remote access is not

  • No inbound router port-forward
  • No Internet-exposed SSH
  • No arbitrary TCP tunnel
  • No standing support access created by a support approval record
  • No dependency for normal local dashboard operation
Still need help?Contact Support with the site, device, time, and exact error—never credentials or recovery secrets.Contact Support