Defence and engineering

Engineers work remotely. The operating boundary does not move.

Reach Linux or Windows GPU workstations from macOS Deck while identity, trust, session policy, traffic, and licence verification remain in systems you operate.

Hand-drawn operator endpoint connected by one copper route through two controlled partitions to a GPU workstation and storage.
Current direct path One route across operator-controlled segments.

The operating problem

Remote access fails the requirement when it adds an outside dependency.

A vendor identity service, connection broker, licence check, or certificate authority outside the operating boundary creates a system the operator must continuously reach and trust.

Connection

Deck connects straight to Pier.

Today the operator's network must provide the route. If Deck cannot reach Pier, no direct session forms.

Identity

Your workstation account stays authoritative.

Linux Piers authenticate through PAM. Windows Piers use the operating-system credential path.

Entitlement

Pier licences verify offline.

Current node-locked Pier licences verify offline against workstation HostID.

Connection paths

Direct and Span solve different network problems.

Direct is the current one-to-one path over an operator LAN or VPN. Planned Span adds one customer address, group-filtered discovery, and either a gateway stream or a policy-approved direct handoff.

Hand-drawn laptop connected by one uninterrupted copper span directly to a single GPU workstation.
Current — Direct One Deck reaches one known Pier over the operator's LAN or VPN.
Hand-drawn topology with several Deck work surfaces converging on one customer gateway, then branching through a policy filter to an authorized subset of workstation resources.
Planned — Span One address filters Piers, then uses a gateway stream or direct handoff.

Trust before credentials

Use your PKI—or verify first contact yourself.

Pier supports an operator-provided certificate or a Pier-generated self-signed certificate. Both paths resolve trust before the workstation receives credentials.

Hand-drawn certificate chain attached to an operator-controlled trust anchor.
Operator certificate

Trust follows your chain.

Deck validates the complete chain against trust anchors you control. A broken, expired, or untrusted chain ends the connection with no override.

Hand-drawn self-signed certificate fingerprint connected to a separate verification token.
Pier-generated certificate

Trust starts with a fingerprint.

Deck shows the SHA-256 fingerprint on first contact. Verify it out of band before acceptance; later change is a hard refusal.

Host-authoritative policy

The gates sit at the workstation.

Pier defines the permitted session channels. The connecting user cannot widen clipboard, audio, or microphone policy from Deck.

Hand-drawn workstation cabinet controlling four physical session conduits.
Policy remains at Pier Permitted channels leave the workstation through host-controlled gates.
Clipboard direction

Permit the required flow.

Allow both directions, one direction, or disable clipboard completely.

Clipboard content

Limit type and size.

Permit text, PNG images, or both within a host-defined transfer limit.

Audio output

Open or close the egress channel.

Workstation audio is controlled independently in Pier configuration.

Microphone input

Control upstream audio separately.

Deck microphone input is independently configured. The packaged default is disabled.

These settings govern the corresponding Arcen channels. They do not prevent photography, endpoint capture, manual transcription, or modification through permitted keyboard, mouse, and pen input.

Operational ownership

Know what remains yours to operate.

Arcen removes runtime dependence on an Arcen service. It does not remove the operator's responsibility for identity, trust, network reachability, approved software, and deployment procedure.

Releases

Control how software enters the environment.

Assess installers, signing, update transport, rollback, and target-native validation against your process.

Trust and identity

Keep existing lifecycle authority.

Workstation accounts and operator trust anchors remain the systems of record.

Licensing

Provision entitlement per Pier.

Current node-locked entitlement is tied to workstation HostID and verifies without a runtime network service.

Continuity

Operate the installed path locally.

Direct sessions, OS authentication, and current licence verification do not require Arcen or the internet to be reachable.

Operational evidence

Ask to see the real control surfaces.

These frames remain reserved until genuine product captures can show the evaluator exactly what is installed, configured, and refused.

Generated interfaces are never used as product proof.

Known limits

Controls are useful only when their boundary is explicit.

Does disabling clipboard create a view-only session?

No. View-only requires host-enforced suppression of keyboard, mouse, and pen input. Arcen does not currently make that claim.

Do channel controls prevent every form of extraction?

No. They control the corresponding Arcen channels; they cannot prevent photography, endpoint capture, or manual transcription.

Does Arcen claim certification for a classified environment?

No. Arcen makes no claim of certification, regulatory approval, compliance, or suitability for a specific classified environment.

Deployment status

macOS Deck with Linux and Windows Pier is the current platform path. Customer-hosted Arcen Span is planned. Operators must assess network architecture, endpoints, release signing, update procedures, and platform validation against their requirements.

Technical evidence

Inspect the connection and trust model.

Review certificate paths, authentication, session policy, architecture, and offline licensing.

Open the technical page