Direct means Deck to Pier.
No Arcen-operated system sits between the user and workstation on the direct path.
Defence and engineering
Reach GPU workstations inside infrastructure you operate. Keep identity, certificates, session policy, data location, and licensing under operator control.
The problem
A vendor identity service, connection broker, licence check, or certificate authority outside the operating boundary creates a path the operator must continuously trust.
No Arcen-operated system sits between the user and workstation on the direct path.
Linux Piers authenticate through PAM. Windows Piers use the operating-system credential path.
Current node-locked Pier licences verify offline against workstation HostID.
The operator sets the boundary
Policy is attached to the workstation configuration—not chosen by the connecting user.
Allow both directions, one direction, or disable clipboard redirection completely.
Permit text, PNG images, or both, with a maximum encoded transfer size.
Workstation audio can be disabled independently in Pier configuration.
Deck microphone publication is controlled independently and packaged off by default.
These controls prevent transfer through the corresponding Arcen channels. They do not prevent photography, endpoint capture, manual transcription, or modification through permitted keyboard, mouse, and pen input.
Trust before credentials
With an operator-provided certificate, Deck validates the complete chain against controlled trust anchors before credentials move. A broken or untrusted chain ends the connection with no override.
Practical questions
Yes. Direct sessions, operating-system authentication, and current node-locked licence verification have no runtime internet dependency.
No. Organisations with internal PKI should provide their own certificates. Arcen asks the operator to retain control of trust anchors.
No. View-only requires host-enforced suppression of keyboard, mouse, and pen input. Arcen does not currently make that claim.
Arcen does not claim certification, regulatory approval, compliance, or suitability for a specific classified environment. Operators must assess network architecture, endpoints, release signing, update procedures, and target-native validation against their requirements.
Technical evidence
Review certificate paths, authentication, session policy, architecture, and offline licensing.
Open the technical page