Defence and engineering

Remote access without an external control plane.

Reach GPU workstations inside infrastructure you operate. Keep identity, certificates, session policy, data location, and licensing under operator control.

Architectural drawing of a user endpoint connected to controlled workstation infrastructure inside one boundary.
One controlled boundary Deck, the network path, and Pier remain inside infrastructure the operator controls.

The problem

Remote access can become an uncontrolled dependency.

A vendor identity service, connection broker, licence check, or certificate authority outside the operating boundary creates a path the operator must continuously trust.

No Arcen broker

Direct means Deck to Pier.

No Arcen-operated system sits between the user and workstation on the direct path.

No Arcen identity

The workstation account remains authoritative.

Linux Piers authenticate through PAM. Windows Piers use the operating-system credential path.

No online licence check

Entitlement verifies locally.

Current node-locked Pier licences verify offline against workstation HostID.

The operator sets the boundary

Control the session channels at Pier.

Policy is attached to the workstation configuration—not chosen by the connecting user.

Clipboard direction

Permit only the required flow.

Allow both directions, one direction, or disable clipboard redirection completely.

Clipboard content

Limit type and size.

Permit text, PNG images, or both, with a maximum encoded transfer size.

Audio output

Disable another egress channel.

Workstation audio can be disabled independently in Pier configuration.

Microphone input

Keep upstream audio off.

Deck microphone publication is controlled independently and packaged off by default.

These controls prevent transfer through the corresponding Arcen channels. They do not prevent photography, endpoint capture, manual transcription, or modification through permitted keyboard, mouse, and pen input.

Trust before credentials

Use the certificate authority you already operate.

With an operator-provided certificate, Deck validates the complete chain against controlled trust anchors before credentials move. A broken or untrusted chain ends the connection with no override.

User endpointArcen Deck
Controlled workstationArcen Pier

Practical questions

What a security or systems administrator needs to verify.

Can Arcen operate without an internet route?

Yes. Direct sessions, operating-system authentication, and current node-locked licence verification have no runtime internet dependency.

Does Arcen operate a root certificate authority?

No. Organisations with internal PKI should provide their own certificates. Arcen asks the operator to retain control of trust anchors.

Does disabling clipboard create a view-only session?

No. View-only requires host-enforced suppression of keyboard, mouse, and pen input. Arcen does not currently make that claim.

Deployment status

Arcen does not claim certification, regulatory approval, compliance, or suitability for a specific classified environment. Operators must assess network architecture, endpoints, release signing, update procedures, and target-native validation against their requirements.

Technical evidence

Inspect the connection and trust model.

Review certificate paths, authentication, session policy, architecture, and offline licensing.

Open the technical page