Skip to content
Vision Central

Self-hosted remote management

Your entire fleet.
One console.

Vision Central gives IT teams and MSPs web-based remote desktop, terminal and file access to every managed device — running on infrastructure you own, not someone else's cloud.

Vision Central console — device list showing the managed fleet with live connection status
100%
Self-hosted — your servers, your data
13+
OS platforms — Windows, macOS, Linux, BSD, Android
1 min
From agent install to full control
TLS
Encrypted agent–server–browser, end to end

Capabilities

Everything between you and the device, removed.

Remote Desktop

Full KVM control of any device from the browser. Multi-monitor, clipboard sync, session recording — no client software on the technician side.

Web Terminal

A real shell on any managed device, straight from the console. PowerShell, bash or sh — without juggling SSH keys and VPNs.

File Access

Browse, upload, download and edit files on remote devices. Push a patch to one machine or a whole device group.

Out-of-band with Intel AMT

Power on, reboot and take KVM control below the OS. Reach machines that are powered off, crashed or mid-reinstall.

Monitoring & Events

Live presence for the entire fleet, hardware and software inventory, and a full event stream with email and messenger alerts.

Hardened Access

Two-factor sign-in with TOTP or hardware keys, per-group permissions, and an audit trail of every remote session.

How it works

Running in an afternoon, not a quarter.

  1. Deploy your server

    One Node.js service on a VM you control — on-prem or any cloud. Your certificates, your domain, your database.

    npm install vision-central && node node_modules/meshcentral
  2. Enroll devices

    Generate a one-line installer per platform from the console. Agents connect outbound — no inbound ports, no VPN, NAT is not a problem.

    msh installer → Windows · macOS · Linux · BSD · Android
  3. Take control

    Devices appear in the console within a minute. Open desktop, terminal or files for any of them — from any browser, anywhere.

    desktop · terminal · files · power · inventory

Security

Remote access your security team can sign off on.

Data sovereignty by default
The server, the database and every recorded session live on hardware you control. Nothing transits a third-party cloud.
Encrypted end to end
TLS on every hop — browser to server, server to agent. Agents authenticate with certificate hashes, not passwords.
Strong authentication
TOTP two-factor, FIDO2/WebAuthn hardware keys and per-account lockout policies for console access.
Accountable by design
Per-user, per-group permissions and a complete audit log: who connected to which device, when, and what they did.
audit stream — liveconnected
12:03:41agent connect — WS-FRONT-04 (cert verified)
12:03:42tls 1.3 channel established
12:05:10auth ok — admin@fv (totp + webauthn)
12:05:33desktop session → WS-FRONT-04 (recorded)
12:18:02session closed — audit entry #84122 written

FAQ

Common questions

Take command of your fleet.

Tell us about your environment and we'll walk you through a live deployment — or sign in if your organisation is already on board.