Remote access you can host inside your own perimeter

Remote access tools that can run on infrastructure you control, rather than only through a vendor's cloud. Useful if you work under data-residency rules, need the relay inside your own network, or simply want the option to move off SaaS later.

The selection criterion is narrow on purpose: every entry here can be deployed on your own server, either as the full product or as a self-hosted relay/gateway. Some are fully open source, some are commercial with a self-hosted tier — that difference is noted per entry.

Disclosure: this list is maintained by the Vexaro team, so we have a stake in this category. Everything below is a third-party tool, and we tried to describe each one by what it actually does rather than how it compares to us.

vexaro_llc
vexaro_llcList by vexaro_llc, last updated 
Copy a direct link to this comment to your clipboard
  1. A clientless gateway: it speaks RDP, VNC and SSH on the back end and renders the session into an ordinary browser tab. You host the gateway, so it sits at your own network edge and the operator installs nothing. Best fit when you want browser-only access to hosts that already run RDP, VNC or SSH.

    Cost / License

    • Free
    • Open Source

    Application type

    Platforms

    • Linux
    • Self-Hosted
    • Cloudron
    Apache Guacamole screenshot 1
    Apache Guacamole screenshot 1
  2. DWService icon
     Like

    Open source agent plus server, with the operator working from a plain browser. The hosted service is free to use, but the entire stack can be run on your own server instead — which is what earns it a place here. Also does file access and a shell, not only screen control.

    Cost / License

    • Freemium
    • Open Source

    Application type

    Platforms

    • Mac
    • Windows
    • Linux
    • Android
    • Raspberry Pi
    It allows you to fully control the remote system by displaying its screen and allowing cursor control and keyboard input
    It allows you to fully access the file system of the remote system
    It allows you to monitor the status of the remote system
    +5
    It allows you to start a terminal session on the remote system.
  3. Self-hosted RMM rather than a remote-desktop tool: agent management, scripting, monitoring and alerting, with remote control provided through MeshCentral. Included because it is the realistic option when "remote access" actually means "manage a fleet" and that fleet is not allowed to leave your network.

    Cost / License

    • Paid
    • Proprietary

    Platforms

    • Mac
    • Windows
    • Linux
    • Online
    • Self-Hosted
    Tactical RMM screenshot 1
    Tactical RMM screenshot 1
  4. X2Go icon
     Like

    Remote X11 desktops served from your own Linux machine over SSH. No broker, no account, no relay — the SSH server you already run is the whole infrastructure. Narrow scope (Linux desktops only) and very little to operate, which is exactly the appeal.

    Cost / License

    • Free
    • Open Source

    Application type

    Platforms

    • Mac
    • Windows
    • Linux
    • BSD
    X2Go screenshot 1
    X2Go screenshot 1
  5. NoMachine icon
     Like

    NX-based remote desktop that connects machine-to-machine by default — the free edition has no broker in the middle at all. The paid Terminal Server and Enterprise tiers add a server you install and run yourself, which is the self-hosted path here. Notably good on high-latency links.

    Cost / License

    • Paid
    • Proprietary

    Application type

    Platforms

    • Mac
    • Windows
    • Linux
    • Android
    • iPhone
    • Android Tablet
    • iPad
    • Raspberry Pi
    NoMachine screenshot 1
    NoMachine screenshot 1
    NoMachine screenshot 2
    +2
    NX client running on Linux (KDE)
  6. TigerVNC icon
     Like

    Plain VNC, actively maintained, with no cloud component whatsoever. You run the server on the target machine and connect to it directly, normally tunnelled over SSH or across a VPN. The floor of this category: nothing to trust, nothing to subscribe to, and nothing that breaks when a vendor changes its pricing.

    Cost / License

    • Free
    • Open Source

    Application type

    Platforms

    • Mac
    • Windows
    • Linux
    • BSD
    Viewer Interface
  7. A full self-hosted remote management server: remote desktop, terminal, file transfer, wake-on-LAN and device inventory in one web console. You run the server, so there is no vendor cloud in the path at all. More to operate than a single-binary tool, but the breadth is hard to match at this price (free).

    Cost / License

    • Free
    • Open Source

    Application type

    Platforms

    • Mac
    • Windows
    • Linux
    • Self-Hosted
    • Raspberry Pi
    • Node.JS
    • npm
    MeshCentral Login Page
    MeshCentral screenshot 1
    MeshCentral screenshot 2
    +5
    MeshCentral screenshot 3
  8. RustDesk icon
     Like

    Open source, and the part that matters for this list is the relay: you can run your own rendezvous/relay server, so session traffic never passes through a third-party host. Clients for Windows, macOS, Linux, Android and iOS. Self-hosting is the documented default rather than an enterprise upsell.

    Cost / License

    • Freemium
    • Open Source

    Application type

    Platforms

    • Mac
    • Windows
    • Linux
    • Android
    • iPhone
    • Android Tablet
    • iPad
    • Self-Hosted
    • Flathub
    • F-Droid
    • Flatpak
    RustDesk screenshot 1
    Main window
    RustDesk screenshot 2
    +2
    File transfer window

A few things worth knowing before you pick one.

"Self-hosted" is not one thing. Some of these put the whole product on your server (MeshCentral, Guacamole, Tactical RMM). Some only let you host the relay, while the client software still comes from the vendor (RustDesk). Some have no server at all and simply connect machine to machine (TigerVNC, X2Go, NoMachine's free edition). Which shape you need usually depends on whether the constraint is data residency, network reachability, or cost.

Hosting it yourself moves work onto you, not away from you: TLS certificates, upgrades, backups, and — the one people skip — an honest answer to who can start a session on which machine, and what the log says afterwards. A self-hosted tool with no access control and no audit trail is not more private than a cloud one, it is just less observed.

If we have missed something that belongs here, leave a comment and we will add it.

No comments so far, maybe you want to be first?
Gu