Mutual TLS, end to end
Every agent authenticates with a uniquely-issued client certificate, pinned by SPKI on the server. There is no shared token, no bearer secret, and no path that bypasses the cryptographic identity of the endpoint.
Products • RMM
vanRoojen RMM is a small, security-first remote monitoring and management platform — a hosted, multi-tenant service designed from the ground up for homelabs and serious hobbyists who want real fleet visibility without standing up their own control plane.
What it is
Most RMM tools were built for managed-service providers running thousands of endpoints under contract. vanRoojen RMM is built for the operator who actually cares what's running on each box — and who reads the release notes before clicking update.
Every agent authenticates with a uniquely-issued client certificate, pinned by SPKI on the server. There is no shared token, no bearer secret, and no path that bypasses the cryptographic identity of the endpoint.
Viewer, operator, admin, and owner roles are enforced on every write — not just the UI. Admins can voluntarily downgrade their own effective role for routine work, and the server respects it.
Removing an endpoint queues an uninstall, revokes its certificate, regenerates the CRL, and only finalizes the deletion once the agent confirms it actually left. Offline boxes self-clean if they ever come back.
Detection, inventory, and actions for Unraid arrays, Docker containers, libvirt VMs, Proxmox QEMU and LXC guests — including cluster-aware migration tracking and ZFS pool health.
Scan and push updates to Linux, Windows ARM endpoints, and guests-via-host through a controlled command pipeline — with approvals, deploy status, and a clear audit trail per agent.
Every customer gets their own logical tenant with cryptographic and database-level boundaries. No cross-tenant data, no third-party analytics SDKs, no opaque telemetry — just your fleet, talking to your tenant.
Who it's for
If your homelab outgrew a single Synology, if you're managing a handful of Proxmox nodes, an Unraid server, a few Pi clusters, and the family laptops — but the commercial RMM tools feel built for someone else entirely — this is for you.
Why we're building it
vanRoojen RMM started as the tool we wanted for our own homelab — something that could manage Windows ARM, Linux, Unraid, and Proxmox endpoints behind one pane without compromising on authentication, auditability, or honest cleanup when an endpoint goes away.
Running it as a hosted service means you don't have to babysit the control plane — but it also means we have to earn that trust every day. We're hardening it through real-world use first, and we'll open invites when the security model is one we'd hand our own homelabs to.
Stay in the loop
We're not running a waitlist or harvesting emails for marketing. Drop us a note and we'll write back when there's something concrete to show you — beta access, source release, or both.