PC remote control: how to do it safely
Giving remote access to your PC is convenient, but badly configured it's an open door for someone who shouldn't come in. PController starts from an architecture designed to cut that risk: no ports open to the internet, tokens that expire on their own, LAN with no external servers. In this guide we go through the real risks of remote control, how that architecture reduces them, and what else you can do yourself.
Risk 1: unauthorised access
What you can do: never share the session token. If you suspect someone got in, close the server on the PC: that invalidates the active session. Restart the server to invalidate the tokens.
Risk 2: traffic interception
Risk 3: exposing your screen in public places
What you can do: don't share the public link with people you don't trust. Once you no longer need it, revoke it from the web app.
Risk 4: the desktop server as an attack surface
What you can do: keep the server up to date. PController checks whether there's a new version and tells you in My panel (system tray icon → "Open my panel"), but it doesn't install anything on its own: the notice takes you to the downloads page and you run the installer yourself. When you do, pick the same installation mode as last time. Step by step in the guide.
General good practice
- Use Google OAuth to sign in — if you have 2FA on your Google account, your PController account inherits it.
- Close PController when you're not going to use it (system tray icon → "Quit"). To end a session without closing the server, revoke it from app.pcontroller.app/security.
- If you're travelling, avoid leaving the server running unattended on your home PC.
- Check from time to time, in the web app, which devices have an active session.
- Don't accept invitations from PCs you don't recognise — only accept invitations from people you trust.
Is it safer than TeamViewer?
We don't make that comparison, because it depends on your threat model. TeamViewer has more years of security audits behind it. PController has the advantage that the server opens no ports to the internet: it only listens on your local network, and external exposure is limited to the encrypted tunnel. Less attack surface by design. But it's a newer product.
If your case calls for certified corporate security, talk to your IT team. For personal use and small companies, PController's architecture is reasonably safe.
Reporting vulnerabilities
If you find a security problem, write to us at hello@pcontroller.app before publishing it. We commit to replying within 48 hours.
You judge an architecture by using it, not by reading about it. The 7-day trial asks for no card: try it and draw your own conclusions.
Get started — free