응용 앱 · SupportReach

동의 기반 보안 원격지원 — 자체호스팅 · 종단간 · 감사 등급

헬프데스크 상담원이나 외부 벤더가 사용자가 쓰고 있는 PC에 원격 접속하는 동의 기반(attended) 원격지원·MSP 도구입니다. 명시적 동의로만 세션이 시작되고, 전체 녹화·위변조 방지 감사 추적· 범위/시간 제한 벤더 접근(PRA)을 기본 제공합니다. TeamViewer·AnyDesk·BeyondTrust PRA의 자체호스팅 · 종단간 암호화 · 감사 등급 대안이며, 넷서브의 4개 SDK(ConnectKit·SessionKit·ServerKit·DeviceKit)를 조립해 만들었습니다.

동의 기반(attended) 종단간 암호화 세션 녹화 · 리플레이 위변조 방지 감사 벤더 PRA 자체호스팅

상담원(운영자)은 설치 없이 브라우저 웹 콘솔로 접속하고, 사용자는 지원 PIN을 받아 동의하면 세션이 열립니다. EdgeReach(무인 장치)의 attended(사람이 개입하는) 형제 제품입니다.

핵심 기능

🤝 명시적 동의(attended)

기기 앞의 사용자가 허용해야만 세션이 시작됩니다(참여 → 보기 → 제어). SessionKit의 제어 승인 게이트 위에 얹은 동의 핸드셰이크.

⏺️ 세션 녹화 · 리플레이

SessionKit 프레임·입력 스트림을 세션 ID로 저장하고 감사용으로 재생합니다.

🧾 위변조 방지 감사

ServerKit의 해시체인 감사 로그session.* 생명주기(시작·동의·제어·종료)를 기록합니다. 독립 검증·내보내기(export) 가능.

🛡️ 벤더 PRA(특권 원격 접근)

외부 벤더를 범위·시간 제한·승인 필수·항상 녹화 조건으로 초대합니다. 공유 크레덴셜이 없고, 종료 시 접근이 회수됩니다.

🌐 브라우저 운영자 콘솔

상담원은 설치 없이 웹 콘솔(ServerKit ViewerGateway)로 화면을 보고 제어합니다. RBAC 권한·단기 토큰·기기별 ACL로 보호됩니다.

🔐 종단간 암호화 · 자체호스팅

ConnectKit J-PAKE·AES-256-GCM으로 종단간 암호화하고, 서버·녹화·감사를 조직이 직접 운영합니다. 데이터가 외부로 나가지 않습니다.

🖧 MSP 플릿(선택)

DeviceKit.Rmm로 무인 자산의 인벤토리·라이브 지표·원격 명령 실행까지 확장할 수 있습니다.

📋 컴플라이언스 팩

감사 export + 무결성 독립 검증(누락 없음), SIEM 전송, 접근 검토, 보존 정책까지 규정준수에 필요한 요소를 제공합니다.

작동 원리 — 넷서브 4-Kit 조립 + 정책 계층

SupportReach는 새 프로토콜을 만들지 않고 넷서브의 개발자 SDK(Kit)를 조립합니다. 파이프·세션·서버·프로토콜은 Kit이 보장하고, SupportReach는 정책(동의·녹화·세션 감사·벤더 접근)을 소유합니다.

Kit은 파이프·세션·서버·프로토콜을 보장하고, SupportReach는 Kit이 통합자에게 남겨둔 정책(동의·녹화·세션 도메인 감사·벤더 접근)을 채웁니다.

이럴 때 씁니다

웹 뷰어 콘솔 접근

상담원은 브라우저 웹 콘솔(ServerKit ViewerGateway)로 세션에 접속합니다 — 설치 불필요, RBAC 권한·단기 토큰·기기별 ACL로 보호. 콘솔은 고객 신뢰 경계 안(온프렘)에 자체호스팅하므로 화면·녹화·감사가 외부로 나가지 않습니다.

구성 요소역할제공/접근
웹 콘솔 (ServerKit ViewerGateway)상담원 브라우저 접속 — 보기·제어·동의자체호스팅(온프렘) · ServerKit
지원 호스트(SupportReach Host)사용자 PC — 지원 PIN·동의·녹화도입 시 제공/배포
관리 콘솔 (Control/Portal)RBAC·감사 열람·과금자체호스팅
🔴 라이브 데모 — 설치 없이 브라우저에서 상담원 웹 콘솔을 바로 체험하세요: console.support.remote-viewer.com — 합성 데모 세션이 실시간 화면을 스트리밍합니다(운영 데이터 없음). 실제 도입은 온프렘 자체호스팅입니다.

넷서브 콘솔 허브응용 앱 운영 구역에서도 이 콘솔을 열 수 있습니다.

SupportReach는 넷서브의 개발자 SDK(ConnectKit · SessionKit · ServerKit · DeviceKit) 위에서 동작합니다. 무인 장치 관제가 필요하면 attended 형제 제품 EdgeReach를, 직접 만들려면 SDK 제품을 참고하세요.
Apps · SupportReach

Consent-based secure remote support — self-hosted · E2E · audit-grade

An attended remote-support & MSP tool for the session a helpdesk agent or an outside vendor opens onto a live user's machine. A session starts only with explicit consent, and it ships with full recording, a tamper-evident audit trail, and scoped, time-boxed vendor access (PRA). It's the self-hosted · end-to-end-encrypted · audit-grade alternative to TeamViewer / AnyDesk / BeyondTrust PRA, built by assembling the NetServ Kits (ConnectKit · SessionKit · ServerKit · DeviceKit).

Attended (consent) End-to-end encrypted Recording & replay Tamper-evident audit Vendor PRA Self-hosted

The agent (operator) connects from a browser web console, no install; the user gets a support PIN and consents to open the session. SupportReach is the attended sibling of EdgeReach (unattended devices).

Key features

🤝 Explicit consent (attended)

A session starts only when the person at the machine allows it (join → view → control), a consent handshake on top of SessionKit's control-approval gate.

⏺️ Session recording & replay

Persist the SessionKit frame / input stream keyed to a session id and replay it for audit.

🧾 Tamper-evident audit

Record session.* lifecycle (start · consent · control · end) in ServerKit's hash-chained audit log, independently verifiable and exportable.

🛡️ Vendor PRA (privileged remote access)

Invite an outside vendor with a scoped, time-boxed, approval-required, always-recorded grant — no shared credentials, access revoked on end.

🌐 Browser operator console

Agents watch and control from a web console (ServerKit ViewerGateway), no install — gated by RBAC permissions, short-lived tokens, and a per-device ACL.

🔐 End-to-end encryption · self-hosted

ConnectKit J-PAKE · AES-256-GCM end-to-end, with servers, recordings and audit run by you — data never leaves your boundary.

🖧 MSP fleet (optional)

Extend to unattended assets with DeviceKit.Rmm — inventory, live metrics, remote command exec.

📋 Compliance pack

Audit export with independent integrity verification (no gaps), SIEM egress, access review, and retention policy.

How it works — assembled from the NetServ Kits + a policy layer

SupportReach invents no new protocol — it assembles NetServ's developer SDKs (Kits). The Kits guarantee pipe / session / server / protocol; SupportReach owns the policy (consent, recording, session audit, vendor access).

The Kits guarantee pipe / session / server / protocol; SupportReach fills the policy the Kits deliberately leave to the integrator — consent, recording, session-domain audit, and vendor access.

Use it when

Web viewer console access

Agents attach to a session from a browser web console (ServerKit ViewerGateway) — no install, gated by RBAC permissions, short-lived tokens and a per-device ACL. The console is self-hosted inside your trust boundary, so screen, recordings and audit never leave your org.

ComponentRoleProvided / access
Web console (ServerKit ViewerGateway)Agent browser attach — view · control · consentSelf-hosted (on-prem) · ServerKit
Support host (SupportReach Host)User PC — support PIN · consent · recordingProvided / deployed at onboarding
Admin console (Control/Portal)RBAC · audit review · billingSelf-hosted
🔴 Live demo — try the agent web console right in your browser, no install: console.support.remote-viewer.com — a synthetic demo session streams a live screen (no production data). A real deployment is on-prem / self-hosted.

The NetServ console hub lists this console under App operations too.

SupportReach runs on NetServ's developer SDKs (ConnectKit · SessionKit · ServerKit · DeviceKit). For unattended devices see its sibling EdgeReach; to build your own, see the SDK Products.