Trust and Security

Last updated: August 2026

This page summarizes how the HopToDesk Dashboard is built, hosted, and secured. We aim to give honest, specific answers rather than marketing claims. If you need anything not covered here for a vendor review, contact us at contact@hoptodesk.com.

Hosting and Infrastructure

The HopToDesk Dashboard runs entirely on managed cloud infrastructure from established providers. We do not operate our own datacenters.

  • Dashboard, API, database, and file storage: a major edge cloud platform that maintains ISO/IEC 27001 certification and a SOC 2 Type II report at the platform level. The primary database is located in the United States.
  • Signal (peer rendezvous) and realtime relay networks: ISO/IEC 27001 certified datacenters in the European Union (Germany) and the United States.

We publish the live availability of the dashboard, database, signal network, and realtime relay on a public status page.

View the status page

Encryption

  • In transit: all dashboard, API, and client traffic is encrypted with TLS.
  • At rest: dashboard data (database, object storage, and key-value storage) is encrypted at rest at the platform level.
  • Remote sessions: remote control sessions between devices are end-to-end encrypted.

Authentication and Access Control

  • Account passwords are stored only as salted hashes, never in plaintext.
  • Two-factor authentication (TOTP), with one-time recovery codes.
  • Passkeys (WebAuthn) for passwordless sign-in, accepted in place of a password and counted as multi-factor.
  • Account owners can require every team member to use two-factor authentication or a passkey.
  • Single sign-on via OIDC for organizations.
  • An IP allowlist that limits dashboard sign-ins, API calls, and real-time connections to the addresses you nominate, set for the whole account or for an individual member.
  • Role-based access control for team members.
  • Scoped, revocable API keys for integrations.
  • An admin activity audit log that records who did what, with export to CSV or JSON for ingestion into a SIEM.

The controls above are available on every plan, including the free plan. Conditional-access policies that restrict device connections by source IP, time of day, or country are available on the Enterprise and MSP plan.

Device Protection

  • Each device is protected by a permanent password you set, a rotating one-time password, or both.
  • Device-level two-factor authentication: a device can require a code from an authenticator app before any session starts. The prompt is supported by every client, including the browser-based web client.
  • Approval mode can require a person at the device to accept each incoming session.
  • Easy Access lets your team connect without a shared password; every session is authorized through your dashboard account first and recorded in the audit log. Easy Access is part of the Business plan.

Sub-processors

To operate the Service we rely on a small number of vetted third-party providers. Each processes only the data needed for its function. This is our current list.

Provider Purpose Location Transfer basis
Cloudflare, Inc. Dashboard and API hosting, database, object storage, and key-value storage Global edge network; databases in the United States and the European Union Standard Contractual Clauses and the EU-U.S. Data Privacy Framework
Hetzner Online GmbH Signal (peer rendezvous) and realtime relay networks Germany and the United States EU processing; Standard Contractual Clauses for the United States location
Brevo SAS Transactional and notification email European Union EU processing
Zoho Corporation Support help desk: receiving and storing inbound support email United States Standard Contractual Clauses and the EU-U.S. Data Privacy Framework
Anthropic, PBC AI Assistant and ticket triage, used only where an account enables those features United States Standard Contractual Clauses and the EU-U.S. Data Privacy Framework

Payments made through our website checkout are handled by Link, LLC (formerly Lemon Squeezy LLC), trading as Lemon Squeezy, as merchant of record. Because that sale is legally between you and them rather than between you and us, they act as an independent controller for the payment transaction rather than as our sub-processor, and their own privacy terms apply to it. If you are on an invoiced agreement instead, you are billed directly by Begonia Holdings LLC and pay by bank transfer, so the sale is with us, we hold your billing details as controller of our own commercial records, and the banks that move the funds act as independent controllers under their own legal obligations. Neither route puts a sub-processor between us and your data.

If you choose to sign in with a Google or Microsoft account, that provider authenticates you under its own terms as an independent controller, and we receive only the email address and name it returns. Sign-in providers are optional and are not engaged by us as sub-processors.

We give customers who hold a Data Processing Agreement with us at least 30 days' notice before adding or replacing a sub-processor. To be added to that notification list, contact us at contact@hoptodesk.com.

Data Residency

You choose where your dashboard data is stored when you create your account: the United States or the European Union.

An account created in the EU region keeps its account, device, ticket and configuration data only on EU-jurisdiction infrastructure, with its own database, file storage and encrypted backups in the European Union.

The signal and realtime-relay networks include a European Union (Germany) location, but those broker connections and relay traffic in real time and do not persistently store session content or corporate data.

Existing accounts remain in the United States region. If you need an account moved to the EU region, contact us and we will migrate it.

A region move is a one-time change per account.

EU-region accounts sign in at eu.dashboard.hoptodesk.com.

Certifications and Compliance

Our underlying infrastructure providers are independently certified as described above. HopToDesk itself does not currently hold an independent SOC 2 Type II or ISO/IEC 27001 certification. The dashboard includes a compliance readiness tracker for your own internal self-assessment; it is a self-assessment tool, not a third-party attestation. We are happy to complete reasonable security questionnaires as part of your vendor review.

Legal Entity

HopToDesk is operated by Begonia Holdings LLC, a Wyoming limited liability company formed in 2020 and registered to do business in California as a foreign LLC (California entity number B20260321378). The registered address is 30 N Gould St Ste R, Sheridan, WY 82801, United States. Contracts and direct invoices are issued by Begonia Holdings LLC.

Reporting a Security Issue

If you believe you have found a security vulnerability, please report it to contact@hoptodesk.com. We appreciate responsible disclosure and will investigate all legitimate reports.