Security Designed Into Every Layer
ExaGuards holds some of your clients' most sensitive information, from passwords to network details. Protection is built in from the sign-in screen to the audit log.
Your Clients Trust You. You Should Be Able To Trust Your Tools.
An IT platform is a high-value target: it knows where every server is, holds the passwords to reach them and can open sessions to them. We treat that responsibility seriously, and ExaGuards is designed so that access is verified, limited to what each person needs, and recorded.
Security features are not an add-on tier. Two-step verification, encryption of sensitive data, permissions and audit logs are part of the platform for every customer.
How ExaGuards Protects Your Data
Two-Step Verification
Sign-in requires a second step by authenticator app, email or SMS code. It is enforced by the server, with an option to trust a browser you use regularly.
Per-Customer Encryption
Sensitive data is encrypted. Each customer has its own master key for information that only they should be able to read, separate from the key used by platform services.
Permission-Based Access
Detailed permissions control who can see costs and profit, open credentials, use remote access, view the ledger, manage HR and more.
Audit Logs
Credential access, RDP sessions, tickets, orders, invoices, estimates and products keep a history of who did what and when.
Protected Public Links
Estimate approvals, file shares and one-time secrets use links stored only as hashes, with rate limiting and expiry.
Sign-In Notifications
Sign-in events can trigger notifications, so unexpected access is noticed quickly.
Remote Access Without Leaving Doors Open
Remote access is often the weakest point in an IT provider's setup. The ExaGuards RDP gateway avoids exposing RDP to the internet: each connection uses a short-lived, single-use signed token and is written to an audit log, and the RDP password stays in the technician's browser.
Agent-based remote desktop sessions can be recorded, and remote access itself is a permission, granted only to the positions that need it.
Least Privilege For Every Password
The credentials vault encrypts stored secrets and limits each record to the positions that should see it. Every time a credential is opened, the access is logged.
Authenticator secrets stay on the server; the vault displays only the current six-digit code, so your team can complete multi-factor sign-ins without the secret ever being handed around.
Is two-step verification required?
Two-step verification is part of the ExaGuards sign-in and is enforced by the server. Users can choose an authenticator app, email or SMS codes, and can mark a browser as trusted.
Who can see our data?
Your data is separated by customer, and access within your company is controlled by permissions. Sensitive data is encrypted, and your company has its own master key for information only you should read.
Is access recorded?
Yes. Credential access, remote sessions and changes to tickets, orders, invoices, estimates and products are recorded in logs.
Where can I learn more?
We are happy to walk through ExaGuards' security design in detail during a demo.
See How ExaGuards Fits Your Business
Tell us about your team and the devices you support. We will prepare pricing for your size, walk you through the modules that matter to you, and help you set up your account.

