Remote access in one click. No VPN, no open port.

No more connecting to the VPN, opening mstsc and typing an address and a password. Your team opens the catalog, clicks the access and is on the Windows or Linux server, from the browser, the desktop app or the CLI. Credentials live in a vault only you can open, and every session lands in the audit trail.

Free for up to 5 users. No credit card.

Guarantees you can check.

0
inbound ports open on your network
0
passwords handed to the browser or the app
100%
of sessions recorded in the trail
12 months
of audit trail the application can't alter
3
ways to connect: browser, app and CLI

Getting to a server shouldn't take this much work.

Working on a remote server usually goes like this: connect to the VPN, open mstsc, remember the address, type the username and password, and hope it works. For IT, it means handing out and maintaining a VPN for every person, opening ports in the firewall and giving the whole network to someone who needed one server.

The shortcut is worse: publishing RDP or RDS straight to the internet. The open port gets found by scanning bots and starts taking password attempts nonstop. Exposed remote access services, RDP and the VPN itself, are among the top ways attackers get in, and leaked credentials do the rest.

And the admin password ends up in a spreadsheet, a chat group, a sticky note. In the end, nobody can say who got in, on which server, with which account, or for how long.

How nuvem.works prevents it: the agent installed on the server only makes outbound connections, over port 443. There's no inbound port open to the internet, so there's nothing to scan and nowhere to try a password.

Fewer steps for the people who work. No port for the people who attack.

What the reports show

84%

of investigated attacks involved attackers abusing RDP

Sophos Active Adversary Report 2025

71%

of attacks got in through exposed remote services such as RDP and VPN

Sophos Active Adversary Report 2025

42%

of attacks started with compromised credentials, the #1 root cause; 59% lacked MFA

Sophos Active Adversary Report 2026

1.8M

RDP servers are still exposed to the internet

Forescout Research 2026, Shodan data

Sources: Sophos Active Adversary Report 2025 · Sophos Active Adversary Report 2026 · Forescout Research, 2026

Before: VPN, mstsc, address and password. Now: one click.

The technical part gets out of the way; the security stays.

Before

  1. Connect to the VPN (and call IT when it doesn't work)
  2. Open mstsc
  3. Remember the server address
  4. Find and type the username and password
  5. An open firewall port, or a VPN reaching the whole network; nobody knows who got in

With nuvem.works

  1. Open the access catalog, in the browser, the app or the CLI
  2. Click the access
  3. The credential comes out of the vault and the session opens directly
No inbound port; each person sees only what was shared with them
Every session recorded in the trail

Three steps, zero open ports.

From download to first connection in under 5 minutes.

  • Your network: no inbound port
  • Agent → nuvem.works over 443
  • Browser, app, CLI and AI agents
01

Install the agent.

A lightweight service on the Windows or Linux server. It only makes outbound connections, over port 443, like any browser. Nothing changes in the firewall.

02

Publish the access.

Choose what to share (the desktop, a terminal or a single application) and with which people and groups.

03

Connect.

Your team opens it from the browser, the Mac or Windows app, or the CLI. The credential leaves the vault only to open the session, and the session goes into the trail.

Your network
Windows · Linux
Agent
nuvem.works
outbound · 443
Browser
App
CLI
AI agent
TRAIL
14:02:11 · ana@acme · connected · srv-erp-01 · account ACME\ana · browser

Everything your team needs to work on the server.

  • Desktop in the browser

    Full RDP in the browser, with text copy and paste, file upload and download, and printing. No client to install.

  • Terminal on Windows and Linux

    PowerShell or a Linux shell right in the browser, with a password or an SSH key.

  • Published applications

    Deliver just the application, not the whole server. Group RDS servers into a pool and nuvem.works picks which server takes each connection.

  • Printing that reaches you

    What the session prints opens in your browser's print dialog, and you pick the printer. Enabled per connection.

  • App for Mac and Windows

    The access catalog, native on your computer, with sessions in their own window.

  • Credential vault

    Save a credential once and connect in one click. It stays in an encrypted vault only you can open; not even our team has access.

  • An organized catalog

    Categories set by your team and favorites for each user, so the right access is always at hand.

  • Trail and reports

    Who connected, when, from where, with which server account and for how long. Export to CSV.

  • A CLI for people and AI agents

    nuvemworks connect opens the access in your terminal; with -c, it runs a single command and returns the result.

A vault only you can open. A server with no port to attack.

Security that doesn't depend on anyone remembering to do the right thing.

No inbound port.

The agent only opens outbound connections, over 443. There's no port to scan and no exposed RDP to brute-force.

Only you open the vault.

Credentials are encrypted in a vault only your organization can open; not even the Nuvem.Online team can see or use them. Save once and forget the paperwork: the credential is only used to open your session.

Using is not seeing.

No screen or API displays a saved credential, not even to the person who saved it. The browser, the app and the CLI never receive it.

Only the person who saved it can use it.

A credential is personal: nobody else on the team can connect with it.

End-to-end encrypted terminal.

For terminal sessions, the channel between your browser and the agent is end-to-end encrypted.

The approved command is the only command.

When the CLI runs a command, it's pinned in the authorization; the agent refuses anything else.

A trail that can't be erased.

Every access becomes an event, including denied ones. The application has no permission to change or delete the trail; only the automatic purge removes events older than 12 months.

Access by role and group.

Each person only sees what was shared with them.

Verified updates.

The agent updates itself during the overnight window and only installs what passes signature verification.

Server access for people and AI agents.

Your AI agents already work in the terminal. Give them access to the server without handing over the password.

The nuvemworks CLI runs only the command that was approved, returns its output and exit code, and records in the trail who asked, on which server, and the exact command text. People and agents go through the same door, with the same trail.

  • nuvemworks connect with -c for a single command, no interactive session.
  • --json on listings, so the agent reads the catalog instead of guessing.
  • nuvemworks skill prints ready-made instructions for your agent.
  • The credential comes from the vault; the AI agent never receives it.
A developer's desk at night with a terminal open on the laptop
$ nuvemworks connect srv-app-01 -c "systemctl status nginx"
● nginx.service - A high performance web server
    Active: active (running)
TRAILperson + AI agentbruno@acme via AI agentsrv-app-01 · systemctl status nginx · exit 0

Start free. Pay per user as you grow.

Every feature on every plan. Only your team size changes.

  • Free

    To try it out, and for small teams.

    US$ 0
    • Up to 5 users
    • 2 agents
    • Every feature, including the 12-month trail
    • No credit card
  • Team

    For teams that rely on remote access every day.

    US$ 6per user/month
    • As many users as you need
    • 1 agent for every 3 users
    • Every feature
    • Support over WhatsApp
  • Enterprise

    For contracts, volume or assisted rollout.

    Custom pricing
    • Lower per-user price above a set size
    • Tailored contract and invoicing
    • Help with the rollout

Illustrative prices, subject to change.

Frequently asked questions

Do I need a VPN?
No. People connect from the browser, the app or the CLI, from anywhere. The server talks to nuvem.works over an outbound connection opened by the agent.
Which firewall ports do I need to open?
No inbound ones. The agent only needs to go out over port 443, like a browser.
Where is the server password kept?
In an encrypted vault only your organization can open, if you choose to save it; if you don't, it's valid for that connection only. Not even the Nuvem.Online team can see or use your credentials. A saved credential is personal: only the person who saved it can use it, and only to open their own session. It's never sent to the browser, the app or the CLI, and no screen or API displays it, not even to the person who saved it. Server accounts and passwords remain your team's: nuvem.works doesn't create or change passwords.
Does it work with Linux?
Yes. The agent runs on Windows and on Linux with systemd, on x86-64 and ARM64. On Linux, the terminal logs in with a password or an SSH key.
How do I install the agent?
Add the server in nuvem.works and run the install command shown on screen, in PowerShell (Windows) or in the terminal (Linux). From then on, the agent keeps itself up to date.
Do the people connecting need to install anything?
No. A browser is enough. The Mac and Windows app and the CLI are optional.
Are sessions recorded?
We don't record the screen or keystrokes. The trail records who connected, when, from where, with which server account and for how long, and, for CLI runs, the command text.
Can AI agents run any command?
No. Each run carries a single command pinned in the authorization, and the agent refuses anything different. It's all in the trail.
How does the Free plan work?
Create your account, register your organization and start with up to 5 users and 2 agents, no credit card. When you need more, talk to us.

Stop opening ports to get work done.

Install the agent, publish your first access and connect from the browser.

Free for up to 5 users. No credit card.

Talk to us