Remote access in one click. No VPN, no open port.
No more connecting to the VPN, opening mstsc and typing an address and a password. Your team opens the catalog, clicks the access and is on the Windows or Linux server, from the browser, the desktop app or the CLI. Credentials live in a vault only you can open, and every session lands in the audit trail.
Free for up to 5 users. No credit card.
Guarantees you can check.
Getting to a server shouldn't take this much work.
Working on a remote server usually goes like this: connect to the VPN, open mstsc, remember the address, type the username and password, and hope it works. For IT, it means handing out and maintaining a VPN for every person, opening ports in the firewall and giving the whole network to someone who needed one server.
The shortcut is worse: publishing RDP or RDS straight to the internet. The open port gets found by scanning bots and starts taking password attempts nonstop. Exposed remote access services, RDP and the VPN itself, are among the top ways attackers get in, and leaked credentials do the rest.
And the admin password ends up in a spreadsheet, a chat group, a sticky note. In the end, nobody can say who got in, on which server, with which account, or for how long.
Fewer steps for the people who work. No port for the people who attack.
What the reports show
of investigated attacks involved attackers abusing RDP
Sophos Active Adversary Report 2025
of attacks got in through exposed remote services such as RDP and VPN
Sophos Active Adversary Report 2025
of attacks started with compromised credentials, the #1 root cause; 59% lacked MFA
Sophos Active Adversary Report 2026
RDP servers are still exposed to the internet
Forescout Research 2026, Shodan data
Sources: Sophos Active Adversary Report 2025 · Sophos Active Adversary Report 2026 · Forescout Research, 2026
Before: VPN, mstsc, address and password. Now: one click.
The technical part gets out of the way; the security stays.
Before
- Connect to the VPN (and call IT when it doesn't work)
- Open mstsc
- Remember the server address
- Find and type the username and password
- An open firewall port, or a VPN reaching the whole network; nobody knows who got in
With nuvem.works
- Open the access catalog, in the browser, the app or the CLI
- Click the access
- The credential comes out of the vault and the session opens directly
Three steps, zero open ports.
From download to first connection in under 5 minutes.
- Your network: no inbound port
- Agent → nuvem.works over 443
- Browser, app, CLI and AI agents
Install the agent.
A lightweight service on the Windows or Linux server. It only makes outbound connections, over port 443, like any browser. Nothing changes in the firewall.
Publish the access.
Choose what to share (the desktop, a terminal or a single application) and with which people and groups.
Connect.
Your team opens it from the browser, the Mac or Windows app, or the CLI. The credential leaves the vault only to open the session, and the session goes into the trail.
Everything your team needs to work on the server.
Desktop in the browser
Full RDP in the browser, with text copy and paste, file upload and download, and printing. No client to install.
Terminal on Windows and Linux
PowerShell or a Linux shell right in the browser, with a password or an SSH key.
Published applications
Deliver just the application, not the whole server. Group RDS servers into a pool and nuvem.works picks which server takes each connection.
Printing that reaches you
What the session prints opens in your browser's print dialog, and you pick the printer. Enabled per connection.
App for Mac and Windows
The access catalog, native on your computer, with sessions in their own window.
Credential vault
Save a credential once and connect in one click. It stays in an encrypted vault only you can open; not even our team has access.
An organized catalog
Categories set by your team and favorites for each user, so the right access is always at hand.
Trail and reports
Who connected, when, from where, with which server account and for how long. Export to CSV.
A CLI for people and AI agents
nuvemworks connect opens the access in your terminal; with -c, it runs a single command and returns the result.
A vault only you can open. A server with no port to attack.
Security that doesn't depend on anyone remembering to do the right thing.
No inbound port.
The agent only opens outbound connections, over 443. There's no port to scan and no exposed RDP to brute-force.
Only you open the vault.
Credentials are encrypted in a vault only your organization can open; not even the Nuvem.Online team can see or use them. Save once and forget the paperwork: the credential is only used to open your session.
Using is not seeing.
No screen or API displays a saved credential, not even to the person who saved it. The browser, the app and the CLI never receive it.
Only the person who saved it can use it.
A credential is personal: nobody else on the team can connect with it.
End-to-end encrypted terminal.
For terminal sessions, the channel between your browser and the agent is end-to-end encrypted.
The approved command is the only command.
When the CLI runs a command, it's pinned in the authorization; the agent refuses anything else.
A trail that can't be erased.
Every access becomes an event, including denied ones. The application has no permission to change or delete the trail; only the automatic purge removes events older than 12 months.
Access by role and group.
Each person only sees what was shared with them.
Verified updates.
The agent updates itself during the overnight window and only installs what passes signature verification.
Server access for people and AI agents.
Your AI agents already work in the terminal. Give them access to the server without handing over the password.
The nuvemworks CLI runs only the command that was approved, returns its output and exit code, and records in the trail who asked, on which server, and the exact command text. People and agents go through the same door, with the same trail.
nuvemworks connectwith-cfor a single command, no interactive session.--jsonon listings, so the agent reads the catalog instead of guessing.nuvemworks skillprints ready-made instructions for your agent.- The credential comes from the vault; the AI agent never receives it.

Active: active (running)
Start free. Pay per user as you grow.
Every feature on every plan. Only your team size changes.
Free
To try it out, and for small teams.
US$ 0- Up to 5 users
- 2 agents
- Every feature, including the 12-month trail
- No credit card
Team
For teams that rely on remote access every day.
US$ 6per user/month- As many users as you need
- 1 agent for every 3 users
- Every feature
- Support over WhatsApp
Enterprise
For contracts, volume or assisted rollout.
Custom pricing- Lower per-user price above a set size
- Tailored contract and invoicing
- Help with the rollout
Illustrative prices, subject to change.
