Your RDP infrastructure,
running on its own.
Redundant architecture, self-healing servers, office-hours VPN and full session recordings. One panel, four plans, first three sessions on us.
Redundant architecture, self-healing servers, office-hours VPN and full session recordings. One panel, four plans, first three sessions on us.
What every IT team lived through before Klyrix existed.
Citrix/VMware bills grow with every renewal and a new 'tier' shows up each year.
Password reset, printer install, Office, frozen screen, broken profile — the loop never ends.
Friday 22:00 RDP drops, nobody can log in, and the logoff script is also dead.
Exit form filed, AD account still active 6 months later, WG key roaming free.
Four pillars that explain Klyrix in one line. The rest is detail.
Runs on Contabo or your own VPS (BYOS). You hold the keys; we just orchestrate.
WireGuard mandatory entry, single-device lock, no open port without a handshake.
9 watchdog layers: from BSOD to certs, every failure is repaired before you notice.
200+ one-click apps, first 3 users free, 99.5% SLA.
From click to session — what happens in 5 steps.
User authenticates with WG key first. No open port without the key.
AD + Klyrix role matrix: which farm, which role, which hours?
HAProxy hits the least-loaded RDS node; failed nodes are skipped; sessions auto-redirect.
FSLogix containers synced via DRBD. Wherever you land — same desktop.
9 watchdog layers: BSOD, hibernate, WinRM, certs, disk, spooler — all auto-remediated.
Everything you need to run a desktop fleet — from one console.
Manage every independent VDS farm from a single panel.
Windows Server 2022/2025 sessions; first 3 users free, then $99/user/month.
Add unlimited RDP nodes (16 users/node); capacity-aware daily scaling.
IP/user/password → cloud-init → bootstrap → metrics; a new node in minutes.
Register Contabo or an existing VPS; via SSH on any provider. Your hardware.
Office, Adobe, your in-house app. Pick from a 200+ catalog, choose target servers, get back to work. New servers receive the same apps automatically.
Pay only for what you use. Three users free in every plan; flat price after — no surprises.
Essentials — getting started
Recommended — 1+1 HA pair
Mission-critical — 1+2 HA triple
Utilization is tracked daily. Upgrades are prorated down to the day and combined into a single consolidated monthly invoice. First 3 users are free on every plan.
No contract, no credit card. Everything ready — just press the next button.
Email sign-in, WireGuard QR ready. First farm provisions in 3 minutes.
Add people to AD, pick department. Install what you need from 200+ catalog.
Pick AppLocker profile, set office hours, toggle DVR, audit log starts streaming.
After real traffic, pick Minimum/Optimum/Ultra. Day-level prorated billing.
Happy? Add a card. Not happy? One-click cancel, zero lock-in.
Your main system is deployed redundantly from day one; add unlimited RDP, warm and cold servers on top. WireGuard required at the gate, office-hours enforced every time.
The main system isn't a single server — it's a cluster of synced nodes. If one node fails unexpectedly, another takes over the load in seconds. Your users never notice a thing.
Servers closed to the internet, keys in your hand. Staff only get in on the terms you set.
Outsiders can't even check if 'the system is up' — no ports, no IPs, no door. Inside only via the WireGuard certificate you issue, one device per user. Compromised? Revoke in one click.
You define working hours; outside them VPN drops and RDP closes. Need an exception? Grant a one-off. Night-shift staff get their own window — individual rules, not blanket policy.
Only apps you've approved can run. Downloaded .exe, sneaky .msi, queued installers — none of it launches. Virus, ransomware and surprise-software incidents drop to zero.
Staff, Supervisor, Manager, Admin. USB ports, screenshots, printing, clipboard — manage who can use what from a single matrix.
One physical device per user (MB+disk+CPU+MAC fingerprint); changes need admin approval.
Every action logged and undeletable — searchable by user, action, timestamp.
Copy/paste operations logged with direction and source/target window.
Semi-transparent user/time/server stamp on every session for accountability.
Social, streaming, gaming and P2P blocked during shift hours; open after.
| SECURITY & COMPLIANCE MATRIX | Citrix / VMware (Legacy VDI) | Traditional RDP | |
|---|---|---|---|
VPN Network Access WG Mesh device-bound tunnels. | |||
AD Privilege Control JIT Elevation with 5min auto-revocation. | |||
Remediation watchdog 9 layers: BSOD, WinRM, Spooler re-healers. | |||
User Compliance Tracking GPO URL Logger & looping Session DVR. | |||
High Availability 1+1 Active-Active DRBD sync replication. | |||
SaaS License Structure Daily prorated consolidated flat cost. |
When something breaks, it doesn't call you. It tries to fix itself first — and usually does.
Service crashed, driver hung, screen frozen. Nine recovery layers spot the issue, restart, verify, log. You read the report with your morning coffee.
Restoring from cold backup isn't an hour of panic, it's a 15-minute automated flow. New server boots, data restores, users activate, DNS updates — you just confirm.
When print spooler dies, your staff don't call you — the agent restarts it before they notice. RDP service, license service, log service — all caught the moment they fall.
Office, Adobe, your in-house app. Pick from a 200+ catalog, choose target servers, get back to work. New servers receive the same apps automatically.
Add a new server and RDP CALs activate themselves. No Microsoft portal navigation, no key entry — the Server 2025 hardened flow runs in the background.
Nine watchdog layers continually query nodes, Active Directory services, and WireGuard tunnels for instant anomaly resolution.
Track staff productivity, system health and compliance from one panel. No extra tools.
Need a specific moment? Jump to last Tuesday 14:32 and watch the screen. Live windows open on demand. Staff see a 'recording' watermark — both deterrent and legally clear.
Which apps stayed open, who plugged in USB, which file got copied, what came through the clipboard. Suspect a leak? One search finds it. Routine audit? Export CSV.
Admin actions and system events land in timestamped logs. Deleted a user, changed a setting, took a backup — searchable, downloadable, audit-ready.
Daily active time, busy hours, break patterns — all in one graph. No separate time-tracking tool to buy and train staff on.
Live servers-online ratio and a per-farm health score at a glance. A failing node turns red instantly; a trend chart shows the last 24 hours of fluctuation.
Per-server CPU, RAM, disk and network usage plus last-heartbeat time. Metrics over threshold are color-coded; click through to the node detail.
Unresolved issues sorted by severity (P0–P3) with auto-refresh. Each alert arrives with its source node, the rule that fired it and a suggested action.
Type, time and result of the latest backup per farm. Failed or overdue backups surface instantly; restore points are listed on a timeline.
Per-user WireGuard status: assigned IP, last handshake, live data rate and connected device. Dropped peers or single-device-rule violations are flagged.
Hiring, leave, sessions — all in one panel. Your staff talk to a bot in their pocket.
'How many hours this week?' 'Leave tomorrow.' 'Log me off.' — Telegram bot takes it, hits the system, replies. No forms, no portals, no IT tickets.
Hiring, role changes, department transfers, offboarding — all run through HR panel. Windows account, RDP slot, permissions sync automatically.
Per-user per-day schedule with shift-transition peak calc for server sizing.
Marked inactive in HR → AD account disabled, WG keys revoked, seat freed.
HRIS → Klyrix → AD sync with slot-reservation seat model.
Talks to your existing tools; not a closed box.
Automatic AD join, AppLocker/RDP/security GPOs, Credential Guard + NLA.
rdp.yourco.com CNAME → Klyrix HAProxy; LetsEncrypt SSL auto-renews.
WG config + RDP link + QR for new hires; operators trigger manual actions via Telegram.
Audit events + notifications over Resend SMTP.
RESTful endpoints for customer scripts; unlocked with subscription.
One tool, 4 operations — same muscles, different shapes.
RDP infra without an IT team. First 3 users free, 200+ apps one-click.
AD integration, department-aware role matrix, office-hour lock, audit log.
Shift access, session DVR, scrub for QA, USB/clipboard tracking.
AppLocker allowlist, GDPR-compliant tracking, strict role layers, immutable logs.
Klyrix is not a single product, but four modules designed for a running business. Start from whichever one you need.
Everything you might want to know before signing up.
Try 14 days free, no card. Want setup help? Our team remotes in and handles it for you.
Audit-ready; the evidence pipeline is visible.
Encryption at rest & in transit · Supabase Vault secrets · ~150 mapped controls