Is Splashtop Secure? Security, Compliance & Architecture Overview

Yes, Splashtop is secure. It uses end-to-end AES-256 encryption, maintains SOC 2 Type 2 compliance, and supports HIPAA BAA for healthcare. For deployments requiring zero-cloud-exposure, Splashtop Enterprise offers a self-hosted on-premise gateway that keeps all session data within your network boundary.

Security Architecture

Splashtop's security model is built on three pillars: end-to-end encryption, zero-knowledge session content, and defense-in-depth access controls. For a full breakdown of Splashtop's feature set, see our Splashtop Enterprise review.

Encryption

  • Signaling: TLS 1.2+ (AES-256) for all control plane communication between client, relay, and streamer
  • Media: DTLS/SRTP with AES-256 encryption for screen capture streams — encrypted before leaving the streamer
  • Key Exchange: ECDHE with P-256 curve for perfect forward secrecy; keys never stored on Splashtop servers
  • Zero-Knowledge: Splashtop cloud infrastructure cannot decrypt session content — encryption is end-to-end between client and streamer

Access Controls

  • Multi-Factor Authentication: TOTP (Google Authenticator, Authy), Duo Security push notifications, hardware tokens
  • SSO/SAML: Integration with Entra ID, Okta, OneLogin, ADFS, Ping Identity, and any SAML 2.0 identity provider
  • IP Allowlisting: Restrict remote access to specific IP ranges or CIDR blocks per policy
  • Time-Based Access: Set access windows — technicians can only connect during approved hours
  • Device Binding: Lock remote access to registered devices; unregistered devices cannot connect

Audit & Compliance

  • Session Recording: Built-in watermarked session recording with visual identifiers for forensic review
  • Audit Logs: Every authentication, connection, and administrative action logged with timestamp, IP, user, and result
  • SIEM Integration: Export audit logs via REST API or syslog to Splunk, Elastic SIEM, Microsoft Sentinel, or your preferred platform

Splashtop vs. Competitors — Security Features

Splashtop vs. Competitors — Security Features
Feature Splashtop EnterpriseTeamViewerAnyDeskCitrix DaaS Action
Encryption AES-256 (E2E)AES-256 (E2E)AES-256 (E2E)AES-256 (E2E)
TLS Version TLS 1.2+TLS 1.2+TLS 1.2+TLS 1.2+
SOC 2 Type 2Type 2Type 2Type 2
ISO 27001 YesYesYesYes
HIPAA BAA YesYesYesYes
FedRAMP NoNoNoYes (Gov Cloud)
On-Premise Option Yes (self-hosted gateway)NoRelay server onlyYes (on-prem VDA)
MFA TOTP, Duo, pushYesYesYes (nFactor)
SSO/SAML Entra ID, Okta, OneLogin, ADFSSAML SSOSAML SSOSAML, OIDC
Session Recording WatermarkedYesLimitedYes
IP Allowlist Yes (per-policy)NoDevice profilesYes (Geo-fencing)
Audit Logs Full event exportSession logsSession logsFull audit trail

Compliance Certifications

  • SOC 2 Type 2: Annual audit by independent CPA firm covering security, availability, and confidentiality
  • ISO 27001: Information security management system certification
  • HIPAA: Business Associate Agreement (BAA) available for healthcare deployments involving ePHI
  • GDPR: EU data processing agreement and data residency options
  • CSA STAR: Cloud Security Alliance certification

For HIPAA-specific compliance details, see our HIPAA-compliant remote access guide.

On-Premise Deployment for Maximum Security

Splashtop Enterprise offers a self-hosted on-premise gateway for organizations that cannot allow session data to transit external infrastructure:

  • All session data stays within your network boundary — no data reaches Splashtop cloud
  • Gateway runs on Windows Server 2016+ or Linux (Ubuntu 18.04+, CentOS 7+)
  • HA clustering for high availability across multiple gateway nodes
  • Air-gapped deployment supported (no internet connectivity required)
  • Meets data sovereignty requirements for government, healthcare, and financial sectors

Frequently Asked Questions

Is Splashtop secure?

Yes. Splashtop uses end-to-end AES-256 encryption, TLS 1.2+ for all signaling, and DTLS/SRTP for media streams. The platform maintains SOC 2 Type 2 compliance, ISO 27001 certification, and supports HIPAA BAA for healthcare deployments. No Splashtop infrastructure can decrypt session content.

Does Splashtop have SOC 2 compliance?

Yes. Splashtop maintains SOC 2 Type 2 certification, audited annually by an independent CPA firm. The SOC 2 report covers security, availability, and confidentiality trust services criteria for the Splashtop cloud platform.

Is Splashtop FedRAMP authorized?

Splashtop is not currently FedRAMP authorized. For federal government deployments requiring FedRAMP, consider alternatives like Citrix or Microsoft AVD with FedRAMP authorization. Splashtop Enterprise with on-premise gateway can meet similar security requirements for non-FedRAMP environments.

Does Splashtop support end-to-end encryption?

Yes. All Splashtop remote access sessions use end-to-end AES-256 encryption. The encryption keys are exchanged using TLS 1.2+ during the initial handshake, and the media stream uses DTLS/SRTP. Splashtop cloud infrastructure cannot decrypt session content.

Can Splashtop be deployed on-premise?

Yes. Splashtop Enterprise offers a self-hosted on-premise gateway that keeps all session data within your network boundary. No data transits Splashtop cloud servers. The gateway supports Windows Server 2016+ and Linux, with HA clustering for high availability.

Deploy Secure Remote Access Today

Splashtop Enterprise with end-to-end encryption, SOC 2 compliance, and optional on-premise deployment.

Try Splashtop Enterprise