No inbound monitoring exposure
The connector calls the broker. The broker and apps do not connect directly to the monitoring interface.
Security
Server Alerts separates mobile access from private monitoring infrastructure using outbound connector traffic, broker authentication, scoped roles, and auditable operations.
Security model
Security applies to connector enrolment, broker traffic, identity, membership, commands, and stored credentials.
The connector calls the broker. The broker and apps do not connect directly to the monitoring interface.
Production broker URLs use HTTPS. Plain HTTP is limited to localhost development.
Connector tokens are hashed and can be rotated from administration controls.
Credentials are verified by the local connector and completed payloads are scrubbed.
Operators manage supported actions; viewers inspect status. Access is per site.
Invites, roles, settings, enrolments, licences, rotations, and actions are recorded.
Traffic flow
Connectors send snapshots and poll command queues. Apps authenticate users, request authorised data, and submit supported actions.
The connector authenticates to its broker over HTTPS.
The broker validates user, membership, role, and licence.
Commands are queued instead of opening an inbound session.
The connector applies supported actions and reports completion.
Identity
Use built-in account authentication or configured organisation OIDC sign-in.
Map approved domains to an identity provider and link existing accounts once.
Built-in MFA protects password sign-in; federated MFA is handled externally.
Delegate operational administration without granting core system control.