Flamingo Raises $4.5M Seed Round

Hey. Kristina here. I looked for some content on remote access software and noticed lots of roundups are in fact vendor promotions. At the same time, I have on my team the person who's been working with MSPs and IT teams for more than 25 years and has used a lot of remote support systems - enterprise grade, consumer grade, commercial grade. It's Conrad, our Solution Architect.

Conrad and I recorded a video for you to help you make a well-informed decision. It's not sponsored, and our product - OpenFrame - is not there. So consider it an independent review.

Below, you'll be able to find pricing that I consolidated from multiple MSP sources (as vendors keep it behind closed doors), a bit more detail on compliance, deployment, and license.

TL;DR

  • Do not pick the best remote access software, pick yours. Get your list of requirements and focus on them. Do not buy the 'best one'. There's no such thing, after all.
  • Basic packages are good enough.
  • Compliance costs more. SSO, recording and audit sit two or three tiers up.
  • Read the exit clause. TeamViewer and AnyDesk both block ordinary mid-term cancellation.

How to Choose

Focus on the need and why you're looking at the software. Do not look at the 'best' solution. A lot of these software platforms, especially in remote access, they've grown to a point where the remote access part is less important. They're adding RMM solutions, security solutions. So if you're just looking for remote access and remote support, you've got to think about why you're paying extra money for an antivirus?

Define your requirements first and then find the right solution. Don't find the right solution and figure out how you're going to use it.

How to Define Requirements

It's really about determining how many technicians you have, how many devices you have, the cost of those technicians' labor, and how many sessions you can create, and your compliance.

Compliance

Clients under HIPAA, PCI or ISO 27001 audit their suppliers, and remote access tooling is a standard line on that questionnaire. They're going to ask you what tools you use, and you're going to have to be able to tell them that you're using something that is secure.

Assessing suppliers is written into ISO 27001 itself, so the question isn't hypothetical. One thing worth checking before it becomes a problem: even a compliant tool has a retention period, and if a client asks what happened three months ago and the logs only go back thirty days, compliant and useful turn out to be two different things.

Devices

Start with attended versus unattended and count your use cases before you count licenses, because vendors price the two differently. Then work out which licensing model your shape of business rewards, and model it at the endpoint count you expect in two years rather than the one you have.

Then hold every candidate to the same bar:

  • MFA on technician accounts, enforced rather than optional
  • Session recording whose storage location you control, with audit logs an auditor can read
  • Role-based permissions per client, device group, and action
  • SSO and automatic session timeouts, and confirmation of which tier they require
  • A patch record you looked up yourself, not the one on the security page

That last one takes ten minutes. Search the vendor name on the NVD, sort by date, and read the last two years. The gap between tools in this roundup is enormous, and none of it is visible in a review score.

Next, run the renewal test before you sign, not after. Find the notice period and whether ordinary mid-term termination is excluded, because at two vendors here it is. Then trial your top two on your worst network, with your slowest client hardware, on real tickets, for longer than a demo.

Meet the account rep, tell them what you're evaluating, and ask what they can do to keep your business.

First Thing to Do When You Start Using the Product

The demo sells every feature, and month three is when the bill and the feature list start disagreeing with each other.

Device hygiene is the first shock. Pay per device, and offline devices still bill you. You might have a hundred devices and you know you've got a hundred devices, but you're getting billed for a hundred and twenty or a hundred and thirty.

Most platforms ship with automated cleanup switched off, so a machine that's been offline for ninety days stays on the invoice until someone deletes it by hand. The fix costs nothing: find the cleanup setting, set a cutoff of 30, 60 or 90 days, and let the tool retire stale devices on its own.

Remote Access Software Comparison Table

ToolFitsWatch out forPublished price, Sep 2026Self-hostCVEs 2024-26
ConnectWise ScreenConnectTechnicians who live in sessions10 CVEs, four rated 9.0+$45/tech/mo annual, $59 monthlyYes10
SplashtopFleet work on a budgetRefuses HIPAA BAA in writing$6-$13/user/mo; SOS from $259/yrYes, quote-only10, all local
LogMeIn RescueCompliance-heavy help desks$109/tech/mo, ~29% renewal step-up$109/tech/mo annualNo0
BeyondTrust Remote SupportRegulated enterprise supportBreached in 2024, reached US TreasuryQuote-onlyYes, appliance7
TeamViewerMixed and legacy device estatesNo MSP PSA integrations at allEUR 16.90-166.90/moNo~30
ISL OnlineData residency, flexible licensingNo verifiable RMM or PSA hookNone publishedYes0
Zoho AssistSmall desks already on ZohoDepartments gated to Enterprise$10-$24/tech/mo annualNo0
LogMeIn ResolveMSPs wanting real tenancyLinux appears unsupportedNot publishedNo0
AnyDeskWeak links, aging hardwareNo ordinary mid-term exitEUR 28.90-111.90/moUltimate only8
RemotePCMany endpoints, few techniciansRoles and grouping are Enterprise-only$59-$1,199 per 2 yearsYes0
TSplus Remote AccessStable Windows server fleetsNo published compliance evidence$200-$2,660 perpetualOnly model5
Chrome Remote DesktopPersonal machinesNot a HIPAA BAA-covered serviceFreeNo1

What MSP Communities Have to Say

Reading roughly 500 comments across seventeen r/msp and r/sysadmin threads from the past twelve months turns up a priority order that doesn't match the feature grids.

Pricing model comes first, and it's the model rather than the sticker. Per-concurrent-technician stays flat as endpoints grow and rewards small teams covering large fleets. Per-computer does the reverse. Per-server perpetual rewards estates that don't change. Whichever you pick, model it against your real counts, because the cheapest tool at 50 endpoints is rarely the cheapest at 500.

Second is the one nobody puts in a comparison table: background access depth. Technicians will take worse video to keep registry, services, command line and file transfer without booting the user off their own screen. It came up 27 times in the corpus, roughly three times more often than latency. As one MSP put it while explaining why they were migrating away from ScreenConnect on security grounds anyway: "nothing beats Screenconnect (self hosted) in features, latancy, 'back stage' capability set".

Third is agent reliability, which almost never appears in reviews and reliably causes replacements. Service lockups, black screens on login, and agents that need a PowerShell restart before they'll accept a session are what push an MSP to migrate a whole fleet.

Then security posture, then performance, then deployment mechanics at scale. Contract behavior ranks near the bottom at first purchase and near the top at renewal, which is exactly why it catches people.

Two things rank lower than you'd expect. RMM and PSA integration barely registers as its own criterion, because it collapses into a pricing question: is remote access already bundled in the RMM I pay for? And session recording matters less than compliance marketing suggests, mostly because it's tier-gated everywhere, which changes your budget rather than your shortlist.

The Compliance Price Is Not the Advertised Price

This is the calculation that catches MSPs with regulated clients, and it's consistent across every major vendor.

ScreenConnect puts session recording at Standard and video auditing at Premium. Splashtop gates SSO, cloud session recording, IP allowlisting and SIEM export to Enterprise, which is quote-only. AnyDesk gates SSO to Ultimate, also quote-only. TeamViewer gates SAML SSO and audit logging to Tensor, likewise quote-only. Zoho Assist gates session recording to Remote Support Enterprise.

So if your client list includes anyone under HIPAA, PCI or CJIS, the tier you end up buying is two or three above the one in the ad, and at three of those four vendors it has no public price at all. Budget a procurement cycle, not a checkout page.

LogMeIn Rescue is the exception worth knowing about: SAML 2.0 SSO and more than 40 granular permissions ship in its published tier rather than behind a quote. It also lets you choose where recordings are stored, including a UNC path, FTP or your own HTTPS server, and can block remote control outright if a recording can't be saved. For chain-of-custody evidence that is a materially different product from one that writes an MP4 to the technician's laptop.

The 12 Tools, Grouped by Who They Suit

For technicians who live inside sessions

ConnectWise ScreenConnect. Backstage mode runs PowerShell and file operations without interrupting the user, the toolbox keeps scripts one keystroke away, and session groups organize hundreds of client machines per tenant with role-based security that can hide groups from a role entirely. It remains the benchmark for technician workflow, and MSPs say so even while leaving. Published pricing is $45 per concurrent technician per month billed annually, $59 monthly, with Premium at $55 and $69; the $30 "One" plan caps at ten unattended agents and one session, so it isn't the small-shop price it looks like. Self-hosting is still offered.

The security record is the problem. Ten CVEs across 2024 to 2026, four of them rated 9.0 or higher, including CVE-2024-1709 at a maximum 10.0 that was mass-exploited, and CVE-2026-84869 at 9.9, published 8 September 2026, which allows files to be transferred and executed through an active session without authorization or host confirmation. The patch floor is 26.6.5. Worth knowing before a compliance conversation: ScreenConnect is not named in ConnectWise's own certification list, and its SOC 2 reports sit behind an NDA. The ConnectWise ScreenConnect review goes deeper on stack fit.

For fleet work on a budget

Splashtop. Business Access runs $6 to $13 per user per month; attended support through SOS is $259 or $399 per year per concurrent technician. Integration coverage is the broadest here, spanning Atera, Datto, Syncro, SuperOps, NinjaOne, HaloPSA and about twenty more, with ConnectWise and Autotask the notable gaps.

Now the part that changes your invoice. Splashtop runs a private-label program, and several RMMs ship its engine as their remote access. Atera's documentation says it's included "at no additional cost," installs automatically with the Atera agent, and adds that it is "not possible to bring your own Splashtop license to Atera." Datto RMM embeds it too, and installing through Datto removes your ability to use your own Splashtop credentials. Syncro and SuperOps both include it in the subscription price. If you run any of those, you are already paying for Splashtop, and buying SOS separately only earns its keep on attended or unmanaged endpoints outside the RMM.

Three caveats that don't appear in the marketing. Splashtop states plainly that it "should not be considered as your business associate," so there is no HIPAA BAA. Enabling session recording proxies every session through Splashtop's servers, which defeats peer-to-peer. And regional data residency covers the account database only, because the US, EU and Australian stacks share the same relay servers. Ten CVEs since 2024, all local privilege escalation, no remote pre-auth RCE. It is also named as an abused tool in four CISA advisories including Black Basta and Scattered Spider, which is an agent-abuse risk rather than a product flaw, but it means EDR will look at it. The Splashtop review covers tiers and security posture.

For compliance-heavy help desks

LogMeIn Rescue. Queue management, session transfer, multi-technician collaboration, and Rescue Lens, which turns the end user's phone camera into a feed so a technician can see the printer or the router lights on a machine with no agent. Zero CVEs from 2024 to 2026. EU data residency is confirmed and chosen at account creation, with no storage link between the EU and US datacenters. The security tier is the published tier, as covered above.

Price it properly: $109 per technician per month billed annually, $149 monthly, per named technician rather than per concurrent session. The terms reserve the right to change price after the initial term and renew you "at the then-current price," which works out around a 29% step-up unless you renegotiate. Cloud only, no self-host, and Linux unattended access is still listed as coming soon. The GoTo-level HIPAA BAA exists but does not name Rescue, so get that in writing.

BeyondTrust Remote Support. Credential injection means technicians authenticate to endpoints without seeing a password, Jump Clients handle unattended endpoints, and protocol tunneling brokers RDP and SSH through the same audited channel. The compliance shelf is the deepest here: FedRAMP Moderate, TX-RAMP, SOC 2 Type II and four ISO certifications. Platform coverage is the broadest of the twelve, including Chrome OS and headless Linux. Pricing is quote-only.

It also has the most serious incident record in this roundup, and any MSP shortlisting it for regulated clients needs to weigh that. In December 2024 attackers used a stolen API key to compromise 17 Remote Support SaaS instances, having exploited CVE-2024-12356 and CVE-2024-12686 as zero-days. CISA added both to the Known Exploited Vulnerabilities catalog with a three-day federal patch deadline, and the US Treasury disclosed a network compromise through its BeyondTrust instance. Five more critical CVEs followed in 2026, three of them pre-auth. The vendor patched and disclosed; whether that record reads as diligence or as risk is a judgment call, and it should be a conscious one.

For mixed and legacy device estates

TeamViewer. Still the longest device list here, covering Windows Server with terminal-server sessions, macOS, six Linux families, Android, iOS, ChromeOS and Raspberry Pi, plus embedded systems newer vendors skipped. Strongest published crypto of the group: 4096-bit RSA key exchange, AES-256, and mutually authenticated TLS 1.3 from version 15.73. All sensitive-data servers sit in Germany or Austria. Its compliance portal and its trust center do disagree with each other on CSA STAR, the portal claiming Level 2, which is third-party audited, and the trust center listing Level 1, which is self-attested. The portal also carries its own disclaimer that the information "may not always be up-to-date and are non-binding," which is worth reading twice before you cite anything from it.

Three things to weigh. It carries roughly 30 CVEs across 2024 to 2026, including CVE-2026-12703, which bypasses the 2FA-for-Connections approval flow through unattended access, and CVE-2026-19042, a command injection on Linux clients through a crafted URL sent in chat. Patch floor is 15.81.5. Its EULA sets a twelve-month auto-renewing term with 28 days' notice and states that "ordinary termination rights are excluded during the Subscription Term." And for MSPs specifically, the PSA gap is total: no ConnectWise, Autotask, HaloPSA, Syncro, NinjaOne or Atera, and TeamViewer ended its NinjaOne agreement at the end of 2025.

The free tier deserves a warning. Commercial use is defined as any use "directly or indirectly paid for," including checking work email from home, the detection heuristics are unpublished, and the failure mode is a bare connection timeout. The flag is sticky on the target device: connections to a device flagged as commercial stay blocked "even if your device has been reset to personal use." One MSP's experience of a related licensing change is instructive: a perpetual license reduced to LAN-only, with no refund, buyout or conversion offered.

See the TeamViewer review for MSPs for the fuller picture.

For data residency and licensing flexibility

ISL Online. An ISO 27001-certified European vendor, certified since 2017, selling three licensing models where nearly everyone else sells one: cloud licensed per concurrent session rather than per named technician, pay-per-use for sporadic volume, and a fully self-hosted server license. Ten technicians can share licenses sized to simultaneous sessions instead of headcount. Session recording and forced 2FA are both there, and admins can remove the "don't ask again on this device" option.

It has zero CVEs published between 2024 and 2026, the cleanest record of the twelve. Two limits: no numeric pricing is published anywhere, and no RMM or PSA integration could be verified at all, which is close to disqualifying if your workflow starts in a PSA ticket. Its SOC 2 and HIPAA language describes alignment rather than its own audit report.

For small desks

Zoho Assist. $10 per technician per month billed annually at Standard, $15 Professional, $24 Enterprise, with a genuine free tier of one technician and five unattended computers. Diagnostic tools reach the remote machine's task manager, services and registry without a full control session, which is unusually good at the price. Zero CVEs. Audit retention runs 730 days with CSV export.

The limits are structural: Departments, which is how you separate client A from client B, is Enterprise-only, session recording is also Enterprise, and there is no verifiable ConnectWise, Autotask, HaloPSA, Syncro, NinjaOne or Atera integration. Cloud only in practice.

Chrome Remote Desktop. Free, browser-based, fine for reaching your own machines. For MSP work the disqualifier is not the missing features, it's the contract: Google classes it an "Optional Service" outside Workspace's data processor terms, and it is absent from the Workspace HIPAA Covered Services list, so it is not a BAA-covered service. There is no tenancy concept, no session recording, no admin audit trail for ordinary sessions, and one CVE in window, CVE-2026-7994, a local privilege escalation on Windows. Treat it as the floor paid tools have to clear.

For many endpoints and few technicians

RemotePC. Priced by how many computers you connect rather than how many technicians you employ, which inverts the licensing math for small teams covering large estates: $59 per two years for Solo, $199 for 10 computers, $599 for 50, $1,199 for 100, with promotional rates running exactly 25% below list. The "save up to 50%" headline compares two-year prepay against monthly billing, not against list. Session recording is included from the entry tier and writes locally as MP4. There is an on-premise option, which is unusual at this price. Zero CVEs.

Two things to check before committing. Roles, access permissions and computer grouping are Enterprise-tier only, and no white-label or rebranding capability could be found at any tier despite the MSP page implying otherwise, so confirm that with sales rather than assuming. On renewal, the expansion tables label the discounted rate "first year" and the terms renew at the published standard plan, so budget year two at list.

For stable Windows server fleets

TSplus Remote Access. Perpetual per-server licenses from $200 to $2,660 in a category that moved to subscriptions years ago, publishing individual apps or full desktops through an HTML5 portal with no client install. Support and updates are included for year one, then 21% annually, and letting that lapse costs you patches, upgrades and the right to rehost the license. The "perpetual" license is capped at ten years by the EULA, and the vendor has form here: Remote Access v12 and earlier ceased functioning on 15 April 2026.

Be clear about what you're buying. It publishes no compliance evidence of any kind, verified across all 692 URLs on its site: no trust center, no SOC 2, no ISO 27001, no HIPAA or GDPR page. Two-factor authentication is a $330-per-server add-on, and enabling it denies RDP connections for those users. SAML SSO exists only in a beta the vendor labels "not ready for production use." Audit logging is off by default, writing to five plain-text local files with no SIEM export. There is no session recording in this product. It has no RMM or PSA integrations, also a verified negative, and its licensing model means one server per client rather than any multi-tenancy. Of its five CVEs, one was credentials stored in cleartext in the login page HTML.

AnyDesk. The DeskRT codec keeps sessions usable on connections that defeat other tools, the client is a small portable binary, and a genuine on-premises option exists at the Ultimate tier. Field technicians on hotel Wi-Fi have a point.

The paperwork is the strictest of the twelve, and it's quotable. AnyDesk's terms, last updated 10 October 2025, set a twelve-month initial term auto-renewing for twelve months with 30 days' written notice, carry a "No Ordinary Termination" clause blocking mid-term exit except for cause, and reserve a separate right to adjust prices during a subscription period. Eight CVEs since 2024, including one at 9.8 that is a heap overflow reachable through a crafted UDP packet, and one at 8.2 that lets a remote party with "Control my device" set a full-access password without the other side confirming. Its January 2024 production-systems breach forced a code-signing certificate rotation and portal-wide password resets.

One due-diligence note that says more than any of the above. AnyDesk's own site contradicts itself on encryption across three pages, listing TLS 1.3 with RSA-2048, RSA-4096 with ECC-256, and "banking-standard TLS 1.2" in different places. It also contradicts itself on ISO 27001: the compliance page says its data center partners hold the certification, another page claims AnyDesk itself does, and its trust center shows no ISO 27001 badge at all. Those are questions for a salesperson, not facts to cite.

For MSPs who want real tenancy

LogMeIn Resolve. Renamed from GoTo Resolve on 28 January 2025, which is worth knowing because it is a different product from LogMeIn Rescue and search results still conflate them. It has the cleanest multi-tenancy here: an explicit Tenants construct grouping devices, tickets and assets by the organization you support, plus brandable sessions and policies applied automatically at onboarding. It integrates with ConnectWise PSA and HaloPSA, which puts it in a small minority. Zero CVEs.

Zero-trust command signing is the differentiated piece: destructive jobs are signed with a key held by the agent rather than by LogMeIn, and endpoints verify before executing, which limits what a stolen console login can do. That is a vendor claim with no independent cryptographic audit behind it. Tier pricing is not publicly retrievable, Linux appears unsupported, and the deployment is cloud only.

Standalone Remote Access vs. Your RMM

If you run an RMM you already have remote access, and as the Splashtop section shows, you may be paying for it twice. A standalone tool still earns its keep in three cases: ad-hoc support for machines without your agent, a second channel for when the RMM agent itself is down, and licensing math where per-technician beats per-endpoint.

Before adding a thirteenth tool, be precise about the sprawl argument, because the popular version of it is out of date. The two most-quoted tool-sprawl figures in this market are vendor assertions repeated secondhand, and the largest actual MSP panel points the other way: in Kaseya's 2026 State of the MSP report, covering 1,061 MSPs, complaints about swapping between IT applications fell to 4% from 15%, and "too many vendors, too many contracts" fell to 5% from 9%. General tool friction is easing. Security tool sprawl is not: managing too many security products rose to 34% from 28%. Sixty percent still name reducing vendor fatigue as a 2026 priority.

The consolidation question runs the other way too. Disclosure again: OpenFrame is ours. It's an open, AI-native infrastructure layer for IT and security carrying remote access, RMM and a native PSA in one system rather than three vendors stitched together, with AI agents built into the infrastructure instead of added as another assistant, and MSPs and in-house IT teams buy it the same way. If three vendors currently bill you to reach one endpoint, that's the comparison worth running.

The Self-Hosted Route

RustDesk and MeshCentral offer what no commercial vendor here will: zero per-technician licensing and full control of the relay. The cost moves off the invoice and onto your calendar, and one MSP put the trade plainly, liking that they "held the kill switch" while growing wary of keeping any port open to the internet with bots constantly scanning these tools.

Start with the MeshCentral review or the RustDesk review on OpenMSP.

Where to Start

Match the tool to the shop. ScreenConnect if your technicians live in sessions all day and you can keep pace with its patch cadence. Splashtop if you're running fleets on a budget, unless a client needs a BAA. LogMeIn Rescue if audits drive your requirements and you can carry $109 a seat. Zoho Assist if the desk is small. ISL Online if residency or licensing flexibility leads. Give the winner two weeks of real tickets.

The demo shows you the codec. The renewal shows you the vendor. The CVE list shows you both. If a renewal notice has already landed, what MSPs did about the ScreenConnect price hike is the next thing to read.

Kristina Shkriabina

Content Marketing Lead

Ohayo! I'm Kristina, and I'm doing good things with content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

Remote Access

Remote access software lets a technician or user view and control a computer or mobile device from another location over an encrypted connection. It powers help desks, MSP fleet management, and remote work, with attended and unattended connection modes.
Attended access connects a technician to a device while a user is present to approve the session, which suits help desks. Unattended access reaches servers, kiosks, and managed endpoints with nobody at the keyboard, using a pre-installed agent.
Splashtop, ConnectWise ScreenConnect, and TeamViewer are the usual MSP shortlist. Splashtop wins on price-to-performance, ScreenConnect on technician control and self-hosting, and TeamViewer on device coverage. Per-technician pricing generally beats per-endpoint pricing for MSPs managing large fleets.
Free tools like Chrome Remote Desktop use solid encryption, but business use needs session recording, audit logs, role-based permissions, and enforced MFA, which free tiers rarely include. For client work or compliance environments, paid or self-hosted options are the safer call.
For support work, usually yes. A VPN places an entire device on the network, while remote access software brokers an encrypted session to a single machine with recording and per-action permissions. That gives auditors more control and shrinks the attack surface.
Look for enforced multi-factor authentication, encryption in transit, session recording with audit logs, role-based permissions per client and device group, SSO support, automatic session timeouts, and device authorization prompts for new endpoints. Compliance-heavy environments add credential vaulting and injection.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.