RMM · Multi-tenant by design

Every endpoint.
Every client.
One console.

MateConnect is the remote monitoring and management platform built for managed service providers. Inventory, patching, automation and unattended remote access — across every tenant you support.

✓ No credit card required✓ Agent deploys in one command✓ Unlimited endpoints in trial
Fleet · northstar.mateconnect.proLive
Alert · disk threshold
SDR-POS-021
System drive below 8% free · remediation script queued
157
Endpoints
94%
Patched
3
Alerts
NSL-WS-042
Northstar Legal · Windows 11 Pro
ONLINE
RSH-MBP-014
Riverstone Health · macOS 15.6
ONLINE
SDR-POS-021
Sundial Retail · Windows 10 IoT
DEGRADED
SDR-LNX-008
Sundial Retail · Ubuntu 24.04
OFFLINE
Managing endpoints for MSPs across three continents
NetaMateNorthstar LegalRiverstone HealthSundial RetailUconnexWalk-In IT
Built for MSPs

Everything you need to run a managed fleet

MateConnect is not a single-tenant RMM with an agency label bolted on. Tenancy, identity and audit are foundations, not features.

Multi-tenant by design

One console, every client. Organizations and sites are enforced in the database, not filtered in the UI — a technician cannot see across a tenant boundary.

Inventory that stays current

Hardware, OS, users, network, security posture and installed software, collected on a schedule and diffed so you see what changed and when.

Patch management

Approval rings, maintenance windows and reboot policy per tenant. Scan, install and verify are server-owned state machines, not fire-and-forget scripts.

Unattended remote access

Native remote desktop over WebRTC with H.264, multi-monitor support and TURN relay fallback. No inbound ports on the endpoint, ever.

Scripting and automation

Approved scripts with typed parameters and secret handling. Turn repeated remediation into scheduled automation instead of tribal knowledge.

Advanced endpoint tools

Processes, services, files, registry, event logs, scheduled tasks, network and diagnostics — every action allowlisted and audited.

157
Endpoints on a single gateway node
94%
Median patch compliance across tenants
< 60s
Inventory change to console
0
Inbound ports opened on managed endpoints
How it works

From zero to a managed fleet in an afternoon

01

Enroll an endpoint

Create a site-scoped enrollment token and run one command. The agent generates its own identity, stores credentials in OS-protected storage, and dials out over TLS. No inbound firewall rule, no shared organization key.

02

Set policy per tenant

Patch rings, maintenance windows, alert thresholds, remote consent and recording rules are configured per organization. Technician permissions are enforced server-side at the capability boundary, not in the interface.

03

Operate the fleet

Watch presence and health in real time, run bounded commands, open a live terminal or take an unattended remote session. Every privileged action is audited with the principal that authorized it.

Security posture

Built to be audited

An RMM has administrative reach over every machine it touches. The architecture assumes that and constrains it.

Outbound only

Endpoints open no inbound management ports. Agents dial out over authenticated TLS.

Tenant isolation

Row-level security is forced at the database, with composite keys preventing cross-tenant joins.

Per-device identity

Every endpoint holds its own credential. Enrollment tokens are short-lived and single-use.

Signed updates

Agent updates are Ed25519-signed against a trust anchor compiled into the binary.