Kaseya designed the Integrated IT Software Suite with comprehensive security throughout. The Kaseya design team
brings over 50 years of experience designing secure systems for government and commercial applications. Kaseya
applied this experience to uniquely combine ease of use with high security.
Kaseya Agent
The Kaseya platform architecture is central to providing maximum security. Each computer managed has
a small agent installed. The agent initiates all communications back to the server. Since the agent will not
accept any inbound connections, it is impossible for a third party application to attack the agent from the network.
Firewalls
Kaseya does not need any input ports opened on client machines. This lets the agent do its job in any
network configuration without introducing susceptibility to inbound port probes or new network attacks.
Encryption
Kaseya protects against man in the middle attacks by encrypting all communications between the agent
and server with 256-bit RC4 using a key that rolls every time the server tasks the agent, typically at least
once per day . Since there are no plain text data packets passing over the network, there is nothing available
for an attacker to exploit.
Secure Access
Administrators access the Kaseya server through a Web interface after a secure logon process. The system
never sends passwords over the network and never stores them in the database. Only the administrator knows
his or her password. The client side combines the password with a random challenge, issued by the Kaseya server
for each session, and hashes it with SHA-1. The server side tests this result to grant access or not. The unique
random challenge protects against a man in the middle attack sniffing the network, capturing the random bits,
and using them later to access the Kaseya server.
Web Access
The Web site itself is protected by Kaseya Patch Management. The Kaseya Patch scan is run on the Kaseya
server every day. As soon as new patches are released, the Kaseya Patch scan automatically detects they are needed
and applies all security patches automatically. Finally, for maximum Web security, the Kaseya server Web pages
fully support operating as an SSL web site.
Kaseya Endpoint Security
Add-on Module
Kaseya Endpoint Security (KES), a powerful and proven add-on to the Kaseya IT Framework, provides an essential security protection component. By incorporating reactive antivirus and spyware detection with the latest proactive technologies, MSPs and Corporate IT Professionals are able to include effective protection against malicious programs ensuring not only anti-virus protection but protection from unknown threats.