Guacamole usually starts as a convenience and ends up as the front door to production: the thing contractors, on-call engineers, and auditors go through to reach RDP and SSH. DepKeep keeps that front door patched, upgraded, and understood — including the native protocol libraries underneath guacd, where most of the real exposure lives.
We don't speak for the Apache Guacamole project; it's a healthy, well-run community. What we provide is the responsive, accountable support, patching, and expertise the volunteer model isn't designed to provide, for teams that need it.
Most Guacamole exposure isn't in the Java client — it's in guacd and the C libraries it links: FreeRDP, libVNCServer, libssh2, libtelnet, and the image and codec libraries beneath them. We triage advisories across that whole tree and ship a patched build.
LDAP, SAML, OpenID Connect, CAS, RADIUS, Duo and TOTP, layered over a JDBC backend. The extension stack is powerful and unforgiving — we review how yours is composed, because precedence between auth extensions is where quiet over-permissiveness hides.
Stay on the Guacamole version your environment is validated against and still receive security and critical bug fixes — so you modernise on your timeline, not upstream's.
Guacamole upgrades mean applying database schema scripts in the right order, keeping guacd and the web application in step, and re-validating every auth extension. We plan and execute the upgrade against a copy of your environment first.
WebSocket proxying that doesn't drop sessions, sticky routing across multiple guacd instances, and session recording that stays affordable to store and actually replayable. These are the things that decide whether Guacamole is invisible or a daily complaint.
Guacamole's Java extension API can source connections from your own systems, enforce bespoke authorization, or rebrand the interface entirely. We build those extensions and keep them compiling as the upstream API moves.
We map your topology — web application, guacd instances, reverse proxy, database, and which auth extensions are stacked in what order — and review who can currently reach what through the gateway.
We agree a coverage plan: which versions are in scope, your CVE-response targets across Guacamole and the native protocol libraries, and a validation baseline for connections and recordings.
New advisories are triaged promptly after disclosure, backported to your supported version, tested against real RDP, VNC and SSH targets, and delivered as a patched build with full change documentation.
Upgrade planning, schema migrations, extension work, and scaling help on call — so the gateway keeps up as your access requirements and audit obligations change.
Vendors reaching internal systems from a browser, with no VPN client to install or revoke. Convenient precisely because it's exposed — which is what makes patch latency on this host matter more than on most.
One audited doorway in front of RDP and SSH estates, replacing a sprawl of per-team jump boxes. The gateway becomes the control point, so its availability becomes an operational dependency.
Session recording to satisfy auditors in finance, healthcare, and public sector environments. Recordings are only worth having if they're complete, retained correctly, and replayable years later.
Browser-delivered desktops for classrooms, demos, and segmented industrial networks where installing a client on every endpoint isn't practical or permitted.
Browse project health pages for CVE history, release cadence, and support options.
Tell us how Guacamole is deployed and who goes through it. We'll come back with a scoped proposal within one business day.