Alternatives ยท 9 min read

RustDesk for business support: where open source fits and where it stops

Written for: IT teams and MSPs weighing self-hosted open-source remote access against a managed remote support service.

Written by the 247connect Marketing Team

Self-operated or managed

A self-hosted relay server surrounded by maintenance tasks on one side, and a managed service with a supported audit trail on the other.A self-hosted relay server surrounded by maintenance tasks on one side, and a managed service with a supported audit trail on the other.
With open source the licence is free and the operating work is not: a public-facing relay to patch, accounts to govern, and a session history someone must be able to export on demand.

In short

Open-source remote desktop tools such as RustDesk are genuinely capable, and for a technically confident team with a small estate they can be a sound choice. The costs are not in the licence: they are in running a relay or rendezvous server as a public-facing privileged service, keeping it patched, proving who connected to what, and having someone available when it fails during a major incident. The honest comparison is not free versus paid but self-operated total cost, including risk and hours, versus a managed service with a supported audit trail.

Key takeaways

  • Open-source remote access is not free to run; the cost moves from licence to hours, risk and on-call cover.
  • Self-hosted relay infrastructure is internet-facing privileged access and needs the patch cadence to match.
  • Audit trails, retention and export are usually the first gap auditors and insurers find.
  • Account governance matters: enforced MFA, scoped permissions and offboarding must be somebody's job.
  • Bus factor is a real risk when one engineer understands the deployment.
  • For small estates with strong in-house skills, self-hosting can be the right answer; write the criteria down and revisit them yearly.

What self-hosting actually costs

The licence line is zero and the operational line is not. Running your own relay or rendezvous infrastructure means provisioning and monitoring servers, renewing TLS certificates, applying security patches promptly, testing backups and restores, watching capacity, and having someone reachable when the service fails at the worst possible moment, which for support tooling is during a major incident.

Price those hours at an honest internal rate for a year and compare that figure with a managed subscription. For a small estate with an engineer who enjoys the work, self-hosting often still wins. For a busy desk where those hours would come out of ticket time, it usually does not.

Security posture and governance

Remote access grants privileged entry into every machine you manage, so the governance around it matters as much as the software. Public guidance from the NCSC, CISA and NIST is consistent on the fundamentals, and they apply identically to open-source and commercial tools.

The rows to close deliberately in a self-hosted deployment are account governance, patch cadence and audit. Can multi-factor authentication be enforced on every operator account rather than left optional? Are permissions scoped so a first-line technician reaches only their devices? Is there a documented process to remove access when someone leaves the same day? Who applies security updates to the relay, and within what window of a published advisory?

None of these are arguments against open source. They are the work that a managed service otherwise absorbs, and they need a named owner either way.

The audit trail question

The gap most often found late is evidence. Insurers, auditors, cyber certification schemes and larger customers increasingly ask a simple question: show me who connected to which machine, when, and for how long, for the last twelve months.

Before committing to a self-hosted deployment, establish exactly what your setup records, where those records are stored, how they are protected from the operators they describe, how long they are kept, and how they are exported into a readable format. If the answer requires an engineer to assemble logs by hand, it will not survive an audit and it will not survive that engineer leaving.

When each option is the right one

Self-hosting fits when the estate is small, the team has genuine infrastructure skills and funded time, the data residency requirement is strict, and the audit expectation is light or already met by other systems.

A managed service fits when support hours are the scarce resource, when the estate spans sites and platforms, when audit evidence must be produced on demand, when access has to be revoked reliably during offboarding, and when someone other than your own team should be responsible at 2am.

Write your criteria down as a short list and revisit it annually. Estates grow, audit expectations tighten, and the engineer who set the deployment up eventually moves on. The answer that was right at twenty machines is often the wrong one at two hundred.

Common mistakes

  • Counting the licence as the cost and ignoring hours, on-call and risk.
  • Leaving a public-facing relay server unpatched between projects.
  • Optional rather than enforced multi-factor authentication on operator accounts.
  • No documented same-day offboarding for operator access.
  • Discovering during an audit that session history cannot be exported in a readable form.
  • A deployment only one engineer understands.

Frequently asked questions

Is open-source remote desktop software safe for business use?
It can be, provided the governance around it is done: enforced multi-factor authentication on operator accounts, scoped permissions, prompt patching of any self-hosted relay, documented same-day offboarding, and an exportable session log. Those controls are the work a managed service absorbs, and they need a named owner in a self-hosted deployment.
What does self-hosting remote access really cost?
Provisioning and monitoring, TLS certificate renewal, security patching on a short cadence, backup and restore testing, capacity management, and out-of-hours availability when the service fails during an incident. Price those hours at an internal rate for a year and compare that against a managed subscription rather than against a zero licence fee.
What audit evidence should a remote access setup produce?
A record of who connected to which device, when, and for how long, retained for as long as your obligations require, protected from the operators it describes, and exportable in a readable format without an engineer assembling it by hand.
When should a team move from self-hosted to managed remote access?
When support hours become the scarce resource, when the estate spans multiple sites or platforms, when audit evidence has to be produced on demand, when reliable same-day offboarding is required, or when only one person understands the deployment.

Why teams choose 247connect

  • Fixed, predictable pricing

    Unlimited operators with five concurrent connections per user, so the bill does not move every time the team grows.

  • Both access models included

    Managed (unattended) access to devices you own and on-demand (attended) access to devices you do not, in the same console.

  • Fast time to session

    Sessions typically connect in around eight seconds, which is the number a support desk feels dozens of times a day.

  • Zero-trust, AES-256 encrypted

    Outbound agent connections with no inbound port to forward, and session activity logged against a named operator.

  • Try it on your own estate

    A 14-day trial with 2 on-demand licences and 10 managed devices, no credit card required.

Where 247connect fits: it is the managed side of this comparison. Agents connect outbound with no inbound port to forward, sessions are AES-256 encrypted under a zero-trust model, and activity is logged against a named operator and device so the audit question has a straightforward answer. If your team has the skills, the time and a small estate, a self-hosted open-source deployment remains a legitimate choice. If the hours or the evidence are the problem, the 14-day trial covers ten managed devices and two on-demand licences.

More alternatives and pricing guides