KORTHEXDocumentation

Docs / INTEGRATIONS

INTEGRATIONS

Korthex Remote

Written and maintained by Hendrik Schneider · Last reviewed · How we check this

Korthex Remote is the mobile companion app for Korthex Desktop. It lets you stay on top of your cryptographic posture from your phone - review findings, trigger remote scans, monitor active operations, and receive critical alerts wherever you are. The desktop and your phone communicate through an end-to-end encrypted channel relayed by a zero-knowledge server : the relay only routes opaque, signed envelopes between paired endpoints and never sees the contents of your data. Pairing is persistent and revocable from either side. Korthex Remote is currently available for Android (8.0 / API 26 and above) . An iOS version is on the long-term roadmap but not yet scheduled.

Installation

System Requirements Getting the App Korthex Remote will be distributed through the Google Play Store on launch. During the beta period, an APK is available on request from your Korthex account portal. Korthex Remote is a free companion app. A paid Korthex Desktop license is required to pair and use it.

ComponentRequirement
OSAndroid 8.0 (API 26) or newer
Storage~30 MB for installation
NetworkWi-Fi or mobile data - same network as the desktop is NOT required
CameraRequired for QR-code pairing
Korthex DesktopInstalled and signed in with a valid Korthex license on at least one machine

Pairing Your Phone

Pairing connects your phone to a specific Korthex Desktop installation. The first pair takes about a minute. Once paired, the phone and desktop reconnect automatically whenever both come online - no QR rescan needed. Step 1 - Sign in on Mobile On first launch, the mobile app asks for your Korthex account email and a 4-digit PIN . The PIN is generated automatically by Korthex Desktop and rotates every 30 seconds. Open Korthex Desktop on your computer. Navigate to Settings → Pairing . The current PIN is displayed in a large monospaced card with a 30-second countdown. Type the email and PIN into the mobile app before the countdown runs out. The PIN never travels to a third party - it is verified by the Korthex backend against your active license. Wrong PIN attempts are rate-limited. Step 2 - Scan the QR Code After login, the mobile app opens its camera scanner. On Korthex Desktop, click "Generate Pairing Code" in the Pairing tab - a QR code appears with a 90-second validity window. Hold your phone up and scan it. Step 3 - Verify the Code (SAS) Once the phone scans the QR, both devices independently derive the same 6-digit verification code (Short Authentication String) from the cryptographic key exchange. Compare the digits on both screens - they must match exactly. This step protects against a sophisticated attack where someone intercepts the pairing in transit. If the numbers differ, abort the pairing and try again. After the codes are confirmed identical, tap Confirm on the desktop. Step 4 - Done The phone is now paired. It appears in Settings → Pairing → Linked Devices on the desktop, and the mobile app lands on the dashboard. The pairing is persistent: the next time both come online they reconnect silently. The pairing code (QR) expires after 90 seconds. If you miss the window, just generate a new one.

Mobile Dashboard

The dashboard is the home screen of Korthex Remote. It summarizes the security posture of the connected desktop at a glance. Posture Card A traffic-light header ( Healthy , Watch , Degraded , Critical ) summarizing the overall security state of the desktop, plus three tiles showing live counts: Tap any tile to jump straight into the findings list filtered by that severity. Quick Actions A 2×2 grid of one-tap shortcuts: Open Inbox , View Findings , Trigger Scan , and Manage Connection . The Inbox tile also displays an unread-count badge. Recent Alerts Inline preview of the three most recent events from the inbox - newest first - for at-a-glance situational awareness without leaving the dashboard. Connection Strip A persistent header bar shows the active desktop instance name, platform tag (e.g. "Windows Server 2022", "macOS 14"), and live connection state ( Online , Reconnecting , Offline ) with measured latency.

TileShows
CriticalNumber of open critical findings.
HighNumber of open high-severity findings.
Resolved (24h)Findings closed or remediated in the last 24 hours.

Inbox & Findings Browser

Inbox The inbox is the chronological event feed pushed from your desktop. Filter by event type, severity, or unread-only with the filter chips at the top of the screen. Findings Browser The findings tab opens directly onto the open-findings list with severity tabs (Critical / High / Medium / Low / Info) at the top. Each row shows the title, affected asset, rule, and a relative timestamp. Finding Detail Tapping a finding opens the detail view with a colored severity stripe and the following sections: Identity - asset path, rule, CVSS score. Timeline - first seen, last seen, current status (Open / Acknowledged / Muted / Resolved). Description - what was detected and why it matters. Evidence - supporting context from the analysis (without leaking your source code itself). Remediation - recommended fix steps.

Event TypeDescription
PanicServer-broadcast alerts requiring immediate acknowledgement.
FindingA new cryptographic finding was detected during a scan.
ScanScan started, progressed, completed, or failed.
SystemConnection events, certificate expirations, pairing requests, session changes.

Triggering Remote Scans

You can start a scan on your paired desktop directly from your phone. The desktop executes the scan locally - your source never leaves the machine - and pushes progress and results back to the mobile inbox in real time. Scan Profiles The active-scan banner appears at the top of the Scans tab while a scan is running, with a live progress indicator. Tap to cancel. Triggering a scan is a sensitive action: on production builds it is gated by a biometric prompt (fingerprint / face) before the request is sent. Scan History The lower part of the Scans tab lists past scans with their profile, duration, file count, and finding totals. Tap a past scan to open its summary.

ProfileBest ForTypical Duration
QuickFast sanity check on staged or recently changed files.Seconds to a minute
StandardFull project scan with the default engine set.Minutes
DeepMaximum-depth scan with every engine and full context analysis enabled.Tens of minutes on large repos

Multiple Desktops

One phone can be paired with any number of Korthex Desktops under the same license. This is useful when you run Korthex on a work machine, a personal laptop, and a build server. Switching Active Desktop The top app bar shows the currently active desktop's name and platform. Tap the Switch button (or the row in Settings → Active Instance ) to open a bottom sheet listing all paired desktops with their online state. Pick one to make it the active focus of the dashboard, inbox, and findings tabs. Pairing Additional Desktops From Settings → Pair New Desktop , the camera scanner opens and the standard QR + SAS flow runs again - no re-login required. Re-pairing the same physical desktop replaces the existing pair record rather than stacking duplicates. When all desktop pairs are revoked, the mobile app returns to the login screen. Your account email stays remembered; only the 4-digit PIN is asked again.

Notifications & Panic Alerts

Korthex Remote uses six dedicated Android notification channels so you can tune the experience per category (sound, vibration, badge, Do-Not-Disturb behavior) from your system notification settings. Panic Alerts Panic events take over the screen immediately, even on a locked device: Lock-screen takeover - the alert wakes the screen and paints over the lock screen. Survives Silent / DND - the alarm sound plays through the alarm stream, which Android exempts from per-app mute and Do-Not-Disturb. Force vibration - paired waveform pattern alongside the audio. Hold-to-Confirm - acknowledgement requires a deliberate 1.6-second hold to prevent accidental dismissal. A conic progress ring around the button shows progress; releasing early cancels. Reduce-motion fallback - when system animations are disabled, a standard confirm dialog appears instead.

ChannelUsed ForImportance
PanicServer-broadcast emergencies. Bypasses Do-Not-Disturb. Plays an alarm sound.High
Findings · CriticalCritical-severity findings discovered during a scan.High
Findings · HighHigh-severity findings rolled up at end of scan.Default
ScansScan running / completed / failed status. Silent.Low
SystemConnection drops, certificate expirations, pairing requests, session events.Default
Connection (background)Persistent collapsed indicator while the background service runs.Minimum

Security Model

Korthex Remote is engineered around a simple principle: the relay server should be unable to read or impersonate either side, even if it is fully compromised. End-to-End Encryption Every payload exchanged between desktop and phone is encrypted with a session key derived during pairing through an ECDH key exchange. The relay only sees opaque signed envelopes - it can route them but cannot read or alter them. Pairing Verification (SAS) The 6-digit code shown during step 3 of pairing is derived from the shared cryptographic material. A man-in-the-middle would force the codes on both screens to differ - which is why visual confirmation by the human user is the final and indispensable step. Long-Term Identities After successful pairing, both sides hold long-lived signing identities used to reconnect silently in the future without re-scanning a QR code. On Android these identities live in Android Keystore (hardware-backed where available) via encrypted shared preferences. On desktop they are stored in the OS secure store (DPAPI on Windows, Keychain on macOS, libsecret on Linux). Revocation You can revoke a paired phone at any moment from Settings → Pairing → Linked Devices on the desktop. Once revoked, the phone loses all access immediately and silently - even if it is offline at the time of revocation, the next reconnect attempt is rejected. Revocations are server-side authoritative and cannot be circumvented by a stolen phone. License Binding A pairing is bound to a specific Korthex license. If the license is reassigned or deactivated, all phones paired under it lose access on the next reconnect attempt and fall back to the login screen. In short: the relay sees only metadata it needs for routing. Your source code, your findings, and your scan output never travel through any server outside of your own Korthex Desktop instance.

Settings

The Settings tab gives you direct access to account, connection, notification, and pairing controls. Connection Diagnostics Manage Connection provides a built-in connection test that measures round-trip latency, identifies the active transport (WebSocket, Server-Sent Events, or long-polling fallback), and reports the reason for the most recent offline state. Useful when debugging captive Wi-Fi portals, corporate proxies, or VPN interference.

SectionControls
AccountProfile information, license status, sign out.
Active InstanceSwitch which paired desktop the dashboard is currently focused on.
Pair New DesktopOpens the camera scanner to add another desktop to your account.
Manage ConnectionConnection status, transport details, latency diagnostic, danger-zone actions (disconnect, force reconnect).
OnboardingReplay the welcome tour.
ThemeLight / Dark / System default.
AboutApp version, build info, open-source licenses.