Privacy & Governance Policy
Effective Date: August 28, 2026 | Governing Entity: PME Energy Corporate IT Infrastructure
Strict Corporate Notice: PME-Stream-R is an internal proprietary software asset of PME Energy Corp. This software is not for sale, not for commercial resale, and not authorized for personal or non-corporate use. Access is restricted solely to authorized company employees and IT administrators.
Core Privacy Guarantee: PME-Stream-R operates exclusively on private self-hosted infrastructure. No session content, video streams, keystrokes, or remote control data are ever sent to public cloud servers or third parties.
1. Scope & Authorized Employee Use
This Privacy & Governance Policy applies exclusively to authorized PME Energy staff members utilizing the PME-Stream-R client and relay infrastructure. The software is provided solely for corporate business operations and approved remote IT maintenance.
2. End-to-End Cryptography (E2EE)
All active remote desktop sessions utilize military-grade cryptographic protocols:
- Handshake Authentication: Verified via 256-bit asymmetric Ed25519 public/private key pairs.
- Stream Encryption: Media and control channels are encrypted using ChaCha20-Poly1305 with unique per-session ephemeral keys.
- Zero Server Decryption: The relay server acts solely as an encrypted transit forwarder; active video/keyboard streams cannot be decrypted by intermediate infrastructure.
3. Data Collection & Minimal Footprint
We adhere to strict data minimization principles:
- Address Book Sync: Stored in an encrypted SQLite database on the central API container with secure password hashing (SHA-256 with salt).
- Connection Metadata: Ephemeral session metrics (timestamps and IP addresses) are held in volatile RAM logs and automatically purged on a 7-day rolling cycle.
- No Commercial Telemetry: All external analytics, tracking, and third-party metrics have been completely purged from the codebase.
4. Employee Rights & Access Controls
Employees maintain direct oversight of their workstations:
- Incoming sessions require explicit user approval via the verification prompt.
- Permanent unattended access requires dual-authorization and cryptographic password registration.
- Active sessions display prominent status badges and can be terminated immediately with a single click.
5. Contact & Compliance
For inquiries regarding enterprise access, licensing compliance, or security governance, contact the PME Energy IT Department at admin@pme-energy.com.