RMM Labs. Operations data in, governance evidence out.
RMM Labs Ltd — a Bulgarian software company founded in Sofia in 2026 by MSP veterans and open-source contributors — is TruSecure’s first confirmed technology partner. Their Xcellerate platform runs the operations; TruSecure turns what the operations produce into governance evidence, mapped to controls, with provenance. This page is the public specification of that integration as agreed between the two companies.
What RMM Labs makes
Three products under one platform, all developed and hosted in the EU:
Xcellerate RMM
Open-core remote monitoring and management (AGPL v3 core, self-hostable, EU cloud option): endpoint and extended inventory, strategy-driven patch management, scripting and automation, remote access, monitoring and alerting, network infrastructure and IPAM, zero-touch onboarding, and a query builder with REST API.
Xcellerate OPS
EU-cloud service desk and operations: omnichannel ticketing with SLAs, AI assist and supervised AI colleagues, an EU AI Act compliance center, a 25-language helpdesk, projects and budgets, quoting and invoicing, automation, knowledge base, and an IT documentation vault.
Xcellerate AIG
Enterprise AI gateway, self-hosted and air-gappable (Docker, Kubernetes or appliance): one OpenAI-compatible API across ten providers, virtual keys with budgets and model allow-lists, prompt and response guardrails, MCP tool governance, searchable request logs, a tamper-evident audit log, and SSO/SCIM/RBAC.
Why this matters in the GRC value chain
Most governance evidence begins life as operations data. The asset register an auditor asks for is an inventory. The patching control is a patch state. The incident-handling requirement is a queue of alerts and tickets. In most organizations somebody copies that data out of the operational tools by hand — screenshots, exports, spreadsheet reconciliations — every audit cycle, and it is stale the day it is filed.
RMM Labs operates the layer where that data is born: what devices exist, what software and certificates are on them, what is patched and what is not, what is alerting, which vulnerabilities are open, and which tickets resolved them. TruSecure is the layer where that data becomes governance: mapped to the control it satisfies, filed as evidence with provenance, and kept current without anyone re-collecting it. The partnership joins those two layers directly, so the value chain from “we patched it” to “we can prove we patch, continuously” has no manual step in it.
With Xcellerate AIG, RMM Labs also operates the layer where AI usage is governed: which models applications call, under which keys, budgets and guardrails, with every request logged and every change in a tamper-evident audit trail. Those records are exactly what the EU AI Act’s logging duties and ISO 42001 ask an organization to produce — which is why AI-governance flows are the natural next extension of the integration, proposed below.
Both companies are European and EU-hosted, which keeps the combined supply chain inside the jurisdictions NIS2 Art. 21(2)(d) and DORA ask you to account for. Each company’s own arrangements remain its own to evidence — RMM Labs’ published claims are theirs, ours are on the sovereignty page.
The integration — what flows, and where it lands
This integration is under joint development; what follows is the agreed specification both teams are building to, published so customers and auditors can see exactly what is coming. It follows TruSecure’s standard connector model: read-only collection, evidence with provenance, no third-party runtime calls from the customer’s environment.
| From Xcellerate | Data | Lands in TruSecure |
|---|---|---|
| RMM · Endpoint & Extended Inventory | Devices, software, certificates, services, network assets | Applicability Engine — asset register and NIS2 scope stay current by themselves |
| RMM · Patch Management | Patch state, update-ring progress, deferrals | Evidence Automation — continuous proof for patching controls (NIS2 Art. 21(2), CIS) |
| RMM · Vulnerability Management plugin | Findings, severity, remediation status | Risk & Exception Management — open findings tracked to closure or accepted risk |
| RMM · Monitoring & Alerting | Events and alerts as they fire | Incident & Resilience Workflows — detection lands in the governance record directly |
| OPS · Service desk & automation | Incident tickets, changes, resolution and SLA records | Incident & Resilience Workflows — response and remediation evidence, closed loop |
The transport is what RMM Labs ships today: the Xcellerate REST API and the official n8n node, which already lets automation read inventory, trigger scripts and act on alerts. RMM Labs’ published roadmap adds a guarded MCP server in 2027, which becomes the AI-assisted query path into the same data. No manual exports, no screenshot folders, no quarterly evidence chase — collection runs on a schedule, and every artifact arrives with where it came from and when.
Under discussion — Xcellerate AIG flows
AIG launched after the specification above was agreed, so the two flows below are proposed, not yet agreed between the teams. They are published here so both sides — and customers — can see the direction; the table above remains the binding specification.
| From Xcellerate AIG | Data | Lands in TruSecure |
|---|---|---|
| AIG · Request logs & audit trail | Per-request records (model, key, tokens, cost, tags) and the tamper-evident audit log | AI Governance — record-keeping evidence for the EU AI Act and ISO 42001 |
| AIG · Guardrail & key state | Guardrail configurations, virtual-key policies, budgets and model allow-lists | Control Library — live evidence that AI policy-enforcement controls are operating |
AIG exposes its own interfaces — signed outbound webhooks, structured logs, Prometheus metrics and OpenTelemetry traces — so the collection path for these flows is being specified separately from the RMM transport above.
For the people inside the company, the practical effect is subtraction: the asset spreadsheet nobody maintains, the patch report somebody rebuilds before every audit, the incident timeline reconstructed from inboxes — each of those stops being a task and becomes a query against current state.
What stays separate
Separate products, separate companies, separate contracts. RMM Labs is not a TruSecure sub-processor, and TruSecure is not an RMM Labs one; neither company’s representations bind the other, and TruSecure’s published sub-processor list is unchanged by this partnership. Each product stands on its own — neither requires the other.
Status, stated plainly: the partnership is confirmed; the integration specified above is in development and is not a shipped feature yet. This page will be updated as each flow goes live.
Running Xcellerate, or considering it?
Tell us what you operate today and we will walk through what the integration automates for your environment — and what it will not.
Talk to us