Skip to main content
TECHNOLOGY PARTNER

RMM Labs. Operations data in, governance evidence out.

RMM Labs Ltd — a Bulgarian software company founded in Sofia in 2026 by MSP veterans and open-source contributors — is TruSecure’s first confirmed technology partner. Their Xcellerate platform runs the operations; TruSecure turns what the operations produce into governance evidence, mapped to controls, with provenance. This page is the public specification of that integration as agreed between the two companies.

What RMM Labs makes

Three products under one platform, all developed and hosted in the EU:

Xcellerate RMM

Open-core remote monitoring and management (AGPL v3 core, self-hostable, EU cloud option): endpoint and extended inventory, strategy-driven patch management, scripting and automation, remote access, monitoring and alerting, network infrastructure and IPAM, zero-touch onboarding, and a query builder with REST API.

Xcellerate OPS

EU-cloud service desk and operations: omnichannel ticketing with SLAs, AI assist and supervised AI colleagues, an EU AI Act compliance center, a 25-language helpdesk, projects and budgets, quoting and invoicing, automation, knowledge base, and an IT documentation vault.

Xcellerate AIG

Enterprise AI gateway, self-hosted and air-gappable (Docker, Kubernetes or appliance): one OpenAI-compatible API across ten providers, virtual keys with budgets and model allow-lists, prompt and response guardrails, MCP tool governance, searchable request logs, a tamper-evident audit log, and SSO/SCIM/RBAC.

Why this matters in the GRC value chain

Most governance evidence begins life as operations data. The asset register an auditor asks for is an inventory. The patching control is a patch state. The incident-handling requirement is a queue of alerts and tickets. In most organizations somebody copies that data out of the operational tools by hand — screenshots, exports, spreadsheet reconciliations — every audit cycle, and it is stale the day it is filed.

RMM Labs operates the layer where that data is born: what devices exist, what software and certificates are on them, what is patched and what is not, what is alerting, which vulnerabilities are open, and which tickets resolved them. TruSecure is the layer where that data becomes governance: mapped to the control it satisfies, filed as evidence with provenance, and kept current without anyone re-collecting it. The partnership joins those two layers directly, so the value chain from “we patched it” to “we can prove we patch, continuously” has no manual step in it.

With Xcellerate AIG, RMM Labs also operates the layer where AI usage is governed: which models applications call, under which keys, budgets and guardrails, with every request logged and every change in a tamper-evident audit trail. Those records are exactly what the EU AI Act’s logging duties and ISO 42001 ask an organization to produce — which is why AI-governance flows are the natural next extension of the integration, proposed below.

Both companies are European and EU-hosted, which keeps the combined supply chain inside the jurisdictions NIS2 Art. 21(2)(d) and DORA ask you to account for. Each company’s own arrangements remain its own to evidence — RMM Labs’ published claims are theirs, ours are on the sovereignty page.

The integration — what flows, and where it lands

This integration is under joint development; what follows is the agreed specification both teams are building to, published so customers and auditors can see exactly what is coming. It follows TruSecure’s standard connector model: read-only collection, evidence with provenance, no third-party runtime calls from the customer’s environment.

From XcellerateDataLands in TruSecure
RMM · Endpoint & Extended InventoryDevices, software, certificates, services, network assetsApplicability Engine — asset register and NIS2 scope stay current by themselves
RMM · Patch ManagementPatch state, update-ring progress, deferralsEvidence Automation — continuous proof for patching controls (NIS2 Art. 21(2), CIS)
RMM · Vulnerability Management pluginFindings, severity, remediation statusRisk & Exception Management — open findings tracked to closure or accepted risk
RMM · Monitoring & AlertingEvents and alerts as they fireIncident & Resilience Workflows — detection lands in the governance record directly
OPS · Service desk & automationIncident tickets, changes, resolution and SLA recordsIncident & Resilience Workflows — response and remediation evidence, closed loop

The transport is what RMM Labs ships today: the Xcellerate REST API and the official n8n node, which already lets automation read inventory, trigger scripts and act on alerts. RMM Labs’ published roadmap adds a guarded MCP server in 2027, which becomes the AI-assisted query path into the same data. No manual exports, no screenshot folders, no quarterly evidence chase — collection runs on a schedule, and every artifact arrives with where it came from and when.

Under discussion — Xcellerate AIG flows

AIG launched after the specification above was agreed, so the two flows below are proposed, not yet agreed between the teams. They are published here so both sides — and customers — can see the direction; the table above remains the binding specification.

From Xcellerate AIGDataLands in TruSecure
AIG · Request logs & audit trailPer-request records (model, key, tokens, cost, tags) and the tamper-evident audit logAI Governance — record-keeping evidence for the EU AI Act and ISO 42001
AIG · Guardrail & key stateGuardrail configurations, virtual-key policies, budgets and model allow-listsControl Library — live evidence that AI policy-enforcement controls are operating

AIG exposes its own interfaces — signed outbound webhooks, structured logs, Prometheus metrics and OpenTelemetry traces — so the collection path for these flows is being specified separately from the RMM transport above.

For the people inside the company, the practical effect is subtraction: the asset spreadsheet nobody maintains, the patch report somebody rebuilds before every audit, the incident timeline reconstructed from inboxes — each of those stops being a task and becomes a query against current state.

What stays separate

Separate products, separate companies, separate contracts. RMM Labs is not a TruSecure sub-processor, and TruSecure is not an RMM Labs one; neither company’s representations bind the other, and TruSecure’s published sub-processor list is unchanged by this partnership. Each product stands on its own — neither requires the other.

Status, stated plainly: the partnership is confirmed; the integration specified above is in development and is not a shipped feature yet. This page will be updated as each flow goes live.

Running Xcellerate, or considering it?

Tell us what you operate today and we will walk through what the integration automates for your environment — and what it will not.

Talk to us

Frequently Asked Questions

Who is RMM Labs?
RMM Labs Ltd is a Bulgarian software company founded in Sofia in 2026 by MSP veterans and open-source contributors. It builds the Xcellerate platform: Xcellerate RMM, an open-core (AGPL v3) remote monitoring and management product; Xcellerate OPS, an EU-cloud service desk and operations platform; and Xcellerate AIG, a self-hosted enterprise AI gateway.
What does Xcellerate AIG mean for the integration?
AIG is RMM Labs’ enterprise AI gateway — a governed, OpenAI-compatible API between applications and AI providers, with request logs, guardrails and a tamper-evident audit trail. Two AIG data flows into TruSecure’s AI governance controls are proposed on this page and are under discussion; they are not part of the agreed specification yet.
Is the TruSecure–RMM Labs integration available today?
Not yet. The partnership is confirmed and the integration is specified on this page as agreed between both teams, but the data flows described are under joint development. This page is updated as each flow goes live.
What data does the integration send to TruSecure?
Per the agreed specification: asset and software inventory, patch state, vulnerability findings and remediation status, monitoring events and alerts, and service-desk ticket and change records. Collection is read-only from the Xcellerate side, via its REST API and official n8n node, and every item lands in TruSecure as evidence with provenance.
Do I have to buy both products?
No. Xcellerate and TruSecure are separate products from separate companies, each with its own contract. Neither requires the other; the integration exists for organizations that run both.
Does using both products change who processes my data?
Each product has its own data processing agreement and its own sub-processor list. Using one does not add the other to your processing chain. TruSecure’s published sub-processor list has a single entry and is unchanged by this partnership.