Skip to main content
TECHNOLOGY PARTNER

RMM Labs. Operations data in, governance evidence out.

RMM Labs Ltd — a Bulgarian software company founded in Sofia in 2026 by MSP veterans and open-source contributors — is TruSecure’s first confirmed technology partner. Their Xcellerate platform runs the operations; TruSecure turns what the operations produce into governance evidence, mapped to controls, with provenance. This page is the public specification of that integration as agreed between the two companies.

What RMM Labs makes

Two products under one platform, both developed and hosted in the EU:

Xcellerate RMM

Open-core remote monitoring and management (AGPL v3 core, self-hostable, EU cloud option): endpoint and extended inventory, strategy-driven patch management, scripting and automation, remote access, monitoring and alerting, network infrastructure and IPAM, zero-touch onboarding, and a query builder with REST API.

Xcellerate OPS

EU-cloud service desk and operations: omnichannel ticketing with SLAs, AI assist and supervised AI colleagues, an EU AI Act compliance center, a 25-language helpdesk, projects and budgets, quoting and invoicing, automation, knowledge base, and an IT documentation vault.

Why this matters in the GRC value chain

Most governance evidence begins life as operations data. The asset register an auditor asks for is an inventory. The patching control is a patch state. The incident-handling requirement is a queue of alerts and tickets. In most organizations somebody copies that data out of the operational tools by hand — screenshots, exports, spreadsheet reconciliations — every audit cycle, and it is stale the day it is filed.

RMM Labs operates the layer where that data is born: what devices exist, what software and certificates are on them, what is patched and what is not, what is alerting, which vulnerabilities are open, and which tickets resolved them. TruSecure is the layer where that data becomes governance: mapped to the control it satisfies, filed as evidence with provenance, and kept current without anyone re-collecting it. The partnership joins those two layers directly, so the value chain from “we patched it” to “we can prove we patch, continuously” has no manual step in it.

Both companies are European and EU-hosted, which keeps the combined supply chain inside the jurisdictions NIS2 Art. 21(2)(d) and DORA ask you to account for. Each company’s own arrangements remain its own to evidence — RMM Labs’ published claims are theirs, ours are on the sovereignty page.

The integration — what flows, and where it lands

This integration is under joint development; what follows is the agreed specification both teams are building to, published so customers and auditors can see exactly what is coming. It follows TruSecure’s standard connector model: read-only collection, evidence with provenance, no third-party runtime calls from the customer’s environment.

From XcellerateDataLands in TruSecure
RMM · Endpoint & Extended InventoryDevices, software, certificates, services, network assetsApplicability Engine — asset register and NIS2 scope stay current by themselves
RMM · Patch ManagementPatch state, update-ring progress, deferralsEvidence Automation — continuous proof for patching controls (NIS2 Art. 21(2), CIS)
RMM · Vulnerability Management pluginFindings, severity, remediation statusRisk & Exception Management — open findings tracked to closure or accepted risk
RMM · Monitoring & AlertingEvents and alerts as they fireIncident & Resilience Workflows — detection lands in the governance record directly
OPS · Service desk & automationIncident tickets, changes, resolution and SLA recordsIncident & Resilience Workflows — response and remediation evidence, closed loop

The transport is what RMM Labs ships today: the Xcellerate REST API and the official n8n node, which already lets automation read inventory, trigger scripts and act on alerts. RMM Labs’ published roadmap adds a guarded MCP server in 2027, which becomes the AI-assisted query path into the same data. No manual exports, no screenshot folders, no quarterly evidence chase — collection runs on a schedule, and every artifact arrives with where it came from and when.

For the people inside the company, the practical effect is subtraction: the asset spreadsheet nobody maintains, the patch report somebody rebuilds before every audit, the incident timeline reconstructed from inboxes — each of those stops being a task and becomes a query against current state.

What stays separate

Two products, two companies, two contracts. RMM Labs is not a TruSecure sub-processor, and TruSecure is not an RMM Labs one; neither company’s representations bind the other, and TruSecure’s published sub-processor list is unchanged by this partnership. Each product stands on its own — neither requires the other.

Status, stated plainly: the partnership is confirmed; the integration specified above is in development and is not a shipped feature yet. This page will be updated as each flow goes live.

Running Xcellerate, or considering it?

Tell us what you operate today and we will walk through what the integration automates for your environment — and what it will not.

Talk to us

Frequently Asked Questions

Who is RMM Labs?
RMM Labs Ltd is a Bulgarian software company founded in Sofia in 2026 by MSP veterans and open-source contributors. It builds the Xcellerate platform: Xcellerate RMM, an open-core (AGPL v3) remote monitoring and management product, and Xcellerate OPS, an EU-cloud service desk and operations platform.
Is the TruSecure–RMM Labs integration available today?
Not yet. The partnership is confirmed and the integration is specified on this page as agreed between both teams, but the data flows described are under joint development. This page is updated as each flow goes live.
What data does the integration send to TruSecure?
Per the agreed specification: asset and software inventory, patch state, vulnerability findings and remediation status, monitoring events and alerts, and service-desk ticket and change records. Collection is read-only from the Xcellerate side, via its REST API and official n8n node, and every item lands in TruSecure as evidence with provenance.
Do I have to buy both products?
No. Xcellerate and TruSecure are separate products from separate companies, each with its own contract. Neither requires the other; the integration exists for organizations that run both.
Does using both products change who processes my data?
Each product has its own data processing agreement and its own sub-processor list. Using one does not add the other to your processing chain. TruSecure’s published sub-processor list has a single entry and is unchanged by this partnership.