End-to-end encrypted remote access
Reach your Home Assistant from anywhere at an address only your Home Assistant can read. The connection stays encrypted from your phone all the way into your home; Vome passes it on without holding a key to it. No open ports, no certificates to manage, nothing to install beyond the Vome integration.
- Vome cannot read it
- The key never leaves your home
- The same door as your usual address
- No open ports
Rolling out now. It is switched on for homes one at a time while we watch it. Ask support if you would like yours early.
1 Your usual address
On yourname.home.vome.io, Vome's edge holds the
certificate. Your browser's connection is encrypted to us; we open
it, check the door (your Vome sign-in or door password), and send
the request down your home's own encrypted link. Both legs are
encrypted, but on our server, between them, your traffic is
readable. We do not look, and we keep no copy of what passes, only
who reached your home and when, for your access log. But "we do
not look" is a promise, not something you can check.
Your usual address: Vome opens the traffic in the middle
2 The end-to-end address
Switch it on and your home also answers at
yourname.e2e.vome.io. There, Vome's router holds no
key. It reads one thing, the name your browser asked for, which
every encrypted connection announces in the clear so it can be
routed, and passes the still-encrypted connection down your home's
link. Your Home Assistant, through the Vome integration, holds the
certificate and the only key, and is the first and only place the
connection is opened.
End-to-end: only your Home Assistant can read it
3 What Vome sees, and what it cannot
| On the end-to-end address | Vome sees it? |
|---|---|
The name asked for (yourname.e2e.vome.io) | Yes, to route it |
| The address of whoever connects, when, and how much was sent | Yes: your access log is made of it |
| The pages, dashboards and camera pictures you open | No |
| Your Home Assistant username and password | No |
| What you switch on or off, and your automations' traffic | No |
| The key that could open any of it | No: it is made in your home and never leaves |
4 Who checks the door
- The same door as your usual address. Whatever that one asks, this one asks too: a Vome sign-in or your door password if it is gated, nothing extra if you have opened it for the Home Assistant app, and webhooks only if you allowed them. Your Home Assistant login comes after, always.
- Your Home Assistant checks it, because Vome cannot see inside. When you sign in with Vome, the portal hands your browser a short-lived pass signed with a key only your home holds; your Home Assistant checks the pass and keeps it as a cookie for that address alone.
- The same protection as at Vome's edge: request limits for anyone who has not signed in, and an address blocked after five failed Home Assistant logins in fifteen minutes, for longer each time. Never the whole home, so a stranger cannot lock you out.
- Your access log keeps working, with the visitor's real address: Vome's router knows it and passes it to your home with each connection, and your home reports what it let in and what it refused.
5 The certificate
Your Home Assistant gets its own certificate from Let's Encrypt, the free certificate authority most of the web uses. Let's Encrypt checks that your home really answers at its name by connecting to it through Vome's router, which passes that check through unopened as well. Your Home Assistant makes the key, keeps it, and renews the certificate a month before it expires.
The certificate: made in your house, renewed there too
6 Switching it on
- Make sure your Home Assistant has the Vome integration 0.9.47 or newer and a Vome address (the free one is enough).
- On your server page on vome.io, switch on End-to-end encrypted address. Your Home Assistant agrees to Let's Encrypt's Subscriber Agreement on your behalf when it asks for the certificate.
- Within a few minutes your home answers at
yourname.e2e.vome.io. Your usual address keeps working alongside it. - Switch it off on the same page and the address stops within a minute.
What it does not change
- Vome's assistant features (the health check, your MCP key, ESPHome, live states) do not use this address. They reach your home over the separate link Vome has always used, which Vome can read; the privacy page says what each one sends.
- Cameras from anywhere already travel end to end: WebRTC video is encrypted between your browser and your Home Assistant, and our own relay passes it on without being able to watch it.
- A home Vome hosts runs on our servers, so for it this protects against our network and our edge, not against the machine it runs on. It is still worth having; it is not the same promise.
- One name. The certificate covers your end-to-end address only, so device addresses stay on your usual one.
- Your Home Assistant login still matters. Turn on multi-factor authentication whatever address you use.