Every server.
One view.
Full control.

SEMA SystemVisor brings the management of your Linux and Windows servers into one interface in the browser — monitoring, terminal, files, services, updates and vulnerabilities. We operate the platform, you connect your servers: via SSH or with an agent that needs no open ports.

systemvisor.sema.one
Dashboard
AM
Servers online
24/24
● all reachable
Open alerts
1
backup-01 · Disk
Updates
37
on 9 servers
Server CPU
web-01 23%
db-01 61%
app-02 12%
backup-01 8%
CPU load · db-01 · 24 h ● live
0
Open ports needed The agent connects outbound — no port forwarding, no VPN
30 s
Sampling interval CPU, RAM, disk, network and processes — with history up to 90 days
20+
Areas with their own permissions Read, change, execute — defined per role and per server

What usually takes five tools.
In one interface.

Monitor, intervene, update, secure — for every server in the same window, without switching between a monitoring tool, SSH client, file manager and update lists.

Monitoring & alerts

CPU, RAM, disk, swap, load, network and processes every 30 seconds. Thresholds per server and metric, process watch for crashes and hangs, availability with response times.

Terminal & remote desktop

A real interactive terminal in the browser — with colours, tab completion, vim, htop and sudo. Windows servers via PowerShell or remote desktop, with no local client.

File manager

Browse folders, upload and download files, edit configurations right in the browser — with root privileges if needed. Every change is kept in the history.

Services, Docker & cron jobs

Start, stop and restart system services and read their logs. Manage containers with images and ports. Create and delete crontab entries — all with confirmation and a log.

Patch management

SystemVisor detects the package manager itself — apt, yum, dnf, zypper, pacman, winget or Chocolatey — lists available updates with versions and installs single ones or all of them.

Vulnerability scan

The installed packages of every server are checked against current CVE data. You see severity, CVSS score, the affected package and the version that fixes the issue.

SSL certificates

Certificates are detected from the Nginx and Apache configuration, even behind a reverse proxy or Cloudflare. Expiry date and issuer at a glance, with a warning well before expiry.

Backups

Backups as an archive, via rsync or as a PostgreSQL dump — with progress, history and a copy to an offsite target. Failed backups are reported.

Network & devices

Even what isn't a server: switches, routers and firewalls via SNMP, Proxmox VE, TrueNAS, and websites and services via HTTP(S) or TCP checks — with a notice when they go down.

Works with
  • Linux
  • Windows Server
  • Docker
  • Proxmox VE
  • TrueNAS
  • Cisco
  • HPE / Aruba
  • MikroTik
  • Ubiquiti
  • OPNsense
  • pfSense
  • Microsoft Teams
  • Slack
  • Discord
  • SEMA TeamTalk
  • Prometheus / Grafana

No open port.
No VPN. One command.

The SystemVisor agent opens the connection from the server — encrypted and outbound. Your firewall stays shut, just as it is. Where the agent isn't wanted, you connect the server the classic way via SSH.

  1. 1
    Add the server

    One at a time or many at once, even as an IP range — with tags and tenant.

  2. 2
    Run the command

    SystemVisor generates the install command for Linux or Windows. The token is shown only once and can be revoked at any time.

  3. 3
    Get going

    Terminal, files, monitoring and scripts are ready right away. If the connection drops, the agent re-establishes it on its own.

root@web-01: ~
root@web-01:~# curl -sSL https://systemvisor.sema.one/api/agent/install.sh \
| bash -s -- --token •••••••• --server-id 42 \
--url https://systemvisor.sema.one
==> Installing SystemVisor Agent
==> Downloading agent bundle
==> Installing dependencies
==> Sudo password verified
==> Service systemvisor-agent started
Connected — web-01 is online
root@web-01:~# ▌
WSS
encrypted, outbound
Linux
as a systemd service
Windows
as a Windows service
Memory · backup-01
71 %
1h 24h 7d 90d
00:0006:0012:0018:00now
Threshold exceeded
backup-01 · memory above 70 % · 1 minute ago
In-App E-Mail Web-Push Microsoft Teams Slack SEMA TeamTalk

You hear about it first.
Not your users.

SystemVisor measures continuously and reports as soon as something is out of line: thresholds, crashed processes, servers offline, expiring certificates, new vulnerabilities, failed backups. Everyone decides which notice reaches them and how — and resolved alerts clear themselves from the chat.

  • History from 1 hour to 90 days, with top processes by CPU and RAM
  • Network per interface and active connections
  • Maintenance mode per server — no false alarms during a planned reboot
  • Monitoring report as a PDF in one click

Defined once.
The same on every server.

Recurring work belongs in a library, not in the shell history. Scripts, schedules and multi-step playbooks run traceably — on one server or on many at once.

Scripts & schedules

bash, sh, python3, node or perl — run right away or on a schedule.

Playbooks

Steps via drag and drop, live output per step, stop at the first error.

Deployments

Deploy tasks with confirmation and history — who rolled out what, and when.

Many servers at once

Command, script or reboot on up to 100 servers, dangerous commands blocked.

Playbook
Weekly maintenance
Sun 03:00 · 12 servers
  1. Create backup
    pg_dump · offsite
    48 s
  2. Install updates
    apt-get upgrade -y
    2 min
  3. Restart service
    systemctl restart nginx
    3 s
  4. Check availability
    curl -fsS https://shop.example.de/health
    1 s
12 of 12 servers succeeded · result per step in the history

Whoever has access to servers
needs clear rules.

A tool with root access is only as good as its safeguards. SystemVisor encrypts credentials, checks host keys, connects to your existing sign-in and records who did what.

Roles govern not only what someone may do, but also where: which servers, devices and tenants they see at all. The contractor gets exactly their slice — and the trainee gets read access instead of a terminal.

  • Single sign-on with Microsoft, Google or Keycloak, plus LDAP / Active Directory
  • Two-factor authentication with an authenticator app and backup codes
  • Host keys are checked — a change is reported as a possible attack
  • GDPR-compliant audit log and history for terminal, files, services and deployments
SEMA SystemVisor by the numbers
Credentials AES-256-GCM
Agent tokens hash only
Rights per area read · change · execute
Sign-in SSO · LDAP · 2FA
Inbound ports for the agent 0

We run SystemVisor.
You take care of your servers.

No server of your own for the tool, no database, no updates for you to schedule. You get your access and start right away.

Operated by SEMA

We provide the platform, install updates and keep it running. New features arrive with no effort on your side — what's new is listed right inside SystemVisor.

Tenants & customer portal

Separate servers by tenant — for sites, departments or the customers of your IT service. Customers see only their servers in their own portal and raise support tickets there.

Available anywhere

In the browser on desktop, tablet and smartphone. Installable as an app on the home screen, with push notifications — including for on-call duty at the weekend.

With a built-in wiki for your own documentation — including a manual for every feature and notes right on the server.

What IT managers ask
us first.

Who operates SystemVisor?
We do. SEMA provides SystemVisor, rolls out updates and keeps the platform running. You sign in from the browser and connect your servers — there is no SystemVisor installation of your own.
What has to be installed on our servers?
Either nothing or a lightweight agent. Servers can be connected via SSH (password or key) or through the SystemVisor agent for Linux and Windows. The agent opens the connection outbound itself — no inbound ports need to be opened. SystemVisor generates the install command; it is a one-liner.
Which systems are supported?
Linux servers with apt, yum, dnf, zypper or pacman, and Windows servers with winget or Chocolatey. On top of that, devices and services without a server entry of their own: switches, routers and firewalls via SNMP v2c/v3, Proxmox VE, TrueNAS, and HTTP(S) and TCP endpoints.
How are our credentials protected?
SSH and SNMP credentials are stored encrypted with AES-256-GCM, agent tokens only as a SHA-256 hash. SSH host keys are remembered on first connection and checked from then on; a change is reported. Sign-ins can be secured with two-factor authentication, and security-relevant actions are recorded in the audit log.
Can we connect SystemVisor to our sign-in?
Yes. SystemVisor supports single sign-on via OAuth 2.0 / OpenID Connect with Microsoft, Google and Keycloak, as well as LDAP and Active Directory. Local accounts can use two-factor authentication with an authenticator app.
Can we separate teams, sites or customers?
Yes. Roles define which areas someone may read, change or execute, and which servers, devices and tenants they see at all. For your own customers there is a lean customer portal that shows only their servers and support.

See your servers in SystemVisor.

We'll show you SystemVisor live and, if you like, connect one of your servers right away as a test — free and without obligation.

Or contact us directly: