ScrewDrivers security
Start here when someone hands you a security questionnaire or a CVE list and asks how it applies to ScrewDrivers. This page doesn't repeat the details. It points you to the page that has them.
There are two kinds of security content here. The sections below describe how ScrewDrivers is built and configured to be secure. Tricerat's responses to outside events, like a Microsoft CVE batch or a scanner flagging a runtime we ship, are dated advisories and live in the Security Advisories registry. Chasing a specific CVE? Go to the registry first.
How ScrewDrivers is secured
Security and Compliance is the overview. It walks through authentication, access control, badge and PIN release, encryption, and audit logging, and it maps those layers to HIPAA, PCI-DSS, GDPR, and FISMA. Its Vulnerability Management section explains how Tricerat handles software updates and vulnerability disclosure.
ScrewDrivers Client Security explains how the Endpoint plug-in operates inside the Microsoft RDP, Citrix ICA, and PCoIP virtual channels, and why print data that crosses the channel is validated and never executed.
Network
Ports and Firewall Rules lists every port each ScrewDrivers component uses, which direction traffic flows, and which ports carry TLS. Version 7 TLS 1.2 Support records when TLS 1.2 became the standard for database connections and secure Print Server ports.
Certificates
Print Server ships with a self-signed certificate. Using Administrator-Specified Certificates for Print Server shows how to replace it with one your organization issues. If a Tricerat service won't start after a certificate change, Service Fails to Start Due to Certificate Error walks through the fix.
Secure Release, in public beta for Enterprise, has its own certificate chain between the release server and the printers. Creating Secure Release Certificates covers it, and Setting Up ScrewDrivers Secure Release is the deployment hub.
Access control
Managing Permissions in ScrewDrivers v7 Administration Console covers the default permission levels, custom permissions, and how to assign them, so administrators see only what their role needs.
Endpoint protection
Antivirus and endpoint detection products sometimes quarantine ScrewDrivers components, or slow printing down while they scan spool data. Anti-Virus File Exceptions for Tricerat Products lists the files to exclude.
ScrewDrivers and the Windows print stack
ScrewDrivers runs inside the Windows Print Spooler on session hosts and uses the local spooler on Windows endpoints, so Microsoft's spooler security updates always apply to a ScrewDrivers deployment. ScrewDrivers replaces manufacturer drivers on the session host with its own universal driver, and it doesn't use the HTTP Print Provider. These pages work through specific update batches:
- PrintNightmare (CVE-2021-34527) Compatibility confirms compatibility with Microsoft's 2021 patches and explains which of the alternative workarounds break ScrewDrivers.
- September 2026 Windows Print Stack Vulnerabilities covers the fifteen print-stack CVEs in Microsoft's September 2026 updates, which Windows components ScrewDrivers depends on, and optional hardening steps you can evaluate.
- Addressing the Visual Studio 2008 Runtime Vulnerability in ScrewDrivers applies if a scanner flags the VS2008 runtime that ScrewDrivers 7.3.0 and earlier installed.
Security advisories
Every advisory Tricerat has issued is listed in Security Advisories, with its status and affected versions, and each entry links back to the procedure page above. To report a vulnerability, contact Tricerat Support.