Patch & Vulnerability Guard
Know which machines are unpatched. Including the ones nothing has looked at.
Active Directory can tell you which Windows a machine runs. It cannot tell you whether that machine is patched — there is no attribute for the revision that changes every Patch Tuesday. Patch Guard asks each machine directly, deploys the fixes in rings, and says out loud how much of your estate it has actually assessed.
The fourth tile is the one no other patch console shows. 1,140 of 1,204 assessed is a different sentence from 1,204 — and a machine with no agent reads Not assessed, never a reassuring green “Clean”.
How it works
Four stages, and what each one refuses to claim.
Find every machine
The appliance binds to Active Directory as its own machine account and reads the directory — no service account to create, no password to store, no inbound port to open.
- LDAPS with certificate verification, falling back through StartTLS and Kerberos sealing rather than to plaintext
- Channel binding for domain controllers hardened against relay attacks
- Every machine account, its operating system, its organisational unit, and when it last logged on
Ask each machine what it is missing
The directory knows which Windows a machine runs. It cannot know whether that machine is patched — there is no attribute for the revision that moves every Patch Tuesday. So an agent asks Windows Update on the machine itself.
- The same answer the machine's own Settings screen gives, with Microsoft's KB numbers and Microsoft's severities
- Deployed to the whole estate by Group Policy in an afternoon; nothing to type on any endpoint
- Endpoints talk only to the appliance on your network — never to us, never to the internet
Say plainly what is not known
A machine nobody has assessed is reported as not assessed, never as clean. This is the one place we differ from every console you have seen, and it is deliberate.
- Coverage is a headline number, not a footnote: 1,140 of 1,204 is a different sentence from 1,204
- A machine that stops reporting goes stale rather than staying green
- An update installed but waiting on a restart is exposure, and is reported as exposure
Deploy without holding your breath
Estates go unpatched because nobody wants to be the person who took the domain controller down on a Tuesday. Rings, windows and a real rollback are the answer to that fear.
- Pilot ring first, soak, then the rest — on a schedule you set
- A snapshot before each install, and a rollback that is one click rather than a restore project
- Change freezes per group, so Finance is untouchable at month end
Deployment
The reason estates go unpatched is not ignorance.
It is that nobody wants to be the person who pushed an update that took the domain controller down on a Tuesday. Rings, maintenance windows and a real rollback are the answer to that, not another list of missing patches.
Architecture
What runs where, and what we can see.
Two questions decide most security reviews: what do we have to open, and what leaves the building. The answers are nothing, and an inventory.
- One appliance, on your network
- A small Windows service on a machine you already have. It reads your directory, receives agent reports, and is the only thing that talks to us.
- Agents that only report
- No inbound port, no listener, no stored credential. Each machine authenticates as its own Active Directory computer account — a secret Windows already rotates and no other machine holds.
- Nothing to distribute
- There is no enrolment key to put on a thousand workstations and no key to rotate. A machine that is not in your domain cannot report at all.
- Pinned, not trusted
- The agent's installer carries the fingerprint of your appliance's certificate. It will talk to that certificate and refuse every other one, with no internal PKI required.
- Your data stays yours
- We receive an inventory: hostnames, builds, and which KB is missing. No file contents, no credentials, no directory passwords.
- Your brand, if you want it
- On Enterprise, the console, the appliance screen and every email wear your name on your domain. Your clients never see ours.
Limits
What it does not do, before you ask.
- Does it patch Linux or macOS?
- Not today. Windows endpoints and Windows Server, through the Windows Update Agent. Saying we cover an estate we cannot assess would be the exact failure this product exists to prevent.
- Do you need domain admin credentials?
- No. The appliance binds as its own machine account, and agents authenticate as theirs. There is no privileged account for us to hold and no password for you to store.
- What about third-party applications?
- Chrome, Adobe Reader and the rest are on the roadmap and are not shipping. Today the honest scope is what Windows Update itself offers, which is where the critical remote-code-execution fixes live.
- Can we keep using WSUS or SCCM?
- Yes, as an explicit choice rather than a silent default. If you already run one, Patch Guard reports which machines take updates from it — including the case where it stopped synchronising and the whole estate is quietly reporting nothing missing.
- What if the appliance is offline?
- Agents keep collecting and report when it returns. The console shows the estate as stale rather than as healthy, because a console that cannot reach its appliance knows nothing new.
Questions
The things people ask before they switch
One sweep. Install the appliance on a domain-joined server and it discovers the directory within minutes — every machine, its operating system and its organisational unit. Patch state follows as agents report, typically within a couple of hours of the Group Policy rollout.
Group Policy. The installer goes on your NETLOGON share, a GPO assigns it, and a Preferences Immediate Task makes machines pick it up at the next policy refresh rather than the next reboot. There is nothing to type on any endpoint — the installer already carries your appliance's name and certificate fingerprint.
Microsoft. Each pending update carries its own MSRC rating and its own KB number, and we report them as given rather than inventing a score. Where an update maps to a published CVE, the identifier is attached; where it does not, the finding stands on the evidence and says so.
A snapshot is taken before each install and the deployment is ringed, so a bad update reaches a pilot group before it reaches production. Rollback is a button, and the job history records who deployed what, when, and to which machines.
Yes. Enterprise includes end-client accounts with scoped access and White Label on your own domain — your name and colours in the console, on each appliance's screen, and in every email the platform sends.
Find out whether your backups actually restore.
Connect one hypervisor, set one policy, and let a scheduled drill try to bring it back. If it doesn't, you'll know in a day rather than during an incident.
No credit card · 14-day trial · Migration assistance included