Features

Keep a fleet up to date and secure, from one console

Monitoring, Microsoft patching, Linux and Docker vulnerabilities, remediation, remote actions, applications, remote control and deployment: each module is described here as it works.

01Monitoring

Your whole fleet on one screen

Online and offline devices, health, alerts and inventory, kept up to date continuously.

  • Dashboard: devices online or offline, health, alerts.
  • Metrics every 60 seconds: CPU, memory, disks, uptime.
  • Health every 15 minutes: pending reboot, antivirus, BitLocker, latest patch, SMART disk status.
  • Complete, up-to-date hardware and software inventory.
  • Email alerts (device offline, disk full…) and a daily summary.
  • Separate Workstations / Servers tabs, with the operating system icon on every machine.
Fleet health · every 15 minillustrative
Pending reboot4 devices
Antivirus active424 / 428
BitLocker97%
Latest patch under 30 days old96%
SMART disk status1 disk
Daily summary sent by email07:30

02Microsoft patching

Microsoft patches that install themselves, in your windows

Missing-update detection, per-group policies, compliance rate.

  • EPM detects missing Windows updates on every workstation and every server.
  • A “Fix now” button that shows the current step: scanning, downloading, installing.
  • Per-group policies: delay after release, maintenance window, reboot at a fixed time, within the window or manual, with advance notice to the user.
  • A scheduler installs within the window, stops after two failures and notifies you by email.
  • Compliance rate per group and a daily summary at 7:30 am.
Patch compliance per groupillustrative
Accounting100%
Management98%
Windows servers94%
Production88%
Window: Tuesday 22:00 – 02:00 · reboot within the window
Advance notice to the user before rebooton
KB5122882 · PC-LOGISTIQUE-112 failures · stopped, email sent

03Stack Radar

Vulnerabilities in your Linux servers and containers

Linux and Docker inventory matched against OSV, CISA KEV, EPSS and CERT-FR.

  • A lightweight, observe-only Linux agent inventories system packages, applications and Docker containers.
  • EPM matches this inventory against public vulnerability sources: OSV, the CISA KEV catalogue (actively exploited flaws), the EPSS score (probability of exploitation) and CERT-FR advisories.
  • Immediate alert for a critical flaw, daily summary for the rest.
Stack Radar · OSV · CISA KEV · EPSS · CERT-FRillustrative
critical · immediate alerthighmedium · daily summary

04Remediation

A single “Fix” button, with rollback

Verified backup before, verification after, approval with a security key.

  • For every flaw, EPM tells you who can fix it (EPM, the application developer or the vendor) and what will happen, in one sentence.
  • A verified backup before every fix, with rollback available.
  • Verification afterwards that the flaw is actually gone. A successful restart is not enough.
  • Docker image updates from the console, with a service stability check after the operation.
  • Every fix is approved with a physical security key.
Remediation · postgres:15illustrative
Who can fix itEPM
What will happen: the Docker image is updated, then service stability is checked.
Backup verifiedrollback ready
Approved with the security keyWebAuthn
Flaw gone, verified afterwardsfixed

05Remote actions

Act on a device, see the result live

Services, processes, scripts, reboots: the result shows live in the console.

  • Start, stop or restart a service, kill a process, run a script, reboot a machine.
  • The result shows live in the console.
  • A device that is switched off receives the order when it comes back, as long as the order has not expired.
Remote actions · live resultillustrative
Restart Spooler service · PC-RH-02done
Kill process setup.exe · PC-VENTES-05done
Run script nettoyage-temp.ps1 · Front desk grouprunning
Reboot · PC-ACCUEIL-01waiting for device
svchost.exe · stop requestedrefused · red list

06Applications

Controlled application deployment

Catalogue with an approval workflow, SHA-256 integrity, maintenance windows.

  • Application catalogue with an approval workflow: draft, pending, published.
  • Four-eyes principle: an administrator cannot approve their own package.
  • Deployments scheduled within maintenance windows.
  • Integrity check (SHA-256) of every package and verification that the installation succeeded.
Application catalogueillustrative
draftpendingpublished
7-Zip 24.08 sha256:3a56…237dpublished
LibreOffice · approval by a 2nd administratorpending
Internal tool · owner signature requireddraft
Scheduled deployment · maintenance windowTuesday 22:00

07Remote control

Remote control the user can always see

From the browser, no third-party software, with an always-visible banner.

  • Take control of the screen from the browser, with no third-party software.
  • The user always sees an EPM banner when someone is connected to their device.
  • Policy per machine group: who can take control, with or without the user's consent.
Remote control · PC-DIR-04illustrative
Management group policywith user consent

08Deployment

Effortless installation and maintenance

Signed MSI agent, 3-step enrolment, updates from the console.

  • Windows agent shipped as a signed MSI installer: a double-click or a silent msiexec command, deployable through GPO or Intune.
  • Guided 3-step enrolment, with a time-limited, use-limited, revocable token.
  • Reinstall without losing history: the machine is recognised by its TPM chip.
  • Windows and Linux agents updated from the console, with automatic rollback to the previous version if the agent does not reconnect.
  • Revoke a device in one click.
Agent installationillustrative
PS> msiexec /i EPMAgent.msi /qn
Signed MSI installer · GPO or Intune
Time- and use-limited enrolment tokenrevocable
Device recognised by its TPM chiphistory kept
Agent update · automatic rollback if no reconnection

See every module in action

We show you the console on a demo fleet and answer your technical questions.

HostCitadel