Endpoint Management · self-hosted · EuropeanYour whole fleet, under control. On your premises.
EPM monitors, updates, troubleshoots and protects your Windows devices and Linux servers from a single console, hosted on your premises, where every sensitive action is signed and approved with a physical security key.
Every order is signed and expires. The agent refuses everything else.
Your server, Docker: no data about your fleet goes to a third party.
Patches, reboots, policies: nothing without your physical key.
01The console
Your whole fleet on one screen
Online devices, health, missing patches, alerts: the state of your fleet reads in seconds. And when something needs fixing, one button does it, approved with your key.
CPU · PC-COMPTA-07—
Missing patchKB5122882
Windows security update · 12 devices
- Scanning
- Downloading
- Installing
02Modules
Eight modules, one console
From monitoring to deployment, every module follows the same rule: nothing runs without a signature, and every action is logged.
Monitoring
Online and offline devices, health, alerts and inventory, kept up to date continuously.
See details 02Microsoft patching
Missing-update detection, per-group policies, compliance rate.
See details 03Stack Radar
Linux and Docker inventory matched against OSV, CISA KEV, EPSS and CERT-FR.
See details 04Remediation
Verified backup before, verification after, approval with a security key.
See details 05Remote actions
Services, processes, scripts, reboots: the result shows live in the console.
See details 06Applications
Catalogue with an approval workflow, SHA-256 integrity, maintenance windows.
See details 07Remote control
From the browser, no third-party software, with an always-visible banner.
See details 08Deployment
Signed MSI agent, 3-step enrolment, updates from the console.
See details03Architecture
How it works
The connection always starts at the device. It is encrypted and authenticated on both ends, and everything stays inside your network.
The connection starts at the deviceNo port open on your devices.
Encrypted both waysTLS 1.3 with mutual authentication.
Everything stays with youServer, console and data inside your network.
04Security
The path of an order, from your key to execution
A tool that can act on all your devices must be the hardest one to hijack. Every step checks it.
For a risky action, the console asks for your key.
WebAuthnIt carries a signature and an expiry date.
Ed25519The agent connects to the server, never the reverse.
outbound · 8443Encrypted and recognised on both ends.
TLS 1.3 · mTLSSignature and expiry, before acting. Otherwise it refuses.
device key in TPMLive result, written to the audit log.
audit log05Who it is for
For the people accountable for the fleet
IT director / IT manager
SMEs and mid-sized companies
See the state of the whole fleet, deploy quickly, fewer tickets.
The whole fleet on one screen, and updates that install themselves in your maintenance windows.
CISO / security officer
NIS2, DORA, GDPR compliance
Attack surface, traceability, compliance.
Nothing runs without a signature, every action is logged, your data stays on your premises.
IT service provider (MSP)
Several customers
Manage several customers, prove your work.
Patch compliance rate per group, daily summary, audit log.
See EPM on your own case
A walkthrough of the console, with your questions about your fleet, your network and your compliance requirements.