Nothing runs without a signature
Every order sent to a device is signed and carries an expiry date. The agent checks the signature before acting and refuses everything else.
What it prevents: A forged order, or an old order replayed, is refused by the device.
Technical details
Ed25519 signature, per-order expiryApproval with a physical security key
Risky actions require your key: installing a patch, updating an agent, rebooting a server, changing a policy.
What it prevents: A stolen password is not enough to act on your fleet.
Technical details
YubiKey / WebAuthnEach device's key inside the TPM chip
The key that identifies the device is stored in the TPM 2.0 chip and cannot leave it.
What it prevents: A machine can be neither cloned nor impersonated.
Technical details
TPM 2.0, non-exportable keyEncrypted connection, authenticated both ways
Each agent and the server authenticate each other. The agent pins the server's authority.
What it prevents: Nobody can put themselves between your devices and the server.
Technical details
TLS 1.3, mutual authentication (mTLS)No open port on devices
The agent always calls the server, never the other way round.
What it prevents: Nothing to scan or attack on your devices from the network.
Technical details
Outbound connection onlyConsole never exposed to the Internet
The console is reachable only from the networks you authorise.
What it prevents: No login page visible from the outside.
Technical details
Access limited to authorised networksSign-in with password and security key
Password plus security key, TOTP code as a fallback, single sign-on (SSO).
What it prevents: A phished credential is not enough to get into the console.
Technical details
WebAuthn, TOTP, Keycloak SSOSigned packages and agent
Deployed applications carry the owner's code signature. The Windows agent is Authenticode-signed and refuses any unsigned update.
What it prevents: A tampered package or a trojanised agent is never installed.
Technical details
Code signing, Authenticode (Microsoft Azure Artifact Signing)Four-eyes principle
In the application catalogue, an administrator cannot approve their own package.
What it prevents: No single person can push software to the whole fleet alone.
Technical details
Draft, pending, published workflowAgent-side red list
The agent refuses to stop vital Windows services and processes, and to disable itself.
What it prevents: Even if the console were compromised, your devices stay up and monitored.
Technical details
Enforced by the agentSecrets encrypted for the recipient only
Run-as account passwords are encrypted, sent encrypted for the target device only and never written to its disk.
What it prevents: A secret can be read only by the device that needs it, when it needs it.
Technical details
AES-256-GCMAudit log of every action
Who, what, when, on which machine, with what result.
What it prevents: You answer an audit or an incident with facts, not guesses.
Technical details
Timestamped log