Expiring enrollment tokens
A public enrollment endpoint issues tokens that expire, so no static secret is baked into an installer that then circulates indefinitely.
Enroll, configure and upgrade endpoints at scale — with an agent that defends itself.
The agent is both the sensor the detection engine runs on and the actuator response is executed through. It is distributed via signed package repositories and a hosted Windows installer.

Platform support
| Platform | Status | Notes |
|---|---|---|
| Linux — Debian / Ubuntu (.deb) | Shipped | Full EDR, file integrity monitoring, configuration assessment, inventory and response. |
| Linux — RHEL / Rocky (.rpm) | Shipped | Full parity with the Debian package. |
| Windows — signed .msi | Shipped | Code-signed, with kernel-level telemetry, on-agent tamper protection and network isolation for host containment. |
| ARM64 — Linux .deb and aarch64 .rpm | Shipped | For ARM servers and edge deployments. |
| macOS (.pkg) | Roadmap | Code is ready; pending a signed and notarized build. Not yet generally available. |
macOS is not yet generally available. The code is ready and the build is pending signing and notarization — it is listed here so the gap is explicit rather than discovered during a deployment.
Fleet management
A public enrollment endpoint issues tokens that expire, so no static secret is baked into an installer that then circulates indefinitely.
Configuration is pushed by group rather than per host, which is what makes a large estate maintainable.
Agents are upgraded remotely without a manual reinstall pass across the fleet.
Live daemon statistics and health views, so an agent that has stopped reporting is visible rather than silently absent.
Agents pull signed content updates without a full reinstall.
Agent state and response actions persist across restarts, and removal is clean when it is genuinely intended.
We will walk through enrollment, grouping and upgrade for the mix of platforms you actually run.