Device and MDM posture,
where most findings live.
Disk encryption, screen lock, OS updates, antivirus or EDR, firewall, automatic updates, password policy and MDM enrolment, reported by a small agent on every laptop and checked continuously, because endpoints are where most SOC 2 and ISO findings actually come from.
What it does
- Agent script for macOS, Linux (shell) and Windows (PowerShell)
- Eight checks: disk encryption, screen lock, OS updates, AV/EDR, firewall, auto-updates, password policy, MDM enrolment
- A fix instruction per failing check, per operating system
- Compliant, at risk and non-compliant, per device
- Manual enrolment for devices the agent cannot run on
The annual screenshot problem
Endpoint controls are usually evidenced once a year with a screenshot of an MDM dashboard. It proves that on one afternoon the fleet looked acceptable, and says nothing about the eleven months either side, which is where the laptop that fell out of compliance in March actually sat.
Continuous checks turn that into a record with dates. Each device's agent checks in with its current state, so when a laptop drifts the drift has a start, an owner and an end, and that history is what an auditor is really asking for when they ask how you manage endpoints.
Count the devices nobody manages
Every fleet has them: a contractor’s laptop, a founder’s personal machine, the build box under someone’s desk. They are unmanaged precisely because the MDM does not reach them, so a report drawn only from the MDM is confidently incomplete.
Manual enrolment exists so those devices appear in the fleet as what they are, with a named owner and attested posture. MDM enrolment is itself one of the eight checks, so the report shows which machines are outside central management instead of quietly leaving them out.
Posture that reaches the framework
Device state is not a separate dashboard here. A non-compliant laptop is a failing control result, so it moves framework readiness and the residual score on the risk register at the same moment, and the evidence ledger records both the failure and the remediation.
That is the difference between knowing your fleet and being able to evidence it: the same result answers the SOC 2 requirement, the ISO 27001 annex control and the internal risk, without being gathered three times.
Where this sits
This is one engine of eleven on a single control graph, which is why a result produced here reaches every framework that asks for it instead of being gathered again under another heading. The platform overview shows the other ten, and coverage lists the regimes they answer.
Related reading: ISO 27001 compliance software.
The things people ask us
Which MDMs do you integrate with?
None directly yet. Posture comes from our own agent, which runs on macOS, Linux and Windows and reports whether the device is enrolled in an MDM such as Jamf, Intune, Kandji or Hexnode. Direct MDM connectors are on the roadmap and are not live.
What is actually checked?
Eight things per device: disk encryption (FileVault, BitLocker or LUKS), screen lock, OS updates, antivirus or EDR, firewall, automatic updates, password policy and MDM enrolment. Each device is classified as compliant, at risk or non-compliant.
What about phones and tablets?
The agent runs on desktop operating systems. Phones and tablets can be enrolled manually with their attested posture and an owner.
Does a non-compliant device affect readiness?
Yes. It is a failing control result, so it moves framework readiness and residual risk, and both the failure and the remediation are recorded.
Can you push fixes to a device?
No. The agent reports state and changes nothing. Each failing check comes with the fix for that operating system, and remediation stays with whoever manages the device.
Your next audit could be a link.
Thirty minutes. We connect one cloud account live and show you real evidence landing in the ledger before the call ends.