Find the risk, ship the fix, stay Cyber Essentials compliant — all in one tool

Unified ITAM, MDM and agent inventory. A KEV-aware risk register that tracks every device against the Cyber Essentials 14-day patch window. 5Rs rationalisation on the whole estate. Version intelligence you control. And self-service PSADT packaging built straight into the console — so the remediation that other tools leave to a separate team happens here, to your standards, with the compliance evidence to prove it.

The capabilities in one console

Unified Inventory Layer

Your ITAM, Microsoft Intune MDM and our lightweight Windows agent feeding one normalised view. An alias resolver untangles the messy real-world product names from each source, so "Microsoft Edge", "Microsoft Edge Update" and "Edge GameAssist" aren't all treated as the same product.

KEV-Aware Risk Register

NIST NVD plus CISA Known Exploited Vulnerabilities overlaid on your live estate. The SLA clock starts the moment a KEV match is found and is mapped to the CE+ 14-day window. A high-confidence filter excludes coarse, major-only version matches so the register shows actionable rows, not noise.

5Rs Rationalisation Engine

Every product — catalogued or not — gets a per-app, per-version recommendation: Retain, Reduce, Replace, Remove or Replatform, driven by usage telemetry, exposure and category. Set actions and categories on any application in the estate, with reviewer, date and notes recorded.

Self-Service Packaging

Choose an application and the platform downloads the latest release and wraps it in PSAppDeployToolkit v3 to your client standards: install syntax, audit-key blocks, security hardening and a generated build document. A live checklist shows exactly what each PSADT section does and where. The skilled work that goes out to a packaging house at thousands of pounds per app is self-served in minutes.

In-Browser PSADT Editor

Adjust the generated Deploy-Application.ps1 right in the console — syntax-highlighted, split by section, with one-click snippets for installs, registry, files, services, firewall and deferral prompts. Every save is parse-checked and backed up before it's written, so a broken edit can't ship.

Version Intelligence

A Product Master view over every application in the estate — thousands of products — showing the true latest version and a working download source, with the gaps flagged so you can close them. Semantic version comparison kills false "update available" alerts, and you own the data: point a monitor at any vendor page, pick the version with a CSS selector, test it live, and it feeds the estate.

Workplace Automation

A library of vetted maintenance and remediation jobs that run on managed devices through the agent — disk cleanup, cache and temp clearing, service and update repair, and policy checks — on a schedule you set per client. Hardware-health monitoring flags failing disks, low memory, battery wear and overheating, and the matching fix is rolled out automatically. Every run is logged, scoped and reversible, so the estate stays clean, efficient and compliant without hands-on effort.

How the platform fits together

One data model, from raw inventory to a deployable package. Each layer can be swapped without rebuilding the others.

1. Data ingestion

Three feeds keep the estate view live:

  • ITAM aggregate · nightly snapshot of every product installed across every device, with publisher and version. Captures the long tail of estate sprawl.
  • Microsoft Intune · for managed devices, a normalised inventory plus device compliance state.
  • APaaS agent · optional lightweight Windows agent that adds accurate per-application usage — last-launched dates and frequency — so you can right-size licences and evidence software savings, plus full-build version reporting. Where ITAM reports "Edge v1", the agent fills in the real build.

2. Normalisation & categorisation

An alias resolver maps each raw product name to a canonical AppId, and a canonical taxonomy classifies every product (browsers, runtimes, BIM tools, antivirus, and more). The result is one clean estate instead of three noisy ones.

3. Vulnerability & version correlation

Every 4 hours the platform pulls the latest CVE records from NIST NVD and CISA's KEV catalogue and matches them against your estate. In parallel, a version feed resolves the current release and download for each product from winget, the Evergreen catalogue or a vendor-page monitor you define — so "what's installed" and "what's current" sit side by side, compared semantically.

4. Decision, packaging & deployment

The 5Rs engine ranks every product by usage and exposure. From the same console your team raises a packaging request: the platform fetches the latest installer, wraps it to your client standards in PSADT v3, lets you fine-tune the script in the editor, and deploys it straight to Microsoft Intune or Configuration Manager — with the build documented and the whole chain auditable.

Workplace automation & estate hygiene

Keeping an estate secure isn't only about patching — it's about keeping every device clean, healthy and running efficiently. The same agent that reports inventory also carries out the fixes.

Maintenance that runs itself

A library of vetted automation jobs runs on managed devices on a schedule you set per client: disk cleanup, temp and cache clearing, Windows Update repair, service restarts, profile and log housekeeping, and configuration checks. Routine work that used to mean a technician touching each machine — or never getting done — happens quietly in the background, keeping devices fast and storage healthy.

Hardware health monitoring & auto-remediation

The agent watches the things that cause tickets and downtime before they fail: SMART disk warnings and failing drives, low free space, memory pressure, battery wear, thermal and overheating signs. When a known issue is detected, the matching remediation is dispatched automatically — or surfaced for approval where a human should sign off first — so problems are resolved before the user notices.

Scoped, scheduled and auditable

Every job is targeted by client and device, runs on a per-client schedule, and is HMAC-signed end to end. Each execution is logged with its result, and actions are designed to be safe and reversible — so you get a cleaner, more efficient, more compliant estate with a full evidence trail and no surprises.

Integrations

Pre-built connectors. Add a credential, accept the consent, see your estate populate within hours.

Microsoft Intune

OAuth app registration in your tenant. Pulls device inventory, compliance state and the published-app catalogue — and pushes finished packages straight to Intune from the console.

Configuration Manager

Packages deploy directly into your existing Configuration Manager (SCCM) application model — no manual hand-off between packaging and deployment.

ITAM & CSV import

Bring your existing ITAM dataset and asset or licence schedules in via tenant credentials or CSV upload. Validated against the same normalisation pipeline.

APaaS agent

MSI-deployed via your existing Configuration Manager, Intune or GPO. HMAC-signed reporting with accurate per-application usage that drives licence right-sizing and savings.

winget & Evergreen

Authoritative version + installer sources for thousands of common applications, refreshed on a schedule. No manual upkeep.

Vendor-page monitors

For anything off the beaten track, define your own version monitor: a URL and a CSS selector, tested live in the console.

NIST NVD & CISA KEV

Authoritative vulnerability sources. Refreshed every 4 hours. No work for you.

Webhook / API

Programmatic access to the risk register, applications and exposures. JSON, HMAC-authenticated.

Try it on your estate.

UK-based onboarding · No procurement friction

Book a demo