Security & Risk

Vulnerability management that ends in a ticket, not a PDF.

Scan targets on a schedule, rank the risks that come back, correlate them with the software inventory on every endpoint, and route the ones that matter into the queue your techs already work.

The shape of it

Three principles that make this work.

Scanning that closes the loop

A finding is not a report line — it is a risk record with an owner, a status, and a ticket. Remediation happens in the same tool that found the problem.

Inside and outside the perimeter

Managed external scanning through HostedScan plus agent-side software inventory and CVE matching, so an exposed service and a vulnerable local package show up in one risk register.

The service desk is an attack surface too

Identity verification puts a real check between a caller claiming to be an executive and a password reset — one-time codes, document capture, and a technician review step, all recorded on the ticket.

Capabilities

Limitless capabilities, one product.

Risk register

Every finding as a tracked risk with severity, exposure, status, and history — not a snapshot you re-download.

Scan targets

Define hosts, ranges, and web targets per customer, with ownership and tags that follow into the findings.

Scheduled scans

Recurring scans per target with a live activity feed, plus on-demand runs when something changes.

Per-agent CVE findings

Software inventory on each endpoint matched against known CVEs, so a vulnerable local package is visible without a network scan.

Requester identity verification

Send a verification challenge from a ticket — one-time code, document capture, technician review — before privileged actions. The whole exchange is logged on the ticket.

Access governance

Granular RBAC, teams, SSO including Microsoft Entra, MFA, per-tenant isolation, and a complete audit log of who did what.

In numbers
Scheduled
Internal + external scans
Per-agent
CVE + software inventory
Tracked
Risks, not report lines
Verified
Requester identity on tickets
Better together

What pairs well.

Find every device. Including the ones nobody told you about.

Continuous LAN scans with SNMP, port scans, and CVE detection.

See Network Discovery

Patches that actually install. At SYSTEM.

MSI-first delivery with Chocolatey bootstrap. winget supported but not preferred — for reasons.

See Patch Management

Every message in and out, captured and provable.

Tenant-branded outbound mail through one dispatcher, with a full audit row for every inbound and outbound message.

See Email & Compliance
FAQ

Questions about Security.

Do I need a separate vulnerability scanner?

No. External scanning runs through the built-in HostedScan integration, and agent-side CVE detection comes from the RMM agent inventory — both land in the same risk register.

What is identity verification for?

Social-engineering defence on the service desk. Before a password reset or a privileged change, a technician sends a verification challenge; the requester completes a one-time code or document capture, and the reviewed result is recorded on the ticket.

How is customer data isolated?

Every record is partitioned per tenant, access is enforced server-side on every route rather than hidden in the UI, and administrative actions are written to an immutable audit log.

Ready to try Security?

See Security in your environment.

Deploy your first agent in minutes. See the platform in action — book a walkthrough or kick the tires on a free trial.

Book a demo30-minute walkthrough. No sales pressure.