Install one agent, get a real-time view of every machine — interactive terminal, full remote desktop, live metrics, scheduled scripts, policy automation. Works on iOS at the Windows lock screen.
WebSocket-streamed framebuffer, sub-100ms latency on broadband. Click, drag, scroll, multi-monitor support, mouse-cursor compositing for accurate hit testing.
Touch-aware floating keyboard bar with per-character VK injection — types real keystrokes (not just text events), so it works at the Windows secure desktop and lock screen.
Full PTY with ANSI/VT100 support. Runs as the logged-in user or as SYSTEM, with copy/paste, scrollback, and resize handling.
Winlogon helper running as SYSTEM injects keyboard and mouse to the secure desktop — UAC consent prompts, lock screen passwords, the lot.
CPU, memory, disk, network — streamed continuously over WebSocket. See changes as they happen, not on a 5-minute polling cycle.
Heartbeat-driven online indicator. Per-agent last-seen timestamps with cron-based offline reconciliation that resists transient network blips.
Hostname, OS version, build, architecture, CPU model, total RAM, IP/MAC, agent version. Snapshotted on every probe registration and refreshed on heartbeat.
Public IP, country, region, ASN — useful for identifying when an endpoint moves networks.
Push PowerShell, Bash, Python scripts to one endpoint or all of them. Get stdout/stderr back in real time, plus exit codes.
Recurring jobs on cron schedules — backups, health checks, log rotation. Per-agent or per-policy targeting.
Group endpoints into policies; apply software lists, registry settings, scheduled scripts uniformly. Compliant or non-compliant status surfaced per policy.
Push a new agent build centrally — every connected machine picks it up on the next check-in. Cryptographically signed manifest, automatic rollback on bind failure.
Browse the entire filesystem, view files, upload/download, edit text. Navigate as the agent's identity (typically SYSTEM).
Live read/write access to HKLM, HKCU, HKU, HKCR. Create, edit, delete keys and values. Type-aware for REG_DWORD, REG_SZ, REG_BINARY, REG_MULTI_SZ.
List, start, stop, configure Windows services. View dependencies, recovery actions, startup type.
Installed programs with publisher, version, install date — per machine and across the fleet.
Per-tenant signed installer EXE. Run it, agent enrolls itself with the tenant's enrollment token, registers with the cloud, and is ready in under 30 seconds.
Generate scoped tokens with expiry. Revoke compromised tokens without affecting already-enrolled agents.
Windows agent today; Linux and macOS agents in active development on the same WebSocket protocol.
Each customer's data lives in its own dedicated database — not a shared multi-tenant table. A strict-mode resolver enforces tenant boundaries at the data-access layer, so cross-tenant access is structurally impossible.
Per-tenant role configuration, granular permissions for terminal, desktop, scripts, file access. Audit-ready.
Time-based one-time passwords compatible with all standard authenticators. Mandatory for admin accounts.
Each managed endpoint maintains a persistent connection to the platform via standard outbound HTTPS — works through any NAT or firewall, no inbound ports to open. Compute runs at the edge so commands feel instant from anywhere.
No credit card. Full feature access. We provision a dedicated database and a per-tenant subdomain — you're operational in under 5 minutes.