Shield-DM is the on-prem platform for regulated teams that need hardware & software inventory, remote patching, and auditor-ready evidence — without Intune, SCCM, WSUS, mature Active Directory, or the cloud.
| Endpoint | OS | Missing | State |
|---|---|---|---|
| PMS-DC-04 | Win 11 | 3 critical | Exposed |
| AIF-APP-12 | Ubuntu 22 | — | Reboot |
| BR-FILE-09 | Rocky 9 | — | Compliant |
| HR-WS-221 | Win 10 | 1 security | Exposed |
When an auditor, a client security team, or a cyber-insurer asks, the honest answer is too often “let me get back to you.” Shield-DM makes every one of these a live query.
Three jobs, done well — the operational core most teams actually pay for, without the rest of a heavyweight endpoint suite.
Hardware, software and OS for every Windows and Linux endpoint — serial, model, CPU, disk, IP/MAC, installed packages, build and kernel. Snapshots over time for evidence.
Scan for missing security & critical updates, push approved patches remotely, and track every job — installs, failures, reboots — through native Windows Update and apt / dnf / yum.
Every lifecycle step produces a record: before-state, approval, execution, result, reboot, exception, verification, closure. Export an evidence pack auditors accept.
One on-prem controller. A lightweight service on each endpoint that polls over outbound HTTPS and executes only signed, allow-listed jobs. No inbound connections, no domain controller, no cloud.
Works without Intune, SCCM/MECM, WSUS, Active Directory, GPO maturity or Azure AD. Roaming, NAT'd and workgroup machines included.
The service only runs signed, allow-listed job types — scan, install security/critical updates, verify, report reboot. Never a generic command framework.
Offline buffering, job expiry and replay protection, idempotent execution, retry with backoff, and a campaign kill-switch.
Patching as a governed activity, not a fire-drill — every stage timestamped and recorded, so closure means closure.
EVERY STEP PRODUCES EVIDENCE — BEFORE-STATE · APPROVAL · EXECUTION · RESULT · REBOOT · EXCEPTION · VERIFICATION · CLOSURE
Shield-DM is built around the controls auditors and regulators actually test — asset management, patch SLAs, and documented exceptions.
Most tools can patch. Few can prove it. Shield-DM generates the register an auditor signs off — per campaign and per endpoint, on demand.
| Artifact | Records | State |
|---|---|---|
| Approval trail | 7 sign-offs | Complete |
| Per-endpoint result | 214 rows | Complete |
| Reboot verification | 189 / 189 | Resolved |
| Exception register | 3 active | Review 06/26 |
We compete where the real operational spend is — inventory, patching and evidence — and deliberately leave out the rest. Less surface, lower cost, easier to audit.
Install the controller on a Linux VM, enrol a Windows and a Linux endpoint, and export your first inventory and patch-compliance evidence — on your own infrastructure.