On-prem endpoint inventory & patch compliance

Know every endpoint.
Prove every patch.

Shield-DM is the on-prem platform for regulated teams that need hardware & software inventory, remote patching, and auditor-ready evidence — without Intune, SCCM, WSUS, mature Active Directory, or the cloud.

Built for ISO 27001 SOC 2 SEBI CSCRF DPDPA Windows + Linux
shield.elytra.security/console/dashboard
Fleet dashboard ON-PREM · 4 MIN AGO
Endpoints
1,284
Win 812 · Linux 472
Patch compliant
92%
+4% this week
Pending reboot
37
in SLA
Failed jobs
6
2 categorised
EndpointOSMissingState
PMS-DC-04Win 113 criticalExposed
AIF-APP-12Ubuntu 22Reboot
BR-FILE-09Rocky 9Compliant
HR-WS-221Win 101 securityExposed
The problem

The questions you can't answer fast enough.

When an auditor, a client security team, or a cyber-insurer asks, the honest answer is too often “let me get back to you.” Shield-DM makes every one of these a live query.

01What endpoints do we actually have?
02What software is installed across them?
03Which systems are missing critical patches?
04Which systems failed patching — and why?
05Which still need a reboot to be compliant?
06Which are running unsupported, end-of-life OS?
07What can we actually show as evidence?
08…all without standing up Intune or SCCM?
What it does

Inventory. Patch. Evidence.

Three jobs, done well — the operational core most teams actually pay for, without the rest of a heavyweight endpoint suite.

Complete inventory

Hardware, software and OS for every Windows and Linux endpoint — serial, model, CPU, disk, IP/MAC, installed packages, build and kernel. Snapshots over time for evidence.

Controlled patching

Scan for missing security & critical updates, push approved patches remotely, and track every job — installs, failures, reboots — through native Windows Update and apt / dnf / yum.

Auditor-ready evidence

Every lifecycle step produces a record: before-state, approval, execution, result, reboot, exception, verification, closure. Export an evidence pack auditors accept.

How it works

The endpoint pulls. Nothing reaches in.

One on-prem controller. A lightweight service on each endpoint that polls over outbound HTTPS and executes only signed, allow-listed jobs. No inbound connections, no domain controller, no cloud.

On-prem · your VM
Shield-DM controller
Admin console, endpoint registry, patch engine, evidence generator. Runs on a Linux VM with PostgreSQL.
◄ pull
mTLS · outbound
HTTPS only
signed jobs ►
Windows · Linux
Shield endpoint service
Runs as a Windows service / systemd unit. Reports inventory, pulls approved jobs, executes native patch actions, reports results.

No Microsoft estate required

Works without Intune, SCCM/MECM, WSUS, Active Directory, GPO maturity or Azure AD. Roaming, NAT'd and workgroup machines included.

No arbitrary remote shell

The service only runs signed, allow-listed job types — scan, install security/critical updates, verify, report reboot. Never a generic command framework.

Resilient by design

Offline buffering, job expiry and replay protection, idempotent execution, retry with backoff, and a campaign kill-switch.

Patch lifecycle

From discovery to proof.

Patching as a governed activity, not a fire-drill — every stage timestamped and recorded, so closure means closure.

01 · Discover
Find & assess
Inventory and scan surface missing patches, EOL OS, pending reboots and stale endpoints.
02 · Approve
Govern
Prioritise by severity, age and criticality. Campaigns and critical systems require approval.
03 · Deploy
Patch now
Patch Now or scheduled campaigns push approved updates to endpoints or groups.
04 · Monitor
Reboot or defer
Live status, failure categories and reboot policy — no forced reboots by default.
05 · Verify
Prove & close
Confirm installation, resolve reboots, record exceptions, export the evidence pack.

EVERY STEP PRODUCES EVIDENCE — BEFORE-STATE · APPROVAL · EXECUTION · RESULT · REBOOT · EXCEPTION · VERIFICATION · CLOSURE

Built for regulated teams

Evidence that maps to your framework.

Shield-DM is built around the controls auditors and regulators actually test — asset management, patch SLAs, and documented exceptions.

Frameworks & mandates

ISO/IEC 27001 SOC 2 SEBI CSCRF DPDPA safeguards RBI / NBFC IT guidance Cyber-insurance controls Client security audits Internal IT audit

Who runs it

PMS · AIF · brokers NBFCs Co-operative banks Healthcare providers Manufacturing Education groups Government contractors Professional services Audited MSMEs
Evidence & audit · the difference

The evidence pack is the product.

Most tools can patch. Few can prove it. Shield-DM generates the register an auditor signs off — per campaign and per endpoint, on demand.

Asset inventory register Patch compliance summary Campaign closure report Critical patch SLA report Pending reboot report Exception register Endpoint patch history Auditor evidence pack
Explore the Evidence Center
console/evidence/campaign-2026-Q1-042
Campaign closure pack SIGNED · PDF + CSV
Targets
214
3 groups
Success
98.6%
211 verified
Exceptions
3
approved
ArtifactRecordsState
Approval trail7 sign-offsComplete
Per-endpoint result214 rowsComplete
Reboot verification189 / 189Resolved
Exception register3 activeReview 06/26
Not a full RMM

Five things, done well.

We compete where the real operational spend is — inventory, patching and evidence — and deliberately leave out the rest. Less surface, lower cost, easier to audit.

Capability
Elytra Shield
Heavy RMM suite
Hardware & software inventory
Core
Snapshots for evidence
Yes
Buried in modules
Remote patching, on-prem
Core
No cloud dependency
Often cloud-tied
Audit evidence packs
Core
Per campaign & endpoint
Add-on / manual
Remote desktop · MDM · scripting
Out of scope
By design — safer, cheaper
Bundled
Pay for it regardless
Needs Intune / SCCM / AD
No
Runs standalone
Frequently
Request an eval licence

Run it on a VM this week.

Install the controller on a Linux VM, enrol a Windows and a Linux endpoint, and export your first inventory and patch-compliance evidence — on your own infrastructure.