Product overview

One controller. Two endpoints.
Five jobs done well.

Shield-DM is a focused endpoint compliance platform: an on-prem controller, a hardened service for Windows and Linux, and a patch lifecycle that ends in evidence — not a sprawling RMM suite.

Capability 01

Complete inventory.

A live asset register for every endpoint — the foundation everything else builds on.

Hardware

Serial, manufacturer, model, CPU, RAM, disk & free space, BIOS/firmware, IP & MAC, network interfaces, architecture, last boot.

Software

Installed packages & applications with version, vendor/source, install date and package manager — across apt, dpkg, rpm, dnf, yum and Windows.

Operating system

OS family, name, edition, version, build, Linux kernel, install date, last scan, last successful update, and pending-reboot state.

CURRENT INVENTORY · HISTORICAL SNAPSHOTS · CHANGE HISTORY · COMPLETENESS SCORE — ALL RETAINED FOR EVIDENCE

Capability 02

Controlled patching.

Scan, approve, push and verify — through native package managers, never a generic remote shell.

Windows

Via the Windows Update Agent. Scan-only, install security and/or critical updates, install specific KBs, verify, report reboot.

Security updatesCritical updatesSpecific KBsHRESULT capture

Linux

Via apt, dnf and yum. Security-only by default, no automatic reboot, reboot-required reported. Specific-package patching supported.

aptdnfyumzypper · later

Allow-listed jobs only

The endpoint executes nothing but signed, allow-listed job types — scan · install_security · install_critical · install_specific · verify · report_reboot. No arbitrary command or script execution, ever.

Endpoint service

Hardened, by design.

A lightweight service that pulls work over outbound HTTPS and proves who it is on every request.

Device identity

Per-endpoint identity via mTLS or signed device token. No permanent shared enrolment secret; controller certificate validated.

Signed jobs

Every job descriptor is signed, carries a nonce and an expiry. Endpoints reject tampered, expired or replayed jobs and log it.

Pull, not push

Outbound HTTPS only — works behind NAT, on roaming and workgroup machines, with no inbound connectivity required.

Supported platforms — v1

Windows 10Windows 11Ubuntu LTSDebianRocky LinuxAlmaLinuxRHEL-compatible

LATER — WINDOWS SERVER · SUSE · ORACLE LINUX · AMAZON LINUX  |  EXCLUDED IN V1 — macOS · MOBILE

Request an eval licence

See it on your own VM.

Controller on a Linux VM, a Windows and a Linux endpoint enrolled, first evidence exported — this week.