Shield-DM is a focused endpoint compliance platform: an on-prem controller, a hardened service for Windows and Linux, and a patch lifecycle that ends in evidence — not a sprawling RMM suite.
A live asset register for every endpoint — the foundation everything else builds on.
Serial, manufacturer, model, CPU, RAM, disk & free space, BIOS/firmware, IP & MAC, network interfaces, architecture, last boot.
Installed packages & applications with version, vendor/source, install date and package manager — across apt, dpkg, rpm, dnf, yum and Windows.
OS family, name, edition, version, build, Linux kernel, install date, last scan, last successful update, and pending-reboot state.
CURRENT INVENTORY · HISTORICAL SNAPSHOTS · CHANGE HISTORY · COMPLETENESS SCORE — ALL RETAINED FOR EVIDENCE
Scan, approve, push and verify — through native package managers, never a generic remote shell.
Via the Windows Update Agent. Scan-only, install security and/or critical updates, install specific KBs, verify, report reboot.
Via apt, dnf and yum. Security-only by default, no automatic reboot, reboot-required reported. Specific-package patching supported.
The endpoint executes nothing but signed, allow-listed job types — scan · install_security · install_critical · install_specific · verify · report_reboot. No arbitrary command or script execution, ever.
A lightweight service that pulls work over outbound HTTPS and proves who it is on every request.
Per-endpoint identity via mTLS or signed device token. No permanent shared enrolment secret; controller certificate validated.
Every job descriptor is signed, carries a nonce and an expiry. Endpoints reject tampered, expired or replayed jobs and log it.
Outbound HTTPS only — works behind NAT, on roaming and workgroup machines, with no inbound connectivity required.
LATER — WINDOWS SERVER · SUSE · ORACLE LINUX · AMAZON LINUX | EXCLUDED IN V1 — macOS · MOBILE
Controller on a Linux VM, a Windows and a Linux endpoint enrolled, first evidence exported — this week.