Estate inventory
Real-time device facts, software, patches and posture collected through signed, allow-listed jobs — Cyber-Essentials-aligned checks across every OS, with soft-delete & 60-day retention.
Sovereign endpoint security & AI
A next-generation sovereign endpoint security platform that runs fully air-gapped — your data, your AI and your control stay entirely inside your own network. No cloud, no internet required. One lightweight agent across Windows and Linux, with autonomous red-teaming and Apex, a self-learning, on-prem AI assistant that finds the attack paths and fixes them without a single byte leaving your network.
How it works
Apex Vantage collapses endpoint management and security into a single lightweight agent that holds an encrypted, outbound-only connection to a central control plane. No inbound firewall rules, no client certs, no bearer secrets on the wire — it survives TLS-inspecting proxies and even runs air-gapped. Everything an operator sees, every job an agent runs, is cryptographically signed and fully audited.
Every device you manage — Windows and Linux — runs one lightweight agent that installs and updates itself, ready to manage and protect from the moment it comes online.
The secure command centre for your estate — where policies are set, work is orchestrated across every device, and every action is signed and recorded.
Capabilities across the platform
Real-time device facts, software, patches and posture collected through signed, allow-listed jobs — Cyber-Essentials-aligned checks across every OS, with soft-delete & 60-day retention.
Declarative desired state with continuous drift detection and remediation. Target device groups with additive, per-device overrides.
Offline OSV match surfaces CVEs, then EPSS + CISA KEV enrichment ranks them by real-world exploitability — KEV-listed first, not raw CVE counts.
Passive-by-default sensor maps topology, neighbours, connections and exposed services. Flags rogue / unmanaged assets and feeds the attack graph.
Approval-gated patch & reboot inside maintenance windows with auto-verify — plus risk-threshold autonomy that auto-approves only below a per-kind posture-score gate.
Every state change logged with actor, target and outcome — plus an AI assurance log capturing every Apex tool call, proposal and delegation for full traceability.
Headline · AutoRedTeam
Apex Vantage continuously reasons over the data it already holds — inventory, software, matched CVEs and network topology — to discover and rank the realistic attack paths an adversary could chain through your estate. It blends CVSS, EPSS and CISA KEV into an exploit-realism score, then Apex's red-team specialist narrates the kill-chain in plain English, citing the exact devices and CVEs.
Headline · Apex · Sovereign AI
Apex is multi-agent — and sovereign. Every model runs on your own infrastructure, so no data ever leaves your network. A supervisor triages your question and delegates to the right domain specialist — each with its own tools to help you remediate. Findings are computed deterministically, never invented by the model; every tool call, proposal and delegation lands in the assurance log; and a human confirms every write.
And Apex never stands still. It automatically and constantly learns your estate — devices joining, software changing, new risk appearing — building an ever-sharper picture of your environment with no manual training or tuning required.
Operations
Pre-stamped Windows MSI and Linux .deb/.rpm installers — no manual enrolment. Identity is written on first run and the token cleared.
Operator-pushed, SHA-256-verified upgrade jobs apply via a detached updater — with a watchdog that rolls back automatically if the new agent fails to reconnect.
Soft-delete with 60-day retention and restore, plus agent self-uninstall on decommission — nothing purged in haste, everything auditable.
Sovereign, cross-platform endpoint security, autonomous red-teaming and multi-agent Apex — air-gapped, on-prem, and entirely under your control.
Contact us