Platforms/ComplianceOS · IT & Security

“Are we exposed?” should take seconds, not a week.

ComplianceOS is self-hosted device management. It shows every laptop you own, what’s installed on it and whether it’s safe, and gives you a controlled way to fix it. You don’t pay per device, and your fleet data never leaves your infrastructure.

One journey
Advisory
Exposure
Approve
Patch
Verify
Prove
01 / One IT admin, one critical CVEFlip the switch

A browser zero-day drops at 9am.

Leadership wants to know who’s exposed. The auditor will later want proof it was fixed. Here is how that day goes with spreadsheets and remote sessions, and then inside ComplianceOS.

5Tools touched
2Spreadsheets
AllDevices fixed by hand
01

Read the advisory

A security bulletin lands in someone's inbox. Which version is affected? Which machines run it?

EmailVendor site
You
02

Check an outdated register

The asset spreadsheet was last updated at the previous audit. Installed versions were never tracked.

Excel
You
03

Ask people what they're running

A Teams post asks everyone to check their browser version and reply. A third answer.

Teams
You + everyone
04

Patch machine by machine

Remote sessions one at a time, or “please update and restart” messages that get ignored.

Remote desktopTeams
You
05

Chase who's left

Laptops that were offline, on leave or “restarting later”. The list lives in your head.

TeamsEmail
You
06

Build the evidence by hand

Weeks later the auditor asks for proof. You assemble screenshots and a spreadsheet.

ExcelScreenshots
You

By Friday most laptops are patched, probably. Nobody can say which ones for sure.

02 / The moment it clicksAlert → approved fix → proof

From advisory to audit trail before lunch.

Installed versions are matched against vulnerability feeds automatically. You approve one reviewed command for the affected group, watch each device report back, and the audit log is your evidence.

Alert09:02
● Critical · CVE match
Browser engine vulnerability: remote code execution
Exposed devices40
Engineering22
Delivery11
Sales7
◇ Self-hosted · data stays in-house
CommandApproved
library / update-browser-stable
target / group: exposed-cve
window / now · user notified
Approved by security lead
Devices reporting back0 / 40
Posture & proofLive
71%
Fleet compliance
09:02CVE matched to 40 devices across 3 teams
09:06Command approved by security lead
09:07Executed on group exposed-cve
…Waiting for devices to report
03 / More journeys in ComplianceOSOne agent on every device · one place to act

Every “can you check the laptops?” answered.

The same inventory, rules and command library power every IT and security routine.

Journey · AccessAdmin rights, just in timeTime-limited elevation with expiry and review, instead of permanent local admin on every machine.
Journey · JoinersLaptops ready on day oneNew starters from PeopleOS arrive with enrolled, encrypted, compliant devices.
Journey · LeaversOffboarding that actually locksWhen an exit is recorded, access is revoked and the device is locked or wiped, and it’s logged.
Journey · DriftUnapproved software, caughtRules fire the moment something off-policy is installed, not at the next audit.
Journey · AuditEvidence on demandCompliance scored per device and rolled up per team, exported when the auditor asks.
Journey · LicencesKnow what you pay forInstalled software reconciled against licences, so you can find unused seats.

Know your fleet. Prove it.

We’ll deploy ComplianceOS on a pilot group and show you your real exposure within the first week.