Device management

Every company laptop,
held to your baseline.

A small agent runs six posture checks on each laptop every hour, against the policy you set, and reports back. The fleet view shows which devices are compliant right now and why the rest are not, and a daily snapshot files that as evidence. Read-only by design: the agent never changes a setting, pushes a profile or wipes a device.

Start for freeBook a conversation
++++
app.devguard.ch / devices
Fleet · 24 devices
Right now
20
of 24 compliant
Compliant20
Non-compliant02
Not reporting01
Awaiting first01
6 of 6 checks enforcedSnapshot filed 03:00 UTC
Fleet
reported hourly
MDM-017 · Jordan’s MacBook Pro
non-compliant41 min ago
Disk encryption
Antivirus
Firewall
Password policy
Screen lock
OS up to date
Screen lock failed: the fix shows up in Jordan’s portal. Nobody sends the laptop a remote command.
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO 9001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO 9001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO 9001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO 9001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO 9001
  • Swiss nFADP
How it works

One baseline, enrolled by the people who use the laptops.

You set the policy once, employees enroll their own machines, and the hourly check-ins keep the verdict and the evidence current without anyone touching a laptop.

01

Set the baseline once.

The device policy is one baseline per organization: six checks, each with a switch, and the thresholds behind them. A disabled check is neither run by the agent nor counted anywhere, so you enforce what your controls actually require and leave the rest off. You set the idle minutes before the screen must lock, the minimum password length, and whether OS currency means the latest major release or every point update as well.

You also decide how long a device may stay silent before that silence becomes a finding. Changes reach every machine on its next check-in, within the hour, and you never reship the agent to change a threshold.

Required and forbidden apps.

The app policy is two lists: apps every device must have, such as a password manager or an EDR agent, and apps no device may have. Each entry is matched by app name, bundle id or package name and can carry a remediation note for the employee. The agent answers presence per entry and never uploads what else is installed.

02

Employees enroll their own machines.

The agent runs on macOS, Windows and Linux and enrolls through the employee portal, where the consent screen shows exactly what will be reported, with a literal example of the data. The browser mints the agent’s key and seals it with a one-time code, so the key only ever reaches the machine that asked, and the enrolling membership is re-checked on every report.

Each employee sees only the computers they enrolled: the six results in plain language, the steps to fix a failing one, and the apps your policy requires or forbids. A machine you record by hand, for the asset register, carries no posture and reads as not monitored rather than as a failure.

03

The fleet reports hourly, the verdict is always current.

Compliance is derived on every read from the last check-in and your policy, never stored, so the fleet view is never stale. A device is compliant when every enforced check passed; a result the agent could not determine shows as undetermined rather than failed, but it is not a pass, so the device is not compliant. A device silent past your window becomes not reporting and stops counting, a fresh enrollment gets a day of grace, and a laptop that comes back after being archived un-archives itself.

Once a day devguard writes a fleet snapshot per check and files it as evidence, using the same maths as the live ratio, so the number the auditor reads is the number the dashboard showed.

Why it’s built this way

Built around what an employee would accept.

Four choices behind how device management works here — each one something you can check, not an adjective.

01

Read-only, and the agent cannot be otherwise.

The agent runs as the employee’s normal user account and holds no elevated privileges. It never changes a setting, installs or removes software, pushes a configuration profile, or locks or wipes a device. When a check fails, the employee sees instructions and a button that opens the right settings pane, and makes the change themselves. That is an architectural limit, not a feature that is coming later.

02

Honest about what it cannot see.

Every check comes back as pass, fail or could not determine, together with the command the agent ran and its output. An unknown result shows as undetermined rather than as a failure, but it is not a pass either, so the device stays not compliant until the agent can decide. OS currency is decided on the server from a version table devguard maintains, not guessed on the machine, and the employee sees the same results on their own computer in the agent’s status window.

03

Written to be handed to the works council.

The disclosure document is meant to be passed on unedited. It lists what the agent never collects: file contents, browser history, keystrokes, screenshots, location, personal accounts, or a list of installed software. The check-in payload has no field that could carry an inventory. Consent is recorded together with the version of the text the employee saw, and devguard processes the data as a processor under the FADP and the GDPR.

04

Evidence, not a screenshot.

Link a device to the controls about endpoint security, encryption at rest and malware protection, and the auditor sees a live verdict instead of a photo of a settings pane. Once a day devguard writes a fleet snapshot per check as evidence, updated in place. A device that has gone silent or never reported counts as not compliant in those figures, even though the fleet view shows it in amber rather than red.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data and evidence are yours and exportable in full at any time, with no lock-in.

See the full feature comparison

One module of the platform

Where device management connects.

A device sits in the asset inventory, files its posture as evidence, appears in the device report, and carries its own tasks and comments.

1,284
assets tracked
+12 today

Assets

The inventory the fleet belongs to, hand-registered or enrolled.

342
artifacts captured
linked to controls

Evidence

A daily fleet snapshot per check, linked to its control.

86%
Shared with
JDAKMR+3

Reports

The device report, fleet posture as a PDF for the auditor.

TSK-012Document backups
TSK-013Access review
TSK-014Scope statementFri

Tasks

Chase a silent agent, schedule the encryption fix.

FAQ

The questions evaluators ask.

Is this an MDM?

Not in the sense of pushing profiles, distributing software or wiping a lost laptop remotely. devguard measures each machine against the baseline you set and turns the result into evidence, which is the part an auditor asks for. If you already run Intune, Jamf or Kandji, keep them: read-only integrations pull the compliance ratio from there, and the agent covers the machines those tools do not.

What does the agent collect, and what does it never collect?

Every hour it reports the machine’s vitals (name, hostname, model, serial number, OS version and agent version), the six posture checks with the command and output behind each, and whether each app on your required-or-forbidden list is present. It never collects file contents, browser history, keystrokes, screenshots, location, credentials or a list of everything installed, and nothing at all once it is uninstalled.

What counts as compliant?

Every enforced check passed on the last check-in. A check you have switched off reads as not required and never counts against a device, and a result the agent could not determine shows as undetermined rather than failed, but it is not a pass, so the device is not compliant until it resolves. A device silent for longer than the window you set becomes not reporting and stops counting as compliant, a fresh enrollment gets a 24-hour grace period before it can show red, and a machine added by hand without an agent stays not monitored rather than failing.

Which platforms does the agent run on, and how does it stay current?

macOS, Windows and Linux, as a tray-only app that checks in hourly and picks up your latest device policy and app policy on each check-in, so an edit reaches every machine within the hour. Where the platform allows it the agent updates itself daily; where it cannot, it shows the employee a newer-version prompt. An outdated agent is a badge and a count on the fleet view, never a compliance failure.

How do employees enroll, and can they see each other’s machines?

Employees enroll from the portal, never from the admin app: the agent opens the browser, the consent screen shows exactly what will be sent with a literal example, and a one-time code seals the agent’s key so it only reaches the machine that asked. Each person sees only the computers they enrolled, with the six results in plain language and the steps to fix a failing one. Revoking an agent from the device’s page stops it reporting immediately.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. Posture data is kept while the device is registered, and the daily fleet snapshots are aggregate counts that identify nobody beyond the device record. Your data and evidence are yours and exportable in full at any time, with no lock-in.

Show the auditor the fleet, not a screenshot.

Set the baseline once, let employees enroll their own machines, and let the hourly check-ins build the evidence while the people who use the laptops keep control of them.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free