Know What Your Laptops Are Doing

An osquery agent on macOS, Windows and Linux reports what a machine actually looks like — disk encryption, firewall, screen lock, what is installed and what is running. Every rule is judged on our servers, never on the device.

Posture, not control

This is not classic MDM. We do not push configuration profiles, we do not lock or wipe machines, and we do not take remote control. The agent collects; the server decides pass or fail; the person gets told what to fix. If you need enforcement, keep your MDM — Engarde tells you whether it is actually working.

What the agent checks

Around 88 controls today, across the three operating systems.

🔒

Disk & Boot

FileVault / BitLocker encryption, Gatekeeper, Secure Boot, firmware password.

🛡️

Network Exposure

Firewall state, file, printer, screen, internet and Bluetooth sharing left on, RDP without NLA.

⬆️

Patch Level

OS supported and up to date, Chrome / Edge / Firefox current, known-CVE versions flagged.

🦠

Malware & Ransomware

Known malicious apps and files, ransomware protection state, antivirus present and running.

🔑

Credentials on Disk

Cleartext cloud credentials sitting in home directories, password-manager version and setup.

📋

Inventories

Browser extensions, launch daemons, kernel extensions, scheduled tasks, services and startup items.

How it gets there

1

One line, one machine

The person runs a shell script (macOS, Linux) or a PowerShell one-liner (Windows), served against a per-organisation enrolment token.

2

The agent enrols

It registers with Engarde, pulls its query pack, runs it through osquery, and posts the raw rows back on a loop. It carries no rules of its own.

3

The server judges

Pass/fail evaluation, posture history and detections all live server-side — so a rule can change without touching a single laptop.

The browser counts as an endpoint

A Chrome extension inventories the other extensions your team has installed — their permissions, host scope and where they came from — and Engarde risk-scores the fleet. It is the same story as the laptop agent: the browser reports, the server rules.

Phones, through Workspace

Mobile posture — compromised or unencrypted devices — comes from Google Workspace rather than an agent, and needs the mobile-device directory scope. Until that scope is granted, the app says so instead of showing you a reassuring empty list.

See your fleet as it actually is

Install the agent on one machine and watch the first posture report land.

Request Early Access

Frequently asked questions

Is this an MDM? +

Not in the enforcement sense. Engarde does not push configuration profiles, lock or wipe machines, or take remote control. The agent collects, the server evaluates pass or fail, and the person is told what to fix. If you already run an MDM, Engarde is the independent check on whether it is doing what you think it is.

What does the agent actually run? +

It is a thin cross-platform wrapper around osquery, close in shape to Fleet’s orbit. It enrols with Engarde, pulls a query pack, runs it through osqueryi and posts the raw rows back on a loop. It holds no pass/fail logic of its own, which means a control can be changed or added without redeploying anything to a laptop.

How is it installed? +

macOS and Linux share one self-detecting shell script; Windows gets a PowerShell one-liner. Both are served against a per-organisation enrolment token, so the install command shown in the app is already scoped to your tenant.

What about phones? +

Mobile posture — compromised or unencrypted devices — is read from Google Workspace rather than an agent, and requires the mobile-device directory scope. Until that scope is granted, the app marks the behaviour as unavailable rather than showing an empty list that reads like a clean bill of health.

Is this the same Engarde as the fencing brand / law firm / arms platform? +

No. This is Engarde the SaaS security company at engarde.cc — distinct from other vendors sharing the Engarde name.