An osquery agent on macOS, Windows and Linux reports what a machine actually looks like — disk encryption, firewall, screen lock, what is installed and what is running. Every rule is judged on our servers, never on the device.
This is not classic MDM. We do not push configuration profiles, we do not lock or wipe machines, and we do not take remote control. The agent collects; the server decides pass or fail; the person gets told what to fix. If you need enforcement, keep your MDM — Engarde tells you whether it is actually working.
Around 88 controls today, across the three operating systems.
FileVault / BitLocker encryption, Gatekeeper, Secure Boot, firmware password.
Firewall state, file, printer, screen, internet and Bluetooth sharing left on, RDP without NLA.
OS supported and up to date, Chrome / Edge / Firefox current, known-CVE versions flagged.
Known malicious apps and files, ransomware protection state, antivirus present and running.
Cleartext cloud credentials sitting in home directories, password-manager version and setup.
Browser extensions, launch daemons, kernel extensions, scheduled tasks, services and startup items.
The person runs a shell script (macOS, Linux) or a PowerShell one-liner (Windows), served against a per-organisation enrolment token.
It registers with Engarde, pulls its query pack, runs it through osquery, and posts the raw rows back on a loop. It carries no rules of its own.
Pass/fail evaluation, posture history and detections all live server-side — so a rule can change without touching a single laptop.
A Chrome extension inventories the other extensions your team has installed — their permissions, host scope and where they came from — and Engarde risk-scores the fleet. It is the same story as the laptop agent: the browser reports, the server rules.
Mobile posture — compromised or unencrypted devices — comes from Google Workspace rather than an agent, and needs the mobile-device directory scope. Until that scope is granted, the app says so instead of showing you a reassuring empty list.
Install the agent on one machine and watch the first posture report land.
Request Early AccessNot in the enforcement sense. Engarde does not push configuration profiles, lock or wipe machines, or take remote control. The agent collects, the server evaluates pass or fail, and the person is told what to fix. If you already run an MDM, Engarde is the independent check on whether it is doing what you think it is.
It is a thin cross-platform wrapper around osquery, close in shape to Fleet’s orbit. It enrols with Engarde, pulls a query pack, runs it through osqueryi and posts the raw rows back on a loop. It holds no pass/fail logic of its own, which means a control can be changed or added without redeploying anything to a laptop.
macOS and Linux share one self-detecting shell script; Windows gets a PowerShell one-liner. Both are served against a per-organisation enrolment token, so the install command shown in the app is already scoped to your tenant.
Mobile posture — compromised or unencrypted devices — is read from Google Workspace rather than an agent, and requires the mobile-device directory scope. Until that scope is granted, the app marks the behaviour as unavailable rather than showing an empty list that reads like a clean bill of health.
No. This is Engarde the SaaS security company at engarde.cc — distinct from other vendors sharing the Engarde name.