Fleet visibility
Asset Monitoring
Available now
Every enrolled device, its certificate, its posture, and what it reported — collected over a post-quantum secure channel and shown in one console.
Shipping today. Ask for access and we will get you a build.
What it does
Device inventory
Hardware model, OS version, app version and build, assigned role, first seen, and enrolment date for every device in the estate.
Certificate posture
Fingerprint, pinning state, and validity window per device — so a certificate approaching expiry or missing its pin surfaces as a row in a console rather than as an outage.
Tamper reports
Devices report tamper conditions back to the hub, and they land in the same place as everything else instead of in a log nobody opens.
Audit log and client errors
What happened, on which device, at what time — including the errors clients hit in the field, which is usually where a problem shows up first.
Collected over a secure channel
The snapshot is pulled through the post-quantum TLS channel, so the monitoring path is not the weakest link in the system it monitors.
What the console shows
One snapshot, refreshed on demand.
- Identity
- Model, OS, role, UUID
- Enrollment
- Status and date
- Certificate
- Fingerprint, pin, validity
- Tamper
- Reported conditions
- Activity
- Audit log, client errors
- Transport
- PQC TLS secure channel
How it goes in
Each step is a checkpoint you sign off before the next begins.
- 01
Enrol
Devices enrol against your authority, which is what gives each one the identity the console reports against.
- 02
Collect
The hub pulls a fleet snapshot over the secure channel — inventory, certificate state, tamper reports, and audit records.
- 03
Review
Work the console: expiring certificates, unpinned devices, tamper conditions, and clients erroring in the field.
- 04
Act
Rotate, re-enrol, or revoke from the same authority that issued the identity in the first place.
Works alongside
Nothing here needs the rest of the line to be useful — but they are built to fit together.
- Phishing-Resistant AuthenticationThe enrolment and pinning this console reports the health of.Learn more
- Enterprise CA SuiteHandles the revocation side when a monitored device should no longer be trusted.Learn more
- Threat DetectionExtends this signal set with behavioural baselines across AI pipelines.Learn more