← All products

Fleet visibility

Asset Monitoring

Available now

Every enrolled device, its certificate, its posture, and what it reported — collected over a post-quantum secure channel and shown in one console.

Shipping today. Ask for access and we will get you a build.

What it does

Device inventory

Hardware model, OS version, app version and build, assigned role, first seen, and enrolment date for every device in the estate.

Certificate posture

Fingerprint, pinning state, and validity window per device — so a certificate approaching expiry or missing its pin surfaces as a row in a console rather than as an outage.

Tamper reports

Devices report tamper conditions back to the hub, and they land in the same place as everything else instead of in a log nobody opens.

Audit log and client errors

What happened, on which device, at what time — including the errors clients hit in the field, which is usually where a problem shows up first.

Collected over a secure channel

The snapshot is pulled through the post-quantum TLS channel, so the monitoring path is not the weakest link in the system it monitors.

Request a Console Walkthrough

What the console shows

One snapshot, refreshed on demand.

Identity
Model, OS, role, UUID
Enrollment
Status and date
Certificate
Fingerprint, pin, validity
Tamper
Reported conditions
Activity
Audit log, client errors
Transport
PQC TLS secure channel

How it goes in

Each step is a checkpoint you sign off before the next begins.

  1. 01

    Enrol

    Devices enrol against your authority, which is what gives each one the identity the console reports against.

  2. 02

    Collect

    The hub pulls a fleet snapshot over the secure channel — inventory, certificate state, tamper reports, and audit records.

  3. 03

    Review

    Work the console: expiring certificates, unpinned devices, tamper conditions, and clients erroring in the field.

  4. 04

    Act

    Rotate, re-enrol, or revoke from the same authority that issued the identity in the first place.