SOC 2 Type II · ISO 27001 · 1,400 security teams
SOC 2 Type II · ISO 27001 · 1,400 security teams
Palisade
Palisade
Risk score82/100open
Next page/
Home
Endpoint · Devices
Every laptop and phone, patched and locked.
Laptops, phones and servers that have fallen behind.
WatchedmacOS and Windows laptopsWatchedLinux serversWatchediOS and Android phonesWhat it closes.
0 of 4 closed
01Open
Patch status
Days since each critical fix was released, per device, with the owner's name beside it.
02Open
Disk and lock
Encryption, screen lock and firewall state read from your device manager, not from a survey.
03Open
Unknown devices
Machines that sign in to company apps but are in no inventory.
04Open
Nudges that work
The owner gets the exact step in Slack; the finding closes when the device reports back.
A light agent and your device manager tell Palisade which machines are unpatched, unencrypted or missing a screen lock. Each device is tied to its owner, so the finding goes to a person and not to a queue.
What it closes
- Critical patches waiting to install
- Disks without encryption
- Phones reading company mail without a passcode
What you get in week one
- Every device that signs in, managed or not
- Days-behind on critical patches, per owner
- Laptops without disk encryption
How it connects
Through Jamf or Intune where you have them, and a 38 MB agent where you do not. The agent reads state; it does not read files.
Endpoint · Devices
Every laptop and phone, patched and locked.
Laptops, phones and servers that have fallen behind.

What it closes.
0 of 4 closed
01Open
Patch status
Days since each critical fix was released, per device, with the owner's name beside it.
02Open
Disk and lock
Encryption, screen lock and firewall state read from your device manager, not from a survey.
03Open
Unknown devices
Machines that sign in to company apps but are in no inventory.
04Open
Nudges that work
The owner gets the exact step in Slack; the finding closes when the device reports back.
A light agent and your device manager tell Palisade which machines are unpatched, unencrypted or missing a screen lock. Each device is tied to its owner, so the finding goes to a person and not to a queue.
What it closes
- Critical patches waiting to install
- Disks without encryption
- Phones reading company mail without a passcode
What you get in week one
- Every device that signs in, managed or not
- Days-behind on critical patches, per owner
- Laptops without disk encryption
How it connects
Through Jamf or Intune where you have them, and a 38 MB agent where you do not. The agent reads state; it does not read files.
Endpoint · Devices
Every laptop and phone, patched and locked.
Laptops, phones and servers that have fallen behind.
WatchedmacOS and Windows laptopsWatchedLinux serversWatchediOS and Android phonesWhat it closes.
0 of 4 closed
01Open
Patch status
Days since each critical fix was released, per device, with the owner's name beside it.
02Open
Disk and lock
Encryption, screen lock and firewall state read from your device manager, not from a survey.
03Open
Unknown devices
Machines that sign in to company apps but are in no inventory.
04Open
Nudges that work
The owner gets the exact step in Slack; the finding closes when the device reports back.
A light agent and your device manager tell Palisade which machines are unpatched, unencrypted or missing a screen lock. Each device is tied to its owner, so the finding goes to a person and not to a queue.
What it closes
- Critical patches waiting to install
- Disks without encryption
- Phones reading company mail without a passcode
What you get in week one
- Every device that signs in, managed or not
- Days-behind on critical patches, per owner
- Laptops without disk encryption
How it connects
Through Jamf or Intune where you have them, and a 38 MB agent where you do not. The agent reads state; it does not read files.
Sources
Connects to what you already run.
Read-only access, no agents to roll out for the first findings. Most teams connect their identity provider and one cloud account in the first hour.
0 / 12 connected· Read-only by default · no credentials stored
- IdentityOktaUsers, groups, admin roles and sign-in policyNot connected
- IdentityEntra IDDirectory roles, conditional access and guestsNot connected
- IdentityGoogle WorkspaceAccounts, super admins and third-party app grantsNot connected
- CloudAWSAccounts, IAM roles, storage and network rulesNot connected
- CloudAzureSubscriptions, role assignments and exposed servicesNot connected
- CloudGoogle CloudProjects, service accounts and public resourcesNot connected
- CodeGitHubSecret scanning on every push and pull requestNot connected
- CodeGitLabPipelines, tokens and repository visibilityNot connected
- DevicesJamfPatch level, encryption and screen lock on Apple devicesNot connected
- DevicesIntuneCompliance state for Windows and mobile devicesNot connected
- AlertsSlackFindings sent to the owner, fixes confirmed in threadNot connected
- TicketsJiraIssues opened with the fix and closed when it landsNot connected
Sources
Connects to what you already run.
Read-only access, no agents to roll out for the first findings. Most teams connect their identity provider and one cloud account in the first hour.
0 / 12 connected· Read-only by default · no credentials stored
- IdentityOktaUsers, groups, admin roles and sign-in policyNot connected
- IdentityEntra IDDirectory roles, conditional access and guestsNot connected
- IdentityGoogle WorkspaceAccounts, super admins and third-party app grantsNot connected
- CloudAWSAccounts, IAM roles, storage and network rulesNot connected
- CloudAzureSubscriptions, role assignments and exposed servicesNot connected
- CloudGoogle CloudProjects, service accounts and public resourcesNot connected
- CodeGitHubSecret scanning on every push and pull requestNot connected
- CodeGitLabPipelines, tokens and repository visibilityNot connected
- DevicesJamfPatch level, encryption and screen lock on Apple devicesNot connected
- DevicesIntuneCompliance state for Windows and mobile devicesNot connected
- AlertsSlackFindings sent to the owner, fixes confirmed in threadNot connected
- TicketsJiraIssues opened with the fix and closed when it landsNot connected
Sources
Connects to what you already run.
Read-only access, no agents to roll out for the first findings. Most teams connect their identity provider and one cloud account in the first hour.
0 / 12 connected· Read-only by default · no credentials stored
- IdentityOktaUsers, groups, admin roles and sign-in policyNot connected
- IdentityEntra IDDirectory roles, conditional access and guestsNot connected
- IdentityGoogle WorkspaceAccounts, super admins and third-party app grantsNot connected
- CloudAWSAccounts, IAM roles, storage and network rulesNot connected
- CloudAzureSubscriptions, role assignments and exposed servicesNot connected
- CloudGoogle CloudProjects, service accounts and public resourcesNot connected
- CodeGitHubSecret scanning on every push and pull requestNot connected
- CodeGitLabPipelines, tokens and repository visibilityNot connected
- DevicesJamfPatch level, encryption and screen lock on Apple devicesNot connected
- DevicesIntuneCompliance state for Windows and mobile devicesNot connected
- AlertsSlackFindings sent to the owner, fixes confirmed in threadNot connected
- TicketsJiraIssues opened with the fix and closed when it landsNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected
