Coverage that fits how your organisation works.
Whole sites, devices that travel and cloud workloads each have their own route in. If one route is not possible for you, that is the start of a conversation rather than the end of one. You can run all three at once, and switching between them later is not a one-way door.
Whichever you pick, the collection boundary is the same: which services were reached, how often, and from where. Never what was sent to them. The full boundary is on the security page.
Three ways in.
All three are agentless by default, with no software or agent to install, and you can mix them freely across the estate.
Cover a whole site
One change by your network team, and every device on that site is covered without touching any of them. Each site is set up and registered separately.
- WHO DOES IT
- One person, a few minutes
- ON THE DEVICES
- No software or agent to install, no change window
- TO UNDO
- Reverse the one change. Nothing left behind
- BEST WHEN
- You want whole-network coverage immediately
Cover devices wherever they are
Set up once per laptop, or pushed through your own device management. Nothing changes on your network, and a pilot on a handful of devices is a normal way to start.
- WHO DOES IT
- Per device, or through your own device management
- ON THE NETWORK
- Nothing changes
- TO UNDO
- Remove the setup from the device. Nothing left behind
- BEST WHEN
- The network team will not move, or your people are remote
Use the logs your cloud platform already keeps
Your cloud or security platform already records which services your workloads reach. You grant read-only access to that record and nothing else, and revoke it from your own console whenever you like. Nothing changes in your network or your account.
- WHO DOES IT
- Your cloud administrator, one read-only permission
- WHAT WE HOLD
- Read-only access you can withdraw. Never an administrator password
- TO UNDO
- Revoke the permission. Instant, no ticket to us
- BEST WHEN
- The concern is cloud workloads rather than laptops
The cloud route is available today for a limited set of platforms — ask us which ones. We would rather you knew that before you relied on it, so we are telling you here.
The laptop that leaves the building.
Office, home, a café: a laptop that moves between networks stays covered, with no software or agent to install.
| EACH DEVICE, SET UP ONCE | |
|---|---|
| Anything to install | No software or agent |
| When it moves | Coverage travels with the device to every network it joins afterwards |
| Rollout | Per device, or pushed through the device management you already run |
| Limits | Some platforms can only be covered in part. Which ones, and what that means for your fleet, we tell you before you start |
Mix this freely with the site and cloud routes across a fleet. There is no need to standardise on one, and moving a device between approaches later is a small change rather than a project.
What none of the three can do.
Stated here rather than discovered in week three of a trial.
- An unmanaged personal device on a mobile connection. Nobody's network-based discovery sees that, and a vendor claiming otherwise is describing something else.
- Every platform in full. Some operating systems allow only partial coverage. That is a platform gap rather than a product decision, and we name the affected platforms before you start.
- What was sent to any service. No content, no payloads, no documents, no keystrokes, no screens. The finding is that a service was reached, never what was said to it.
- Purpose, until a person tells us. Discovery establishes that something is in use. What it is for, and whether it touches personal or customer data, comes from the accountable owner.
Two things worth knowing before your security review.
An observation point, not a control point
Nothing is redirected, blocked or altered, and every connection still goes where it always did. Only the sites, devices and platforms you register are accepted; anything else is refused outright.
No new kind of access
Your network and security providers already handle exactly this category of information: which services were reached, not what was said to them. What changes is who holds it and what they do with it.
Scope is yours to set
Coverage extends only to the networks and devices you choose to include. Nothing obliges whole-organisation coverage on day one, and teams can be excluded. A single site or team is a normal way to start.
Start with whichever your IT team will say yes to today.
None of the three is a one-way door, and you can widen coverage later or never. The thirty-day trial works on any of them.