From assumed control to evidence of what is actually running
Patched is the product I wanted when I was accountable for regulated endpoint estates. It establishes what is on the estate, what changed and whether the controls are working, and leaves the fixing to the tools you already run.
The pattern
For six years I was accountable for regulated, multi-platform endpoint estates, and the question I found hardest to answer well was the plainest one an auditor asks: what is actually installed on these devices, and how do you know? The management platform could tell me what it had been asked to deploy and whether each deployment reported success, which is a record of what was intended. It had much less to say about software that arrived some other way, about the browser extensions people had added for themselves, or about a control that was switched on once and had since drifted.
A large organisation has a team whose job is to close that gap. In most smaller ones, endpoint management is one responsibility among many for an infrastructure team, where servers, networks and identity take priority and the laptops and Macs become a side project. Every business workflow still depends on one of those devices, so the gap is the same size and there are fewer people to close it.
What I am building
Patched is endpoint assurance and software governance. It continuously inventories a Windows and macOS estate from the devices themselves, identifies risky or unexpected software and browser extensions, tracks vulnerabilities and configuration posture, and keeps the evidence you need to decide what belongs. It covers six areas, and each answer is shown with the basis for it.
- Estate visibility. Every Windows and macOS device, when it last reported and how fresh its evidence is. A device that has gone quiet is shown as unknown and is never counted as passing.
- Software risk. Every installed application and version, where it is installed and how far its identity can be trusted, with name-only matches labelled as such.
- Browser extensions. Extensions across Chrome, Edge, Firefox and Safari, with the permissions each one holds and the devices it is on.
- Vulnerabilities and CVEs. Applications and operating system builds matched against NVD and vendor advisories, with known exploitation called out. The absence of a fresh match reads as unknown, because it is.
- CIS posture. Benchmark results for the controls that matter, from firewall and disk encryption to screen lock, read from the device and not from the management platform.
- Change evidence. Each finding keeps its history, so the record already exists when an audit asks for it.
Evidence before actuation
Patched does not deploy software and does not enforce anything. It identifies a finding and explains it, and the change is carried out by whatever you already use, whether that is Intune, Jamf, a patch-management product or a ticketing platform. There is no MDM prerequisite and nothing to replace.
That was a deliberate decision and it came from running these estates. An organisation that already has a management platform gains very little from a second tool with the right to change its devices, and takes on a second thing that can break them. What it usually lacks is an independent check on whether the first tool is doing what everyone assumes it is doing. So when you fix something in your own tool, Patched confirms the closure from the device, and the report of success from the tool that made the change is no longer the only evidence that it happened.
Built on the Isle of Man
Patched is built and run from the Isle of Man, where the economy runs on regulated firms in financial services, fiduciaries, insurance and e-gaming, all of them answerable to auditors and regulators who expect evidence. That is the standard I am building to, and those firms are the community Patched serves first. It is incorporated here as Patched.im Ltd.
Where it is now
Windows and macOS are available today, Windows Server is in development and Linux is on the roadmap. Patched is not on general sale yet and there is no price list, because publishing a price for something a handful of people are still shaping would be guessing at it in public.
I am taking on a small number of design partners first. The arrangement is early access and a direct line to me in exchange for running it against devices you actually care about, and telling me when a finding is wrong, a report is unreadable or something is not worth paying for.
If you run a mixed Windows and macOS estate and want it evidenced from the endpoint, the design partner page sets out the arrangement.
Become a design partner