Patch Management

Patch Management

OS and third-party patches are tested through a staging ring, scheduled around your business hours, and rolled out fleet-wide - without you having to approve a single update yourself.

Starting at $3.50/endpoint/monthview full pricing →

24-48 hrsTypical patch window from release
99.9%Patch compliance, not best-effort
0Patches you have to manually approve
What's covered

Every patch, every platform, one schedule

Patch management is the single most consequential thing running on a fleet, and the easiest thing to let slide. We run it as a standing operation, not a monthly fire drill.

Operating systems

Windows, macOS, and Linux all patch on a single coordinated schedule, so you're never chasing three separate update cadences across your fleet.

  • Windows cumulative and feature updates
  • macOS security and system updates
  • Linux distribution and kernel patches

Third-party applications

The applications attackers actually target - browsers, PDF readers, collaboration tools - are patched on the same cycle as the OS, not left to whatever auto-update the vendor shipped.

  • Browser and plugin updates
  • Common productivity and collaboration software
  • Detection of end-of-life software still in use
How it's tested

Nothing reaches your whole fleet untested

Patches fail. The question is whether that failure happens on two test machines or two hundred production laptops.

Staged rollout rings

Every patch lands on a small canary ring first, then a broader pilot group, before it's cleared for the rest of the fleet - each stage watched for failed installs or device instability.

  • Canary ring: a handful of low-risk devices
  • Pilot ring: a representative cross-section of the fleet
  • General release: the remaining fleet, once both stages are clean

Rollback on regression

If a patch causes a measurable spike in crashes, failed logins, or device instability, the rollout pauses and the offending patch can be pulled the same day.

  • Automatic rollout pause on regression
  • Same-day rollback capability
  • Root-cause review before re-attempting
How we operate this

Fully managed means we run it, not you

This isn't software we hand you a login for. Our operations team runs patch management as a standing service against your fleet.

01

Baseline the fleet

We inventory current patch levels across every device and flag what's already overdue before writing a single policy.

02

Set the cadence

Patch windows are scheduled around your actual business hours and blackout periods - not a generic default.

03

Run the rings

Canary, pilot, then general release, with our team watching each stage rather than a dashboard no one checks.

04

Report monthly

You get a standing compliance report - patch levels, exceptions, and any devices that fell out of the cycle.

Common questions

About Patch Management

What happens to devices that are offline during a patch window?

They pick up the pending patch automatically at next check-in and are flagged in the compliance report as delayed, not dropped.

Can we exclude specific devices from automatic patching?

Yes - servers, kiosks, or specialized machines can be scoped out and handled on a manual or extended-review cycle.

Related modules

Explore more of the platform

Get started

See patch management running on your own fleet.

We'll run a free audit and show you exactly what this looks like on your devices before you commit to anything.

Get started → Calculate your cost →