Every feature exists because a real SMB asked "how do I prove this to my insurer?" or "what does my auditor need to see?" — not because a roadmap spreadsheet said so.
Deploy patches to a pilot ring first. Watch for regressions. Auto-ramp to production when the success threshold is met — or hold with a single click.
Continuous matching of your installed package inventory against NVD, CISA KEV, and CVSS v3 scores — with SLA tracking so nothing silently ages out.
Map your patch and posture data to ISO 27001, Cyber Essentials Plus, NIS2, SOC 2, PCI DSS, and HIPAA. Export PDF or SIEM-ready evidence in one click.
Recovery keys are encrypted at the application layer with AES-256-GCM before they touch the database — so a DB dump alone reveals nothing.
Manage all your client organisations from a single login. Hard data isolation between tenants — GDPR and DPA evidence is per-org, not shared.
Every administrative action — patch approval, key reveal, role change, data export — is written to an immutable audit log with a UNION-ALL timeline view.
PatchPilot's SYSTEM-level agent runs even on locked and headless machines — no user session required. Paid tiers unlock remote PowerShell and Bash execution, just like Intune Remediation Scripts but without needing a Microsoft licence.
Co-management mode: PatchPilot reads device state from Intune via Microsoft Graph and writes compliance signals back — so your existing Intune policies keep working.
These features are in active development. View the full roadmap →
Full patch management and compliance for Apple devices — Homebrew, softwareupdate, FileVault posture. Windows + Linux ship at v1.
Mobile estate inventory and basic policy enforcement for personally-owned devices. MDM management module builds on this in Q2 2027.
Full SNMP polling for switches and routers — live port utilisation, bandwidth, uptime, SNMP traps. Network discovery and topology graph ship at v1.
Exchange, SharePoint, and OneDrive backup to BYO storage — point-in-time restore and retention reporting. File/folder backup to BYO ships at v1.
LLM-generated risk summaries for each patch — severity, business impact, rollback risk. Competes NinjaOne AI and Atera Action AI.
End-users self-serve: submit tickets, view their device's patch status, request software, see audit data about their own laptop. White-labellable per MSP.
Per-client password vault, knowledge base, network diagrams, and runbooks. Competes IT Glue and Hudu.
Volume-level continuous backup with bare-metal restore to BYO storage. File/folder backup to BYO ships at v1. Competes Datto, Veeam, Acronis.
Phones + tablets, device-level enrolment and MDM commands. Builds on Q3 2026 iOS/Android agent. Competes Jamf Now lite, Intune lite.
Join the early access programme — or start free with 25 devices, no card required.