Devices are the part of a company that walks around. An encrypted laptop left in a taxi is a lost object. An unencrypted one is a disclosure, and the distance between the two is a single setting. Reading that setting takes a device management integration, and ours is still being built.
One setting decides which, and it is usually set once at purchase and never checked again. We look at disk encryption and name the machines where it was never switched on, and at screen lock and the devices sitting without one.
A fleet is only as accurate as its inventory, and the risky device is the one missing from it. We find devices in daily use that are not enrolled in management at all, devices that are rooted or jailbroken, and devices that stopped checking in and how long ago they went quiet.
Enrolment is not hardening. We read the operating system patch level and how far behind a machine has fallen, and the browser configuration, including the extensions that can be installed and the settings a person is free to override.
A finding will name the device, not just the policy it breaks.
Every change is prepared for you, made only once you approve it, logged, and reversible where the platform allows. How that works
Endpoint coverage needs a device management integration, and that one is in development. Some mobile device and Chrome browser policy is already visible through Google Workspace; the rest of this page arrives with the integration.