Device posture

The user checked out. Is the laptop lying?

25 health-check types against 144 named rules — evaluated before access, and re-evaluated during it.

25Health-check types
144Named rules
Some health-check types
OS & patchingAntivirusFirewallDisk encryptionSecure bootScreen lockUSB storageDeveloper toolsOS versionNetwork profileVirtual machineAnd 15 more

Trust the device. Then trust the user.

  • Tata
  • Siemens
  • HDB Financial Services
  • Aditya Birla Group
  • Asian Paints
  • Mphasis
  • Landmark Group
  • NHPC
  • Pidilite
  • Axis Max Life
  • Haldiram's
  • Allcargo Logistics
  • Mirae Asset Sharekhan
  • Jana Small Finance Bank
  • DTDC
  • Bajaj General Insurance
  • Samsonite
  • Cafe Coffee Day

What is device posture checking?

Device posture

A credential says who. Posture says what from.

Device posture checking verifies the security health of a device before giving it access to applications or data — and keeps verifying it afterwards.

  • It reads the signals that actually matterOS version and patch level, disk encryption, antivirus state, firewall status, screen lock, secure boot, jailbreak and root detection, and the rest of 25 check types across 1,500+ OS and device combinations.
  • Checks become named rules144 of them. A rule is a check plus a threshold plus who it applies to, which is what makes a posture policy something you can hand an auditor rather than describe.
  • Failing is not always all-or-nothingOnly devices that meet the bar get in. Non-compliant ones can be blocked outright or given a reduced set of applications until the problem is fixed — a policy choice, not a fixed behaviour.
  • And it does not stop at the doorPosture is re-evaluated during the session. A device that drifts out of policy loses the access it already had, mid-session, without waiting for the next login.
The user's devicePosture check6 of 7 passedOS up to datepassSecurity patchespassDisk encryptionpassAntivirus activepassFirewall onpassRoot / jailbreakfailScreen lock setpassAccess grantedCorporateapplicationsAccess blockedRestrictedaccess until fixedEvaluated in real time, and again during the session.A device that drifts out of policy loses the access it already had.
25health-check types
144named rules
1,500+OS combinations
Device posture check

The user checked out. Is the laptop lying?

Authentication answers whether the person is who they claim. It says nothing about the machine in their hands. A perfectly valid login from a device with disabled antivirus, an unencrypted disk and six months of missing patches is a breach that simply hasn’t finished happening yet.

Before an application becomes reachable, InstaSafe takes the device apart and reads its actual state — then does it again, continuously, for as long as the session lasts.

SESSION & IDENTITYBrowserID · TenantIdMALWARE PROTECTIONAntivirus · AntiVirusStatusAntiVirusLastUpdate · SEPLastAVUpdateAntiSpyWare · AntiSpywareStatusOPERATING SYSTEMOS · OSName · OSVersion · ServicePack · HotfixRUNNING PROCESSESProcessRunning · ProcessNotRunningDISK ENCRYPTIONBitLockerDOMAIN & MANAGEMENTInDomain · DomainName · mdmNETWORK PROTECTIONFirewall · FirewallStatusFILES & REGISTRYFileExists · FileNotExists · RegistryKeyExistsDEVICE POSTURE CHECKEVALUATED AT CONNECTION + CONTINUOUSPOSTURE VERIFIEDDEVICE TRUST★ COMPLIANT ★

Every check above is a condition you can write policy against. Combine them into named rules per user group — Windows 11 with current patches, BitLocker on, and antivirus definitions under seven days old, or no connection. Fail mid-session and the response is yours to define: step-up MFA, restricted access, alert, or disconnect.

Nothing here is inferred. Each result is recorded as an event and exportable to your SIEM.

  • 25+ check types
  • 144 named rules
  • 1,500+ OS/device combinations
  • Windows · macOS · Linux
How it's used

One engine. Three very different rooms.

The same twenty-five checks read the same way every time. What changes is which of them a group is held to — and that is a policy decision, not a different product.

Finance: The strictest profile in the building — and it still passes

The people who move money get every check turned on: encryption, antivirus, patch level, screen lock, and a device bound to a named person. On a company desktop that is twenty-five out of twenty-five, and nobody in the team notices it happening.

Learn more
Managed desktop · on-site
Posture · 25 of 25
  • Disk encryption
  • Antivirus running
  • OS patch levelcurrent
  • Screen lock ≤ 5 min
+ 21 more, all passing
Allow — pay run approvalFull access · the hardest profile, survived
Signature interactive

Break the device. Watch the verdict move.

Switch off the antivirus, or the encryption, or the patch level, and see what the policy does about it — with the rule that failed named, because “denied” on its own tells an administrator nothing.

Toggle the device's state
100/100
Access granted

Every named rule passed. The tunnel opens, and posture keeps being re-checked while it is open.

Failing rulesnone — 6 of 6 passed
Quick scan

The posture engine, as a checklist.

Tick what your evaluation actually needs and copy the shortlist straight into your ticket. Filtering hides rows; it never clears a tick.

11 specs · none selected

DEVICE SIGNALSOS & SystemSignalSecuritySignalNetworkSignalApplicationsSignalIdentitySignalREAL-TIME DEVICE ASSESSMENTCorporate LaptopWindows 11 ProHEALTHYOS VersionUp to dateSecurity PatchesUp to dateEndpoint ProtectionActiveDisk EncryptionEnabledFirewallEnabledTPMEnabledSecure BootEnabledDevice CertificateValidPOSTURE SCORE100 / 100GrantedFull accessAWSSlackSAPInternal appsRestrictedLimited / containedSalesforceFilesBlockedNo accessJenkinsSensitive data
Posture outcomes

Signals in.Three answersout.

The same 25 checks produce one of three verdicts on every connection — and produce it again while the session is open.

Compromised devices stop at the door

Spoofing a user is hard. Spoofing a user and a compliant, certificated device is dramatically harder.

Compliance becomes continuous

Endpoint standards are enforced at every connection, not sampled once a year at audit time.

BYOD with eyes open

Personal devices meet a defined bar or get contained access — a policy choice instead of a blind spot.

FAQ

Posture checks, answered.

Tap a question — or open them all and read straight through.

Talk to us

//Ready when you are//

Ditch the VPN. Keep your apps invisible.

Runs alongside the VPN you have, app by app, until there is nothing left to switch off. Nothing to rack, no network to re-architect.

Regulated, air-gapped, or on-premise? See deployment options