The user checked out. Is the laptop lying?
25 health-check types against 144 named rules — evaluated before access, and re-evaluated during it.
Trust the device. Then trust the user.
What is device posture checking?
Device posture
A credential says who. Posture says what from.
Device posture checking verifies the security health of a device before giving it access to applications or data — and keeps verifying it afterwards.
- It reads the signals that actually matterOS version and patch level, disk encryption, antivirus state, firewall status, screen lock, secure boot, jailbreak and root detection, and the rest of 25 check types across 1,500+ OS and device combinations.
- Checks become named rules144 of them. A rule is a check plus a threshold plus who it applies to, which is what makes a posture policy something you can hand an auditor rather than describe.
- Failing is not always all-or-nothingOnly devices that meet the bar get in. Non-compliant ones can be blocked outright or given a reduced set of applications until the problem is fixed — a policy choice, not a fixed behaviour.
- And it does not stop at the doorPosture is re-evaluated during the session. A device that drifts out of policy loses the access it already had, mid-session, without waiting for the next login.
The user checked out. Is the laptop lying?
Authentication answers whether the person is who they claim. It says nothing about the machine in their hands. A perfectly valid login from a device with disabled antivirus, an unencrypted disk and six months of missing patches is a breach that simply hasn’t finished happening yet.
Before an application becomes reachable, InstaSafe takes the device apart and reads its actual state — then does it again, continuously, for as long as the session lasts.
Every check above is a condition you can write policy against. Combine them into named rules per user group — Windows 11 with current patches, BitLocker on, and antivirus definitions under seven days old, or no connection. Fail mid-session and the response is yours to define: step-up MFA, restricted access, alert, or disconnect.
Nothing here is inferred. Each result is recorded as an event and exportable to your SIEM.
- 25+ check types
- 144 named rules
- 1,500+ OS/device combinations
- Windows · macOS · Linux
One engine. Three very different rooms.
The same twenty-five checks read the same way every time. What changes is which of them a group is held to — and that is a policy decision, not a different product.
Finance: The strictest profile in the building — and it still passes
The people who move money get every check turned on: encryption, antivirus, patch level, screen lock, and a device bound to a named person. On a company desktop that is twenty-five out of twenty-five, and nobody in the team notices it happening.
Learn more- Disk encryption
- Antivirus running
- OS patch levelcurrent
- Screen lock ≤ 5 min
- Browser & version
- Certificate present
- Geo / networkin region
- 21 checks need an agent
- Disk encryption
- Local adminwaived
- Screen lock ≤ 2 mintightened
- Production data on disk
Break the device. Watch the verdict move.
Switch off the antivirus, or the encryption, or the patch level, and see what the policy does about it — with the rule that failed named, because “denied” on its own tells an administrator nothing.
Every named rule passed. The tunnel opens, and posture keeps being re-checked while it is open.
The posture engine, as a checklist.
Tick what your evaluation actually needs and copy the shortlist straight into your ticket. Filtering hides rows; it never clears a tick.
11 specs · none selected
Signals in.Three answersout.
The same 25 checks produce one of three verdicts on every connection — and produce it again while the session is open.
Compromised devices stop at the door
Spoofing a user is hard. Spoofing a user and a compliant, certificated device is dramatically harder.
Compliance becomes continuous
Endpoint standards are enforced at every connection, not sampled once a year at audit time.
BYOD with eyes open
Personal devices meet a defined bar or get contained access — a policy choice instead of a blind spot.
//Ready when you are//
Ditch the VPN. Keep your apps invisible.
Runs alongside the VPN you have, app by app, until there is nothing left to switch off. Nothing to rack, no network to re-architect.
Regulated, air-gapped, or on-premise? See deployment options