Available Now

Patch Management.
Vulnerability Detection.
Compliance Automation.

TridentStack Control

One platform for OS updates across Windows, macOS, and Linux, plus application patches, CVE scanning, and security compliance. One agent, one price, every feature included.

200 endpoints free forever. No credit card required.
Compliance
CIS, DISA STIG, Microsoft
Comprehensive
Application Catalog
Real-Time
Vulnerability Detection
Lightweight
Minimal resource footprint

Patch. Detect. Comply. Control.

OS updates, application patches, vulnerability scanning, and compliance tracking in one platform.

Patch Management

Unified update management with intelligent applicability filtering, approval workflows, and phased deployments.

  • Intelligent applicability filtering per endpoint
  • Supersedence tracking and automatic cleanup
  • Deployment rings for phased rollouts
  • Pre-staging for scheduled deployments
  • CVE enrichment and security metadata
System Updates
3 pending
KB
Status
KB5044284
Cumulative Update for Windows 11 23H2
Pending
KB5044285
Security Update for .NET Framework 4.8
Pending
KB5041587
Cumulative Update for Server 2022
Pending
KB890830
Malicious Software Removal Tool
Installed

3rd Party Application Updates

Unified management of third-party applications with package manager integration, version targeting, and custom packages for your own installers.

  • Comprehensive application catalog
  • Custom packages: deploy your own installers, security-scanned on upload
  • Silent deployment with progress tracking
  • Version targeting and pinning
  • Configuration profiles per endpoint group
  • Application inventory and compliance
Application Updates
8 Enabled
Application
Status
Google Chrome
Google Chrome121.0.6167
Mozilla Firefox
Mozilla Firefox122.0
7-Zip
7-Zip24.09
Adobe Reader
Adobe Reader24.001

Vulnerability Detection

Automatic CVE detection across your fleet with severity-based prioritization and compliance tracking.

  • Automatic CVE detection across your fleet
  • CVSS scoring and severity prioritization
  • CIS and DISA-STIG compliance frameworks
  • Exception management with expiration
  • Fleet-wide vulnerability dashboard
Look up any CVE in our free CVE & CISA-KEV catalog
Vulnerabilities2 KEV
Critical: 8High: 14Medium: 23Low: 12
CVE-2024-50201KEV
Critical
Adobe Reader 24.001
CVE-2024-49138KEV
High
Windows Common Log
CVE-2024-43451
High
NTLM Hash Disclosure
CVE-2024-38812
Medium
VMware vCenter

Network Exposure Monitoring

Real-time visibility into listening ports, firewall state, and network attack surface across your endpoints.

  • Listening port discovery with service identification
  • Risk assessment based on port, exposure, and process
  • Firewall state correlation per port
  • Process verification with digital signature checks
  • Port change history and timeline tracking
Network ExposureFirewall Enabled
23 listening8 exposed2 high risk12 events (24h)
Port
Firewall
Risk
3389TCP
Allow
High
445TCP
Block
Info
5985TCP
Allow
Medium
135TCP
Block
Info

Policy Management

Deploy configuration policies directly to endpoints through the agent. No domain dependency required.

  • Extensive policy settings catalog
  • Web-based configuration UI
  • Works without Active Directory
  • Policy versioning and rollback
  • Enforcement verification and compliance
Policy Objects
4 policies
Policy Name
Status
Default Security Baseline
Enabled
Workstation Hardening
Enabled
Server Configuration
Enabled
Development Endpoints
Disabled

Compliance Framework Management

Continuously evaluate your fleet against industry-standard security baselines. Track compliance scores, identify gaps, and get actionable remediation guidance.

  • CIS Benchmarks (Level 1 & Level 2)
  • DISA STIG baselines
  • Microsoft Security Baselines
  • NIST 800-53 control mapping on CIS controls
  • Automated baseline sync from authoritative sources
  • Control-level exemption management with audit trails
Compliance Overview
78%
+0%
142 Agents Evaluated
Framework
Score
CIS Windows 11 Enterprise v3.0
78%
DISA STIG Windows 11
65%
Microsoft Security Baseline
98%
CIS Ubuntu Linux 22.04 LTS
72%

Frequently asked questions

What operating systems does TridentStack Control support?

TridentStack Control supports Windows 10, Windows 11, and Windows Server 2012 R2 through Windows Server 2025 on the Windows side. The macOS agent supports macOS 14 (Sonoma) and later on both Apple Silicon and Intel Macs. The Linux agent supports Ubuntu 20.04+, Debian 12+, RHEL 8+, CentOS Stream 8+, Rocky Linux 8+, AlmaLinux 8+, Fedora, and Amazon Linux 2+, with native apt and dnf/yum integration.

Does TridentStack Control replace WSUS or Intune?

Yes. TridentStack Control replaces WSUS for native Windows update delivery and replaces Intune for patch management, vulnerability detection, compliance baselines, and policy management. It also covers Linux patching and third-party application updates in the same product, which neither WSUS nor Intune address natively.

Does TridentStack Control require Active Directory?

No. TridentStack Control was designed to deliver policy management without Active Directory. The agent can be deployed to domain-joined or workgroup endpoints, and policies are enforced through the agent regardless of directory state.

How does TridentStack Control detect vulnerabilities?

The agent reports a full software inventory including registry-installed applications, package manager state, and OS update history. TridentStack Control matches that inventory against an enriched CVE catalog with CVSS scoring, applies severity prioritization, and surfaces a fleet-wide vulnerability dashboard with exception management and expiration.

What compliance frameworks does TridentStack Control support?

TridentStack Control ships compliance baselines for CIS Benchmarks Level 1 and Level 2 across Windows, macOS, and Linux, DISA STIGs for Windows, and Microsoft Security Baselines for Windows. Each baseline produces an automated score with trend tracking and per-control evidence, and CIS controls carry NIST 800-53 control cross-references.

Can I deploy my own custom application packages?

Yes. The Package Catalog accepts your own installers: MSI and EXE on Windows, PKG and DMG on macOS, DEB and RPM on Linux. Each package holds multiple versions with their own install arguments, success exit codes, timeouts, and install detection, and every uploaded installer is security-scanned before it can be deployed. Custom packages deploy on demand to selected endpoints on all three platforms, and Windows and macOS packages can also ride the same application update policies and deployment rings as catalog applications.

How do deployment rings work in TridentStack Control?

Deployment rings allow phased rollout of approved updates. Updates progress through canary, expanding, and complete phases with configurable cohort sizes and auto-promotion criteria. Each ring has its own reboot policy, service-restart behavior, and Linux kernel-update handling so rollouts can be paced safely.

How much does TridentStack Control cost?

Every tenant gets 200 endpoints free forever. Beyond that, TridentStack Control is $5 per endpoint per month with all features included. There are no feature tiers and no enterprise sales gate. Annual billing saves about two months. Fleets of 1,000 or more endpoints get custom pricing.

Is TridentStack Control multi-tenant for MSPs?

Yes. TridentStack Control supports MSP-style multi-tenant management. Each managed customer is an isolated tenant, and MSP technicians can switch between tenants from one console.

How does TridentStack Control compare?

Honest, side-by-side comparisons against the platforms TridentStack Control replaces.

Ready to Take Control?

200 endpoints free forever. No credit card required. Deploy your first agent in under 5 minutes.