Endpoint Security

    Fleet-wide patching, approved and tracked

    One global queue answers two questions: which patches are approved to install anywhere, and how compliant your fleet is against the patches that exist. Approve once, push to every agent instantly.

    Try Demo
    Approval workflow

    Approve once, roll out everywhere

    A single global queue governs every patch, with bulk actions and instant propagation to your agents.

    Pending

    Newly discovered patches awaiting a decision.

    Approved

    Cleared to install on every targeted device.

    Rejected

    Held back and never offered to agents.

    Deferred

    Postponed — automatically returns to Pending once the defer window elapses.

    Bulk actions

    Approve, reject, defer, or reset to pending across one or many selected patches at once.

    Global by design

    Approval is fleet-wide; per-policy filtering and deployment rings narrow the rollout to a subset of devices.

    Compliance model

    Know your patch posture at a glance

    Each patch shows install progress and a severity-driven SLA status, so risk is never hidden.

    Each patch row reports how many devices have it Installed versus still Pending, and an SLA status of Compliant, At Risk, or Overdue.
    Critical7 days to compliant

    Tightest window — critical patches must land fast.

    High15 days to compliant

    High-severity patches with a short grace period.

    Moderate30 days to compliant

    Moderate-severity patches on a monthly cadence.

    Other60 days to compliant

    Everything else, on the most relaxed window.

    Visibility & intelligence

    More than an approval queue

    Patch Management also proves what happened after rollout and shows where your fleet is still exposed.

    Full update history

    Every update install is recorded — successes and failures alike — so you can prove what landed, when, and on which devices, and quickly find the ones that need another look.

    Coming soon

    CVE cross-reference, on the roadmap

    A planned Vulnerabilities view will load known CVEs from the National Vulnerability Database and cross-reference them against your device inventory, so you can see exactly which managed devices are exposed. This capability is on the NetLock RMM roadmap and is not yet available.

    Platforms & sources

    Every platform, one queue

    OS and package updates from every major platform are managed in the same approval queue.

    WindowsLinuxDocker

    OS-Mandatory

    Operating-system updates Windows marks as required.

    Winget

    Application updates from the Windows Package Manager.

    Chocolatey

    Application updates from the Chocolatey repository.

    Apt

    Package updates on Debian and Ubuntu families.

    Dnf

    Package updates on Fedora and RHEL families.

    Yum

    Package updates on older RHEL-family systems.

    Docker

    Container image updates managed in the same queue.

    What lives here — and what lives in a policy

    Patch Management is the global decision layer. Rollout mechanics belong to each policy.

    On the Patch Management page

    • Global approve / reject / defer decisions
    • Fleet-wide compliance and SLA status
    • Deployment-wide SLA thresholds and settings

    In a policy's Patch Management tab

    • Approval filtering and deployment rings
    • Install scheduling and reboot behaviour
    • Per-policy retry handling

    Stay patched, stay compliant

    Approve patches once and watch your compliance posture across the whole fleet.

    View Pricing