Open source · self-host it or use mine · free to start

Remote management
without the per-seat bill.

Patching, monitoring, remote access, software inventory and scripted remediation — the boring, essential half of running a fleet. Same project as the EDR, sharing one agent and one console.

Running in production One agent, six platform targets 1.15M metric samples

 rmm — what the fleet reported this week
00:15:00 scheduled task ran across the fleet — results back in the console
metrics: 1,150,570 samples collected (cpu, memory, disk, uptime, network)
inventory: 9,825 installed packages tracked across 11 machines
patching: 1,270 updates seen · 1,557 vulnerability findings matched to installed software
access: 89 remote commands executed — every one written to the audit log
status: 8 agents reporting · linux ×8 · macos ×2 · windows ×1

Two ways to run it

The RMM and the EDR are one platform. Whichever way you run it, you get both — there is no edition that holds features back.

Self-host

Your server, your fleet

One control plane, however many agents you like. Useful if you're an internal IT team who wants management tooling without a vendor relationship, or a consultant who wants to run this for your own clients rather than resell somebody else's dashboard with a markup.

  • No seat count. Ten machines or a thousand, it's the same software.
  • No phone-home. Air-gap it if you want to; nothing checks a licence server.
  • Your data stays put — inventory, metrics and command history never leave your Postgres.
Use my instance

Or just install the agent

One command on the machine, and it shows up in a console you didn't have to build. Free while it's useful to you. If it turns into a serious fleet running on my hardware, we'll have a conversation about that before it costs you anything — and you can always take your data and leave.

  • Nothing to maintain — no server, no Postgres, no certificate renewals.
  • Same console as the EDR — one login for management and security, not two products bolted together.
  • Portable by design — it's the same open stack, so moving to your own box is an export, not a migration project.

no card · no seat count · no feature gating

What the agent handles

One Go binary per machine. No runtime to install, no Python on your endpoints, no separate agent per feature.

Monitoring

Live health, not a nightly email

CPU, memory, disk, uptime and network sampled continuously — 1.15 million samples on my own fleet so far — with offline detection and a per-device health grade so you can see what needs attention without reading a dashboard full of green.

Patching

Updates, and what's rotting

Installed software is inventoried (9,825 packages across my fleet) and matched nightly against the OSV vulnerability database. Patch-aging means you can see what's been unpatched for ninety days, not just what turned red today.

Remote access

Shell, desktop, and scripts

Click-to-SSH from the console with host-key pinning on first use, scripted remediation across the fleet, and remote desktop through an embedded MeshCentral instance — someone else's excellent open-source project, not mine.

Inventory

What you actually own

Hardware and software inventory per device, so the question "what are we running and where" has an answer that isn't a spreadsheet somebody last updated in March.

Alerting

Alerts that mean something

Rule-based alerting with throttling and per-organization notification policy, pushed to ntfy, email or webhook. The throttle matters more than the rules — an alert channel nobody reads is worse than no alert channel.

Audit

Everything on the record

Every remote command, every script run, every configuration change lands in a hash-chained audit log. If someone reaches into a machine through this tool, there is a record of who and when.

Architecture

One agent, one console, one database

Management and security share the same agent and the same control plane, which is the whole reason this is worth running. The patch data feeds the vulnerability matching; the inventory feeds the detections; the audit log covers both. Most stacks make you buy those separately and then integrate them yourself.

  • Control plane — FastAPI over Postgres, 41 tables, multi-tenant with per-organization scoping and role-based access.
  • Agent — one Go binary, six platform targets, enrolled with a signed token. No agent-side secret travels on the wire.
  • Optional offload node — the same second box the EDR uses for binary scanning and detonation. Not required for pure RMM use.
Server
Python / FastAPI · Postgres · runs comfortably on one small VPS
Agent
Go · Linux, macOS, Windows · static binary, no dependencies
Desktop
MeshCentral, embedded rather than reimplemented
Alerting
ntfy, email or webhook, with per-org policy and throttling

Where it actually is

The parts I'd trust on your fleet tomorrow, and the parts I wouldn't.

Monitoring & inventory Working 1,150,570 metric samples and 9,825 inventoried packages across a live fleet. This is the most exercised part of the platform.
Patching & vulnerabilities Working 1,270 updates tracked, 1,557 findings matched against OSV. Reporting is solid; automated patch deployment is deliberately conservative and still mostly a human decision.
Remote access Working 89 commands executed through the console, click-to-SSH with host-key pinning, and MeshCentral for desktop. Used daily.
Windows installer Known bug The branded installer reports success even when enrolment fails, so a machine can look deployed and never appear in the console. Install tokens are also single-use per download. Both are on the fix list and both are exactly the sort of thing that makes an open-source deployment miserable.
Database migrations Missing There is no migration framework — schema changes have been manual because I've been the only operator. That is fine for one person and completely unacceptable for a project other people upgrade. It's a prerequisite for the public repo.
Packaging for strangers In progress The deployment still assumes my infrastructure in places. Untangling that into something you can stand up from a clean VPS is the current work, and it's the honest blocker on the repo going public.
Endpoint security See the EDR page Detection works and has real production time; real-time blocking is built but not armed. The full status is written out there.
Third-party audit None No SOC 2, no external penetration test. Self-reviewed and self-hardened, which is not the same thing.

Numbers queried from the live platform on 30 August 2026.

The model

Built for my own fleet

Written to manage my own machines properly, then open-sourced. It's the same codebase I run everything on.

If you want it on your own hardware and you'd like a hand — deployment, integration with the identity and mail you already have, alert tuning, or just someone to call — that's the part I charge for.

Open
The source, the hosted instance while it's useful to you, and a straight answer
Paid
Deployment, integration, tuning, and ongoing hands-on support
Never
A licence key, a seat count, or a feature held back to sell you an upgrade

Want a hand getting it running?

Tell me what you're managing — how many machines, what they run, and what you're using today — and I'll come back within a business day with a straight answer on whether this is worth your time. If something off-the-shelf fits you better, I'll say so.

  • The one workflow AI could take off your team's plate first
  • Where your endpoints and mail flow are actually exposed
  • One quick win you can act on right away

Prefer email? info@sd-techsolutions.com · Reply within one business day.

No spam, no sales funnel — it comes straight to me.

Book a free audit →