◆ Enterprise · Passive · Outbound-only · Self-hosted

Security that cannot become the breach.

Apate gives you passive, read-only visibility across every site, segment and OT network - without opening a single inbound port or installing an endpoint agent. Each sensor only observes and pushes a small posture snapshot outbound to your own console. It complements your EDR and SIEM, and reaches the places an agent can't.

No inbound ports No endpoint agent Self-hosted · your data Complements EDR/SIEM OT / air-gapped friendly
Why it's different

The one security tool that can't be weaponized.

The biggest risk a security tool can add is becoming the incident itself - a kernel agent that crashes a fleet, a supply-chain implant, an exploitable inbound service. Apate is built so that entire class of risk does not apply.

👁️

Read-only by design

It only observes. It cannot block, quarantine, push config or modify any device - so it can't be turned into a control plane by an attacker.

🚪

No inbound exposure

Sensors push outbound only to your central console. No listening port is opened on a monitored segment.

🧩

No endpoint agent

Network-level and passive - no driver or agent on your endpoints, so no added endpoint attack surface and no fleet-crash risk.

🏢

Self-hosted

Runs on your infrastructure, on-prem or in a DMZ. No mandatory third-party cloud; your telemetry never has to leave your environment.

📉

Data-minimized

Snapshots carry posture and metadata only - never packet payloads, files or credentials. Storage is bounded, not an ever-growing data lake.

🔒

Authenticated & audited

TLS in transit, token-based RBAC (admin/viewer/ingest), and a tamper-evident audit log of every action.

Sensor → Central

One console across every segment.

Each Apate install runs in sensor mode and pushes a small posture snapshot - score & grade, findings by severity, device count and recent events - outbound to Apate Central, a self-hosted collector that aggregates the whole fleet into one read-only console and a JSON API for your SIEM.

  • Outbound-only push - the model OT and restricted networks actually allow
  • One fleet view: which sensors are online, fleet-wide critical/high, per-sensor posture
  • JSON / CEF feed into Splunk, Sentinel, QRadar or Elastic
  • Role-based access, audit log and TLS front - pilot-ready hardening included
Apate fleet topology - sensors pushing posture to a central console
Where it fits

Complements your stack - it doesn't replace it.

Apate isn't another agent to fight for the endpoint. It adds a passive visibility layer exactly where your existing tools can't run.

🛡

Your EDR

Protects managed endpoints. But it can't run on OT controllers, printers, cameras, IoT or unmanaged devices - and it's an agent on every host.

🗂

Your SIEM

Aggregates logs you already collect. Apate feeds it a new, passive signal - device posture and findings - via CEF / JSON, no new agents required.

What Apate adds

Agentless, passive visibility of every device on the segment - including the ones your EDR will never cover - with zero added attack surface.

Built for

Where passive wins first.

🏭

OT / ICS & critical infrastructure

Environments where an active agent is forbidden. Outbound-only push is the one model these segments actually permit.

🏦

Regulated sectors

Finance, healthcare, insurance - data minimization and a passive architecture simplify privacy and compliance review.

🏢

Multi-site & multi-segment

One console across HQ, datacenter, branches and OT - each covered by a light, passive sensor.

🤝

MSSPs & consultants

One collector aggregates many client sensors; branded, board-ready reports per engagement.

Trust & compliance

Transparent about where we are.

The passive, read-only, self-hosted architecture is a security control in itself. We're candid about formal attestations - they're on a defined roadmap, and we run design-partner engagements under NDA meanwhile.

In place today

Passive/read-only design, TLS transport, RBAC, audit logging, on-prem data residency and data minimization.

In progress

SSO (SAML/OIDC), code-signed builds, an independent penetration test, a DPA and a public Trust Center.

Planned

SOC 2 Type II and ISO 27001, high-availability and multi-tenant deployment, and cross-platform sensors.

Visit the Trust Center - posture, compliance & disclosure →

Get started

Run a passive pilot on one segment.

A 30–60 day proof-of-concept on a single site or OT segment - no agents, no inbound ports, no risk. See what a passive layer surfaces that your current tools can't.