Bastion Patch Manager Become a partner
Self-hosted · Windows & macOS

Patch every PC in the fleet from one console.

Bastion Patch Manager approves Windows Updates, upgrades third-party applications, deploys software and restarts machines on your terms, then lets you help the person at the keyboard from the browser. The agent only dials out, so no PC needs an open port.

  • Windows 10 & 11, macOS
  • Outbound-only HTTPS agent
  • Runs on your own server
  • No telemetry
Illustrative view, sample data
Features

The whole patch cycle, not only the install button

Pick what goes out, choose who gets it first, stop when something breaks, and restart without losing anyone's work. Every step is written to the audit log.

Windows Update control

Every pending update with its KB number, severity and category, across the fleet.

  • Approve, decline or defer each update
  • Automatic approval rules
  • CVEs mapped from Microsoft's Security Update Guide
  • Updates can be uninstalled again

Third-party applications

An application catalogue built from what is actually installed, with fleet-wide upgrades.

  • WinGet under LocalSystem
  • Private WinGet sources
  • Chocolatey inventory and upgrades
  • Homebrew on macOS

Software deployment

Packages made of steps the agent runs: installers, scripts, files and commands.

  • Run as SYSTEM or as the signed-in user
  • Install only where the app is missing
  • Standing deployments reach PCs that match later
  • Export and import a package as one zip

Staged rollouts

Test on a few machines, then widen. A ring that fails too often stops the next one.

  • Rings with soak days
  • Failure-rate gate between rings
  • Concurrency cap and start jitter
  • Runs start when an offline PC reconnects

Restarts that respect people

A reboot policy per patch policy, with a prompt on the user's screen instead of a surprise.

  • Postpone limit and a hard deadline
  • Skip machines someone is using, in working hours
  • Alert when a restart has been pending too long
  • Restart a host now, on demand

Targeting

Group machines the way your organisation is actually organised.

  • Dynamic groups from membership rules
  • Tags and custom fields
  • CSV import
  • Target preview before anything runs

Reporting and audit

Know which machines are behind and who decided what.

  • Windows compliance in scheduled reports
  • Fleet health alerts
  • Live output from every run
  • Audit log of approvals, rules, restarts and policy changes

Enrolment at scale

Silent MSI for Group Policy or Intune, or a shared key with an approval queue.

  • Approve a whole batch at once
  • Agent update rings
  • Laptop-aware offline handling
  • macOS installer from the Add Host wizard

macOS alongside Windows

The same agent and console for the Macs in the fleet.

  • Package inventory
  • Updates through softwareupdate and Homebrew
  • Self-updating agent
  • Watch and assist through Screen Sharing
Remote support

Help the person at the PC, straight from the browser

Two ways in, both carried over the agent's own outbound connection. Nothing to install on the operator's machine and no RDP or VNC port exposed on the network.

Attended

Watch and assist

See the user's own desktop and take the mouse when they ask. They stay signed in, and nothing happens until they agree.

Consent
Asked on the user's screen first
Visibility
Shows the user who is watching
Credentials
A new password for every session
Platforms
Windows (VNC) and macOS (Screen Sharing)
Unattended

Take over

Full Remote Desktop to any Windows PC in a browser tab, for machines nobody is sitting at or work that needs its own session.

Protocol
RDP rendered in the browser
Sign-in
Asks for an account per session
Limits
Three sessions per operator
Setup
A shipped package turns Remote Desktop on

Every session is recorded in the audit log with the operator, the machine and the time.

How it works

The agent calls home. Nothing calls in.

Each PC runs a small service that connects out to your server over HTTPS and holds a WebSocket open. Jobs, live output and remote sessions all travel over that one connection.

Architecture Windows PCs and Macs run the agent and connect outbound over HTTPS and WebSocket to the Bastion server behind a TLS reverse proxy. The server stores data in PostgreSQL and Redis and uses guacd for remote sessions. Operators use a web browser. FLEET Windows PCs Agent service · MSI Laptops Online now and then Macs Agent · launchd outbound 443 · HTTPS + WSS TLS proxy your certificate YOUR SERVER · DOCKER COMPOSE Bastion server API, console, job queue postgres redis guacd remote sessions, loopback only Operators web browser Architecture: PCs and Macs connect outbound over HTTPS to a TLS proxy and the Bastion server with PostgreSQL, Redis and guacd; operators use a browser. Windows PCs, laptops, Macs Agent on every machine outbound 443 TLS proxy Bastion server API, console, job queue postgres redis guacd remote sessions, loopback only Operators · browser
  1. Enrol

    Push the MSI through Group Policy or Intune, or run the one-line installer. New machines wait in an approval queue.

  2. Inventory

    The agent reports pending updates, installed applications, restart state and hardware details.

  3. Decide

    Approve updates by hand or by rule, and assign policies to groups with rings, windows and a reboot policy.

  4. Roll out

    Runs start on schedule or when a PC comes back online. Watch the output live and stop a run mid-flight.

Security

Built for software that runs as SYSTEM on every PC

A patch server can change every machine you own. It is designed on that assumption.

  • No inbound ports on endpointsThe agent opens every connection. No SSH, WinRM or VPN is needed to reach a PC.
  • Signed agent releasesAgent updates are verified with ed25519 before they run. The MSI is Authenticode-signed when a certificate is configured.
  • Protected agent credentialsCredentials on Windows are encrypted with DPAPI and the agent's data folder is locked down.
  • Approval before installThe Windows profile requires an approval before an update is installed. Nothing lands unreviewed.
  • Granular rolesCustom roles separate who can write a package, who can patch and who can approve. Single sign-on through any OIDC provider.
  • Hardened endpointsRate limits on enrolment, one-time enrolment tokens, security headers and a content security policy.
  • No telemetryThe server sends nothing to anyone, and there is no mechanism to switch it on.
  • Only the modules you useA module allow-list switches whole features off at the server, and the console hides them.
Deployment

One server, one compose file

The server is a single Go binary with the console built in. It runs in Docker behind the TLS reverse proxy of your choice, and your data never leaves it.

  • HostLinux with Docker Compose
  • NetworkOne HTTPS name reachable by the PCs
  • CertificatePublic CA, internal CA or self-signed
  • EndpointsWindows 10, Windows 11, macOS
  • OfflineAir-gapped bundle available
# on the server
$ cp env.example .env        # secrets, URL, modules
$ docker compose up -d

# on a PC, or through Group Policy / Intune
> msiexec /i patchmon-agent.msi /qn ^
    SERVER_URL=https://patch.example.org ^
    ENROLLMENT_KEY=bpm_••••••••
serverAPI and console
postgresData
redisJob queue
guacdRemote sessions
Partners & contact

Become a partner, or run it in your organisation

We work with IT service providers and integrators who deploy, run and support Bastion Patch Manager for their clients, and with organisations that want it for their own fleet.

  • PartnersDeploy and operate it for your clients, with help on setup, packaging and pilots.
  • OrganisationsA pilot on a group of your own PCs, on your own server.
  • ReplyWithin a couple of business days.

Or email info@bastion.lt

I'm interested in