Security that adds visibility, not attack surface.
Apate gives you visibility across every site, segment and OT network - without opening a single inbound port or installing an endpoint agent. Each sensor pushes a small posture snapshot outbound to your own console. It complements your EDR and SIEM, and reaches the places an agent can't.
Designed to minimize its own attack surface.
The biggest risk a security tool can add is becoming the incident itself - a kernel agent that crashes a fleet, a supply-chain implant, an exploitable inbound service. Apate is built to keep that entire class of risk to a minimum: no agent, no inbound service, outbound-only.
Non-destructive by default
It won't block, quarantine, push config or modify any device, so it can't be turned into a control plane by an attacker.
No inbound exposure
Sensors push outbound only to your central console. No listening port is opened on a monitored segment.
No endpoint agent
Network-level - no driver or agent on your endpoints, so no added endpoint attack surface and no fleet-crash risk.
Self-hosted
Runs on your infrastructure, on-prem or in a DMZ. No mandatory third-party cloud; your telemetry never has to leave your environment.
Data-minimized
Snapshots carry posture and metadata only - never packet payloads, files or credentials. Storage is bounded, not an ever-growing data lake.
Authenticated & audited
TLS in transit, token-based RBAC (admin/viewer/ingest), and a tamper-evident audit log of every action.
One console across every segment.
Each Apate install runs in sensor mode and pushes a small posture snapshot - score & grade, findings by severity, device count and recent events - outbound to Apate Central, a self-hosted collector that aggregates the whole fleet into one console and a JSON API for your SIEM.
- Outbound-only push - the model OT and restricted networks actually allow
- One fleet view: which sensors are online, fleet-wide critical/high, per-sensor posture
- JSON / CEF feed into Splunk, Sentinel, QRadar or Elastic
- Role-based access, audit log and TLS front - pilot-ready hardening included

Complements your stack - it doesn't replace it.
Apate isn't another agent competing for the endpoint. It adds a visibility layer exactly where your existing tools can't run.
Your EDR
Protects managed endpoints. But it can't run on OT controllers, printers, cameras, IoT or unmanaged devices - and it's an agent on every host.
Your SIEM
Aggregates logs you already collect. Apate feeds it a new signal - device posture and findings - via CEF / JSON, no new agents required.
What Apate adds
Agentless visibility of every device on the segment - including the ones your EDR will never cover - with zero added attack surface.
Where Apate wins first.
OT / ICS & critical infrastructure
Environments where an active agent is forbidden. Outbound-only push is the one model these segments actually permit.
Regulated sectors
Finance, healthcare, insurance - data minimization and a self-hosted architecture simplify privacy and compliance review.
Multi-site & multi-segment
One console across HQ, datacenter, branches and OT - each covered by a lightweight sensor.
MSSPs & consultants
One collector aggregates many client sensors; branded, board-ready reports per engagement.
Transparent about where we are.
The self-hosted, outbound-only architecture is a security control in itself. We're candid about formal attestations - they're on a defined roadmap, and we run design-partner engagements under NDA meanwhile.
In place today
Opt-in active modes, TLS transport, RBAC, audit logging, on-prem data residency and data minimization.
In progress
SSO (SAML/OIDC), code-signed builds, an independent penetration test, a DPA and a public Trust Center.
Planned
SOC 2 Type II and ISO 27001, high-availability and multi-tenant deployment, and cross-platform sensors.
Run a pilot on one segment.
A 30-60 day proof-of-concept on a single site or OT segment - no agents, no inbound ports, no risk. See what Apate surfaces that your current tools can't.