Predictive Unified Endpoint Management

Manage every endpoint.Prevent the outage.

The unified endpoint management platform for IT and security teams that run fleets across every modern platform — with an ML layer that forecasts disk, battery, thermal, and memory failures days before users notice.

enrevia-augur.com / fleet
Online
1,247
of 1,302 enrolled
Predicted failures · 30d
14
ML-flagged · auto-grouped
Compliance
96%
across 5 policies
Smart Group · Critical predictionsAuto-populated by ML
predictions has { severity: "critical" }→ 6 devices match
!
mac-marketing-04
aaron@ · SSD · 894 GB
92%
14-day risk
!
win-eng-117
kim@ · Battery · 81% wear
76%
14-day risk
macOSWindowsLinuxiOSAndroidChromeOSCIS · NIST · HIPAA · PCISAML SSO · SCIMSplunk HECConditional Access
Built for production

Operate fleets at scale, with the SLOs to back it.

6
Endpoint platforms
mac · win · linux · iOS · Android · CrOS
99.97%
Backend uptime SLO
multi-AZ, autoscaled
≤1%
Agent CPU footprint
instrumented; CI-gated
7 yr
Audit log retention
SOC 2 CC7.2-aligned
Four modules, one console

Everything an IT team buys, in one product

Insight + Manage + Automate + Connect. The four-quadrant UEM. Each module stands alone or compounds with the others.

Augur Insight
Shipping
Predictive endpoint analytics
  • ML-driven failure forecasting (disk, battery, thermal, memory)
  • Per-device + cross-fleet cohort intelligence
  • On-device ONNX inference (no telemetry leaves the device just to score)
  • Auto-flag → Smart Group → push remediation in one click
Augur Manage
Shipping
Full Unified Endpoint Management
  • 209 configuration-profile templates across all six platforms
  • 5 pre-baked compliance baselines · 87 ChromeOS Workspace policies · Samsung Knox SDK
  • Smart Groups · Extension Attributes · Software Catalog (223 titles · CVE-scanned · licence-tracked)
  • 7 verbs · phased ring rollouts · 2-person rule on every tier · 7-year audit log
Augur Automate
Shipping
Playbooks · the connective tissue
  • Triggers (predictions, events, schedules) → conditions → actions
  • Flagship playbook: predict disk failure → open ticket → migrate data → ship replacement
  • Exponential-backoff webhooks · dead-letter pause · HMAC-signed payloads
  • Approval gates compose with the 2-person rule
Augur Connect
Shipping
Cross-platform MDM channels + identity + threat-defence
  • Native agents for macOS · Windows · Linux · Apple MDM · Android (incl. Knox) · ChromeOS
  • Identity-bound local Mac accounts (Jamf Connect equivalent) for Okta · Azure · Google
  • Conditional Access (any IdP) · SAML SSO · SCIM · MAM for BYOD · Apple DDM
  • EDR/MTD ingress: Defender · Falcon · S1 · Lookout · Zimperium · LLM-powered insights
Policy depth

Depth where it matters. Honest numbers, not a feature list.

We are not "yet another MDM with two checkboxes for compliance." The catalog ships pre-baked across all six platforms, against every framework procurement asks about.

Configuration profiles
Apple
macOS + iOS payloads
58
Windows
OMA-DM CSP
48
Linux
config drop-ins
10
Android + ChromeOS
AE + Workspace · Knox-aware
87+34
Compliance baselines
CIS Level 1 macOS
controls
16
CIS Level 1 Windows
controls
16
NIST 800-53
moderate baseline
10
HIPAA + PCI-DSS
workstation controls
16
Operational depth
Software catalog
curated titles
42
Extension Attributes
custom inventory scripts
EDR / MTD integrations
Defender · Falcon · S1 · Lookout · Zimperium
5
IdP integrations
Okta · Azure · Google · generic OIDC
4
Every platform

One console. Six operating systems.

Native agents where they buy us deep telemetry. Official MDM channels where the OS forbids agents. Same Smart Groups, same audit log, same 2-person rule everywhere.

PlatformIntegrationInsightManageZero-touch path
macOSNative Rust agent (mTLS MQTT)Apple Business Manager DEP
WindowsNative agent (WMI · PDH · ATA pass-through)Windows Autopilot (Microsoft Graph)
LinuxNative agent (procfs · sysfs · journald)apt / dnf / yum / zypper repo
iOSApple MDM protocol via APNSApple Business Manager DEP
AndroidAndroid Management API (AMAPI)Android Enterprise QR + Zero-Touch
ChromeOSGoogle Workspace Admin SDKWorkspace domain auto-enrolment
Full — native agent telemetry + on-device inferenceChannel — via the OS's official MDM surfaceLimited — what the platform exposes (e.g. ChromeOS lockdown)
Why Augur

Seven things no other MDM ships.

The predictive layer is plumbed into the dispatch surface. The compliance layer feeds your identity provider. The ML layer flags failures days before users notice. Each layer is what the others should have been.

ML-driven Smart Groups
The bridge from Insight to Manage

Augur predicts which devices will fail this week — those devices automatically join a Smart Group. One click pushes a remediation script, a config profile, or an app to the matching set. Detect → fix in one product.

Cross-fleet cohort intelligence
Other customers' fleets help yours

Our ML doesn't just train on your fleet; it pools failure signals across anonymised cohorts and learns which device generations, OS combinations, and software patterns predict outages. A failure pattern that hit one customer's fleet flags yours before it reaches you.

2-person rule on destructive ops
N-of-N approval, every tier

Wipe, mass-uninstall, bulk reboot — every destructive verb supports an approval gate. Issuer cannot self-approve. Built into every tier, not gated behind enterprise SKUs like Intune Multi-Admin Approval.

Conditional Access for any IdP
Compliance-to-identity loop

Okta / Azure AD / Google / generic OIDC asks Augur "is this device compliant?" before issuing a session token. The Intune-killer feature, available without Microsoft.

One-click compliance baselines
CIS · NIST · HIPAA · PCI

5 pre-baked baselines, 62 controls, automatic delta-against-fleet. Click "Apply CIS Level 1" and ~16 settings land at once. Kandji ships this for macOS only; we ship it cross-platform.

Approval-gated Self Service
Employees self-serve; IT keeps control

End-users open the portal on their device, browse approved apps, click install. Sensitive apps queue for one-click admin approval. Removes the "I need Slack installed" ticket queue that swallows 30-40% of IT time.

Plus a 7th — Conversational rule builder. Type "Macs with disk warnings older than three years" → the Smart Group is built.
By industry

Built for the verticals that take fleet management seriously

Compliance posture, integration roadmap, and pricing model adapted to where your regulators, end-users, and procurement office actually live.

Financial Services
NYDFS · FINRA · SOC 2 audit-log retention by default
Learn more →
Healthcare
HIPAA-ready · BAA available · PHI never touches telemetry
Learn more →
Public Sector
CJIS-aligned · FedRAMP roadmap · GovCloud deployment 2027
Learn more →
Education
Apple School Manager + Google Workspace · 1:1 device programmes
Learn more →
SaaS & Technology
Cross-platform engineering fleets · GitHub-flow change management
Learn more →
Manufacturing
Shop-floor kiosks · ruggedised Android · OT-isolated networks
Learn more →
Professional Services
Mixed Mac/Windows fleets · client-billable IT operations
Learn more →
Managed Service Providers
Multi-tenant from the kernel up · white-label option · per-region isolation
Learn more →
Compare

Functional parity, plus three differentiators competitors can't match

Augur ships the same control-plane verbs as the incumbents. The differentiators are structural — they require both the ML and the MDM under one roof.

CapabilityAugurJamfKandjiIntune
Run scripts on devices
Configuration profiles (mobileconfig / CSP / AE policy)
App deployment + Self Service catalog
Compliance evaluation + drift detection
Smart Groups (dynamic device queries)
Remote lock / wipe / power
Append-only audit log
Audit log → SIEM (Splunk HEC + webhooks)
SAML SSO + SCIM provisioning
Zero-touch enrolment (DEP · Autopilot · AE · Workspace)
Pre-baked CIS / NIST / HIPAA / PCI baselines
Extension Attributes (custom inventory scripts)
Conditional Access (compliance-to-IdP loop)
EDR / MTD integration (Defender · Falcon · S1 · Lookout)
MAM — App Protection Policies for BYOD
Apple DDM (Declarative Device Management)
Samsung Knox SDK (Knox-enrolled fleets)
Identity-bound local Mac accounts (Jamf Connect-style)
All six platforms (mac/win/linux/iOS/Android/CrOS)
Native Linux agent
2-person rule on destructive ops (every tier)
Approval-gated Self Service
Predictive ML (disk · battery · thermal · memory)
Time-to-failure forecasts with p10/p90 bounds
Per-prediction explainability (feature attribution)
LLM-powered audit + incident summarisation
Cross-fleet cohort intelligence
ML-driven Smart Group membership
Conversational rule builder (natural language)
Phased ring deployment (5→25→50→100% with auto-pause)
Software Catalog with CVE annotation + license seats
Bulk-action wizard + scheduled reports + custom dashboards
≤1% CPU agent SLO (instrumented)

Marks reflect each platform's documented general-availability surface as of mid-2026. Some competitor offerings exist as add-ons or in enterprise SKUs.

Pricing

Pick what you need

Three packaged tiers, plus a fully custom enterprise option for MSPs and regulated industries.

Insight
$3–5/ device / mo
Has Intune/Jamf, wants predictive
  • Predictive analytics
  • Inventory
  • Health monitoring
Manage
$6–10/ device / mo
Replacing legacy MDM
  • Full UEM verbs
  • Profiles + Apps
  • Compliance + Audit
  • Smart Groups
Insight + Manage
Flagship
$10–15/ device / mo
Single-vendor fleet management
  • Everything in Insight
  • Everything in Manage
  • ML-driven Smart Groups
  • Approval-gated Self Service
Enterprise
Custom≥ $50K/yr
MSPs, regulated, large fleets
  • White-label option
  • Dedicated CSM
  • Custom SLA
  • Per-region isolation
  • Phased rollout support
Trust

Built to pass a security review

Privacy and security aren't afterthoughts — they're constraints from line one.

mTLS in transit

Every agent–broker connection uses mutual TLS with per-tenant topic ACLs. Device A can't see device B's commands, even within a tenant.

Privacy by default

Telemetry is metadata only — never screen content, keystrokes, or file contents. The agent's data model literally can't carry PII.

Append-only audit log

Every command, every approval, every policy change → 7-year-retention audit trail. SOC 2 CC7.2-aligned.

SIEM-ready audit stream

Forward the audit log to Splunk HEC or any webhook. HMAC-signed, exponential-backoff retries, dead-letter pause on bad receivers.

2-person rule on destructive ops

Wipes, mass uninstalls, fleet reboots — every destructive verb supports an N-of-N approval gate. Issuer cannot self-approve.

SAML SSO + SCIM

Federated auth via your IdP (Okta, Azure AD, Google). Automatic user provisioning + deprovisioning via SCIM 2.0.

Audited tenant isolation

28 cross-tenant regression tests across 7 services. The same "not found" wording on foreign-tenant access — no ID enumeration.

Resource SLO

Rust agent runs at ≤1% avg CPU, ≤80 MB RAM, ≤50 MB/day egress on idle. Instrumented; CI fails builds that exceed it.

Compliance & integrations

SOC 2 Type II
Observation Q3 2026
ISO 27001
Planned 2027
GDPR
Data residency in EU
HIPAA-ready
BAA on request
SAML 2.0 + SCIM
Okta · Azure AD · Google
Splunk HEC
Audit-log forwarding

Bring Augur to your fleet.

30-minute demo. We'll walk you through Insight, Manage, and the Smart-Group bridge against a simulated fleet — then talk through rollout sequencing for your platforms.

No credit card required · Self-serve demo available immediately