Back to home
◆ Deploy your way

Deploy your way.
Patch on your terms.

Use VulnDetect for agent-based vulnerability scanning and patch management, or use PatchPro to publish supported applications to Microsoft Intune.

1
Deploy, with an agent or agentless
Push the lightweight SecTeer agent via Intune, Group Policy, or your RMM, or run agentless through Microsoft Intune with nothing installed on the endpoint. Either way you're scanning in minutes, with nothing to stand up on-prem.
2
Review prioritized risk
VulnDetect inventories every endpoint and ranks findings by real exploitability, so your team sees exactly what to fix first instead of a flat CVSS list.
3
Automate remediation
Approve a patch policy once. VulnDetect patches OS and third-party apps from its own agent, or PatchPro ships the same patches through Intune, both in staged rings with automatic rollback if anything breaks.
◆ Watch it work

Detection to remediation, in one minute.

A short walkthrough of what VulnDetect finds, and the two ways to patch it, using a 12,400-endpoint estate as the example.

SECTEER · CATCH & PATCH
See it on your own estate.
20 minutes with an engineer. Bring your patch numbers, we’ll show you the gap.
Book a demo
◆ Architecture

One agent, one console, no infrastructure.

The agent handles inventory and patch delivery locally; the cloud console handles intelligence, policy, and reporting. Communication is outbound-only over HTTPS.

Outbound HTTPS only, no inbound firewall changes
Works for remote and roaming devices, not just LAN
Role-based access and SSO for the console
EU data residency
Deployment methods
Microsoft IntuneRecommended
Group Policy (GPO)Supported
RMM / software distributionSupported
Manual / scripted installSupported
◆ Infrastructure

Zero on-prem servers

There is nothing to host, scan or maintain in-house. The agent talks outbound over HTTPS to the cloud console, so there are no scanning servers, no distribution points and no inbound firewall changes.

No scanning servers or distribution points to run
Outbound HTTPS only, no inbound firewall rules
Reaches remote and roaming devices, not just the LAN
◆ Scheduling

Patches in your windows

Updates land when your organisation allows them. Maintenance windows, restart rules and deferral limits are set per device group, so patching follows the operating hours each part of the business runs on.

Maintenance windows defined per device group
Restart policies and deferral limits you control
Staged rollout rings before fleet-wide deployment
Set it up before your next patch cycle.
Free 14-day trial · live in under an hour · no credit card.
Start free trial