Management state
Policies, assignments and management platforms describe what an organization expects or believes is configured.
MetalAudit is being built to help IT and security teams independently verify the effective state of Windows security controls, preserve technical evidence, and identify discrepancies that deserve investigation.
Early-stage product · Windows-first · Pilot program
Modern Windows environments can be managed through multiple layers. A management console can describe intended or reported state, while the endpoint itself remains the source of truth for what is actually effective.
Policies, assignments and management platforms describe what an organization expects or believes is configured.
MetalAudit focuses on collecting independent evidence from Windows to establish what can actually be observed on the device.
MetalAudit is designed around an assurance workflow rather than a simple checklist of security settings.
Collect structured, read-only evidence about relevant Windows security controls.
Separate intended state from independently observed effective state.
Preserve provenance, confidence and evidence instead of hiding uncertainty behind a binary result.
Re-check a control after corrective action and preserve the before-and-after history.
Security tools lose trust when they imply certainty that the evidence does not support. MetalAudit is designed to make uncertainty explicit.
MetalAudit is opening an early pilot program for a small number of organizations and Microsoft-focused service providers. We are looking for technical feedback from teams that manage real Windows environments.
10–15 minute introduction · No commitment