Windows-first security control assurance

Your console says it's configured. MetalAudit checks what is actually there.

MetalAudit is being built to help IT and security teams independently verify the effective state of Windows security controls, preserve technical evidence, and identify discrepancies that deserve investigation.

Early-stage product · Windows-first · Pilot program

Independent evidence
Observe the endpoint directly
Explainable results
Evidence before conclusions
Windows-first
Focused endpoint assurance
Built for trust
Fail closed when evidence is insufficient

Configured does not always mean effective.

Modern Windows environments can be managed through multiple layers. A management console can describe intended or reported state, while the endpoint itself remains the source of truth for what is actually effective.

Management state

Policies, assignments and management platforms describe what an organization expects or believes is configured.

Endpoint state

MetalAudit focuses on collecting independent evidence from Windows to establish what can actually be observed on the device.

Management view
Assurance view
EXPECTED Security control enabled
OBSERVED Effective endpoint state
Policy reported successfully
Evidence independently collected
Configuration changed
Historical regression can be investigated

From expectation to evidence.

MetalAudit is designed around an assurance workflow rather than a simple checklist of security settings.

01

Observe

Collect structured, read-only evidence about relevant Windows security controls.

02

Compare

Separate intended state from independently observed effective state.

03

Explain

Preserve provenance, confidence and evidence instead of hiding uncertainty behind a binary result.

04

Revalidate

Re-check a control after corrective action and preserve the before-and-after history.

Evidence first. Confidence second. Claims last.

Security tools lose trust when they imply certainty that the evidence does not support. MetalAudit is designed to make uncertainty explicit.

CONTROL     Windows security control
EXPECTED    Enabled
OBSERVED    Mismatch
RESULT      FAIL
CONFIDENCE   HIGH
ROOT CAUSE   Not established
EVIDENCE    Preserved
Observed facts stay separate from inference. A mismatch can be demonstrated without inventing why it happened.
Insufficient evidence is explicit. When MetalAudit cannot establish a result confidently, it can classify the outcome as inconclusive instead of guessing.
History matters. Assurance is more useful when teams can understand when a control changed and whether a correction restored the expected state.
Designed to complement existing tooling. MetalAudit is not intended to replace endpoint management, EDR or Microsoft security platforms.

Built with MSPs and Windows teams in mind.

MetalAudit is opening an early pilot program for a small number of organizations and Microsoft-focused service providers. We are looking for technical feedback from teams that manage real Windows environments.

10–15 minute introduction · No commitment