NetSecWall Enterprise

The whole fleet.
Your network. Your server.

The NetSecWall Management Server is an on-prem console that enrols every endpoint, deploys policy with a guided wizard, pushes silent updates and meters its own seats — with no cloud dependency after a one-time activation.

25–250 seats per key100% self-hostedmTLS agentsWorks air-gapped
check-in · events ↗↙ policy · updates · commandsdeploy · respondone-shot activationFIN-WS-014agent · mTLS certENG-BUILD-03agent · mTLS certSALES-LT-19agent · mTLS certNetSecWall Management Serverpolicies · updates · seats · analytics:8090:8091 mTLSSQLite / SQL Server🔒 internal CA · audit logAdmin consolepolicy wizard · TLS :8443NetSecWall cloudlicensing only · then offline
check-in · events policy · updates · commands admin actions isolate command one-time licensing
Up and running

Three steps to a managed fleet.

  1. 1 · Install the serverOne self-contained executable runs as a Windows service — console on day one, SQLite included, SQL Server when you outgrow it.
  2. 2 · Activate with your keyPaste your Enterprise key on the Licensing page. It fetches your plan, features and seat cap once — then the server runs fully on-prem.
  3. 3 · Onboard your endpointsDownload a netlens-mgmt.json from the Onboarding page. Import it in the app — or ship it with a silent GPO / Intune install — and each device enrols into the right group automatically.

Inside the console

The management console, up close.

Actual, unretouched screenshots from a live NetSecWall Management Server deployment. Select a view below — the console ships with light and dark themes and follows your preference.

NetSecWall Management Server — Fleet overview
Selected console view (dark theme)Selected console view (light theme)
Dashboard
Fleet dashboard: agents online, seat usage, event activity and detectionsFleet dashboard: agents online, seat usage, event activity and detections
Agents, seats, versions, detections.
Policy wizard
Policy deployment wizard: templates, multi-group targeting and instant pushPolicy deployment wizard: templates, multi-group targeting and instant push
Template → targets → deploy + push.
Agents
Agents table with groups, compliance, versions and bulk actionsAgents table with groups, compliance, versions and bulk actions
Groups, compliance, bulk actions.
Onboarding
Onboarding page generating the netlens-mgmt.json bootstrap fileOnboarding page generating the netlens-mgmt.json bootstrap file
One file onboards a device.

What you get

Enterprise control, without the cloud.

Everything in NetSecWall Pro on every seat — plus the management plane IT actually needs.

console

Fleet console, on your metal

A self-hosted management server with live dashboards: agents online, seat usage, detections, version spread and per-device history — all inside your network.

policy

Policy deployment wizard

Start from Balanced, Strict, Kiosk or Monitor-only, adjust, pick target groups, review the blast radius, deploy — and optionally push it to online agents instantly.

groups

Groups with inheritance

Organise endpoints into an OU-style tree. Policies flow down the chain — categories and locks accumulate, settings override nearest-first — with an effective-policy preview.

onboard

One-file onboarding

Generate a netlens-mgmt.json on the server's Onboarding page. Users import it in the app, or GPO / Intune / SCCM drops it beside a silent install — the device enrols itself.

update

Silent update push

Publish a release once, push fleet-wide. SHA-256-verified, silently installed, with a per-device version trail and quarantine for machines that fall behind.

respond

Respond in seconds

Isolate a machine, force a policy resync or push an update from the console — commands arrive over a live WebSocket channel, not on the next check-in.

mtls

mTLS agent identity

Every agent receives its own client certificate from the server's internal CA — with automatic renewal, rotation-revokes-the-old-cert, and keys sealed at rest.

compliance

Host integrity gate

Set a minimum version and drift rules; a non-compliant endpoint quarantines itself off the network until it's back in line. Location-aware policy covers on-site vs off-site.

govern

RBAC, SSO & audit

Owner / admin / operator / viewer roles, optional OIDC single sign-on (Entra ID, Okta, Keycloak), and an immutable audit trail of every console action.

Built for IT

Deploys like the tools you already run.

  • Single self-contained Windows service — no runtime to install
  • SQLite out of the box; SQL Server for larger fleets
  • Deploy agents via GPO, Intune or SCCM with a token in the installer
  • Air-gapped content import (feeds, GeoIP, installers) for offline sites
  • LAN relay agents fan out content without hammering the WAN
  • TLS admin console, separate mTLS agent port
Private by architecture

Nothing to trust but your own box.

  • Activate once with your Enterprise key — then zero phone-home
  • Telemetry, events and analytics stay on your server
  • Agents keep working offline with a 30-day rollback-proof grace
  • Blocking a device frees its seat instantly
  • Internal PKI keys DPAPI-sealed at rest
  • Every export, deploy and command is audit-logged
Enterprise pricing

Sized by seats. Same console on every tier.

A key's seat count becomes your server's cap the moment you activate. Every tier includes the full console and every desktop feature on every seat — and keys stack if you grow.

Billed yearly · pay with crypto · one-shot activation — the server then runs fully on-prem