Outbound HTTPS only

Agents initiate their own HTTPS connection to the Ordantra API. They refuse plain HTTP URLs and do not require inbound firewall rules on endpoint devices.

Per-device authentication

A workspace enrolment key bootstraps registration. Ordantra then issues a separate device credential so routine heartbeats and signed commands are isolated per endpoint.

Verified update channels

Windows and Linux use separate release channels. Clients require HTTPS, verify the published SHA-256 digest, and report the update result; Linux also supports atomic rollback.

Silent scheduled check-ins

Agents run on a schedule: heartbeats report roughly every 15 minutes, while full software inventory syncs are less frequent to keep the signal useful without constant churn.

Risk becomes work

Endpoint posture is used to explain risk, link findings to assets, and create service work when policy thresholds are met.

Enough context to support the device.

The agent sends operational and posture data that helps a resolver understand the endpoint, its security state, and the work already linked to it.

  • Device identity, hostname, platform, OS version, CPU, RAM, disk, IP, and MAC details.
  • Agent version, check-in status, update state, and last-seen time.
  • Local account counts or privacy-preserving identifiers, according to workspace policy, for ownership and support routing.
  • Antivirus and security product posture, including protection state and definition freshness where available.
  • Installed software inventory and optional privacy-preserving application usage signals for risk and asset context.

No surveillance payload.

Ordantra is built to connect service work with endpoint posture. It is not positioned as employee monitoring, remote desktop, or content inspection tooling.

  • Keystrokes, screenshots, screen recordings, microphone, or camera data.
  • Browser history, personal files, email bodies, chat contents, or document contents.
  • Remote shell access or inbound control channels from Ordantra to the endpoint.

Evaluate the endpoint workflow in context

Start in the queue, review endpoint risk, open the ops graph, then move into controlled change.