# Device Agent | Device Security Posture &amp; Audit Evidence

Device Agent

# Your devices, with proof they're secure.

Enroll every laptop and server in minutes, then let disk encryption, firewall, and password checks report automatically, while your team keeps a live record for the audit. 
[
Book a demo
](/contact) [
Read the docs
](/docs/product/device-agent/overview) 
## Give every device in your fleet a documented, continuous security posture.

Enroll laptops and servers in minutes, then watch nine posture checks
report automatically, so your team always knows what state your fleet is
in.

### Continuous posture for every device

Track nine security checks across every laptop and server you enroll, from disk encryption to malware protection.

### Self-service enrollment

Let employees install the agent and enroll their own laptop in a few clicks, with no IT ticket required.

### The same nine checks everywhere

Run identical checks on macOS, Windows, Linux, and FreeBSD, so posture data means the same thing across your fleet.

### Not a MDM

Keep the agent purely observational, since it can never push commands, wipe, or lock a device.

### Evidence ready for your auditor

Give auditors a per-device history of every check, with timestamps and correlation IDs for each report.

## Fleet visibility without the MDM baggage

Enroll each device once, get the same nine checks everywhere,
everytime.

### Enroll a device in minutes

- Install the agent in one click on macOS or Windows. 
- Let your employees enroll themselves through their employee portal. 
- No technical commands. People install the app and follow the instructions. 

### Run the same nine checks everywhere

- Check disk encryption, firewall, password policy, and six more signals on every device. 
- Keep checks identical across macOS, Windows, Linux, and FreeBSD. 
- Stop the server from adding, changing, or removing any check remotely. 

### Hand your auditor a paper trail

- Push heartbeats and check results to Probo on a set schedule. 
- Give every device a report history with timestamps and correlation IDs. 
- Let an admin revoke a device the moment it leaves the fleet. 

## All your device evidence, organized for security review

Organize enrolled devices, live posture checks, report history, and
enrollment tokens into one place instead of screenshots and
spreadsheets.

### Devices

List every enrolled laptop and server with its owner, platform, and last check-in. 

### Current Postures

Show the live state of all nine checks for each individual device. 

### Report History

Keep a timestamped log of every check result, tagged with its own correlation ID. 

### Enrollment Tokens

Issue a one-time token per device, so nobody reuses or shares a credential. 

### Device Agent API

Handle enroll, heartbeat, posture, and unenroll requests over agent-initiated HTTPS only. 

### Agent CLI

Run install, status, collect, and update from the command line on servers. 

## Trusted by 130+ companies

Security and IT teams use Device Agent to track every laptop and
server, catch posture drift early, and hand auditors a live record
instead of a spreadsheet.

"Probo handled our SOC 2 and compliance, so we could focus
on building."
Paul Sinai 
CEO & Co-founder of Blaxel

Trusted by teams building compliance-ready workflows

## Questions, answered

### How long does enrollment take?

Just a few minutes. Install the package, then finish enrollment in the browser, and posture checks start reporting shortly after.

### Do you support Linux and FreeBSD servers, not just laptops?

Yes. Install with the install.sh script or the CLI, and pass the server URL and an enrollment token on the command line.

### Can Device Agent lock, wipe, or remotely control a device?

No. The agent is a posture reporter, not an MDM, so the server can never push shell commands, scripts, or device-control actions to it.

### What does the agent actually check?

Nine signals. Disk encryption, screen lock, firewall, time sync, OS version, automatic updates, password policy, remote login, and malware protection.

### Can an employee enroll their own laptop?

Yes. On macOS and Windows, they can install and enroll themselves through their Probo employee portal.

### Does the agent open a channel the server can call back into?

No. Every request is agent-initiated over HTTPS through four endpoints, enroll, heartbeat, postures, and unenroll, with no WebSocket or command queue.

### Does the agent stay up to date on its own?

Yes. It checks GitHub Releases for the latest signed build and installs it in place, with every release verified through Cosign and Sigstore.

### Can we remove or revoke a device ourselves?

Yes. Run probo-agent uninstall on the device, or revoke it from the Devices list in Probo, and it stops reporting once revoked.

### Who can see this data, and is the agent open source?

Only the owner user in your organization can see this data. The agent is open source, written in Go, and every release is signed, so your security team can audit exactly what it collects.

## Discover what else Probo can do

- [ 
### Compliance Officer Service

Expert-led compliance, end to end 
](/) 
- [ 
### Compliance Portal

Share security documents securely 
](/products/compliance-portal) 
- [ 
### Access Review

Monitor user access across all your systems 
](/products/access-review) 
- [ 
### AI Agents

Run compliance from the tools you use 
](/products/ai-agents-for-compliance) 
- [ 
### Cookie Banner

Consent that follows every visitor's law 
](/products/cookie-banner) 
- [ 
### Device Agent

Monitor device security posture continuously 
](/device-agent)
