Cross-platform patch management for Windows, macOS, Ubuntu and RHEL — automated OS and third-party patching, KEV/CVSS/EPSS risk-based prioritization, phased ring rollouts, maintenance windows, reboot orchestration and one-click rollback. Fully on-premises: your patch catalog, approvals and deployment data never leave your datacenter.
Enterprise patch management with full OS parity — designed from the ground up for on-premises sovereignty
The patch catalog, approvals, deployment history and vulnerability intelligence all live in your datacenter on ArangoDB. Agents talk only to your server — no dependency on a vendor cloud to decide what lands on your endpoints.
One console for Windows (Windows Update Agent), macOS (softwareupdate + Installomator), Ubuntu (apt) and RHEL (dnf). Same approval, scheduling and rollback workflow across every platform — no separate tools per OS.
Every patch is scored KEV-first, then by CVSS and EPSS, so actively-exploited and high-impact vulnerabilities rise to the top automatically. Patch what attackers are using now — not just what's newest.
Ring-based deployment (pilot → early → broad) with success gates and soak windows, maintenance windows, and Test-and-Approve. Catch a bad patch on a few devices before it reaches the fleet.
Everything you need to keep the fleet current, running entirely on your infrastructure
Windows OS updates and drivers via the Windows Update Agent (deployed by update GUID), macOS system updates, and Ubuntu/RHEL package updates via apt/dnf — detected on every scan and applied on your schedule.
Patch third-party apps via winget, Homebrew and Installomator, or upload your own MSI / EXE / PKG / DMG / DEB / RPM with silent-install arguments. Every installer is SHA-256 verified on the endpoint before it runs.
Approve or decline per patch, per severity or per category. Auto-approve rules govern routine updates; Test-and-Approve soaks a patch on a pilot group before it's eligible for the fleet. Every decision is audited.
Release in rings (pilot, early, broad) gated by success rate and soak time, and only inside the maintenance windows you define. Halt or promote a rollout at any time from the console.
User-facing reboot prompts with configurable postpone limits and hard deadlines, reboot-pending tracking, and Wake-on-LAN relay to bring offline machines online for patching.
Full per-device install history and one-click rollback of a patch on a device or group when an update misbehaves — with the reason recorded in the audit trail.
TS Patch Manager enriches every patch with the intelligence you need to prioritize
Continuously synced from NVD, CISA KEV, EPSS, Microsoft MSRC, Apple security releases, Red Hat RHSA, Ubuntu USN and OSV — mapping CVEs to the exact patch that fixes them.
KEV-first ranking, weighted by CVSS severity and EPSS exploit probability, surfaces the patches that matter most. Filter and search the whole catalog by severity, platform, vendor, KEV and CVE.
Fleet-wide patch posture, per-device compliance, KEV exposure, SLA breaches and top vulnerabilities — with alerting, an attention rollup, and exportable reports for auditors.
How enterprises run TS Patch Manager
Auto-approve routine Microsoft and OS updates, roll them out in rings inside the maintenance window, and let deadlines handle reboots — with a compliance report at the end of the cycle.
When a CVE lands on the CISA KEV list, TS Patch Manager surfaces it at the top. Deploy-now bypasses the window to push the fix to affected devices on their next check-in.
Keep browsers, runtimes and business apps current across Windows and macOS through package managers or your own signed installers — no manual per-app packaging.
Demonstrate patch SLAs and vulnerability remediation for SOC 2, ISO 27001 and HIPAA with per-device compliance history, KEV exposure tracking and immutable audit logs.
Cross-platform coverage, cryptographically-signed delivery, on-premises by design
SOC 2 Type II • ISO 27001 • GDPR (data sovereignty) • HIPAA • CISA KEV-aligned remediation
Automated, risk-prioritized, cross-platform patching — running entirely on your own infrastructure.