PATCH MANAGEMENT

TS Patch Manager
Patch Every Endpoint, On Your Terms

Cross-platform patch management for Windows, macOS, Ubuntu and RHEL — automated OS and third-party patching, KEV/CVSS/EPSS risk-based prioritization, phased ring rollouts, maintenance windows, reboot orchestration and one-click rollback. Fully on-premises: your patch catalog, approvals and deployment data never leave your datacenter.

Why Choose TS Patch Manager?

Enterprise patch management with full OS parity — designed from the ground up for on-premises sovereignty

🏢

True On-Premises

The patch catalog, approvals, deployment history and vulnerability intelligence all live in your datacenter on ArangoDB. Agents talk only to your server — no dependency on a vendor cloud to decide what lands on your endpoints.

🖥

Full OS Parity

One console for Windows (Windows Update Agent), macOS (softwareupdate + Installomator), Ubuntu (apt) and RHEL (dnf). Same approval, scheduling and rollback workflow across every platform — no separate tools per OS.

📈

Risk-Based Prioritization

Every patch is scored KEV-first, then by CVSS and EPSS, so actively-exploited and high-impact vulnerabilities rise to the top automatically. Patch what attackers are using now — not just what's newest.

🔄

Phased, Safe Rollouts

Ring-based deployment (pilot → early → broad) with success gates and soak windows, maintenance windows, and Test-and-Approve. Catch a bad patch on a few devices before it reaches the fleet.

Comprehensive Patch Capabilities

Everything you need to keep the fleet current, running entirely on your infrastructure

OS & Security Updates

Windows OS updates and drivers via the Windows Update Agent (deployed by update GUID), macOS system updates, and Ubuntu/RHEL package updates via apt/dnf — detected on every scan and applied on your schedule.

Third-Party & Custom Patches

Patch third-party apps via winget, Homebrew and Installomator, or upload your own MSI / EXE / PKG / DMG / DEB / RPM with silent-install arguments. Every installer is SHA-256 verified on the endpoint before it runs.

Approval Workflow

Approve or decline per patch, per severity or per category. Auto-approve rules govern routine updates; Test-and-Approve soaks a patch on a pilot group before it's eligible for the fleet. Every decision is audited.

Ring Rollouts & Windows

Release in rings (pilot, early, broad) gated by success rate and soak time, and only inside the maintenance windows you define. Halt or promote a rollout at any time from the console.

Reboot Orchestration

User-facing reboot prompts with configurable postpone limits and hard deadlines, reboot-pending tracking, and Wake-on-LAN relay to bring offline machines online for patching.

Rollback & History

Full per-device install history and one-click rollback of a patch on a device or group when an update misbehaves — with the reason recorded in the audit trail.

Vulnerability Intelligence, Built In

TS Patch Manager enriches every patch with the intelligence you need to prioritize

📡

Authoritative Feeds

Continuously synced from NVD, CISA KEV, EPSS, Microsoft MSRC, Apple security releases, Red Hat RHSA, Ubuntu USN and OSV — mapping CVEs to the exact patch that fixes them.

🎯

Priority Scoring

KEV-first ranking, weighted by CVSS severity and EPSS exploit probability, surfaces the patches that matter most. Filter and search the whole catalog by severity, platform, vendor, KEV and CVE.

📊

Compliance Dashboards

Fleet-wide patch posture, per-device compliance, KEV exposure, SLA breaches and top vulnerabilities — with alerting, an attention rollup, and exportable reports for auditors.

Use Cases

How enterprises run TS Patch Manager

📅

Monthly Patch Tuesday

Auto-approve routine Microsoft and OS updates, roll them out in rings inside the maintenance window, and let deadlines handle reboots — with a compliance report at the end of the cycle.

🚨

Emergency KEV / Zero-Day

When a CVE lands on the CISA KEV list, TS Patch Manager surfaces it at the top. Deploy-now bypasses the window to push the fix to affected devices on their next check-in.

📦

Third-Party App Updates

Keep browsers, runtimes and business apps current across Windows and macOS through package managers or your own signed installers — no manual per-app packaging.

📋

Compliance & Audit

Demonstrate patch SLAs and vulnerability remediation for SOC 2, ISO 27001 and HIPAA with per-device compliance history, KEV exposure tracking and immutable audit logs.

Technical Specifications

Cross-platform coverage, cryptographically-signed delivery, on-premises by design

4 OS Families | KEV / CVSS / EPSS | On-Premises
Platforms
  • Windows 10/11 & Server
  • macOS (Intel & Apple Silicon)
  • Ubuntu / Debian
  • RHEL / Rocky / Alma / Fedora
Sources
  • Windows Update Agent (WUA)
  • apt / dnf
  • winget / Homebrew / Installomator
  • Custom MSI/EXE/PKG/DEB/RPM
Intelligence Feeds
  • NVD, CISA KEV, EPSS
  • Microsoft MSRC, Apple
  • Red Hat RHSA, Ubuntu USN
  • OSV
Delivery & Deployment
  • Ed25519-signed task envelopes
  • SHA-256 installer verification
  • Docker Swarm + ArangoDB
  • Offline installer
Compliance

SOC 2 Type II  •  ISO 27001  •  GDPR (data sovereignty)  •  HIPAA  •  CISA KEV-aligned remediation

Take Control of Patching Across Your Fleet

Automated, risk-prioritized, cross-platform patching — running entirely on your own infrastructure.