Endpoint hygiene your security team actually approves.
Disk cleanup and local-AI file analysis for macOS & Windows fleets — built so file content never leaves the endpoint. No files in a vendor cloud means no data-residency question and minimal DPA surface area. It’s the compliance story, shipped as an architecture.
Signed & notarized · Jamf / Intune / SCCM-pushable · no kernel extension
What leaves the endpoint
Data that never moves can’t become a data-residency problem
Because the scanning engine and the AI run entirely on each machine, most of what a vendor review usually has to reason about simply doesn’t exist for the reviewed file data.
No data-residency question
There’s no region to pin and no cross-border transfer of file content to assess — the file data never leaves the device it lives on.
Minimal DPA surface area
The only data we process as a processor is account, licensing, and aggregate scan-summary metrics — counts and sizes, never content. A small, honest list your legal team can actually finish reviewing.
Verifiable, not just asserted
The app makes only a few narrow connections — and your team can watch every one with Little Snitch, Wireshark, or Activity Monitor. Trust you can confirm, not just claims. See how →
Push it like any vetted app. License it across the fleet.
Signed and notarized builds go out through the MDM you already run — and the organization licensing backbone is built to hand devices a seat without an interactive per-user sign-in.
Fleet deployment Available today
Standard installers, verified at launch by the OS.
- Jamf, Intune, and SCCM-pushable — package the signed installer and deploy like any other approved application.
- macOS: Developer ID + Apple notarization, stapled and Gatekeeper-verified. Universal (Intel + Apple Silicon).
- Windows: Authenticode via Azure Trusted Signing.
- No kernel extension, no background agent to vet — and system files are always excluded from cleaning.
Volume licensing & seat pooling In development
Backbone built in the backend; provisioning offered via pilot.
- Pooled seats under one license key, with per-seat device limits — the organization + membership schema, oversell-safe seat counter, and per-org isolation are implemented.
- An active org seat is Pro-equivalent and supersedes a member’s individual plan while active.
- MDM headless activation via license key — designed against the shipped schema so a device can be seated without per-user OAuth. Available to pilot partners as it lands.
- Self-serve provisioning, an admin console, and Stripe Invoicing for POs are the next build steps.
Straight talk on status: the durable licensing core (orgs, pooled seats, per-seat device limits, provisioning) is implemented; the operator-facing self-serve flows and MDM headless activation are in active development and delivered today through a guided pilot, not self-serve checkout. We’d rather tell you exactly where the line is than imply a console that isn’t shipped.
The procurement pack, ready to forward
Everything a security, IT, or GRC reviewer asks for — answered truthfully, including what’s still on the roadmap.
Security Whitepaper
Architecture-to-controls mapping: no-egress design, signing chain, recoverable deletion, minimal data, subprocessors, and roadmap.
Read online →Vendor Questionnaire
Pre-answered CAIQ / SIG-lite: data handling, encryption, access, build integrity, incident response, subprocessors. We’ll complete yours against this baseline.
Request a copy →DPA (draft template)
GDPR Art. 28 processor-terms shape, with subprocessor annex. A draft pending legal review — not an executed agreement — to start your legal review.
Request the draft →On certifications, plainly: Vaulith does not hold its own SOC 2, and has not yet had an independent third-party penetration test — both are on the roadmap. We rely on our subprocessors’ certifications for the parts they run: Supabase holds SOC 2, Stripe holds PCI DSS Level 1. We do not claim any certification Vaulith does not have.
Built by someone whose job was reviewing tools like this
Vaulith is built by a founder with a security and governance / risk / compliance background. The no-egress architecture, the recoverable-by-default safety model, and the deliberately minimal data posture aren’t bolted-on features — they’re the direct expression of that background. The product was designed to be the thing a security reviewer would actually approve.
Let’s scope a pilot
Tell us your fleet size and OS mix. We’ll send the whitepaper, complete your security questionnaire, share the DPA draft, and stand up a pilot on real machines.
Talk to us — request a pilot Sales-led · no self-serve seat checkout yet · support@vaulith.com