Healthcare
Verify endpoint hardening across clinical workstations without disrupting patient care systems.
See the engagement pattern →EWSAF runs modular, read-only checks across Windows endpoints and servers, then turns the results into evidence-backed reports your security, governance, and audit teams can all trust — without installing an agent or touching production systems.
The same sequence runs every time, on every host — which is exactly what makes the output defensible.
Point EWSAF at a Windows host or server. It reads posture using native OS tooling only — nothing is installed.
Each of the 60 modules runs in its own independent failure domain, strictly read-only, with no mutation operations.
Raw command output is captured as-is and indexed into EvidenceManifest.json and AuditManifest.json with SHA-256 hashes.
Executive and technical deliverables are generated locally — ready for governance, operations, or audit review.
Any organization with Windows endpoints or servers carries audit and compliance exposure. Three sectors below are backed by a documented engagement pattern further down this page; EWSAF is built to fit well beyond them too.
Verify endpoint hardening across clinical workstations without disrupting patient care systems.
See the engagement pattern →Produce evidence-backed control mapping for regulator, internal audit, and board-level review.
See the engagement pattern →Audit OT-adjacent Windows hosts on the plant floor without installing agents on legacy machines.
See the engagement pattern →These are representative engagement patterns describing how EWSAF is typically deployed for each scenario, based on common deployment patterns for organizations of this shape — not disclosures of a specific named customer.
Every EWSAF install ships with the full baseline catalog. A signed offline license unlocks the advanced module set — no reinstall, no change to your evidence pipeline.
Everything needed to run a complete audit and generate governance-ready reports, forever, at no cost.
Deeper, higher-signal checks for teams that need to go beyond the baseline — unlocked with one signed license file.
Grouped into eight areas — identity, endpoint protection, network, logging, platform integrity, infrastructure roles, patch/baseline, and deep AD hardening — so you can see coverage at a glance instead of scrolling a flat list. Expand a group, or search by name or module ID.
Every downloadable package is hashed the moment it's published, so what you download is exactly what was signed off.
The free tier is not a trial. You can download, install, and use the baseline modules indefinitely without ever purchasing premium.
Modules 001–040, full reporting, and evidence manifests — no license file required.
Adds modules 041–060 through a signed, offline license file. No cloud dependency, no workflow change.
No. EWSAF is agentless — it runs read-only checks using native OS tooling and does not require any persistent service to be installed on the endpoint.
No. EWSAF is offline-ready: evidence capture and report generation happen locally, and the analyst narrative uses a lightweight local text process with no external model dependency.
Nothing is taken away. Modules 001–040 and the full reporting suite remain fully installable and usable, indefinitely, at no cost.
Premium is priced per audited system, per year: INR 5000/system/year or USD 65/system/year, depending on your billing currency.
Contact [email protected]. Licenses are issued offline as a signed file with entitlements and an expiration date set by the issuer, and activate on any machine — no per-device binding required.
Yes. Every run produces an EvidenceManifest.json and an AuditManifest.json containing SHA-256 hashes of captured artifacts and generated reports.
Yes. ExecutiveSummary.html is written for governance and leadership audiences, with a plain-language local narrative, while TechnicalReport.html gives engineering teams the full detail they need.
Reach the technical support team at [email protected].