How It Fits Together
The AuditToolkit Platform is a single-licence, fleet-wide compliance suite of five core products covering asset discovery, audit execution, controlled remediation, and tamper-evident evidence packaging across your entire estate.
Further products are licensed independently — they are not part of the Platform, and each runs on its own with no Platform subscription required: AuditToolkit Lite (single-host auditing for Linux, Windows, and macOS — one licence covers all three host tools), the Hordian (distributed storage inventory), Meldian (agentless audit and remediation), and Taldian (infrastructure data ingestion). Each is its own product. The first three are priced and supplied separately; Taldian is governed by its own Business Source Licence terms and is not included in a Platform subscription.
Complete Architecture
Each specialised tool operates independently as a satellite producer, can be deployed where it has the best access to its target infrastructure. The central AuditToolkit sees everything — and correlates, remediates, and packages evidence for the entire estate. The diagram below shows how the tools interoperate, not what a Platform licence covers: Taldian appears as a producer because it can feed the platform, but it is an independent product licensed separately.
Toolkit Structure
The AuditToolkit is the core platform, with distinct sub-tools and agent models that support different deployment patterns across five products.
| Layer | What it includes | Why it matters |
|---|---|---|
| Core platform | Web application, central workflow engine, and REST API (390+ endpoints) | Single control plane for findings, evidence, scheduling, and reporting |
| Audit script libraries | Linux scripts, Windows PowerShell scripts, and hypervisor audit scripts | Covers server, endpoint, and virtualisation audit scenarios in one platform |
| Agent execution layer | Standalone Agent, Fleet Agent, Hypervisor agent, plus Fleet Agent coordinator service | Supports single-host, fleet-scale, and hypervisor-native collection modes |
| Platform products | Aldian, Ladian, Findian, Sothian | Linux audit and reporting depth, asset governance context, switch exposure intelligence, and distributed execution — each covered by the same Platform subscription |
| Remediation and evidence | SuperAdmin-gated direct host remediation over SSH and WinRM. Secondary auth token required. Atomic rollback by execution ID. SHA-256 signed evidence packages with MANIFEST.json for auditor delivery. | Controlled change execution with full audit trail, rollback safety, and tamper-evident compliance evidence output. |
Tool Map
Each product is purpose-built, but designed to interoperate in one governance and operations model.
Ingestion and normalisation layer
Audit operations and evidence layer
Linux audit and reporting platform
Asset intelligence and enrichment layer
Network switch exposure operations layer
Execution Layer
The distributed execution backbone of the platform. The Sothian runs audit scripts across large host inventories in parallel — local or remote — and delivers cryptographically signed evidence bundles to the central platform. It is the execution layer that makes fleet-scale auditing reliable and tamper-evident.
AuditToolkit Lite
A separate product family for single-host security auditing. Each tool is self-contained, requires no central server, and produces structured findings, a Hardening Index, and a human-readable HTML report entirely on-device. Designed for consultants, small teams, pre-deployment host checks, and air-gapped environments.
DEB / RPM · Python 3.9+ · CLI
MSI · PowerShell 7 · CLI + GUI
DMG / PKG · Python 3.10 · CLI + Web viewer
Hordian
A standalone product, licensed and priced independently of the AuditToolkit suite. Lightweight agents run on each storage node and publish results to a self-hosted control plane — distributed file inventory, classification, and change-tracking across RHEL, Ubuntu, Lustre, GPFS, ZFS, and Windows Server, with no cloud dependency.
The first scan establishes a baseline; every subsequent scan only processes new, modified, or deleted files. Large NAS, Lustre, and ZFS filesystems complete in minutes with no measurable I/O impact on production workloads.
Agents always initiate the connection and never block on server availability. If the control plane is unreachable, scan jobs complete locally and results are held until the connection resumes — no lost data, no missed scan windows.
Docker images for the server and agent ship as loadable tarballs. The agent auto-update mechanism serves packages from a local path with SHA-256 verification — no external package repository required at run time.
Meldian
A standalone product, licensed and priced independently of the AuditToolkit Platform. Meldian audits and remediates assets agentlessly over SSH, WinRM, SNMP, and API — attach a connection profile to each node, run scheduled audits, and review findings, drift, and trends, with approval-gated remediation and rollback. Nothing to install on the target hosts.
Reach Linux, Windows, network, and API targets over their native protocols — no agent to deploy, package, or maintain on the assets under audit. A node becomes managed the moment a connection profile is attached.
Scheduled audits feed a dashboard of findings, trends, and configuration drift. Remediation is approval-gated with atomic rollback, so changes stay controlled and fully auditable.
Licensed by connected-node band — a flat annual price up to the node count in your tier. SSO, scheduled audits, and reporting are included from the free tier; air-gapped offline licensing is available on higher tiers.
Use-Case Matrix
Primary indicates the main owning tool. Supporting indicates where companion tooling adds value.
| Use Case | Primary Tool | Supporting Tool(s) | Typical Output |
|---|---|---|---|
| Infrastructure data intake and connector polling | Taldian | Ladian | Normalised inventory + vulnerability-linked records |
| Audit finding lifecycle and remediation tracking | AuditToolkit | Aldian | Findings queue, evidence reports, closure records |
| Direct host remediation with atomic rollback | AuditToolkit | SuperAdmin remediation APIs | Execution history, rollback records, change evidence |
| Asset discovery with CVE and KEV correlation | AuditToolkit (native asset discovery) | Taldian | Normalised asset records with CVE and KEV risk context |
| Linux hardening and compliance control verification | Aldian | AuditToolkit | Control-level pass/fail evidence and reports |
| Asset governance and command-centre views | Ladian | Taldian | Asset context dashboards and enrichment state |
| Compliance evidence packaging for review | AuditToolkit | Aldian, Taldian | Evidence exports for internal/external assurance |
| Switch firmware advisory and network exposure tracking | Findian | Taldian, Ladian | Switch-centered exposure reports with CVE and advisory context |
| Storage inventory and classification for RHEL / Ubuntu / Lustre / GPFS | Hordian | AuditToolkit | Timestamped file inventory, classification breakdown, migration delta reports |
| Single-host Linux posture check — no platform deployment | Cunnian | — | Local JSON + CSV + HTML with Hardening Index |
| Single-host Windows posture check — no platform deployment | Borian | — | Local JSON + CSV + HTML with Hardening Index |
| Single-host macOS posture check — no platform deployment | Kithian | — | Local JSON + HTML with Hardening Index and web viewer |
Operational Flow
The tools are designed as an operational chain, not isolated silos.
Taldian and asset discovery gather host, software, and network inventory. CVE and KEV context are applied per asset.
Ladian layers governance context, ownership, and lifecycle visibility. Findian adds network infrastructure posture.
AuditToolkit runs audit workflows and Aldian adds deeper Linux control verification.
SuperAdmin-gated direct host remediation over SSH and WinRM with secondary auth and dry-run preview before every execution.
Post-remediation validation with automatic or manual rollback by execution ID when outcomes are not compliant.
SHA-256 signed evidence packages, SIEM export, trend analysis, and compliance trajectory reporting for continual improvement.
Start Paths
Quick entry points for teams that need an immediate operating path.
Deployment Models
| Mode | Description | Best for |
|---|---|---|
| Single-host (Standalone Agent) | Core platform plus Standalone Agent on one machine. Local dashboard, local findings, and no coordinator required. | Small environments, evaluation, developer workstations |
| Fleet (Fleet Agent + Coordinator) | Fleet Agent deployed to target hosts with a coordinator service for centralised collection and reporting. | Multi-server environments and recurring scheduled audits |
| Hypervisor-native | Hypervisor agent for ESXi, KVM, Nutanix, Proxmox, and Xen with audit scripts run against hypervisor layers directly. | Virtualisation estate audit and compliance |
| Air-gapped / offline | Offline MSI installers with no outbound internet requirement and agent deployment without external connectivity. | Financial services, healthcare, government, and defence supply chain |
| CI/CD integration | Aldian with AUDIT_SKIP_LICENSE_CHECK for pipeline use, stable control IDs, and JSON/CSV outputs with GitHub issue creation. | DevSecOps, developer workstations, and pipeline gates |
Tell us your environment goals and we will map the right starting sequence across the five products.