How It Fits Together
The AuditToolkit Platform is a single-licence, fleet-wide compliance suite of six core products covering asset discovery, audit execution, controlled remediation, and tamper-evident evidence packaging across your entire estate.
Three further products are sold and licensed independently — they are not part of the Platform, and each runs on its own with no Platform subscription required: AuditToolkit Lite (single-host auditing for Linux, Windows, and macOS — one licence covers all three host tools), the Storage Intelligence Platform (distributed storage inventory), and Litmus (agentless audit and remediation). Each is its own product, priced and supplied separately.
Complete Architecture
Each specialised tool operates independently as a satellite producer, can be deployed where it has the best access to its target infrastructure. The central Audit Admin Toolkit sees everything — and correlates, remediates, and packages evidence for the entire estate.
Toolkit Structure
The Audit Admin Toolkit is the core platform, with distinct sub-tools and agent models that support different deployment patterns across six products.
| Layer | What it includes | Why it matters |
|---|---|---|
| Core platform | Web application, central workflow engine, and REST API (390+ endpoints) | Single control plane for findings, evidence, scheduling, and reporting |
| Audit script libraries | Linux scripts, Windows PowerShell scripts, and hypervisor audit scripts | Covers server, endpoint, and virtualisation audit scenarios in one platform |
| Agent execution layer | Standalone Agent, Fleet Agent, Hypervisor agent, plus Fleet Agent coordinator service | Supports single-host, fleet-scale, and hypervisor-native collection modes |
| Extension and companion tools | Linux Security Lite, CMDB API Data Collection Tool, Asset Command Centre, Switch Exposure Centre | Adds deeper Linux controls, ingestion/normalisation, and asset governance context |
| Remediation and evidence | SuperAdmin-gated direct host remediation over SSH and WinRM. Secondary auth token required. Atomic rollback by execution ID. SHA-256 signed evidence packages with MANIFEST.json for auditor delivery. | Controlled change execution with full audit trail, rollback safety, and tamper-evident compliance evidence output. |
Tool Map
Each product is purpose-built, but designed to interoperate in one governance and operations model.
Ingestion and normalisation layer
Audit operations and evidence layer
Linux control depth extension
Asset intelligence and enrichment layer
Network switch exposure operations layer
Execution Layer
The distributed execution backbone of the platform. The Audit Assurance Node runs audit scripts across large host inventories in parallel — local or remote — and delivers cryptographically signed evidence bundles to the central platform. It is the execution layer that makes fleet-scale auditing reliable and tamper-evident.
AuditToolkit Lite
A separate product family for single-host security auditing. Each tool is self-contained, requires no central server, and produces structured findings, a Hardening Index, and a human-readable HTML report entirely on-device. Designed for consultants, small teams, pre-deployment host checks, and air-gapped environments.
DEB / RPM · Python 3.10 · CLI
MSI · PowerShell 7 · CLI + GUI
DMG / PKG · Python 3.10 · CLI + Web viewer
Storage Intelligence Platform
A standalone product, licensed and priced independently of the AuditToolkit suite. Lightweight agents run on each storage node and publish results to a self-hosted control plane — distributed file inventory, classification, and change-tracking across RHEL, Ubuntu, Lustre, GPFS, ZFS, and Windows Server, with no cloud dependency.
The first scan establishes a baseline; every subsequent scan only processes new, modified, or deleted files. Large NAS, Lustre, and ZFS filesystems complete in minutes with no measurable I/O impact on production workloads.
Agents always initiate the connection and never block on server availability. If the control plane is unreachable, scan jobs complete locally and results are held until the connection resumes — no lost data, no missed scan windows.
Docker images for the server and agent ship as loadable tarballs. The agent auto-update mechanism serves packages from a local path with SHA-256 verification — no external package repository required at run time.
Litmus
A standalone product, licensed and priced independently of the AuditToolkit Platform. Litmus audits and remediates assets agentlessly over SSH, WinRM, SNMP, and API — attach a connection profile to each node, run scheduled audits, and review findings, drift, and trends, with approval-gated remediation and rollback. Nothing to install on the target hosts.
Reach Linux, Windows, network, and API targets over their native protocols — no agent to deploy, package, or maintain on the assets under audit. A node becomes managed the moment a connection profile is attached.
Scheduled audits feed a dashboard of findings, trends, and configuration drift. Remediation is approval-gated with atomic rollback, so changes stay controlled and fully auditable.
Licensed by connected-node band — a flat annual price up to the node count in your tier. SSO, scheduled audits, and reporting are included from the free tier; air-gapped offline licensing is available on higher tiers.
Use-Case Matrix
Primary indicates the main owning tool. Supporting indicates where companion tooling adds value.
| Use Case | Primary Tool | Supporting Tool(s) | Typical Output |
|---|---|---|---|
| Infrastructure data intake and connector polling | CMDB API Data Collection Tool | Asset Command Centre | Normalised inventory + vulnerability-linked records |
| Audit finding lifecycle and remediation tracking | Audit Admin Toolkit | Linux Security Lite | Findings queue, evidence reports, closure records |
| Direct host remediation with atomic rollback | Audit Admin Toolkit | SuperAdmin remediation APIs | Execution history, rollback records, change evidence |
| Asset discovery with CVE and KEV correlation | Audit Admin Toolkit (native asset discovery) | CMDB API Data Collection Tool | Normalised asset records with CVE and KEV risk context |
| Linux hardening and compliance control verification | Linux Security Lite | Audit Admin Toolkit | Control-level pass/fail evidence and reports |
| Asset governance and command-centre views | Asset Command Centre | CMDB API Data Collection Tool | Asset context dashboards and enrichment state |
| Compliance evidence packaging for review | Audit Admin Toolkit | Linux Security Lite, CMDB API Data Collection Tool | Evidence exports for internal/external assurance |
| Switch firmware advisory and network exposure tracking | Switch Exposure Centre | CMDB API Data Collection Tool, Asset Command Centre | Switch-centered exposure reports with CVE and advisory context |
| Storage inventory and classification for RHEL / Ubuntu / Lustre / GPFS | Storage Intelligence Platform | Audit Admin Toolkit | Timestamped file inventory, classification breakdown, migration delta reports |
| Single-host Linux posture check — no platform deployment | Linux Host Lite | — | Local JSON + CSV + HTML with Hardening Index |
| Single-host Windows posture check — no platform deployment | Windows Security Lite | — | Local JSON + CSV + HTML with Hardening Index |
| Single-host macOS posture check — no platform deployment | macOS Security Lite | — | Local JSON + HTML with Hardening Index and web viewer |
Operational Flow
The tools are designed as an operational chain, not isolated silos.
CMDB API and asset discovery gather host, software, and network inventory. CVE and KEV context are applied per asset.
Asset Command Centre layers governance context, ownership, and lifecycle visibility. Switch Exposure Centre adds network infrastructure posture.
Audit Admin Toolkit runs audit workflows and Linux Security Lite adds deeper Linux control verification.
SuperAdmin-gated direct host remediation over SSH and WinRM with secondary auth and dry-run preview before every execution.
Post-remediation validation with automatic or manual rollback by execution ID when outcomes are not compliant.
SHA-256 signed evidence packages, SIEM export, trend analysis, and compliance trajectory reporting for continual improvement.
Start Paths
Quick entry points for teams that need an immediate operating path.
Deployment Models
| Mode | Description | Best for |
|---|---|---|
| Single-host (Standalone Agent) | Core platform plus Standalone Agent on one machine. Local dashboard, local findings, and no coordinator required. | Small environments, evaluation, developer workstations |
| Fleet (Fleet Agent + Coordinator) | Fleet Agent deployed to target hosts with a coordinator service for centralised collection and reporting. | Multi-server environments and recurring scheduled audits |
| Hypervisor-native | Hypervisor agent for ESXi, KVM, Nutanix, Proxmox, and Xen with audit scripts run against hypervisor layers directly. | Virtualisation estate audit and compliance |
| Air-gapped / offline | Offline MSI installers with no outbound internet requirement and agent deployment without external connectivity. | Financial services, healthcare, government, and defence supply chain |
| CI/CD integration | Linux Security Lite with AUDIT_SKIP_LICENSE_CHECK for pipeline use, stable control IDs, and JSON/CSV outputs with GitHub issue creation. | DevSecOps, developer workstations, and pipeline gates |
Tell us your environment goals and we will map the right starting sequence across the four tools.