Windows Patch & Posture Assurance
Self-hosted patch and security-posture assurance for Windows estates that cannot reach the internet. Discover what you run, assess it against recognised baselines, prioritise by real exposure, remediate under change control, and leave an assessor a signed trail of exactly what happened.
Weardian is generally available. Release v2.3.0 is published and signed, with the console and the Content Builder available to download for Windows x86_64 and Linux x86_64, each carrying its SBOM, vulnerability scan and detached signature.
Production use requires a paid licence under the Business Source Licence 1.1 — there is no free production tier. Pricing is below; licences are provisioned directly by our team rather than through online checkout. Get in touch and we will confirm scope, sizing and fit for your estate.
Capabilities
Weardian covers the whole loop rather than a slice of it — the gap most teams fill with a scanner, a deployment tool, a spreadsheet and a screenshot folder.
Build a live inventory of managed Windows hosts — installed software, update state, configuration and ownership — without an internet path.
Evaluate hosts against DISA STIG, CIS and Microsoft security baselines, and against a curated vulnerability catalogue delivered as signed content packs.
Rank exposure by what is actually reachable and actually exploited, so remediation effort follows risk rather than raw CVE counts.
Deploy updates under change control with staged rollout rings and defined change windows — approval-gated, auditable, and reversible.
Produce signed, hash-verifiable evidence bundles an assessor can follow end to end, plus an assurance score that shows its working rather than asserting a number.
Separate duties between operators, approvers and auditors, with a complete audit log and a risk register tracking accepted risk, ownership and remediation commitments.
Architecture
The trust boundary is the design rather than a configuration option. Weardian runs entirely inside your network, with no outbound connection required at any point in normal operation.
The console serves both the API and the web interface. No separate web server, no Node runtime, no external database required — an embedded database by default, or PostgreSQL if you prefer.
Ships as a relocatable bundle carrying its own runtime, so it installs on a disconnected Windows Server or Ubuntu LTS host with no internet access and no package manager involved.
No telemetry, no runtime callbacks, no outbound connectivity in the isolated environment. Licensing is a signed file applied by hand — there is no activation server to reach.
The companion Content Builder fetches and curates vulnerability and baseline content on a connected host, signs it, and ships it across the boundary as a verifiable content pack.
Compliance
Weardian maps its live signals onto the controls they genuinely evidence, and is deliberate about not overclaiming. Every assessment leads with a coverage statement — how many controls were assessed, how many are mapped but supporting, and how many are out of scope — so an assessor knows precisely what a score does and does not represent.
| Framework | What Weardian evidences |
|---|---|
| Cyber Essentials Plus | Security update management and secure configuration directly; firewalls, access control and malware protection as supporting. |
| NCSC CAF (v4.0) | Risk, asset and system-security principles directly; others supporting or out of scope. |
| ISO/IEC 27001:2022 | 7 of the 93 Annex A controls — the technically observable ones, led by A.8.8 vulnerability management, A.5.9 asset inventory and A.8.19 software installation. The remainder require separate assessment. |
| SOC 2 | CC6.1 asset inventory, CC7.1 vulnerability remediation, CC8.1 change and configuration management. |
| NIST CSF 2.0 | ID.AM inventory, ID.RA-01 vulnerability identification, PR.PS configuration and software maintenance. |
| DORA | Article 8 ICT asset identification; Article 9 vulnerability and patch management, and secure configuration. |
| NIS2 | Article 21(2) asset management, vulnerability handling and secure configuration. |
This is assurance and readiness evidence — never a certification, and never a vendor claim standing in for proof.
Licensing & Pricing
Weardian is a commercial product, source-available under the Business Source Licence 1.1. Production use requires a paid licence — there is no free production tier. All prices are annual, in GBP, excluding any applicable tax.
£7,500/year
Includes 50 managed hosts
The complete platform including Content Builder and every capability described above, licensed for a defined number of managed hosts.
£2,500/year
Adds 50 managed hosts
Expands an existing subscription. Capacity is carried on the installed licence file, so the console picks it up without reinstallation.
£25,000/year
No per-host limit
Added to an existing subscription for estates beyond the point where per-host licensing is practical.
Licences are delivered as offline, cryptographically signed files and applied by hand — suited to disconnected deployment, with no activation server and no phone-home. Because each licence is issued and bound to your estate directly by our team, Weardian is purchased through sales rather than online checkout; contact us to confirm sizing and provision your licence.
Known Limitations
We publish the boundaries of the product alongside its capabilities, because a security tool you cannot calibrate is a security tool you cannot rely on. The list below is maintained with each release and shipped in full with the release notes — nothing here is a surprise we would rather you found later.
| Area | Limitation |
|---|---|
| Platform support | Both the console and the Content Builder are published for Windows x86_64 and Linux x86_64. Other architectures (for example ARM64) are not currently built. |
| Intune / WSUS / SCCM | These connectors are experimental and optional. They have not been validated against live infrastructure — Intune is covered only against a mock Graph server. The supported path is the native engine. |
| Vendor intelligence | Advisories cover Microsoft MSRC only. No third-party vendor feeds yet, and vendor intelligence is display-only context — it never alters the assurance score. |
| Malware protection | Weardian observes anti-malware update findings, not installed AV products or their versions. Malware protection is therefore assessed as a supporting control, never directly evidenced. |
| ISO 27001 coverage | 7 of the 93 Annex A controls are mapped. Most of Annex A requires separate assessment, and every report states its coverage explicitly. |
| Compliance history | Framework assessments are point-in-time. Only the Assurance Score is snapshotted, so reported trends reflect assurance rather than per-framework history. |
| Patch windows | Framework-specific windows (for example Cyber Essentials Plus 14-day) are cited rather than independently recomputed. Assessment runs against the SLA you configure. |
| Sizing figures | Published sizing is a planning starting point, not a validated benchmark. It should be confirmed against your own environment. |
| Deployment guides | Deployment, upgrade and disaster-recovery guides are written but not yet hands-on validated on a clean host. |
| Licence enforcement | Each activated console receives the full entitlement, and an air-gapped console cannot know that others exist — so host limits are enforced contractually rather than technically across consoles. An issued licence bundle cannot be recalled before its TTL expires. |
The complete list, including items we judged too minor for this page, ships with every release — see the release notes. If a limitation here is material to your estate, tell us: it is better raised before a purchase than after one.
Tell us about your estate — size, isolation posture and the frameworks you report against — and we will come back with scope, timing and whether Weardian is the right fit.