Windows Patch & Posture Assurance

AuditToolkit Weardian

Self-hosted patch and security-posture assurance for Windows estates that cannot reach the internet. Discover what you run, assess it against recognised baselines, prioritise by real exposure, remediate under change control, and leave an assessor a signed trail of exactly what happened.

Available now · v2.3.0 Self-hosted Air-gap native BSL 1.1

Availability

Weardian is generally available. Release v2.3.0 is published and signed, with the console and the Content Builder available to download for Windows x86_64 and Linux x86_64, each carrying its SBOM, vulnerability scan and detached signature.

Production use requires a paid licence under the Business Source Licence 1.1 — there is no free production tier. Pricing is below; licences are provisioned directly by our team rather than through online checkout. Get in touch and we will confirm scope, sizing and fit for your estate.

Capabilities

One platform, from finding to evidence

Weardian covers the whole loop rather than a slice of it — the gap most teams fill with a scanner, a deployment tool, a spreadsheet and a screenshot folder.

Discover

Build a live inventory of managed Windows hosts — installed software, update state, configuration and ownership — without an internet path.

Assess

Evaluate hosts against DISA STIG, CIS and Microsoft security baselines, and against a curated vulnerability catalogue delivered as signed content packs.

Prioritise

Rank exposure by what is actually reachable and actually exploited, so remediation effort follows risk rather than raw CVE counts.

Remediate

Deploy updates under change control with staged rollout rings and defined change windows — approval-gated, auditable, and reversible.

Prove

Produce signed, hash-verifiable evidence bundles an assessor can follow end to end, plus an assurance score that shows its working rather than asserting a number.

Govern

Separate duties between operators, approvers and auditors, with a complete audit log and a risk register tracking accepted risk, ownership and remediation commitments.

Architecture

Air-gap native, not air-gap adapted

The trust boundary is the design rather than a configuration option. Weardian runs entirely inside your network, with no outbound connection required at any point in normal operation.

Single host, single process

The console serves both the API and the web interface. No separate web server, no Node runtime, no external database required — an embedded database by default, or PostgreSQL if you prefer.

Zero prerequisites on the target

Ships as a relocatable bundle carrying its own runtime, so it installs on a disconnected Windows Server or Ubuntu LTS host with no internet access and no package manager involved.

No phone-home. Ever.

No telemetry, no runtime callbacks, no outbound connectivity in the isolated environment. Licensing is a signed file applied by hand — there is no activation server to reach.

A signed supply line

The companion Content Builder fetches and curates vulnerability and baseline content on a connected host, signs it, and ships it across the boundary as a verifiable content pack.

Compliance

Framed honestly

Weardian maps its live signals onto the controls they genuinely evidence, and is deliberate about not overclaiming. Every assessment leads with a coverage statement — how many controls were assessed, how many are mapped but supporting, and how many are out of scope — so an assessor knows precisely what a score does and does not represent.

Framework What Weardian evidences
Cyber Essentials Plus Security update management and secure configuration directly; firewalls, access control and malware protection as supporting.
NCSC CAF (v4.0) Risk, asset and system-security principles directly; others supporting or out of scope.
ISO/IEC 27001:2022 7 of the 93 Annex A controls — the technically observable ones, led by A.8.8 vulnerability management, A.5.9 asset inventory and A.8.19 software installation. The remainder require separate assessment.
SOC 2 CC6.1 asset inventory, CC7.1 vulnerability remediation, CC8.1 change and configuration management.
NIST CSF 2.0 ID.AM inventory, ID.RA-01 vulnerability identification, PR.PS configuration and software maintenance.
DORA Article 8 ICT asset identification; Article 9 vulnerability and patch management, and secure configuration.
NIS2 Article 21(2) asset management, vulnerability handling and secure configuration.

This is assurance and readiness evidence — never a certification, and never a vendor claim standing in for proof.

Licensing & Pricing

Annual subscription, priced by managed hosts

Weardian is a commercial product, source-available under the Business Source Licence 1.1. Production use requires a paid licence — there is no free production tier. All prices are annual, in GBP, excluding any applicable tax.

Weardian Platform

£7,500/year

Includes 50 managed hosts

The complete platform including Content Builder and every capability described above, licensed for a defined number of managed hosts.

Additional host pack

£2,500/year

Adds 50 managed hosts

Expands an existing subscription. Capacity is carried on the installed licence file, so the console picks it up without reinstallation.

Unlimited hosts

£25,000/year

No per-host limit

Added to an existing subscription for estates beyond the point where per-host licensing is practical.

Licences are delivered as offline, cryptographically signed files and applied by hand — suited to disconnected deployment, with no activation server and no phone-home. Because each licence is issued and bound to your estate directly by our team, Weardian is purchased through sales rather than online checkout; contact us to confirm sizing and provision your licence.

Known Limitations

What Weardian does not do

We publish the boundaries of the product alongside its capabilities, because a security tool you cannot calibrate is a security tool you cannot rely on. The list below is maintained with each release and shipped in full with the release notes — nothing here is a surprise we would rather you found later.

Area Limitation
Platform support Both the console and the Content Builder are published for Windows x86_64 and Linux x86_64. Other architectures (for example ARM64) are not currently built.
Intune / WSUS / SCCM These connectors are experimental and optional. They have not been validated against live infrastructure — Intune is covered only against a mock Graph server. The supported path is the native engine.
Vendor intelligence Advisories cover Microsoft MSRC only. No third-party vendor feeds yet, and vendor intelligence is display-only context — it never alters the assurance score.
Malware protection Weardian observes anti-malware update findings, not installed AV products or their versions. Malware protection is therefore assessed as a supporting control, never directly evidenced.
ISO 27001 coverage 7 of the 93 Annex A controls are mapped. Most of Annex A requires separate assessment, and every report states its coverage explicitly.
Compliance history Framework assessments are point-in-time. Only the Assurance Score is snapshotted, so reported trends reflect assurance rather than per-framework history.
Patch windows Framework-specific windows (for example Cyber Essentials Plus 14-day) are cited rather than independently recomputed. Assessment runs against the SLA you configure.
Sizing figures Published sizing is a planning starting point, not a validated benchmark. It should be confirmed against your own environment.
Deployment guides Deployment, upgrade and disaster-recovery guides are written but not yet hands-on validated on a clean host.
Licence enforcement Each activated console receives the full entitlement, and an air-gapped console cannot know that others exist — so host limits are enforced contractually rather than technically across consoles. An issued licence bundle cannot be recalled before its TTL expires.

The complete list, including items we judged too minor for this page, ships with every release — see the release notes. If a limitation here is material to your estate, tell us: it is better raised before a purchase than after one.

Interested in Weardian?

Tell us about your estate — size, isolation posture and the frameworks you report against — and we will come back with scope, timing and whether Weardian is the right fit.