NetFoundry

One console for the infrastructure you're responsible for.

You already run an RMM, an EDR, a SOC portal, a registrar, a DNS provider and a cloud console. None of them can see each other. NetFoundry is the virtual layer — one console over every yard and every cloud account, correlating what your tools already know — adds the telemetry nobody else collects, and gives you a safe way to act on it.

NetFoundry · All clients · 4 yards · 98 hosts · 13 integrationslive
Yards 4 sites · 3 clients
Miami HQ41 devices · NetYard
Warehouse 218 devices · NetYard
Clinic North27 devices · uplink degraded
Doral Office12 devices · NetYard
Cloud & services read-only integrations
AWS2 accounts
Cloudflare9 zones
Workspace146 users
Datto RMM98 agents
*.exora.comcert · 9 days left
Hosts recent
HostYardAgentStatus
hq-fw-01edgeMiami HQLinuxOK
wh2-nasstorageWarehouse 2LinuxOK
clinic-dc-01Clinic NorthWindowsDrift
api-prod-euaws— cloudLinuxOK

The virtual layer. Every yard and every cloud account you're responsible for, on one console.

What you're living with

Nothing is wrong with your tools. The problem is the space between them.

The gap

Nothing is wrong with your tools. The problem is the space between them.

If you manage infrastructure for more than one client, site or cloud account, your visibility is split across a dozen consoles — and the failures live in the seams.

A customer reports an outage.You know the symptom. You don't know which hop broke — so you start guessing. DNS? Certificate? Proxy? Container? Host? ISP?
A machine is quietly unmanaged.It has an RMM agent but no VPN agent. Or EDR but no RMM. Nothing reports this, because no single tool sees both sides.
A certificate or domain expires.It was on somebody's calendar once.
A headless host loses its network.Now it needs a site visit, a drive, and an afternoon.
Cloud spend drifts.You find out at invoice time, from an invoice.
A config change goes wrong at 2am.No snapshot, no diff, no rollback — just SSH and hope.
What it does

One console. Six views. Every client.

📊

Dashboard

Everything needing attention today, ranked by severity across every client — one click to the thing itself. Plus a Map mode showing where your fleet physically is.

🖥

Hosts

Deep live telemetry on every machine, and safe remote control without opening a terminal.

📍

Sites

Physical locations as first-class objects — what's installed, who the ISP is, how good the link is — enriched by NetYard.

🔗

Services

A service drawn as the chain of things it depends on, with live status on every link.

🔌

Integrations

Thirteen platforms you already pay for. Read-only, credentials encrypted, scoped per client.

🛡

Security

RMM, EDR and SOC data from different vendors correlated into one posture per machine — including the machines missing from one of them.

The flow-map

Answer "where is it broken?" in one screen.

A service is modeled as the chain of hops it actually depends on. NetFoundry resolves live status for each hop from the best source available. The degraded hop is the answer — no bisecting a dependency chain under pressure.

◆ acme-client-portal  ·  portal.acme.example
! Degraded
DNS · CNAME
portal.acme.example
✓ Resolving
TLS cert
Let's Encrypt · 68 days left
✓ Valid
Proxy
Nginx Proxy Manager
✓ Online
Docker
portal-api · unhealthy
! Degraded
Host
acme-app01 · active
✓ Reachable
Cloud
GCP · us-east1
✓ Running
!
The container is running but failing its healthcheck. Everything upstream is fine — DNS resolves, the certificate is valid, the proxy is up, the host is reachable. You have your answer before you've opened a terminal.
◎

No new probes required

Container state and host reachability come from telemetry NetFoundry already collects. DNS, certificates, proxy and cloud status come from the APIs of tools you already run.

⌖

It finds the hop for you

Point a service at its URL and NetFoundry auto-matches the DNS record and certificate, rather than making you browse account → domain → record.

⚐

Honest failure messages

When a hop can't be read because an API token is missing a scope, it says exactly that — it never reports a permission problem as "record not found".

⧉

It stays readable

Consecutive container stacks collapse into one card; so do consecutive DNS records. A long chain stays legible on a single screen.

⧗

Expiry is part of the chain

Domain registration and TLS expiry aren't a calendar reminder — they're a warning on the hop that will take the service down.

⚯

It survives messy real estate

A domain in two linked accounts, a zone past 100 records, a registrar separate from the DNS provider — all handled, because each one broke it once and was fixed.

Telemetry

See more about a host than the host's own owner does.

A lightweight agent on every machine — Linux, macOS and Windows — reports in on a regular cycle over the overlay. Gateways maintain a continuous heartbeat. What comes back is substantially deeper than typical RMM inventory.

🌡

Hardware health that isn't noise

CPU, memory, disk; physical-disk SMART; and temperatures with hardware-aware thresholds — a classifier knows 70 °C means something different for an NVMe drive than a CPU package. Real alerts, not a wall of amber.

📦

Containers, with upstream drift

Every Docker container and Compose stack with state, image and health. NetFoundry classifies how far behind each image is — major / minor / patch. "We're behind" becomes "one major version on three images".

🔍

What's actually on the machine

Independent detection of ZeroTier, Tailscale and NetBird, plus RMM and MDM enrollment (Datto, Mosyle, Jamf, Intune, Kaseya, Fleet). This is how you find out what's really installed — not what the asset sheet claims.

🖧

Misconfiguration you'd never spot

A Nebula listen port statically pinned in a way that defeats UDP hole-punching — quietly forcing traffic through relays and costing you throughput. Flagged with a badge, not buried in a config file.

🧱

Platform & virtualization

OS and kernel version, hypervisor detection with Proxmox guest inventory, pending OS updates split out by security severity, and reboot-required state.

📜

Certificate lifecycle

Expiry tracking, soft revocation, and duplicate-certificate detection catching both IP oscillation and hostname mismatch — with a full detected → active → resolved history.

Sites & NetYard

Know what's happening at every physical site.

Hosts tell you about machines. Sites tell you about places — and a place has things a machine can't report: who the ISP is, how good the uplink is, what gear is installed, and whether it's still alive. NetYard, our on-site monitoring product, is the authoritative source for what's happening on the ground.

◎

Infrastructure in engineer-order

Cloud → modem → router → switch → access points → WiFi point-to-point → bridges → servers, each with live state. Ordered the way you actually troubleshoot.

⇅

ISP and link quality

Internet provider plus speedtest history. When a client says "the internet is slow", you answer with data instead of their impression of it.

◴

Reachability at a glance

Gateway ping, upstream ping and DNS resolution as an indicator grid, with paginated active alerts — including a "device down" entry for every piece of gear that's gone silent.

🔗

Auto-detected setup

NetFoundry spots a NetYard instance on a monitored host and offers to connect it from the site card. Paste the key once — encrypted at rest, never returned to the browser.

↗

Open NetYard from anywhere

A reverse proxy puts the NetYard interface on NetFoundry's own origin, so your browser never needs to reach the site's internal IP. Each site also gets a permanent bookmarkable URL that works with a password manager.

🔒

Deliberate boundaries

The integration is read-only, and NetYard's behavioral endpoints are intentionally excluded — that data is governance-sensitive and has no business in a fleet console.

Remote action

Change configuration remotely — with a seatbelt.

Visibility you can't act on is just a dashboard. Update agents, update the Nebula binary, restart, reboot, apply OS updates, repair a broken config — one click, no SSH. And for the changes that can actually break something, a staged apply with real rollback.

✎

Firewall rules with real autocomplete

Autocomplete over your actual certificate groups — ranked exact → prefix → substring, tie-broken by how many hosts carry the group, with a hover preview of which hosts those are. Stale groups flagged.

≠

Line-by-line diff before anything writes

Review the exact YAML change, then watch a 5-step apply progress through snapshot → validate → write → reload → verify.

↺

Atomic rollback across all four surfaces

If any step fails, the revert covers the config file, iptables, sysctl and the running tunnel — together. Not three of four. Every attempt is audit-logged, success or not.

⚠

Pre-flight, not post-mortem

Gateway mode refuses to engage on an nftables host with a clear explanation rather than half-applying. A certificate whose permitted subnets don't match blocks the toggle and hands you the signing command.

Resilience

Infrastructure that recovers without a site visit.

🩹

Agent self-heal with rollback

The agent keeps a last-known-good config. If the tunnel is down it attempts known repairs, restarts and verifies — and if the repair fails it rolls back to the last good config. Every action is reported and visible, so self-healing is never silent.

📶

NetRescue — a rescue AP for headless hosts

A host that loses connectivity raises its own rescue WiFi access point. Join it and a captive portal lets you add a WiFi network or set Ethernet static/DHCP. The host reconnects itself.

⏱

A trigger that respects uptime

Two-tier: a freshly-booted host that never reached the internet raises the AP after a short grace. A host that was online waits a rigid 10-minute grace before disrupting a service that might just be blipping.

🛰

And you don't even need to be on site

Drive a host's rescue settings remotely over the overlay — read live status, force the AP up or down, set a static IP or DHCP on its Ethernet interfaces. Credentials encrypted at rest, superadmin-gated.

Security correlation

Catch the machines falling through the cracks.

Your RMM knows about endpoints. Your EDR knows about threats. Your SOC portal knows about incidents. None of them knows what the others are missing. NetFoundry correlates all three into one posture row per machine.

HostRMMEDRSOCNetFoundry agentVerdict
acme-app01 ✓ Online ✓ Protected ✓ Monitored ✓ Reporting ✓ Healthy
acme-jdoe-laptop ✓ Online ✕ Threat ✓ Monitored — not installed ✕ At risk
acme-fs02 ✓ Online ✓ Protected — not in SOC ✓ Reporting ! Coverage gap
acme-bkup01 — not in RMM — not installed — not in SOC ✓ Reporting ! Unmanaged
①

"At risk" means a real event

An EDR threat or an open SOC incident — not a coverage gap. An earlier build conflated the two and flagged nearly every managed laptop; correcting it took at-risk from 167 to 7 on live data.

②

Only medium-and-above counts

Low-severity behavioral telemetry stays visible as detections but doesn't inflate the number. On live data this was the difference between 190 "threats" and 24 real ones.

③

Gaps reported separately, and precisely

The RMM Gap Report lists machines your RMM manages with no NetFoundry agent, and the inverse — matching acme-jdoe-laptop to an RMM hostname of jdoe-laptop without false positives on short names.

④

Restraint where it matters

Archive an EDR alert — reversible, confirmation-gated. Host isolation is deliberately not exposed: an undocumented API that disconnects live endpoints isn't something a dashboard should offer.

Integrations

Everything else you're paying for, in one place.

Thirteen read-only integrations. Credentials encrypted at rest and scoped per client, so a client administrator sees their own accounts and nothing else. NetFoundry never needs write access to your DNS, your cloud, or your security tooling.

☁
Cloudflare
DNS · registrar
🌐
GoDaddy
DNS · registrar
🟦
Google Cloud
Cloud
▲
Vercel
Hosting
🅢
Sanity
CMS
Ⓦ
Webflow
CMS
🅆
Wix
CMS
🅝
Nginx Proxy Mgr
Proxy
🛡
Authentik
Identity
🛰️
Datto RMM
Security
🦠
Datto EDR
Security
🚨
RocketCyber
Security · SOC
🐵
Mailchimp
Marketing
💳

Real cloud spend, not estimates

Read from your BigQuery billing export, net of credits, this month and last — the only way to get actual spend out of GCP. NetFoundry finds the export table for you, and shows configured budgets beside it.

🫧

Waste you can't currently see

Reserved-but-unattached external IPs, which GCP bills at a higher rate than attached ones. Quiet, recurring, easy to miss. Plus firewall rules opening SSH, RDP or database ports to the world.

∑

One billing total

A unified overview totals spend across Google Cloud, Vercel, Sanity and Mailchimp — visible to client administrators for their own projects, because the person accountable for the bill should see it.

ⓘ

Setup documented in the product

Every integration form carries exact step-by-step instructions — which token type, which scopes, which API to enable, which IAM role, and where in that vendor's console to find it. Least-privilege throughout.

Onboarding

Adding a machine is a single command.

A single command, generated for you by an in-app installer that walks through picking the reachable network, naming the certificate, and verifying the certificate bundle exists before you start. Windows enrollment in particular is hardened against what actually breaks in the field:

⤓

The target never needs GitHub

NetFoundry mirrors and caches the Nebula release itself, so the host downloads from the server it has already proven it can reach — removing a hop that fails behind TLS-inspecting EDR or a corporate proxy.

🔐

TLS 1.2 forced up front

Many Windows builds still default to a protocol set that is TLS 1.0-only. Enrollment forces 1.2 before any HTTPS call, with a clear error if the machine genuinely can't.

🛡

Antivirus quarantine named, not guessed

The installer pre-excludes the install directory, verifies the binary at two checkpoints, and if something quarantined it, names the actual product by scanning running protection services — instead of blaming Defender on a machine where Defender isn't installed.

📋

Every attempt logged

Live streaming output during deploy, with recent attempts shown in the UI. When we say enrollment is reliable, that reliability is each of these failure modes being hit in production and closed.

Deployment

One self-contained service. On your own infrastructure.

NetFoundry installs as a single service and runs where you put it. No separate database to provision, no message broker, no cluster to operate.

Gatewayscontinuous heartbeat
Client hostsLinux · macOS · Windows — regular reports
│   push over the overlay   ▼
NetFoundryone self-contained service, for your infrastructure
▼   read-only   ▼
NetYardper site
Your existing platformsDNS · cloud · RMM · EDR · SOC · proxy
🏠

Your data never leaves your hardware

Deployment runs on infrastructure you control. Your telemetry, your credentials and your clients' data stay there. There is no NetFoundry cloud to send it to.

🪶

Nothing proprietary on your endpoints

Agents are lightweight scripts run by each operating system's own built-in scheduler. No third-party runtime to install on a managed host.

👥

Built for multi-tenant work

Companies, sites and tag-based grouping run through every view and permission check. Superadmin, client administrator and guest roles, enforced on the server — not merely hidden in the UI.

📱

Works on the phone you actually have

Full iPhone portrait and landscape layouts — not a shrunken desktop site — with adjustable UI scale, plus light and dark themes. Authentik single sign-on and superadmin impersonation for support calls.

Why this is credible

Every hardened path here exists because it broke something real first.

317
Releases of production iteration
546
Commits
13
Platform integrations
167→7
False "at risk" hosts, corrected against live data
🔬

Validated against live data, repeatedly

The most meaningful improvements came from running against real production accounts and finding the numbers wrong — security counts 8× too high, a gap report matching 0 of 21 obvious pairs, a cloud account undercounting incidents by 34. Each traced to a cause and fixed. That's why the dashboard numbers can be trusted.

🤝

Honest about its limits

Where a vendor exposes no API, NetFoundry says so and links you to the console rather than inventing a number. Where a capability is risky, it isn't shipped just because it's possible.

You already have the tools. NetFoundry gives you the one thing none of them can: the whole picture, correlated, with a safe way to act on it.