You already run an RMM, an EDR, a SOC portal, a registrar, a DNS provider and a cloud console. None of them can see each other. NetFoundry is the virtual layer — one console over every yard and every cloud account, correlating what your tools already know — adds the telemetry nobody else collects, and gives you a safe way to act on it.
| Host | Yard | Agent | Status |
|---|---|---|---|
| hq-fw-01edge | Miami HQ | Linux | OK |
| wh2-nasstorage | Warehouse 2 | Linux | OK |
| clinic-dc-01 | Clinic North | Windows | Drift |
| api-prod-euaws | — cloud | Linux | OK |
The virtual layer. Every yard and every cloud account you're responsible for, on one console.
If you manage infrastructure for more than one client, site or cloud account, your visibility is split across a dozen consoles — and the failures live in the seams.
Everything needing attention today, ranked by severity across every client — one click to the thing itself. Plus a Map mode showing where your fleet physically is.
Deep live telemetry on every machine, and safe remote control without opening a terminal.
Physical locations as first-class objects — what's installed, who the ISP is, how good the link is — enriched by NetYard.
A service drawn as the chain of things it depends on, with live status on every link.
Thirteen platforms you already pay for. Read-only, credentials encrypted, scoped per client.
RMM, EDR and SOC data from different vendors correlated into one posture per machine — including the machines missing from one of them.
A service is modeled as the chain of hops it actually depends on. NetFoundry resolves live status for each hop from the best source available. The degraded hop is the answer — no bisecting a dependency chain under pressure.
Container state and host reachability come from telemetry NetFoundry already collects. DNS, certificates, proxy and cloud status come from the APIs of tools you already run.
Point a service at its URL and NetFoundry auto-matches the DNS record and certificate, rather than making you browse account → domain → record.
When a hop can't be read because an API token is missing a scope, it says exactly that — it never reports a permission problem as "record not found".
Consecutive container stacks collapse into one card; so do consecutive DNS records. A long chain stays legible on a single screen.
Domain registration and TLS expiry aren't a calendar reminder — they're a warning on the hop that will take the service down.
A domain in two linked accounts, a zone past 100 records, a registrar separate from the DNS provider — all handled, because each one broke it once and was fixed.
A lightweight agent on every machine — Linux, macOS and Windows — reports in on a regular cycle over the overlay. Gateways maintain a continuous heartbeat. What comes back is substantially deeper than typical RMM inventory.
CPU, memory, disk; physical-disk SMART; and temperatures with hardware-aware thresholds — a classifier knows 70 °C means something different for an NVMe drive than a CPU package. Real alerts, not a wall of amber.
Every Docker container and Compose stack with state, image and health. NetFoundry classifies how far behind each image is — major / minor / patch. "We're behind" becomes "one major version on three images".
Independent detection of ZeroTier, Tailscale and NetBird, plus RMM and MDM enrollment (Datto, Mosyle, Jamf, Intune, Kaseya, Fleet). This is how you find out what's really installed — not what the asset sheet claims.
A Nebula listen port statically pinned in a way that defeats UDP hole-punching — quietly forcing traffic through relays and costing you throughput. Flagged with a badge, not buried in a config file.
OS and kernel version, hypervisor detection with Proxmox guest inventory, pending OS updates split out by security severity, and reboot-required state.
Expiry tracking, soft revocation, and duplicate-certificate detection catching both IP oscillation and hostname mismatch — with a full detected → active → resolved history.
Hosts tell you about machines. Sites tell you about places — and a place has things a machine can't report: who the ISP is, how good the uplink is, what gear is installed, and whether it's still alive. NetYard, our on-site monitoring product, is the authoritative source for what's happening on the ground.
Cloud → modem → router → switch → access points → WiFi point-to-point → bridges → servers, each with live state. Ordered the way you actually troubleshoot.
Internet provider plus speedtest history. When a client says "the internet is slow", you answer with data instead of their impression of it.
Gateway ping, upstream ping and DNS resolution as an indicator grid, with paginated active alerts — including a "device down" entry for every piece of gear that's gone silent.
NetFoundry spots a NetYard instance on a monitored host and offers to connect it from the site card. Paste the key once — encrypted at rest, never returned to the browser.
A reverse proxy puts the NetYard interface on NetFoundry's own origin, so your browser never needs to reach the site's internal IP. Each site also gets a permanent bookmarkable URL that works with a password manager.
The integration is read-only, and NetYard's behavioral endpoints are intentionally excluded — that data is governance-sensitive and has no business in a fleet console.
Visibility you can't act on is just a dashboard. Update agents, update the Nebula binary, restart, reboot, apply OS updates, repair a broken config — one click, no SSH. And for the changes that can actually break something, a staged apply with real rollback.
Autocomplete over your actual certificate groups — ranked exact → prefix → substring, tie-broken by how many hosts carry the group, with a hover preview of which hosts those are. Stale groups flagged.
Review the exact YAML change, then watch a 5-step apply progress through snapshot → validate → write → reload → verify.
If any step fails, the revert covers the config file, iptables, sysctl and the running tunnel — together. Not three of four. Every attempt is audit-logged, success or not.
Gateway mode refuses to engage on an nftables host with a clear explanation rather than half-applying. A certificate whose permitted subnets don't match blocks the toggle and hands you the signing command.
The agent keeps a last-known-good config. If the tunnel is down it attempts known repairs, restarts and verifies — and if the repair fails it rolls back to the last good config. Every action is reported and visible, so self-healing is never silent.
A host that loses connectivity raises its own rescue WiFi access point. Join it and a captive portal lets you add a WiFi network or set Ethernet static/DHCP. The host reconnects itself.
Two-tier: a freshly-booted host that never reached the internet raises the AP after a short grace. A host that was online waits a rigid 10-minute grace before disrupting a service that might just be blipping.
Drive a host's rescue settings remotely over the overlay — read live status, force the AP up or down, set a static IP or DHCP on its Ethernet interfaces. Credentials encrypted at rest, superadmin-gated.
Your RMM knows about endpoints. Your EDR knows about threats. Your SOC portal knows about incidents. None of them knows what the others are missing. NetFoundry correlates all three into one posture row per machine.
| Host | RMM | EDR | SOC | NetFoundry agent | Verdict |
|---|---|---|---|---|---|
| acme-app01 | ✓ Online | ✓ Protected | ✓ Monitored | ✓ Reporting | ✓ Healthy |
| acme-jdoe-laptop | ✓ Online | ✕ Threat | ✓ Monitored | — not installed | ✕ At risk |
| acme-fs02 | ✓ Online | ✓ Protected | — not in SOC | ✓ Reporting | ! Coverage gap |
| acme-bkup01 | — not in RMM | — not installed | — not in SOC | ✓ Reporting | ! Unmanaged |
An EDR threat or an open SOC incident — not a coverage gap. An earlier build conflated the two and flagged nearly every managed laptop; correcting it took at-risk from 167 to 7 on live data.
Low-severity behavioral telemetry stays visible as detections but doesn't inflate the number. On live data this was the difference between 190 "threats" and 24 real ones.
The RMM Gap Report lists machines your RMM manages with no NetFoundry agent, and the inverse — matching acme-jdoe-laptop to an RMM hostname of jdoe-laptop without false positives on short names.
Archive an EDR alert — reversible, confirmation-gated. Host isolation is deliberately not exposed: an undocumented API that disconnects live endpoints isn't something a dashboard should offer.
Thirteen read-only integrations. Credentials encrypted at rest and scoped per client, so a client administrator sees their own accounts and nothing else. NetFoundry never needs write access to your DNS, your cloud, or your security tooling.
Read from your BigQuery billing export, net of credits, this month and last — the only way to get actual spend out of GCP. NetFoundry finds the export table for you, and shows configured budgets beside it.
Reserved-but-unattached external IPs, which GCP bills at a higher rate than attached ones. Quiet, recurring, easy to miss. Plus firewall rules opening SSH, RDP or database ports to the world.
A unified overview totals spend across Google Cloud, Vercel, Sanity and Mailchimp — visible to client administrators for their own projects, because the person accountable for the bill should see it.
Every integration form carries exact step-by-step instructions — which token type, which scopes, which API to enable, which IAM role, and where in that vendor's console to find it. Least-privilege throughout.
A single command, generated for you by an in-app installer that walks through picking the reachable network, naming the certificate, and verifying the certificate bundle exists before you start. Windows enrollment in particular is hardened against what actually breaks in the field:
NetFoundry mirrors and caches the Nebula release itself, so the host downloads from the server it has already proven it can reach — removing a hop that fails behind TLS-inspecting EDR or a corporate proxy.
Many Windows builds still default to a protocol set that is TLS 1.0-only. Enrollment forces 1.2 before any HTTPS call, with a clear error if the machine genuinely can't.
The installer pre-excludes the install directory, verifies the binary at two checkpoints, and if something quarantined it, names the actual product by scanning running protection services — instead of blaming Defender on a machine where Defender isn't installed.
Live streaming output during deploy, with recent attempts shown in the UI. When we say enrollment is reliable, that reliability is each of these failure modes being hit in production and closed.
NetFoundry installs as a single service and runs where you put it. No separate database to provision, no message broker, no cluster to operate.
Deployment runs on infrastructure you control. Your telemetry, your credentials and your clients' data stay there. There is no NetFoundry cloud to send it to.
Agents are lightweight scripts run by each operating system's own built-in scheduler. No third-party runtime to install on a managed host.
Companies, sites and tag-based grouping run through every view and permission check. Superadmin, client administrator and guest roles, enforced on the server — not merely hidden in the UI.
Full iPhone portrait and landscape layouts — not a shrunken desktop site — with adjustable UI scale, plus light and dark themes. Authentik single sign-on and superadmin impersonation for support calls.
The most meaningful improvements came from running against real production accounts and finding the numbers wrong — security counts 8× too high, a gap report matching 0 of 21 obvious pairs, a cloud account undercounting incidents by 34. Each traced to a cause and fixed. That's why the dashboard numbers can be trusted.
Where a vendor exposes no API, NetFoundry says so and links you to the console rather than inventing a number. Where a capability is risky, it isn't shipped just because it's possible.
You already have the tools. NetFoundry gives you the one thing none of them can: the whole picture, correlated, with a safe way to act on it.