Nodara

Ten thousand machines. One instrument.

Nodara is the control plane for every endpoint an organisation owns — a stream held open to each machine, command execution that only runs what was signed, and remote support that waits to be let in.

See what it does Find your fit

The premise

Most consoles ask you to watch. This one decides.

A monitoring tool that reports everything reports nothing. Nodara collapses the noise before it reaches a person: alerts are fingerprinted so one failure raises one ticket, thresholds only fire once a breach has held, and scheduled maintenance suppresses the pager while still counting what it silenced.

Heartbeat
60 seconds
Declared offline
0 delay — on stream drop
Inventory sweep
6 hours
Rollout halts at
20% failure

The instrument

Everything an operator needs, engraved into one surface.

Live fleet telemetry

Every endpoint holds an authenticated gRPC stream open and reports on a sixty-second heartbeat. Offline is not inferred from missed beats — the moment the stream drops, the console knows. No silent failures waiting to be discovered by a user.

gRPC · per-device keys

Inventory on a slow ticker

Hardware, disks, services and installed software are swept every six hours and kept per device, so a machine's configuration is something you look up rather than something you go and ask it for.

6h sweep · per-device

Alerting without the storm

Alerts are grouped by root cause and asset, gated on sustained duration, and muted inside maintenance windows. Anything critical left unacknowledged escalates on a deadline — exactly once.

Dedup · escalation SLA

Remote support that asks first

Screen control runs peer-to-peer in the browser over encrypted WebRTC, relayed through TURN when firewalls block a direct path. Where policy requires it, the person at the desk approves before anything is seen.

DTLS-SRTP · consent gate

Patching on your calendar

Policies decide which categories are approved, which are denied, and when installs may run. Active hours are honoured, so a business-critical machine is never rebooted mid-shift. Every device carries a live count of what it is missing, security updates called out separately.

Policy windows · active hours

Rollouts that stop themselves

Ship to a canary ring first, pause, then widen. If failures in any ring pass the budget, the rollout halts on its own and raises a technician rather than continuing into the fleet.

Rings · 20% budget

Commands with a short vocabulary

Agents execute a vetted list and nothing else — scripts on allow-listed interpreters, service restarts, reboots, patch scans. Scripts can run as an unprivileged user, or be switched off entirely.

Allow-list · privilege drop

Policy that resolves predictably

Settings inherit from tenant to site to group to device, with a precedence order that is written down and tested. Change one and the configuration epoch increments, pushing to every online agent at once.

4 levels · live push

Reports your client can read

Uptime derived from recorded status history rather than optimistic maths, exported as PDF, HTML or CSV under your own logo and colours, on a schedule that lands in an inbox without anyone remembering.

White-label · scheduled

Who holds it

Built for whoever holds the keys.

Service providers

Every client, one pane, no bleed between them.

Run hundreds of client estates from a single console with hard logical isolation, then prove the value at the end of the month.

  • Tenant, site and device-group scoping keeps one client's fleet invisible to another
  • White-label reports carry your logo and colours, not ours
  • Per-technician audit trail on every command, reveal and remote session
  • Staged rollouts let you patch a hundred estates without betting all of them at once

Enterprise IT

A fleet that reports to you before a user does.

For internal teams answerable to a change board — deterministic policy, maintenance windows, and an approval gate in front of anything risky.

  • Patch windows that respect active hours on business-critical machines
  • Approval requests in front of high-risk actions, with a recorded decision
  • Escalation policies that page the right tier on an SLA deadline
  • Signed agent releases, so nothing runs that your key did not sign

Individuals & small teams

The machines you look after for everyone else.

A home lab, a family's laptops, a studio of a dozen workstations — the same instrument, without the enterprise on top of it.

  • One command installs the agent and enrols the device
  • Remote support that asks permission, for helping family at a distance
  • Updates and disk warnings before they become a weekend
  • Runs on your own server — the fleet stays yours

Underneath

Nothing runs that wasn't signed.

The agent
A single native binary in Go — no runtime to install, no framework to patch. Windows, Linux and macOS, holding one outbound connection and buffering to disk when the link drops.
Enrolment
A device joins with a use-capped site token, then establishes its own key pair. Every later message is authenticated as that specific machine, and a re-imaged endpoint is restored through an audited reset rather than a weakened check.
Updates
Releases are signed Ed25519 over the binary's digest and verified against a key compiled into the agent. Neither the download path nor the control plane can make an endpoint run unsigned code.
Remote sessions
Screen and input travel peer-to-peer over WebRTC, encrypted end to end, with a TURN relay only when the network leaves no direct route. The session token is the agent's credential and never reaches the browser.
Secrets
Stored credentials are encrypted at rest and never serialised into an API response. Revealing one is rate-limited and written to the audit log with the technician's name against it.

Take the instrument.

One command enrols a machine. The console has it on screen before the window closes.