Know what every laptop
is actually running.
Every laptop in your organisation, described in one document you own. You can see what each machine runs, and prove it.
Modernise the workplace, or keep control of it. Most tools make you pick one.
Public organisations are told to do both. The mature fleet managers are excellent — and they are somebody else’s cloud. Your devices, your policies and your evidence sit where you cannot see them and cannot leave.
Sextant is the other option. You run it yourself. The fleet’s configuration is a document in your own git, so you can read it, review it, and hand it to an auditor.
- configuration
- a document in your git
- direction
- devices pull, never pushed
- evidence
- exportable, per control
Three steps. That is the whole loop.
No console button edits a device directly. There is nothing to click that could go wrong.
Write it down
Every device’s setup lives in one document you own. Change a line, and you have described what the fleet should become.
Nothing ships broken
The change is built and checked before anyone can approve it. If it does not work, it never reaches a laptop.
Roll out in waves
Start with a handful of machines. Widen when it holds. Stop the moment it does not.
Two questions, answered by the same document.
What runs on the fleet, and how you prove it.
Running the fleet
Settings flow from the organisation down to the device. A higher level can hold a value the ones below may not weaken.
- One document decides what every machine installs
- Groups for sites, teams or roles
- Directory login, networking and secrets are ordinary settings
- Imaging a new laptop takes one pass, not one day
Proving it
Every policy carries a name and a reason an auditor can read. What can only be observed is reported as observed.
- Who changed what, and when
- Evidence and CSV exports, annotated per BIO and ISO control
- Recovery keys held in escrow, every reveal logged
- Operators see only the groups they are responsible for
NIS2 moved the question from trust to proof.
Directors are personally accountable now. NixOS installs everything by cryptographic hash, so what an auditor asks for is already there.
A complete bill of materials
We can show which code runs on which laptop, rather than infer it from a scan afterwards.
A feed you hold
We mirror the package sources. A compromised upstream does not reach your fleet.
Machines that image cleanly
Specific Dell and Lenovo models where everything works out of the box, firmware included.
Compliance dossier
BIO and NIS2 evidence, DPIA annexes and pentest reports, mapped to what enforces them.
Public provenance
The source lives on code.overheid.nl. You can verify what you are buying before you buy it.
Stable releases
You run a certified long-term release, so an upgrade is a decision you make.
Hosted by us, or entirely yours.
Same software, same licence, same fleet document. The only question is who operates the control plane.
Tell us about your fleet.
How many devices, what they run today, what an auditor last asked. We will say honestly whether Sextant fits.