mTLS agent identity
Use machine-bound agent identity and mutual TLS between agents and the control plane.
PROD_02 | Enterprise Governance
Essential Eight visibility across a fleet, hosted on your infrastructure and protected by mTLS.
FederE8 is the fleet layer of the NebulE8 Security Suite. It coordinates detect-only Essential Eight audits across Windows and Ubuntu estates from a self-hosted control plane.
The problem
Large endpoint estates need repeatable evidence, scheduled checks and clear separation between sites, tenants and operators.
FederE8 is designed to run on customer-controlled infrastructure so audit evidence, agent identity and operational governance can stay inside the customer environment.
Capabilities
The platform coordinates endpoint audit tasks, consolidates results and exposes fleet posture through API and dashboard workflows.
Use machine-bound agent identity and mutual TLS between agents and the control plane.
Provide REST interfaces for agents, tasks, scheduling and logs.
View fleet health, audit results, policies, tasks and tenant-scoped information from one interface.
Use tenant-scoped keys and operator controls to separate data and authority across customers or organisational units.
Keep encrypted at-rest storage and certificate lifecycle tooling within the platform design.
Dispatch repeatable fleet audit tasks across Windows and Ubuntu through a queue-based workflow.
Who it is for
FederE8 suits organisations that need direct control over where evidence is stored and how fleet assessment is governed.
Run self-hosted Essential Eight assessment across distributed endpoint fleets.
Separate customers or managed estates with tenant-scoped controls.
Retain evidence locally and run repeatable technical assurance in controlled environments.
Use API-oriented evidence handoff in existing assurance and governance workflows.
Safety model
The fleet audit path is separate from any change workflow.
Collectors query configuration and report findings. They do not harden endpoints during an audit.
Change-oriented workflows are gated separately instead of being implicit in fleet assessment.
Real apply behaviour belongs in controlled validation, not in the current public production capability claim.
Suite fit
FederE8 carries the same assessment logic used by NebulE8 into scheduled and distributed fleet workflows.
| Product | Role | Current boundary |
|---|---|---|
| NebulE8 | Standalone endpoint assessment | No host changes |
| FederE8 | Fleet control plane, agents, API, dashboard and tenant governance | Fleet audits are detect-only |
| RemedE8 | Remediation planning from audit findings | Dry-run and simulation |
Contact
Tell us how many sites or endpoint groups you manage and what evidence you need to collect across the estate.