PROD_02 | Enterprise Governance

FederE8

Essential Eight visibility across a fleet, hosted on your infrastructure and protected by mTLS.

FederE8 is the fleet layer of the NebulE8 Security Suite. It coordinates detect-only Essential Eight audits across Windows and Ubuntu estates from a self-hosted control plane.

Fleet audits: detect-onlySelf-hostedmTLS agentsMulti-tenant

The problem

Fleet assurance needs more than a spreadsheet

Large endpoint estates need repeatable evidence, scheduled checks and clear separation between sites, tenants and operators.

Keep the control plane local

FederE8 is designed to run on customer-controlled infrastructure so audit evidence, agent identity and operational governance can stay inside the customer environment.

Capabilities

One control layer for distributed evidence

The platform coordinates endpoint audit tasks, consolidates results and exposes fleet posture through API and dashboard workflows.

01

mTLS agent identity

Use machine-bound agent identity and mutual TLS between agents and the control plane.

02

Central API

Provide REST interfaces for agents, tasks, scheduling and logs.

03

Operations dashboard

View fleet health, audit results, policies, tasks and tenant-scoped information from one interface.

04

Tenant separation

Use tenant-scoped keys and operator controls to separate data and authority across customers or organisational units.

05

Encrypted storage

Keep encrypted at-rest storage and certificate lifecycle tooling within the platform design.

06

Scheduled audit tasks

Dispatch repeatable fleet audit tasks across Windows and Ubuntu through a queue-based workflow.

Who it is for

Fleet-scale assurance without a SaaS control plane

FederE8 suits organisations that need direct control over where evidence is stored and how fleet assessment is governed.

Enterprise security teams

Run self-hosted Essential Eight assessment across distributed endpoint fleets.

MSSPs and consultants

Separate customers or managed estates with tenant-scoped controls.

Government and critical infrastructure

Retain evidence locally and run repeatable technical assurance in controlled environments.

GRC teams

Use API-oriented evidence handoff in existing assurance and governance workflows.

Safety model

Audit first, approve change separately

The fleet audit path is separate from any change workflow.

A

Detect-only audits

Collectors query configuration and report findings. They do not harden endpoints during an audit.

B

Separate approval

Change-oriented workflows are gated separately instead of being implicit in fleet assessment.

C

Lab validation

Real apply behaviour belongs in controlled validation, not in the current public production capability claim.

Suite fit

From one endpoint to the full estate

FederE8 carries the same assessment logic used by NebulE8 into scheduled and distributed fleet workflows.

ProductRoleCurrent boundary
NebulE8Standalone endpoint assessmentNo host changes
FederE8Fleet control plane, agents, API, dashboard and tenant governanceFleet audits are detect-only
RemedE8Remediation planning from audit findingsDry-run and simulation

Contact

Book a fleet walkthrough

Tell us how many sites or endpoint groups you manage and what evidence you need to collect across the estate.