A Fortify 24x7 brand. Plain dealing, printed rates, and a name against every job.Sign in at the counterSend us a line
Stars and Stripes ITCarried · Posted · Signed for
Route 02 / The approved list

Nothing executes unless its name is on the manifest

Almost everything else on this storefront begins by assuming hostile code will run and sets out to catch it. This one begins somewhere else entirely. Each machine keeps a manifest of software it may execute. Anything absent from that manifest never executes, no matter how plausible the file looked or who double clicked on it.

ThreatLockerDeny unless listedApprovals worked at our desk
FORM 3802
Items carried1
Rate followsEndpoint
Worked byOur approval desk
Runs onThreatLocker

How the opening month feels

The agent goes on and simply observes for a stretch, blocking nothing. That is how the manifest gets written, out of your own working software rather than off a list assembled by strangers who have never seen your office. Then the door closes, and unfamiliar software has to be argued for.

The arguing arrives at our desk, and in practice it is settled in minutes. Even so it is a step nobody had in their day previously, and printing that here beats you discovering it in week three. A firm forever pulling in new tooling notices. A firm whose bookkeeper and estimator open the same six programs every morning barely does.

A stranger with no name on the manifest waits outside, however good the story

Which machines to cover first

Cover the desks where a bad hour costs most. Whoever moves money. Whoever holds the drawings. The server keeping the job files. The laptop carrying the client list. Most firms settle on strict there and lighter elsewhere, and that is a sensible place to land.

Ringfencing is the half nobody discusses. Beyond the question of execution, it decides which helpers a permitted program may summon, which documents it may touch, and which destinations are open to it. That is what keeps a legitimate utility from doubling as a convenient exit for somebody else's records.

Every item on this route

Item by item, with the figure attached

Each figure here is pulled out of the billing service as this page opens. Load a line now and it waits in the bag until you have finished reading.

Fortify-ZeroTrustROUTE 02

Application Allowlisting

per endpoint

ThreatLocker turns the machine around. Instead of guessing which programs are hostile, it permits the ones on the list and refuses everything else. A stranger arriving at the door with no name on the manifest does not get carried, however convincing the package looks.

  • It opens by observing, and the manifest gets written out of your own working software.
  • Listed software may still patch itself, so a routine release never strands the office.
  • Ringfencing draws a boundary round each permitted program: what it may launch, read, and reach.
  • Requests land with an engineer who is already at the desk, not in a queue.
Carried onThreatLocker agent, one per endpoint
CoversManaged Windows and macOS endpoints in the enrolled policy
Held in transitPending approval requests sit with our desk until a person decides them
Postmarked byFortify 24x7 engineers, working elevation requests around the clock
Signed forOne endpoint, one line, one monthly rate
Rate loadingcounted per endpoint
paid a month ahead
HOW MANY
Honest scope

Where this route ends

Execution control rules on software. It has nothing at all to say about the judgment of the human who approves something, and that distinction deserves printing before you order.

  • Software is ruled on. People are not. A colleague who opens a permitted browser, lands on a convincing page, and hands over their password consulted no manifest anywhere in that sequence. That road belongs to the mailroom and to the drill that comes with it.
  • The observing stretch is genuine work. It costs somebody a real week of attention. Selling it as a checkbox buys a miserable first month and a workforce that carries a grudge against the tool for years.
  • Browser add-ons do not read as new software. Something pulled in through the usual store never looks like fresh code to the agent. Keeping add-ons sane is a written policy question, and we would rather help you draft the policy than invoice you for a line that will not solve it.
  • Your documents are never read here. Working out which records are sensitive, and where the copies drifted to, belongs to the sealed pouch. This item rules on execution and holds no view on value.
  • Machines outside management are outside the manifest. Policy applies where the agent is enrolled. A personal computer that never enrols is not covered, and no configuration anywhere changes that.
NOTE 01

Heads up: card statements show FORTIFY 24X7 - Stars and Stripes IT is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.