Blue Lantern Security's device agents are lightweight programs for macOS and Windows that check a machine's security posture about once an hour: disk encryption, endpoint protection, firewall, automatic updates, remote access, backups, and more. Only pass/fail results leave the device. Each report is scored Healthy, At Risk, or Critical in your Monitoring Hub, and the results feed the attestation report insurers ask for.
Access: included with a Seat License at $15 per monitored user per month. Device monitoring is seat-only; each agent is assigned to a seated member. Download the macOS agent or Windows agent after signing in. See current pricing.
Cyber insurance applications and customer questionnaires ask the same things: is every disk encrypted, is endpoint protection running, are backups in place, is remote access closed? Device monitoring answers those questions with evidence from the machines themselves, updated every hour, instead of a checkbox someone filled in from memory.
What does the agent check?
The agent evaluates a baseline posture pack locally, using osquery, and reports the results. Checks come in two kinds: scored controls that pass or fail, and inventories reported for context that never affect the verdict.
macOS
| Scored controls | Reported for context |
|---|---|
| FileVault disk encryption enabled | Time Machine backup destination configured and completed within 7 days |
| System Integrity Protection enabled | macOS software updates pending |
| Gatekeeper app assessment enabled | Device managed by MDM |
| Remote access and sharing services disabled (Screen Sharing, File Sharing, Remote Login, Remote Management, and others) | Local administrator accounts |
| Automatic login and guest login disabled | Third-party launch daemons and agents |
| Known EDR or antivirus agent running | Remote-access and tunneling tools installed |
| Application firewall on, with stealth mode | |
| Automatic update checks not disabled | |
| No third-party root certificates in the system trust store | |
| No unsigned or ad-hoc-signed launch daemons or agents | |
| No third-party kernel extensions loaded |
Windows
| Scored controls | Reported for context |
|---|---|
| BitLocker enabled on the system drive and all capable drives | Startup items |
| UEFI Secure Boot enabled | Local administrator accounts |
| Antivirus enabled with up-to-date signatures; known EDR or antivirus agent running | Device managed by MDM |
| User Account Control enabled | Consumer cloud file-sync clients installed |
| Remote Desktop disabled; SMBv1 not enabled | Remote-access and tunneling tools installed |
| Automatic logon disabled | Removable storage writes blocked by policy |
| Volume Shadow Copy service not disabled | |
| Windows Firewall and automatic updates reported healthy by Security Center | |
| No non-default SMB file shares exposed | |
| No unsigned or untrusted startup items | |
| Built-in Guest account disabled | |
| Backup mechanism present (a known backup agent or OneDrive folder backup) | |
| Local password policy requires length of at least 8 and complexity |
How the verdict is decided: any high or critical failure marks the device Critical. Lower-severity failures mark it At Risk. All controls passing marks it Healthy. Each failed check comes with an explanation and the setting to change, so the fix is a click away rather than a research project. The full, current check list for each platform is on the macOS agent and Windows agent pages.
How do I deploy the agent?
- Create a Device Monitor key in the Monitoring Hub, with the seat assignment set to the person who uses the machine. The key is shown once.
- Download the agent. The macOS package is signed and notarized. The Windows installer is signed with an EV code-signing certificate, and a SHA-256 checksum is shown next to the download so you can verify it.
- Install and enroll. On macOS, run the enroll command in Terminal; on Windows, run the enroll script from an elevated PowerShell. Each prompts for the device key.
- Watch the reports come in. The agent scans about once an hour, and each run appears in the Monitoring Hub under the Device monitor type, with the hostname as the target and the full posture report a click away.
Pair device monitoring with an alert rule on Critical or At Risk verdicts to hear about posture drift, such as someone turning off the firewall or a backup that stopped running, without watching the dashboard.
Already running CrowdStrike Falcon?
Connect it read-only from Integrations. Falcon sensor health lands beside the rest of your security data: whether each sensor has checked in recently, and whether a prevention policy is applied so the sensor blocks threats rather than only observing. A health run per device appears in the Monitoring Hub after each daily scan.
What leaves the device?
- Pass/fail results and inventory facts only. No file contents and no browsing data are collected.
- The device key is scoped to posture scans. It cannot run other tools or read any account data. Revoke it and the agent stops.
- The key is stored with restrictive permissions: root-only on macOS, and a SYSTEM/Administrators-only ACL on Windows. It is never logged.
- Reports are evaluated server-side. The agent's own summary is never trusted for the verdict.
Common questions
Is this an antivirus or EDR?
No. The agent does not detect or block malware. It verifies that your protections are in place and configured, including that a known EDR or antivirus product is actually running. Think of it as the evidence layer for the controls you already pay for.
How often does it check?
About once an hour. The Monitoring Hub shows each device's latest report, and the attestation report summarizes devices reporting in the last 7 days.
Does it work with MDM?
Yes. MDM enrollment is reported as an inventory fact, and the agent runs alongside any management tool. It does not change settings on the machine; it reports them.
What about Linux?
The current agents are built for macOS and Windows. Linux is not covered today.
Why do insurers care about these checks?
Disk encryption, endpoint protection, backups, MFA, and closed remote access are the controls most cyber-insurance applications ask about directly. Blue Lantern Security's attestation report compiles device, identity, and mail posture results into a document you can hand to a broker. See how to get started with small business security for where these controls fit in a plan.
Related guides
- How to get started with small business security
- Monitor browsing with Chrome Monitor
- Monitor identity: MFA coverage and dormant accounts
- Is This File Safe? Scan a suspicious file