Info Host Systems

PRODUCT — PEAK-UEM

Peak UEM

Beta

Endpoint deployment and policy management for immutable Linux — nothing phones home

BUILT FOR — SECURITY-CONSCIOUS IT LEADS

OVR — OVERVIEW

What it does

Peak UEM is on-premises unified endpoint management for immutable Linux desktops. Where cloud UEM platforms assume an always-online Windows estate, Peak assumes the opposite: a fleet you can trust precisely because nothing phones home.

Every desktop runs an immutable operating system — Fedora Silverblue with rpm-ostree, Ubuntu Core with snapd — and boots from a signed, versioned image that cannot drift. Autopilot-style enrolment provisions devices with an enrolment token or out-of-box greeter, anchored to the hardware’s TPM and secured with mutual TLS. Declarative, Intune-style policies describe the desired state as plain intent, and endpoints continuously reconcile towards it — desktop configuration, packages and even domain join, without agent sprawl. Updates roll out through deployment rings that pin endpoints to specific, cryptographically verified images, so a bad update is a rollback, not an incident.

Peak runs entirely inside your network as a self-hosted appliance. Its artifact cache mirrors OS images and software on-premises, carrying updates to sites with no internet at all, and licensing is enforced offline with ECDSA-signed licences validated on the endpoint. No fleet data leaves your perimeter — there is no vendor cloud to leave it to.

For security-conscious IT leads, that is the difference: data sovereignty by architecture, air-gap compatibility as a feature, and compliance that holds whether or not the outside world is reachable.

CAP — CAPABILITIES

Inside the product

  • F-01

    Immutable foundations

    Fedora Silverblue (rpm-ostree) and Ubuntu Core (snapd) images that boot to a known state and never drift.

  • F-02

    Autopilot-style enrolment

    Devices claim themselves on first boot from an enrolment token or out-of-box greeter, with TPM-anchored identity over mutual TLS.

  • F-03

    Declarative compliance

    Intune-style policy describes the intent; endpoints continuously reconcile desktop configuration, packages and domain join towards it.

  • F-04

    Ring-based staged updates

    Assign devices to deployment rings and stage rollouts against cryptographically pinned images, with image-level rollback.

  • F-05

    Air-gapped artifact cache

    OS images, packages and software mirrored on-premises, so sites with no internet still update on schedule.

  • F-06

    Offline licensing

    ECDSA-signed licences validated on the endpoint itself — the fleet never calls home to check in.

PLN — PLANS

Plans that fit the operation

Up to 25 seats

Contact for pricing

DRAFT — PRICING PENDING CONFIRMATION

Per-seat licensing for small fleets — up to 25 seats with guided onboarding; a signed licence (peak.lic) is issued after purchase.

  • Up to 25 seats, licensed per seat
  • Autopilot-style enrolment
  • Declarative compliance policies
  • Ring-based staged updates
  • Guided onboarding
Talk to us

Up to 100 seats

Contact for pricing

DRAFT — PRICING PENDING CONFIRMATION

Per-seat licensing for departmental fleets — up to 100 seats with guided onboarding; a signed licence (peak.lic) is issued after purchase.

  • Up to 100 seats, licensed per seat
  • Air-gapped artifact cache
  • Declarative compliance policies
  • Ring-based staged updates
  • Guided onboarding
Talk to us

Unlimited

Contact for pricing

DRAFT — PRICING PENDING CONFIRMATION

Per-seat licensing for organisation-wide rollouts — unlimited seats, guided onboarding and priority support; a signed licence (peak.lic) is issued after purchase.

  • Unlimited seats, licensed per seat
  • Air-gapped artifact cache
  • Offline ECDSA licensing
  • Ring-based staged updates
  • Priority beta support
  • Guided onboarding
Talk to us

PRICES IN AUD, EXCL. GST · COMPARE BOTH PRODUCTS ON THE PRICING PAGE