Our story

I built the tool
I couldn't find

PatchPilot exists because every endpoint management platform I evaluated was either priced for enterprise, weak on compliance evidence, or hosted somewhere I couldn't trust with client data. So I built what I needed — and kept it honest.

🇬🇧Built and hosted in the United Kingdom
🏛️Registered UK company
🔒ICO-registered data processor
🌍Data stays within EEA. Always.

Why PatchPilot exists

I run IT for a small portfolio of UK businesses. Every year, cyber insurance renewals got harder — insurers wanted proof that devices were patched, that BitLocker was enforced, that someone had actually checked the endpoints rather than just assumed they were fine.

The tools that existed fell into two camps. Either they were built for enterprises with a six-figure budget and a dedicated compliance team, or they were cheap but gave you no evidence worth anything to an insurer or auditor. A few were both expensive and evidence-light.

"The hardest part wasn't patching devices. It was proving, on demand, that patching had happened — in a format a cyber-insurance underwriter would actually accept."

So I built PatchPilot. The goal was simple: make the compliance evidence that used to take days to compile a thing you can export in 30 seconds — mapped to real frameworks like Cyber Essentials, ISO 27001, and SOC 2, not just a CSV of hostnames.

We built it in the UK, for UK and European IT teams first. That means UK GDPR by design — not bolted on. Data processed inside the EEA. No "we'll evaluate EU hosting later." That's where we started.

For regulated UK industries — NHS trusts, central government bodies, MoD supply chain — we offer sovereign deployment: PatchPilot installed within your own infrastructure, with no data leaving your network boundary. This aligns with NHS DSPT requirements, G-Cloud 13 framework obligations, and MoD JSP 440 data-handling policy. If you're a public-sector buyer evaluating endpoint management, talk to us before committing to a US-hosted vendor.

We're still early. The app is in controlled early access with real paying customers — including Vehicle Data Global Ltd, whose entire endpoint estate was one of our first test environments. Every bug they surface makes PatchPilot better for the next customer.

What we stand for

Four things we won't compromise on

Not a mission statement. Things we've actually made hard decisions based on.

🏗️

Honest evidence, not audit theatre

We map patch state, BitLocker status, and vulnerability posture to specific control clauses — not just tick boxes. If a control isn't evidenced, we say so.

🔒

Security that isn't a marketing checkbox

Per-connection step-up MFA for destructive actions. Native session recording. Cryptographically signed audit trail. Not bolt-ons — built into the core auth layer.

🇬🇧

UK-first, EEA-hosted

Your data doesn't transit the Atlantic. We're ICO-registered. Our infrastructure runs in European data centres. UK GDPR compliance is structural, not contractual.

💰

Pricing you can defend to a CFO

Per-device pricing. No surprise overages. No "contact sales" for features that should be standard. You know what you'll pay before you add a device.

What we are — and aren't

We'll tell you what we don't do

We're not trying to be everything

  • No macOS support in v1.0 — we don't have Apple hardware to validate the agent properly. We'll add it when we can test it properly.
  • We're not a full MDM replacement. Intune handles device enrolment and policy distribution better than we do. We integrate with it, we don't try to replace it.
  • We're honest about these gaps in writing — on the pricing page, in the docs, and now here. No hidden asterisks.

Under the hood

Built on things that last

Nothing exotic. Boring, proven choices that make it easier for a security-conscious customer to audit what we run.

Backend
Node.js + Next.js 15
Database
SQLite (self-hosted instance)
Agent (Windows)
PowerShell + MSI installer
Agent (Linux)
POSIX shell + systemd / cron
Auth
Session cookies + step-up MFA
Hosting
UK-based VPS (EEA)
Payments
Stripe (EU-processed)
Audit trail
Immutable, signed log

Want to see it running on real devices?

Early access is open. Install takes under 5 minutes on Windows or Linux.