Autonomous patching & protection · for 1–200+ device businesses

Patched. Protected. On the record.

PatchAudit keeps small businesses - 1 to 200 or more devices - patched automatically across Windows, macOS, and Linux, and actively protected around the clock if you need it. No IT hire, no MSP retainer. Just a monthly record you can hand straight to your insurer, your board, or your own peace of mind.

1–200+ devices Windows · macOS · Linux Core or Core + Shield Month-to-month
Live patch log
sample activity
DESKTOP-7F2AWindows 11 · KB5041773 installedverified02:14
MBP-SALES-03macOS Sonoma · Security Update 2026-004verified02:15
SRV-FILES01Ubuntu 22.04 LTS · openssl 3.0.13 → 3.0.14verified02:17
SRV-ACCT14Server 2025 · Chrome 127 → 128verified02:19
LAPTOP-HR02macOS Sequoia · Zoom 6.1.11 → 6.1.12verified02:21
DESKTOP-3B91Windows 11 · Adobe Acrobat Reader → 24.003verified02:24
SRV-APP02Rocky Linux 9 · kernel 5.14.0-427 → 503verified02:27
LAPTOP-WFH07Windows 11 · Microsoft Teams 24298 → 24312verified02:30
IMAC-DESIGN01macOS Tahoe · Firefox 129 → 130verified02:32
WKS-OPS22Windows 11 · 7-Zip 23.01 → 24.05verified02:35
SRV-DB01Ubuntu 24.04 LTS · postgresql-client 16.3 → 16.4verified02:38
SERVER-9C14Server 2016 · Java 8u411 → 8u421verified02:41
The problem

You don't need an IT department. You need three things done reliably.

If you're running a business with a handful of computers up to a couple of hundred, you almost certainly don't have - and don't need - a full-time IT team. But three things still have to happen: every device needs to stay patched, something needs to be watching for actual threats, and you need to be able to prove both when someone asks.

And someone is asking. Cyber insurance renewals increasingly ask directly whether you have endpoint detection and response (EDR) deployed and a documented patch management process. The Australian Cyber Security Centre's Essential Eight lists patching applications and patching operating systems among its eight baseline strategies. None of that requires an in-house IT department - it requires a system that runs on its own and can show its work.

$97k

average self-reported cost of a cyber incident for an Australian medium-sized business (up 55%).
For small business this number is $56,600 (up 14%)

- ACSC Annual Cyber Threat Report (FY24-25)
622

record-breaking vulnerabilities (CVEs) addressed in the July 2026 Microsoft Patch Tuesday alone, with over 400 targeting Windows components. Manual patching can no longer keep up.

- Microsoft Release Notes (July 2026)
128%

surge in Remote Code Execution (RCE) vulnerabilities in 2025. Attackers are exploiting vulnerabilities faster than organizations relying on legacy patching workflows can remediate them.

- Action1 Software Vulnerability Ratings Report (2026)
How it works

One subscription, five steps, running quietly in the background

Patching genuinely is a sequence - enroll, assess, deploy, verify, report - and each step depends on the one before it. Here's the order it runs in, every day.

01 / enroll

Enroll devices

A lightweight agent is deployed remotely to every device - Windows, Mac, or Linux - in minutes. No site visit, no downtime.

02 / assess

Continuous assessment

Every enrolled device is scanned around the clock for missing OS and application updates, including known, actively exploited vulnerabilities.

03 / deploy

Schedule & deploy

Patches roll out in maintenance windows built around your business hours. Critical, actively-exploited vulnerabilities can go out same-day.

04 / verify

Verify

Every patch is confirmed installed and functioning after deployment - not just marked as sent.

05 / report

Monthly report

A plain-English record each month: what was patched, what's pending and why, and your overall compliance rate.

Want more than patching? Shield adds continuous endpoint monitoring on top of everything above - if something suspicious happens on a device, a security analyst investigates and responds, 24 hours a day, not just when patches run. See Shield in Pricing →
Coverage

If it runs on the device, it's in scope

Operating systems:

Windows 10 / 11 Windows Server 2016–2025 macOS Monterey+ Ubuntu Debian Linux Mint RHEL / CentOS Stream Rocky / AlmaLinux openSUSE

Applications:

Chrome, Firefox, Edge Adobe Product Suite Java Zoom Microsoft Teams Slack 7-Zip VLC 300+ more
Remote and hybrid devices are included by default. If a laptop is offline when a patch ships, it's applied the moment it reconnects - no VPN or office network required. Shield's 24/7 monitoring currently covers Windows and macOS endpoints; Linux servers stay covered by Core patching.
Where this fits

Not quite DIY. Nowhere near a full outsourced IT department.

An honest look at how small-medium businesses (1–250 devices) handle patching and protection today.

  Doing it in-house PatchAudit Core PatchAudit Shield Full-service MSP
Monthly cost Often $0 in software cost - but real, unbilled staff time One flat fee per device One flat fee per device - includes Core Bundled retainer, usually priced well above patching + protection alone
What's covered Whatever there's time for OS + application patching, start to finish Everything in Core, plus 24/7 endpoint monitoring & response Everything - patching, help desk, procurement, and more
Who owns a missed patch or threat You Us, under a response SLA (patching) Us, under a response SLA (patching + threat response) Your provider, per their contract
Insurance / compliance evidence You assemble it yourself, if you remember to Monthly patch compliance report Monthly patch + protection report Varies by provider
Time to get running As long as it takes internally Days Days Often weeks of onboarding
Typical contract N/A Month-to-month Month-to-month Usually annual
Best fit Businesses with real in-house time to spare Businesses that just need patching handled Businesses that also want active threat monitoring - often for insurance or compliance reasons Businesses that want IT fully outsourced, end to end
Pricing

Type in your device count. See both prices.

One number for patching alone, one for patching plus 24/7 protection. No quote form required.

40
150100150200
Core - patch only
$280
≈ $7.00 AUD / device / month
Shield - patch + 24/7 protection
$920
≈ $23.00 AUD / device / month

PatchAudit Core

Patch management for OS + apps, across Windows, macOS & Linux.


1–9 devices$15.00 / device / mo
10–49 devices$12.50 / device / mo
50+ devices$10.00 / device / mo
$75 AUD/month minimum
  • Unlimited patch deployments
  • Windows, macOS & Linux + 300+ apps
  • Monthly compliance report
  • Cancel anytime
Get Core

Indicative pricing shown above. Your exact rate is confirmed after a short scope call - device mix (workstation vs. server) and support tier can move the number slightly.

Trust & security

What we run on, and what we don't touch

  • Core's patch engine is an autonomous endpoint management platform independently certified to SOC 2 Type II and ISO 27001.
  • Shield's threat monitoring and response is powered by Malwarebytes ThreatDown, backed by a 24/7/365 security operations centre.
  • Data encrypted in transit and at rest (AES-256).
  • We deploy, monitor, and verify - we don't remotely access your devices outside that scope.
  • You keep ownership of your data and can export your full patch and protection history at any time.

Service levels

Core - critical CVEsPatched within 24 hrs of disclosure
Core - standard patchesApplied in your scheduled window
Shield - suspicious activityTriaged by an analyst, usually within minutes
Support requestsAcknowledged within 4 business hrs
ReportingMonthly, in plain English
FAQ

Questions we get asked before signing up

Isn't a patch tool free if I do it myself?

Some patch management platforms give away a generous free tier if you're the one configuring policies, watching dashboards daily, and troubleshooting failures. That's a fine option if someone on your team has the spare hours for it. PatchAudit is for the businesses that don't - we own the whole process end to end and put a response time in writing.

What's the actual difference between Core and Shield?

Core keeps every device patched automatically. Shield does that and adds 24/7 endpoint detection and response - a security analyst is watching for active threats around the clock, not just missing updates. Most businesses start with Core and add Shield when insurance, compliance, or peace of mind calls for it.

Will this help with our cyber insurance renewal?

It can. Many carriers now ask directly whether you have EDR deployed and a documented patch management process - Shield plus Core's monthly reports cover both. We're not brokers and can't guarantee approval or premium, but we'll give you and your broker the documentation to make the case.

What if a patch breaks something?

Patches are staged and tested before wide rollout, and deployed inside scheduled maintenance windows rather than the moment they're released. If something still needs rolling back, that's on us to resolve - not a ticket you have to chase.

Do you cover remote and hybrid devices?

Yes. Devices connect over the internet from anywhere - no VPN or office network required. If a laptop is offline when a patch ships, it's applied the moment it reconnects.

Do you patch servers as well as workstations and laptops?

Yes - a server counts as a device like any other endpoint, and is priced the same way.

Can we cancel any time?

The service is month-to-month. Cancel with 30 days' notice - no multi-year lock-in.

Is this a replacement for our IT support or MSP?

No - PatchAudit handles patching only. If you already have internal IT or an MSP, we plug in alongside them and take one specific, ongoing task off their plate.

Get started

Tell us roughly how many devices you have

We'll come back with a real quote and a couple of clarifying questions - no obligation.

Prefer to talk first?

Book a 15-minute call - we'll ask about your device mix and current patching process, and tell you honestly whether PatchAudit is a good fit.

hello@patchaudit.com