A platform that scales with your needs
Two license tiers, three usage profiles: start with patch governance on Core, and grow into risk, compliance, and MSP multi-customer operations with Enterprise.
License tiers
Patch Governance
Start with visibility — no credit card required.
- ✓ Inventory management
- ✓ Read-only patch view
- ✓ Readiness report
- ✓ Up to 10-25 servers
- ✓ Single tenant
Risk + Compliance + Service Awareness
Full capability for scale, compliance, and multi-customer operations.
- ✓ Approval workflow and ring deployment
- ✓ Compliance reporting
- ✓ Multi-customer (MSP multi-tenant) mode
- ✓ Audit trail and evidence pack
- ✓ Policy automation (guardrails)
- ✓ No server/tenant limit
Pricing is quoted separately based on environment scale and scope.
An MSP manages multiple customers from a single OpsGuard deployment — each one isolated individually, without any cross-contamination. This is achieved by running the Enterprise license in multi-customer mode.
- ✓ Tenant isolation is enforced across the UI, API, background jobs, reports, and exports
- ✓ Every request uses a server-side-verified tenant context — a tenant ID coming from the browser is never trusted
- ✓ Cross-tenant views are only possible with explicit MSP-level authorization
- ✓ Empty or access-denied states never imply the existence of unauthorized data
A consolidated MSP dashboard (a federated view showing all customers from a single pane) is still on the roadmap — today's multi-customer mode manages each customer separately, in isolation.
Easy to install, built to scale
Single-Script Install
Sits on top of your existing AWX/Ansible infrastructure — no rip-and-replace required.
Air-Gapped / Regulated Environments
Installation has been validated at real scale in fully air-gapped environments.
Multi-Tenant Architecture
MSPs can manage multiple customers separately from a single platform.
Standard, Repeatable
Every new environment is deployed consistently, using the same method.
Frequently Asked Questions
How long does setup take?
A 30-day, fully-featured PoC starts with a single command. Agentless discovery runs over SSH/WinRM, and the first inventory and vulnerability scan usually complete the same day.
Where is our data stored?
OpsGuard runs on-prem — your data never leaves your own servers. The architecture supports regulatory requirements such as KVKK and NIS2.
How does pricing work?
The Core edition is free for visibility features. The Enterprise edition (approval workflows, compliance, multi-tenant MSP support) is quoted separately based on your environment's scale — contact us for details.
Does it work alongside our existing tools (Defender, CrowdStrike, SCCM, etc.)?
Yes. OpsGuard connects to your servers agentlessly over SSH/WinRM/API and also reports on the install status, version, and conflicts of your existing security/management agents (Defender, CrowdStrike, SentinelOne, Wazuh, SCCM) — it doesn't replace your current stack, it adds visibility on top of it.
Will servers reboot automatically during patching?
No — under the "Never Auto Reboot" principle, reboots always go through your defined approval/window workflow; OpsGuard never restarts a server on its own.
Does it support multi-customer / multi-tenant (MSP) scenarios?
Yes, the Enterprise edition is built for multi-tenant MSP usage, with each customer environment isolated from the others.
Let's find the right tier for you.
Try it in your own environment with a 30-day, fully-featured PoC. Installation is a single command; your data stays on your servers.