Optional

The Tier Two Client, for managed devices.

You do not need this to use Tier Two. Agents connect to the hosted endpoint with no install at all. The Client v0.3.1 is for organizations that want the machine to count too: it carries a device identity and reports posture, so policy can require an org-managed device on the tools that warrant one.

macOS packages are signed with a Developer ID certificate and notarized by Apple. They install with no security overrides. There is no Windows build yet; agents on Windows use the hosted endpoint directly, which needs no install.

What it adds

A machine identity, and posture you can require.

Everything below is on top of the hosted endpoint, not instead of it. The same agents, the same connections, the same three modes.

A device identity

The machine gets a key it generates locally and never exports. Calls from it are attributable to the device as well as the person.

Posture you can require

Managed is earned, not declared: enrollment through an admin-minted secret or MDM, plus a recent posture heartbeat. Miss either and the tools that require it refuse.

Hosts register themselves

The Client writes the endpoint into the MCP hosts on the machine, so a new laptop is set up without anyone typing a command.

Rolling out a fleet? Push the Client by MDM with a managed config, or bake an admin-minted enroll secret into your image. Machines enroll without a human, land unassigned, and fail closed. Nothing is allowed until each device is bound to its owner at first sign-in.

Also reachable from Settings → Advanced inside the dashboard.

Connect your first agent.

Start free. One command, no credit card required.