Prove every signedscript run

Govern PowerShell with signing policy and exportable audit - so MSPs can answer assessors and insurers without RMM log archaeology.

Install one agent, run one signed script, and export the audit file - most teams do it in under thirty minutes.

<30m
Pilot to first audit export
1
Platform for governed scripts
15MB
Lightweight agent target

No credit card · Pilot access within two business days · Enterprise reviewed manually

Night view of connected regions representing multi-tenant MSP fleet operations

Try it before you buy

Most teams export their first audit file in under thirty minutes.

<30min to first export

One pilot session

Install one agent, run one signed script, export the audit file. That is usually enough to answer the buy-or-not question.

Four modules, one platform

Scripts, agents, trust evidence, and optional monitoring.

Developer workspace with code on screen for PowerShell orchestration

Scripts

Sign, approve, and run PowerShell

Block unsigned scripts when policy requires it. Every run is recorded with who ran what on which machine.

  • PowerShell IDE with approval workflows
  • Push/pull file pipeline in script runs
  • Platform catalog duplication into tenant libraries
  • Execution queue with a clear audit record
  • Complex install pipelines when Win32 is the wrong tool
<30 mintypical first signed script + export
Explore script governance
Endpoint laptop on desk representing managed Windows fleet deployments

Agents

Lightweight Windows agents

Deploy a small agent that polls outbound. Search and target machines with catalog APIs built for large fleets.

  • ~15MB single-file deployment target
  • Outbound polling - no inbound firewall holes
  • Catalog APIs for 100k+ agents per tenant
15MBagent footprint target
Explore agent management
Procurement reviewer signing vendor security questionnaire documents

Trust

Evidence for security reviewers

Download what is built vs. not. Export audit rows from trial and attach them to your questionnaire.

  • Shipped and Gap tables on the trust hub
  • Downloadable trust pack
  • Architecture notes for procurement
1trial session to export audit rows
Download trust materials
NOC-style analytics display for monitoring module evaluations

Monitoring

Optional probes and NOC views

Add SNMP ingest and NOC dashboards when your SKU includes the Monitoring module.

  • Packaged Monitoring module gates
  • Probe ingest with rollup retention controls
  • Lazy policy trees for fleet-scale operators
Optionalmodule - buy when entitled
Explore monitoring module

What you get from a pilot

Three distinct outcomes - pilot fit, audit export, and fleet scale.

Test on one customer first

1pilot tenant before portfolio rollout

Run a pilot group before you mandate Trustholm fleet-wide.

Compare options

Hand auditors a file

JSON/CSVexportable script run history

Export who ran which signed script on which machine - without digging through RMM logs.

Review security evidence

Grow the fleet safely

100k+agents per tenant via catalog APIs

Server-backed search and pagination - not full-fleet dropdowns.

See platform architecture

What early evaluators report

Design-partner MSPs and security reviewers validating script governance fit-not certification marketing.

“We reproduced a signed script run and CSV audit export in one pilot session-that export slice is what our cyber insurer actually asked for.”

MSP operations leadAustralian MSP · 120-endpoint pilot · Q2 2026 evaluation
40+MSP evaluations in progress
<30mMedian time to first audit export in trial
Shipped/GapHonest evidence tables published
69%MSP leaders reporting 2+ breaches in 12 months

Privileged script runs need governance proof

Signing, four-eyes approval, and exportable audit-verify in a trial tenant. No SOC 2 badge claims; honest Shipped/Gap evidence for assessors.

Simple, Transparent Pricing

Public bundles from your operator catalog-or contact us for enterprise

Enterprise
Contact sales
Invoice/PO, dedicated isolation, custom entitlements

Frequently asked questions

What does Trustholm do?

We prove which signed scripts ran on which client machines. MSPs use Trustholm to enforce signing policy, run scripts with a clear record, and export audit files for assessors and cyber insurers.

What makes Trustholm different from NinjaOne or ConnectWise Automate?

We're built for script governance, not full endpoint management. If you need both, check our comparison pages to see if we're a fit.

Do you hold SOC 2 or ISO certifications?

We're not SOC 2 certified yet. We publish exactly what's built vs. not, mapped to common audit controls, so your security team can verify it themselves.

How long does deployment take?

Most teams install one agent, run one signed script, and export audit rows in under thirty minutes. Fleet-scale rollouts use paginated catalog APIs -no loading every endpoint into a dropdown.

Where is data hosted?

Launch region options and subprocessors are on the trust hub. Exact residency for your contract is confirmed during onboarding -not inferred from marketing copy.

What should a business owner get from a trial?

A working audit export you can show your security reviewer or insurer -before you commit portfolio budget. If script evidence is your bottleneck, one pilot session usually answers the buy-or-not question.

More detail for evaluators

What we do: Block unsigned scripts when your policy requires it. Record who ran what on which machine. Export that history for auditors and insurers -separate from RMM operational logs.

What we are not: We do not hold SOC 2, Essential Eight, CMMC, or other third-party certifications. See the trust hub for what is built vs. not.

Where to go next: Platform overview for modules and architecture. Compare how we fit beside NinjaOne, ConnectWise, and PDQ. Trust downloads for procurement packs. Start a trial on Govern (no credit card); Evidence and Enterprise tiers are reviewed within two business days.