v0.2 · MIT-licensed · self-hosted

Endpoint management,
unified.

Manage, secure, and monitor every Windows, macOS, and Linux device from one console. One lightweight agent — no Apple or Microsoft MDM program required.

RUNS EVERYWHERE
Windows macOS Linux
console.neouem.app
Fleet overview
Devices
1,284
Online
1,196
Compliant
97.2%
MBP-EXEC-01macCompliant
WIN-FIN-0421WinCompliant
UBT-CI-03LinAt risk
WIN-OPS-088WinAlert
Remote command
run_script ✓ 1,196
How a device actually connects — the real request path, not a sales pitch Agent · Windows Agent · macOS Agent · Linux mTLS · HTTPS+SSE NeoUEM Server (Go) Admin console REST row-level security PostgreSQL
ONE CONSOLE, EVERY ACTION

Everything you need to run a fleet

From enrollment to remote control — full-cycle endpoint management without stitching tools together.

Remote commands

Run scripts, install or update software, lock, reboot, and wipe — across one device or the whole fleet.

Policy & compliance

Define required software, scheduled scripts, and compliance checks with automatic remediation.

Patch management

Scan installed software across the fleet, then multi-select devices and push updates in bulk.

Remote terminal & desktop

Live shell streaming and a JPEG screen stream with mouse and keyboard injection — built in.

App & file store

Upload installers and files, assign to devices or groups, and let the agent deploy them automatically.

Inventory & location

Hardware, OS, and software inventory enriched by osquery, plus IP and Wi-Fi location per device.

UP AND RUNNING IN MINUTES

No MDM program. Just one agent.

1

Generate a token

Create a one-time enrollment token in the console. No Apple Business Manager or Intune setup required.

$ neouem enroll --token=••••
2

Run the agent

Drop the single Go binary on any Windows, macOS, or Linux machine. It installs as a boot service.

$ ./mdm-agent --server=…
3

Manage from one console

The device appears in seconds over a persistent push channel. Send commands, assign policies, go.

✓ device online · streaming
SECURE BY DESIGN

Enterprise-grade security, fully in your control

mTLS device identity, role-based access, and a tamper-monitored agent. Self-host it — it's open source, so there are no black boxes.

mTLS device identity

Every agent is issued an X.509 client cert signed by your internal CA.

Role-based access

Owner, admin, and viewer roles enforced server-side, per tenant.

Tamper detection

The agent watchdog monitors binary integrity and raises alerts on mismatch.

Full audit log

Every command and session is recorded with per-tenant isolation.

MIT licensed. Run it yourself — no seat fees, no vendor lock-in.

GET STARTED

Request access

NeoUEM is self-hosted and onboarded by an operator, not a self-serve signup — tell us about your fleet and we'll set up your tenant and email you an invite.

Take control of every endpoint today

Enroll your first device in under five minutes. No credit card, no MDM program, no lock-in.