Know what every laptop
is actually running.

Every laptop in your organisation, described in one document you own. You can see what each machine runs, and prove it.

The Sextant console showing fleet health, compliance and recent device activity
The fleet overview: what each machine actually runs, how healthy it is, and what needs attention.

Modernise the workplace, or keep control of it. Most tools make you pick one.

Public organisations are told to do both. The mature fleet managers are excellent — and they are somebody else’s cloud. Your devices, your policies and your evidence sit where you cannot see them and cannot leave.

Sextant is the other option. You run it yourself. The fleet’s configuration is a document in your own git, so you can read it, review it, and hand it to an auditor.

configuration
a document in your git
direction
devices pull, never pushed
evidence
exportable, per control

Three steps. That is the whole loop.

No console button edits a device directly. There is nothing to click that could go wrong.

Write it down

Every device’s setup lives in one document you own. Change a line, and you have described what the fleet should become.

Nothing ships broken

The change is built and checked before anyone can approve it. If it does not work, it never reaches a laptop.

Roll out in waves

Start with a handful of machines. Widen when it holds. Stop the moment it does not.

The Sextant console rolling a change out across the fleet in waves
A change rolling out in waves. It stops itself if a device does not report back.

Two questions, answered by the same document.

What runs on the fleet, and how you prove it.

Running the fleet

Settings flow from the organisation down to the device. A higher level can hold a value the ones below may not weaken.

  • One document decides what every machine installs
  • Groups for sites, teams or roles
  • Directory login, networking and secrets are ordinary settings
  • Imaging a new laptop takes one pass, not one day

Proving it

Every policy carries a name and a reason an auditor can read. What can only be observed is reported as observed.

  • Who changed what, and when
  • Evidence and CSV exports, annotated per BIO and ISO control
  • Recovery keys held in escrow, every reveal logged
  • Operators see only the groups they are responsible for

NIS2 moved the question from trust to proof.

Directors are personally accountable now. NixOS installs everything by cryptographic hash, so what an auditor asks for is already there.

A complete bill of materials

We can show which code runs on which laptop, rather than infer it from a scan afterwards.

A feed you hold

We mirror the package sources. A compromised upstream does not reach your fleet.

Machines that image cleanly

Specific Dell and Lenovo models where everything works out of the box, firmware included.

Compliance dossier

BIO and NIS2 evidence, DPIA annexes and pentest reports, mapped to what enforces them.

Public provenance

The source lives on code.overheid.nl. You can verify what you are buying before you buy it.

Stable releases

You run a certified long-term release, so an upgrade is a decision you make.

Hosted by us, or entirely yours.

Same software, same licence, same fleet document. The only question is who operates the control plane.

SaaSOn-premise
Control plane runs On our EU infrastructureOn yours
Fleet document Your own gitYour own git
Upgrades and backups We operate themYou do, we support
Restricted or air-gapped networks Supported
Keys and logs held by YouYou
Time to a running fleet FastestAfter your setup

Tell us about your fleet.

How many devices, what they run today, what an auditor last asked. We will say honestly whether Sextant fits.

hello@bb-open.com 085 2500 791