SecureSlate Device Agent
Data collection
The Agent runs the same five read-only checks on both macOS and Windows.
macOS
| Check | What's checked |
|---|---|
| Disk encryption | Whether FileVault is turned on |
| Screen lock | Whether the screen locks within 15 minutes of inactivity, and requires a password to unlock |
| Password policy | Whether automatic login is disabled and a minimum password length of at least 8 characters is enforced |
| Antivirus | Whether antivirus or endpoint protection is enabled |
| Firewall | Whether the firewall is enabled |
Windows
| Check | What's checked |
|---|---|
| Disk encryption | Whether the system drive is encrypted and actively protected. This covers both BitLocker and Device Encryption, the simplified version available on Windows Home. Requires administrator rights to read, see the note below. |
| Screen lock | Whether the screen locks within 15 minutes of inactivity, and requires a password to unlock |
| Password policy | Whether a minimum password length of at least 8 characters is enforced |
| Antivirus | Whether antivirus or endpoint protection is enabled |
| Firewall | Whether the firewall is enabled |
A note on the Windows disk encryption check
Windows only reports disk encryption status to administrators. If the
Agent is not running with administrator rights, it records that the
status could not be verified rather than assuming the device is fine. See
Troubleshooting.
Windows Home is included. It does not have BitLocker, but most modern
Home devices support Device Encryption, which this check covers.
Device identity
Alongside check results, the Agent reports basic device identity so
results can be matched to the correct asset in SecureSlate:
- Device name / hostname
- Operating system and version
- Hardware model
- Serial number
What's not collected
The Agent does not collect:
- Personal files, documents, or browsing history
- Keystrokes, screen contents, or clipboard data
- Application usage or activity unrelated to the five checks above
- Data from other user accounts on a shared device
