PremioGuard combines kernel-level device control, hardware-bound licensing, and a cloud management dashboard — built specifically for Windows environments that can't afford a data breach.
The enforcement engine that keeps storage locked and peripherals free
Automatically blocks USB mass storage devices — flash drives, external hard drives, SSDs, memory cards, and phones in MTP mode. Keyboards, mice, printers, webcams, and other HID peripherals continue working without any restriction.
Uses Windows Management Instrumentation (WMI) events for instant device detection. The moment a storage device is plugged in, PremioGuard identifies and blocks it before the OS can mount a volume.
Approved devices are identified by their unique Vendor ID, Product ID, and Serial Number triplet. Once authorized, a device always works on that machine — no prompts, no friction.
When a blocked device is detected, the user sees a popup with device details and an authorization option. The request is verified against your admin credentials through a secure online API — no local bypass possible.
Hardware-bound licenses that can't be shared, cloned, or spoofed
Each license is tied to a hardware fingerprint derived from CPU, motherboard, disk, and network adapter — preventing unauthorized sharing across machines. Supports trial, monthly, yearly, and lifetime plans.
A background watchdog process monitors the main agent and relaunches it if killed. Registry keys and service entries are protected against manual removal — even by local admins.
License validation responses are signed with a 2048-bit RSA private key held only on the server. The agent verifies the signature before honoring any license grant — no offline spoofing.
The built-in updater downloads packages over HTTPS and verifies each file against a SHA-256 manifest before installation. Updates can be deferred by admins from the dashboard.
Logs and dashboards built for auditors, not just administrators
Every USB connection, disconnection, block, and authorization is recorded with timestamps, device metadata, and the acting user. Exportable for HIPAA, ISO 27001, and internal compliance reviews.
Web-based dashboards for both admins and customers. Manage licenses, view per-machine activation status, inspect USB event history, and push policy changes — all from a single portal.
The dashboard flags machines with repeated unauthorized device insertions. Spike detection highlights endpoints that may be under active exfiltration attempts so you can respond before data leaves.
Generate time-range reports filtered by machine, user, or event type. Reports include blocked device counts, authorized device lists, and admin credential usage — ready to attach to a security audit.
Designed to drop into existing Windows environments without disruption
The agent runs as a Windows service with no persistent tray icon and no UI visible to end users unless a device triggers an authorization prompt. Zero distraction, constant enforcement.
The Windows service and user-facing notification process communicate over a secure named pipe. No open network ports on the endpoint — lateral movement from the agent is not possible.
Extensively tested against common enterprise peripherals — Dell, Logitech, HP, and Zebra devices. HID, printer class, and audio class devices are never blocked regardless of policy.
Certain machines — like IT workstations — can be exempted from blocking policy via the admin dashboard without uninstalling the agent. Overrides are logged and auditable.