Full Feature Overview

Every Tool You Need to Lock Down USB Access

PremioGuard combines kernel-level device control, hardware-bound licensing, and a cloud management dashboard — built specifically for Windows environments that can't afford a data breach.

Core Protection

The enforcement engine that keeps storage locked and peripherals free

Selective USB Blocking

Automatically blocks USB mass storage devices — flash drives, external hard drives, SSDs, memory cards, and phones in MTP mode. Keyboards, mice, printers, webcams, and other HID peripherals continue working without any restriction.

  • Flash drives & external HDDs
  • MTP phones & cameras
  • HID devices always allowed
Millisecond Detection

Uses Windows Management Instrumentation (WMI) events for instant device detection. The moment a storage device is plugged in, PremioGuard identifies and blocks it before the OS can mount a volume.

  • WMI event-driven, not polling
  • Sub-100ms response time
  • No volume ever mounts
Hardware Device Whitelist

Approved devices are identified by their unique Vendor ID, Product ID, and Serial Number triplet. Once authorized, a device always works on that machine — no prompts, no friction.

  • VID + PID + Serial fingerprint
  • Permanent per-machine approval
  • Admin-only whitelist management
Admin Authorization Workflow

When a blocked device is detected, the user sees a popup with device details and an authorization option. The request is verified against your admin credentials through a secure online API — no local bypass possible.

  • On-screen device detail popup
  • Credential-verified via cloud API
  • Zero local bypass path

Licensing & Identity

Hardware-bound licenses that can't be shared, cloned, or spoofed

Hardware-Bound Licensing

Each license is tied to a hardware fingerprint derived from CPU, motherboard, disk, and network adapter — preventing unauthorized sharing across machines. Supports trial, monthly, yearly, and lifetime plans.

  • CPU + motherboard + disk + NIC hash
  • Transfer to new hardware via portal
  • Trial, monthly, yearly & lifetime
Tamper Watchdog

A background watchdog process monitors the main agent and relaunches it if killed. Registry keys and service entries are protected against manual removal — even by local admins.

  • Auto-restart on kill
  • Registry key protection
  • Resistant to local-admin tampering
RSA-Signed License Tokens

License validation responses are signed with a 2048-bit RSA private key held only on the server. The agent verifies the signature before honoring any license grant — no offline spoofing.

  • 2048-bit RSA signatures
  • Agent-side signature verification
  • No offline license files
Secure Auto-Updates

The built-in updater downloads packages over HTTPS and verifies each file against a SHA-256 manifest before installation. Updates can be deferred by admins from the dashboard.

  • HTTPS-only delivery
  • SHA-256 manifest verification
  • Admin-controlled rollout

Visibility & Compliance

Logs and dashboards built for auditors, not just administrators

Full Activity Audit Log

Every USB connection, disconnection, block, and authorization is recorded with timestamps, device metadata, and the acting user. Exportable for HIPAA, ISO 27001, and internal compliance reviews.

  • Connect / disconnect / block events
  • Device metadata & username recorded
  • CSV export for auditors
Cloud Management Dashboard

Web-based dashboards for both admins and customers. Manage licenses, view per-machine activation status, inspect USB event history, and push policy changes — all from a single portal.

  • Per-machine activation view
  • USB event history per endpoint
  • Policy changes pushed instantly
Unauthorized Attempt Alerts

The dashboard flags machines with repeated unauthorized device insertions. Spike detection highlights endpoints that may be under active exfiltration attempts so you can respond before data leaves.

  • Repeated-attempt spike detection
  • Per-machine risk flagging
  • Dashboard alert badges
Compliance Reporting

Generate time-range reports filtered by machine, user, or event type. Reports include blocked device counts, authorized device lists, and admin credential usage — ready to attach to a security audit.

  • Time-range & per-machine filters
  • Blocked vs. authorized breakdown
  • Audit-ready report format

Deployment & Operations

Designed to drop into existing Windows environments without disruption

Silent Background Operation

The agent runs as a Windows service with no persistent tray icon and no UI visible to end users unless a device triggers an authorization prompt. Zero distraction, constant enforcement.

Named-Pipe IPC Architecture

The Windows service and user-facing notification process communicate over a secure named pipe. No open network ports on the endpoint — lateral movement from the agent is not possible.

Peripheral Compatibility Tested

Extensively tested against common enterprise peripherals — Dell, Logitech, HP, and Zebra devices. HID, printer class, and audio class devices are never blocked regardless of policy.

Per-Machine Policy Overrides

Certain machines — like IT workstations — can be exempted from blocking policy via the admin dashboard without uninstalling the agent. Overrides are logged and auditable.

GET STARTED TODAY

Ready to Put These Features to Work?

Download the free trial and have USB ports locked down in under five minutes.